## cr18366-perufsap

## Source details

**Canonical URL:** [cr18366-perufsap](https://www.imf.org/-/media/files/publications/cr/2018/cr18366-perufsap.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2018/cr18366-perufsap.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2018/cr18366-perufsap.pdf.json)

---

### Summary
- Overall quality of Peru’s supervisory approach and regulation of the banking sector is strong; key area needing strengthening relates to powers and regulatory framework for consolidated and cross-border supervision.
- FSAP undertook a full graded Basel Core Principles (BCP) assessment of the essential criteria; current assessment reflects framework "as of the date of the completion of the assessment (November 1, 2017)."
- SBS maintained and enhanced regulatory and supervisory framework since 2011; followed up on most 2011 recommendations (expanded resources and specialized units, strengthened consolidated supervision, continuous monitoring of beneficial ownership, implemented Pillar 2, improved governance and internal controls).
- Outstanding legal recommendation: improve legal protection of SBS staff (requires amendment to the General Financial System Law (LGSF)).
- Basel reform progress:
  - implemented capital conservation buffer, counter-cyclical buffer, D-SIB buffer and framework;
  - retained Basel II capital definition embedded in the LGSF (substantive difference);
  - implemented Liquidity Coverage Ratio (LCR);
  - in process of implementing Net Stable Funding Ratio (NSFR) tailored to local characteristics;
  - incorporated Basel corporate governance guidelines.
- Remaining supervisory enhancements: SBS internal governance, control and accountability (strengthen internal audit department, set up an Audit Committee), and deeper engagement with Boards of supervised institutions.

### Assessment scope and methodology
- Prepared by Dirk Jan Grolleman, IMF and Valeria Salomao Garcia, World Bank; jointly undertaken by IMF and World Bank.
- Full graded BCP assessment reflecting 2012 revisions; Peruvian authorities chose Essential Criteria only.
- Compliance grades used: compliant; largely compliant; materially noncompliant; noncompliant; non-applicable.

### Responsibilities, powers, independence (CPs 1–2) — key findings and recommendation
- Findings:
  - SBS responsibilities, objectives and powers clearly defined but impaired by legal limitations on consolidated supervision and limited direct access to parents and affiliates outside supervisory perimeter.
  - Legal protection currently extends only to the Superintendent and Deputy Superintendents and covers only the first five years after they have left office.
  - Resource allocation considers risk profile and systemic importance; "about 55 percent of its resources are spent on bank supervision"; "about 130 staff are involved on a day-to-day basis in prudential supervision of the twenty (sixteen commercial and four state-owned) licensed banks."
- Assessment:
  - Principle 1: Materially Non-Compliant.
  - Principle 2: Largely Compliant.
- Recommendations:
  - Amend legal framework to grant SBS powers for full consolidated supervision.
  - Amend legal framework to further protect all SBS staff for acts or omissions in good faith including current and former staff, irrespective of the number of years after leaving SBS.
  - Amend Superintendence tenure so it does not coincide with the constitutional term of the government.
  - Enhance Internal Audit Function, including establishment of an Internal Audit Committee; operationalize Financial Stability Committee.

### Cooperation, consolidated supervision and home-host (CPs 3, 12, 13)
- Findings:
  - Cooperation and MoUs with domestic and foreign authorities in place; SBS participates in supervisory colleges (e.g., Banco Santander, BBVA, Scotiabank) and organized supervisory college for Credicorp in June 2017.
  - Consolidated supervision is a priority but impaired by legal gaps; SBS acts de facto as home supervisor for two systemic conglomerates but lacks enforceable powers over holding companies.
  - Cross-border operations concentrated: two systemic conglomerates hold on a gross basis 23 and 21.8 percent and on a net basis 6.3 and 13 percent respectively of total assets abroad; cross-border operations represent almost on a net basis 11 and on a gross basis 22 percent of total assets for these conglomerates.
- Assessment:
  - Principle 3: Compliant.
  - Principle 12: Largely Compliant.
  - Principle 13: Compliant.
- Recommendation:
  - Establish Crisis Management Groups for the two systemic conglomerates.
  - Enhance consolidated supervision approach to governance, risk management, capital and liquidity at group level.

### Permissible activities, licensing, ownership transparency (CPs 4–7)
- Findings:
  - Market entry and licensing are highly controlled; SBS reviews and may impose prudential conditions.
  - Prior authorization required for transfers of significant ownership or controlling interest above 10 percent.
  - Significant owner concept is quantitative (10 percent) and does not capture significant influence below 10 percent; SBS can require information on shareholders owning over 4 percent up to ultimate beneficiary.
  - Minimum capital stock for commercial banks for July - September 2017: S/26,609,326.
- Recommendations:
  - Incorporate "significant influence" as a qualitative indicator to capture influence with holdings below 10 percent.
  - Consider lowering maximum percentage allowed to be held in a non-financial company to prevent controlling interest/influence.

### Ongoing supervision, off-site and on-site integration (CPs 8–10)
- Findings:
  - Robust supervisory approach moving toward risk-based framework; rating methodology is forward-looking with seven building blocks: Solvency; Credit risk; Liquidity risk; Market risk; Operational risk; Profitability and efficiency; Management and control.
  - On-site and off-site integration beneficial; off-site surveillance lacks a platform comparable to on-site activities.
  - Supervisory staff allocation: SABM has 173 staff (half dedicated to banks); SAR has 86 staff (roughly 60 percent time allocated to Banks).
- Recommendations:
  - Streamline off-site surveillance reports through coordination between SAR and SABM; speed up establishment of an off-site surveillance IT platform.
  - Establish a process for assessing resolvability of systemic banks.

### Corrective and sanctioning powers (CP 11)
- Legal powers and practice:
  - Broad corrective powers under Articles 349, 355, 356 and 361 of the LGSF; sanctions include admonition; fines; suspension; removal; destitution; ineligibility; prohibition of dividends; intervention; suspension or cancellation of authorization; dissolution and liquidation. One UIT is currently 4,000 soles.
  - Early intervention thresholds include: available regulatory capital lower than 10 percent for 3 consecutive months or 5 alternate months; 40 percent decrease of regulatory capital (surveillance regime); 50 percent decrease triggers intervention.
  - SBS heavily relies on moral suasion and experienced senior staff; lacks written procedures operationalizing legal powers into a systematic range of supervisory tools.
- Assessment: Largely Compliant.
- Recommendation:
  - Operationalize legal powers into regulation or procedures comprising a range of supervisory tools by severity.

### Corporate governance and risk management (CPs 14–15)
- Findings:
  - Corporate Governance & Risk Management Regulation issued 2017 (Resolution SBS No. 272-2017) incorporating Basel principles; to replace GIR per April 1, 2018.
  - Governance and risk management requirements apply to licensed institutions but not at holding/group level; group Board members are not subject to formal fit and propriety review.
  - Engagement with Boards is limited (mainly an annual meeting with one independent Board member).
  - GIR/Corporate Governance & GIR and specific risk regulations exist for credit, FX-induced credit risk, over-indebted retail clients, country risk, market, liquidity (LCR), operational risk, AML/CFT, consolidated supervision.
- Assessment:
  - Principle 14: Largely Compliant.
  - Principle 15: Largely Compliant.
- Recommendations:
  - Apply group-level governance and fit-and-proper requirements where SBS is home supervisor.
  - Intensify Board engagement; enhance Board committee composition (independent members and chair).
  - Develop model governance guidelines and require recovery/resolution planning for D-SIBs.

### Capital adequacy and ICAAP (CP 16)
- Findings:
  - Minimum capital requirement is 10 percent (Basel II capital definition embedded in LGSF).
  - Additional capital buffers (Additional Capital Requirements Regulation Resolution SBS No. 8425-2011) implemented via tailored approaches (CCB composed of single name, sectoral, geographical, IRRBB and propensity to risk elements).
  - Countercyclical buffer activation rule: activated if moving average of annual GDP growth over 30 months is higher than 5 percent (may be ineffective when excessive credit growth occurs while GDP growth < 5 percent).
  - D-SIB methodology: banks with assets > 3 percent of GDP attract additional buffer; top 4 commercial banks attract 0.6 percentage points for the 4 dominant commercial banks.
  - Capital Requirements comparison (Jun-2017) table preserved in source:
    - Peru - All Banks (Min / Max): Min. Req. 10.0% / 10.0%; CCB 0.8% / 4.3%; CCyB* 0.7% / 5.0%; D/G-SIB 0.0% / 0.6%; Total** 11.8% / 16.6%
    - Peru - D-SIBs (Min / Max): Min. Req. 10.0% / 10.0%; CCB 1.0% / 1.1%; CCyB* 1.7% / 2.0%; D/G-SIB 0.1% / 0.6%; Total** 13.0% / 13.3%
    - Basel III (Min / Max): Min. Req. 8.0% / 8.0%; CCB 2.5% / 2.5%; CCyB* 0.0% / 2.5%; D/G-SIB 0.0% / 2.5%; Total** 10.5% / 15.5%
    - * Considers the numbers of CCyB if cyclical rule was activated.
    - ** Corresponds to the total required capital considering the cyclical rule was activated.
  - ICAAP required annually since 2010; ICAAP supervisory review largely off-site and not yet integrated into rating methodology (planned integration in revised methodology in 2019).
- Assessment: Largely Compliant.
- Recommendations:
  - Incorporate ICAAP supervisory review into rating methodology.
  - Finalize review and recalibration of additional capital requirements (CCyB trigger, single name concentration, D-SIB calibration).
  - Enhance consolidated capital adequacy assessment: consider capital adequacy of holding on solo level, capital location and ringfencing/non-transferability, and extent to which excess group capital can support financial activities; account for accounting differences (SBS solo vs IFRS consolidated).

### Prudential regulations and requirements (CP17–CP25) — selected findings
- Credit risk (Principle 17): Compliant.
  - Classification and provisioning framework detailed (Resolution SBS No. 11356-2008); provisioning rates for Watch, Substandard, Doubtful, Loss preserved exactly in source (e.g., Loss: 100.00% / 60.00% / 30.00% depending on collateral).
  - Recommendation: review CCFs for provisioning (undisbursed/unused lines currently assigned 0% CCF for provisioning purposes).
- Problem assets and provisioning (Principle 18): Compliant.
- Market risk (Principle 22): Largely Compliant.
  - Market risk regulation outdated (1998); revised regulation issued for consultation and later issued (Resolution SBS No. 4906-2017 on December 20, 2017); trading activities limited; average market risk capital requirement < 1 percentage point of regulatory capital as of mid-2017.
  - Recommendation: issue revised Market Risk Management Regulation and evaluate recalibration to align with Basel III.
- Interest rate risk in banking book (Principle 23): Compliant.
  - EaR limit: EaR must not exceed 5 percent of regulatory capital.
  - EVE outlier criterion: interest rate shock exceeds 15 percent of regulatory capital triggers additional buffer.
  - Recommendation: consider implementation of Basel III standards for IRRBB.
- Liquidity risk (Principle 24): Largely Compliant.
  - LCR implemented (tailored); daily LCR reporting (Annex 15-B daily); other liquidity limits: Liquidity Ratio in Local Currency LC ≥ 8 percent (10 percent if concentration > 25 percent), Liquidity Ratio in Foreign Currency FC ≥ 20 percent (25 percent if concentration > 25 percent), Liquidity Securities Ratio ≥ 5 percent.
  - SBS monitoring and NSFR implementation in progress; group-level liquidity requirements limited.
  - Recommendation: intensify liquidity supervision of financial groups; continue NSFR implementation.
- Operational risk (Principle 25): Compliant.
  - Operational risk regulations (Resolution SBS No. 2116-2009) and capital requirements (Resolution SBS No. 2115-2009); business continuity exercises executed (2014 and 2017).
- Internal control/internal audit (Principle 26): Compliant.
  - Internal Audit Regulation (Resolution SBS No. 11699-2008); SIRAI reporting; quality assurance and external evaluation at least every 5 years.
- Financial reporting and external audit (Principle 27): Largely Compliant.
  - Accounting Manual aligned with IFRS with specific deviations (provisioning rules, fixed asset revaluation, fee treatment); external audits required to follow IAASB standards; rotation of audit partners after five consecutive annual financial years.
  - Recommendation: assess impact of IFRS9 on provisioning; strengthen engagement with external auditors; consider structured trilateral meetings.
- Disclosure and transparency (Principle 28): Compliant.
  - Quarterly and annual disclosure requirements; SMV disclosure regime applies to listed banks; SBS publishes extensive quantitative information on website.
  - Recommendation: consider Enhanced Disclosure Task Force recommendations and Pillar 3 implementation.
- Abuse of financial services (AML/CFT) (Principle 29): Largely Compliant.
  - Robust AML/CFT framework: AML/CFT Risk Management Regulation (Resolution 2660-2015); FIU responsibilities; CDD regime (general, simplified, enhanced) and retention rules (records at least ten years).
  - Limitation: sanctioning for banks confined to fines up to USD 250,000 (maximum for very serious infractions), assessed as "not enough to curb behavior." One UIT is equivalent to 4,050 soles in AML context; elsewhere one UIT is currently 4,000 soles.
  - Gaps: no explicit requirement for banks to report suspicious activities to banking supervision when material to safety/soundness; CDD framework overly prescriptive and lacks customer acceptance policy; correspondent banking due diligence gaps.
  - Recommendations include ability to impose sizable fines, explicitly require banks to report suspicious activities to SBS when material, require banks to develop internal CDD policies and require adequate due diligence on respondent banks.

### Institutional and market structure — key statistics and structure
- Total financial system assets:
  - 2011: 351,340 Millions of Soles; 75.6% of GDP.
  - 2017: 669,476 Millions of Soles; 98.6% of GDP.
- Banks — total assets:
  - 2011: 224,639 Millions of Soles; 48.3% of GDP; 63.9% of total system assets; 19 institutions.
  - 2017: 425,375 Millions of Soles; 62.6% of GDP; 63.5% of total system assets; 21 institutions.
- Commercial banks:
  - 2011: 193,056 Millions of Soles; 41.5% of GDP; 54.9% of total system assets; 15 institutions.
  - 2017: 371,303 Millions of Soles; 54.7% of GDP; 55.5% of total system assets; 16 institutions.
- Four largest commercial banks:
  - 2011: 160,820 Millions of Soles; 34.6% of GDP; 45.8% of total system assets; 4 institutions.
  - 2017: 309,539 Millions of Soles; 45.6% of GDP; 46.2% of total system assets; 4 institutions.
- Foreign-owned commercial banks:
  - 2011: 92,212 Millions of Soles; 19.8% of GDP; 26.2% of total system assets; 11 institutions.
  - 2017: 181,998 Millions of Soles; 26.8% of GDP; 27.2% of total system assets; 12 institutions.
- Pension funds:
  - 2011: 81,881 Millions of Soles; 17.6% of GDP; 23.3% of total system assets; 4 institutions.
  - 2017: 156,247 Millions of Soles; 23.0% of GDP; 23.3% of total system assets; 4 institutions.
- Insurers:
  - 2011: 19,786 Millions of Soles; 4.3% of GDP; 5.6% of total system assets; 14 institutions.
  - 2017: 45,146 Millions of Soles; 6.6% of GDP; 6.7% of total system assets; 21 institutions.
- Non-bank MFIs:
  - 2011: 16,345 Millions of Soles; 3.5% of GDP; 4.7% of total system assets; 35 institutions.
  - 2017: 28,218 Millions of Soles; 4.2% of GDP; 4.2% of total system assets; 28 institutions.
- System concentration and performance:
  - Total financial system assets are "95 percent of GDP."
  - Banking sector concentrated: "the four largest banks accounting for more than 83 percent of commercial banks assets."
  - Foreign presence: eleven of the sixteen banks are foreign-owned and they account for "about 48 percent of commercial bank assets."
  - System ROE "at around 19 percent in 2016."
- Microfinance: MFIs represent "about 6 percent of the total financial sector assets."

### Financial dollarization and macroprudential framework
- Dollarization:
  - Peak around 80 percent in early 2000s; credit and deposit dollarization around 29 and 40 percent, respectively.
  - Exchange rate depreciation May 2013–February 2016 led to partial re-dollarization of deposits.
  - Policy measures to disincentivize foreign currency lending contributed to dedollarization (dedollarization repos, FX credit reduction targets, additional capital surcharges on dollar lending).
- Macroprudential arrangements:
  - No designated macroprudential authority; SBS holds bulk of macroprudential tools (capital surcharges, conservation buffers, countercyclical requirements, dynamic provisioning, liquidity requirements).
  - Systemic risk analysis fragmented among BCRP, SBS and SMV; BCRP publishes Financial Stability Report semiannually; both BCRP and SBS prepare reports.

### Crisis management, recovery and deposit insurance
- Resolution framework:
  - Resolution legal framework is administrative with potential judicial review; LGSF grants SBS power to impose surveillance regime (45 days renewable) and intervention leading to recovery or liquidation.
  - SBS is the resolution authority; FSD provides financial support but is not involved in tool selection.
  - BCRP can provide Emergency Liquidity Assistance (ELA).
- Deposit insurance (FSD):
  - FSD is a "paybox plus" arrangement; Articles 144–157 of LGSF govern FSD; SBS supplies personnel and premises.
  - Membership compulsory for deposit-taking institutions: currently 44 institutions (16 banks, 10 financial companies, 12 municipal savings and loan institutions, 6 rural savings and loan institutions).
  - Deposit insurance premium determined on external rating; LGSF requires at least two external ratings.

### Reporting and supervisory data architecture (selected)
- Prudential reporting cadence includes daily, monthly, quarterly and annual returns; notable items:
  - Annex 15-A: Treasurer's Report and Daily Liquidity Position (daily).
  - Annex 15-B: Liquidity Coverage Ratio (daily).
  - Annex 16-B: Stress Test and Contingency Plan (quarterly).
  - Annex 6: Credit Debtors Report (monthly) — includes all loans above PEN 1.00.
  - Annex 10 "Deposits, Loans and Personnel by Offices" (monthly) provides portfolio balances by currency and district.
  - Report 2 A: Risk-weighted assets for Credit Risk (monthly).
  - Report 19-I and 19-II: Information on the economic group (semi-annual).
  - ICAAP required annually since 2010.

### Selected supervisory assessments and ratings summary (selected CPs and grades)
- Principle 1: Materially Non-Compliant.
- Principle 2: Largely Compliant.
- Principle 3: Compliant.
- Principle 8: Largely Compliant.
- Principle 11: Largely Compliant.
- Principle 12: Largely Compliant.
- Principle 13: Compliant.
- Principle 14: Largely Compliant.
- Principle 15: Largely Compliant.
- Principle 16: Largely Compliant.
- Principle 17: Compliant.
- Principle 18: Compliant.
- Principle 22: Largely Compliant.
- Principle 23: Compliant.
- Principle 24: Largely Compliant.
- Principle 25: Compliant.
- Principle 26: Compliant.
- Principle 27: Largely Compliant.
- Principle 28: Compliant.
- Principle 29: Largely Compliant.

### Key policy recommendations (condensed)
- Legal/regulatory reforms:
  - Grant SBS full consolidated supervision powers and broaden legal protection for SBS staff (good faith protection, apply to all staff and beyond five years).
  - Amend tenure arrangement for the Superintendent.
  - Enable higher sanctions for AML/CFT breaches (fines beyond current USD 250,000 cap) and consider other enforcement tools (suspend dividends, restrict asset growth).
- Supervisory framework and tools:
  - Operationalize corrective powers into documented procedures; integrate ICAAP into SREP/rating methodology (planned roll-out 2019).
  - Recalibrate additional capital requirements (CCyB trigger, single name concentration, D-SIB buffers); consider moving capital definition toward Basel III.
  - Intensify group-level supervision (governance, liquidity, capital location, resolution planning) for conglomerates where SBS is home supervisor.
  - Implement NSFR (tailored), finalize market risk regulation update, consider Basel III IRRBB standards, and review CCFs for provisioning of undisbursed/unused lines.
- Governance and resources:
  - Strengthen SBS internal governance (internal audit, Audit Committee), operationalize Financial Stability Committee, enhance Board engagement with supervised entities, and improve off-site IT platform and coordination between SAR and SABM.
- AML/CFT and disclosures:
  - Require banks to report suspicious activities to SBS when material to safety/soundness; require banks to develop internal CDD policies including a customer acceptance policy; strengthen correspondent banking due diligence requirements; consider Enhanced Disclosure Task Force and Pillar 3 implementation.

*Source: cr18366-perufsap — assessment reflects the regulatory and supervisory framework as of November 1, 2017.*

### INTRODUCTION AND METHODOLOGY ______________________________________________________ 10

### INTRODUCTION AND METHODOLOGY

### Summary
- The overall quality of Peru’s supervisory approach and regulation of the banking sector is strong; key area needing strengthening relates to powers and regulatory framework for consolidated and cross-border supervision.
- The FSAP undertook a full graded Basel Core Principles (BCP) assessment of the essential criteria.
- The 2011 BCP update assessment found high quality bank regulation and supervision with no principles scored non-compliant or materially non-compliant. The current assessment shows SBS has maintained and further enhanced its regulatory and supervisory framework.
- SBS followed up on most 2011 recommendations: expanded resources and specialized units (e.g., information technology supervision); strengthened consolidated supervision; established continuous monitoring of beneficial ownership; implemented Pillar 2; improved supervision of governance, management and internal controls.
- Outstanding recommendation: improvement of legal protection of SBS staff requires amendment to the General Financial System Law (LGSF).
- Progress on Basel regulatory reform: implemented capital conservation buffer, counter-cyclical buffer, buffer and framework for domestic-systemically important banks (D-SIBs) with a tailored approach; retained Basel II capital definition embedded in the LGSF (substantive difference); implemented Liquidity Coverage Ratio (LCR); in process of implementing Net Stable Funding Ratio (NSFR) tailored to local characteristics; incorporated Basel corporate governance guidelines.
- Remaining enhancements needed: SBS internal governance, control and accountability (e.g., strengthen internal audit department, set up an Audit Committee), and engagement with Boards of supervised institutions.

### Assessment scope and methodology
- Detailed Assessment Report prepared by Dirk Jan Grolleman, IMF and Valeria Salomao Garcia, World Bank.
- The assessment is jointly undertaken by the IMF and the World Bank.
- The 2011 FSAP was a full graded assessment but assessed only 19 of then 25 principles in depth; current assessment is a full graded BCP assessment reflecting the 2012 revisions.

### Responsibilities, Objectives, Powers, Independence, and Accountabilities (CPs 1–2)
- SBS responsibilities, objectives and powers are clearly defined but impaired by legal limitations on consolidated supervision.
- SBS can authorize banks, conduct ongoing supervision, ensure compliance and take corrective actions.
- Shortcoming: limited supervisory powers for direct access to parents and affiliates, including non-financial subsidiaries and affiliates outside direct supervisory perimeter.
- SBS mitigates absence of direct powers by acting through licensed subsidiaries in Peru and imposing limitations on licensed institutions when group-level weaknesses are observed; however these measures are not as comprehensive, notably regarding corporate governance and risk management.
- Legal protection currently extends only to the Superintendent and Deputy Superintendents and covers only the first five years after they have left office.
- Governance and accountability could be improved by enhancing transparency of supervisory actions beyond annual reports and assessing effectiveness of supervisory activities.
- Resource allocation considers risk profile and systemic importance, but the proportion of staff allocated to banks vs microfinance institutions may need reevaluation.

### Cooperation, Consolidated Supervision and Home-Host Relationships (CPs 3, 12, and 13)
- Cooperation and collaboration arrangements with local and foreign authorities are in place and reflect confidentiality needs.
- SBS actively engages in cross-border cooperation, including information exchanges and cooperation on examinations, even beyond formal supervisory powers.
- Consolidated supervision is a priority but impaired by legal gaps; SBS has gathered information on conglomerates, monitored activities, enforced prudential requirements through supervised entities and used moral suasion, acting to some extent as de facto home supervisor.
- Concerns: lack of legal enforceability of supervisory requirements directly to holding companies; non-negligible cross-border operations; holding companies may have investments in non-financial entities not under formal SBS scrutiny (investments are deducted from regulatory capital at the financial group level).
- Supervisory approach to group-level governance, risk management, capital adequacy and liquidity risk management needs enhancement.

### Permissible Activities, Licensing, Transfer of Ownership and Major Acquisitions (CPs 4–7)
- Market entry is highly controlled; SBS performs thorough reviews for authorizations.
- SBS can review, reject and impose prudential conditions on transfers of significant ownership or controlling interest above 10 percent held directly or indirectly in existing banks.
- Legal and regulatory framework does not use the concept of significant influence as a qualitative indicator for significant ownership, which would capture influence with stakes below 10 percent.
- SBS can approve or reject major acquisitions or investments by a bank, including establishment of cross-border operations.
- Investment limit for banks in publicly traded companies: no more than 50 percent of the invested company, up to 10 percent of regulatory capital—this may allow banks to acquire high stakes and controlling interest/influence in non-financial companies.

### Ongoing Supervision (CPs 8–10)
- SBS has a robust supervisory approach moving toward a more risk-based framework.
- Supervisory rating methodology is forward-looking, assesses and addresses bank and system risk; conglomerate elements are considered for overriding purposes but are not embedded into the rating.
- SBS has deep knowledge of major banks’ operations and risk profiles and effectively uses a broad range of information sources.
- Interactions with senior management and Boards have been enhanced but could be further improved; resolvability of banks remains unaddressed.
- Supervisory structure: split between Specialized Risk Deputy Superintendence (SAR) and one (SABM) in charge of individual banks works well.
- On-site and off-site integration beneficial; some overlap in reports between Superintendences. Off-site surveillance lacks a platform comparable to on-site activities for analysis and follow-up monitoring.

### Corrective and Sanctioning Powers (CP 11)
- Early action and moral suasion are important to SBS effectiveness.
- Legal framework grants broad powers; moral suasion culture enables early intervention on unsafe or unsound practices.
- Experienced senior staff ensure consistent application of corrective actions.
- Recommendation: develop written procedures operationalizing broad legal powers into a systematic range of supervisory tools depending on severity.

### Corporate Governance and Risk Management (CPs 14–15)
- In 2017 SBS issued a new Corporate Governance and Risk Management Regulation incorporating main elements of the Basel Corporate Governance Principles for Banks.
- SBS emphasizes risk management and corporate governance of licensed institutions, setting clear expectations for Board roles and committee structures.
- Engagement with Boards and individual Board members remains limited (mainly an annual meeting with one independent Board member); could be intensified.
- Governance and risk management regulation applies explicitly to banks and banking groups but does not apply on a group-level for institutions where SBS is home supervisor.
  - Consequences: group Board members are not subject to formal fit and propriety review by SBS; group Board members are not required to sign-off on responsibilities as required for Board members of supervised institutions; supervisory approach to group-level governance is less developed.
- Consolidated Supervision Regulation requires licensed institutions to ensure the group has adequate risk management frameworks; this indirect regulation currently works because main activities remain in Peru but may lose effectiveness as cross-border activities increase.

### Capital Adequacy (CP 16)
- SBS has made significant progress implementing the Basel III reform agenda; implemented approaches aim to achieve same objectives and broadly equivalent overall capital levels despite differences.
- Notable differences:
  - Use of the Basel II capital definition embedded in the LGSF remains a substantive difference.
  - Countercyclical buffer activation rule: activated if GDP growth is above 5 percent—may be ineffective when excessive credit growth occurs while GDP growth is below 5 percent.
  - Systemic risk and single name risk buffers need review as currently not commensurate with risks they should cover.
- These issues are part of the review of the Additional Capital Requirements Regulation currently taking place.
- Supervisory group capital adequacy assessment needs enhancement by incorporating:
  - Capital adequacy of the holding company on a solo level to determine availability of excess capital at holding level.
  - Location of capital within the conglomerate, including risk of ringfencing/non-transferability of capital allocated to entities supervised by authorities abroad.
  - Extent to which excess capital at group level can be allocated to support the conglomerate’s financial activities.
  - Adjustments to account for change in accounting standards: solo financials based on SBS accounting standards while consolidated financials may be based on IFRS, which could impact provisioning levels and available consolidated capital.

### Prudential Regulations and Requirements (CP17–CP25)
- The report proceeds to assess Prudential Regulations and Requirements in detail (CP17–CP25) in subsequent sections.

*Source: cr18366-perufsap - INTRODUCTION AND METHODOLOGY*

### 20.      The regulatory and supervisory approach and practices regarding the other prudential

### 20.      The regulatory and supervisory approach and practices regarding the other prudential

### Market risk, liquidity, and liquidity contingency planning
- Market risk regulation was identified as outdated in the 2011 BCP assessment.
- The SBS has recently issued a revised regulation for consultation; when issued it "should bring this regulation again in line with international standards."
- Footnote: After the completion of the assessment (November 1, 2017) the SBS issued the revised market risk regulation (Resolution SBS No. 4906-2017) on December 20, 2017.
- In practice the outdated market risk regulation "has not constrained the SBS in conducting effective supervision."
- Liquidity frameworks in place:
  - The SBS has implemented the LCR (tailored to the local circumstances).
  - The SBS is in the process of implementing the NSFR.
  - A revised liquidity risk management regulation was issued in 2012.
  - Since 2012 the SBS requires groups for which it is the home supervisor to have liquidity contingency plans on a group level.
  - Development of liquidity contingency plans remains "still in their initial phase."

### Internal control, internal and external audit, financial reporting and disclosures (CP26–28)
- The regulatory and supervisory frameworks for internal control, audit and financial reporting and disclosures are assessed as adequate.
- Areas for further improvement identified:
  - The SBS could further improve qualitative disclosures by implementing the recommendations of the Enhanced Disclosure Task Force of the Financial Stability Board and/or the implementation of Pillar 3.
  - The SBS could improve its engagement with external auditors.
  - The SBS could assess more in depth whether current provisioning requirements are adequate when compared with the new IFRS9 standard.
  - Consideration is needed of "possible issues as a result of the widening gap in accounting standards between supervised institutions (SBS standards) and consolidated financial groups (might be based on IFRS standards)."
- Overall conclusion: "The frameworks covering these principles are considered adequate taking into account the current state of development and complexity of the financial markets and banking system."

### Abuse of Financial Services (CP29) — AML/CFT
- The SBS has a robust AML/CFT framework.
- The regulatory and supervisory framework has been strengthened in recent years with:
  - The issuance of the AML/CFT risk management regulation.
  - Continuous enhancements in supervisory procedures.
- Important limitation: sanctioning for banks is confined to fines "up to USD 250,000," which is assessed as "not enough to curb behavior."

### Assessment context, scope, and methodology
- This assessment of the implementation of the Basel Core Principles for Effective Banking Supervision in Peru was completed as part of the FSAP mission undertaken in October of 2017 at the request of the Peruvian authorities.
- The assessment reflects the regulatory and supervisory framework in place "as of the date of the completion of the assessment (November 1, 2017)."
- The assessment focused on the Superintendence of Banks, Insurers and Private Pension Funds (SBS) in its role as supervisor of the banking system.
- Peru was assessed against the Revised Core Principles Methodology issued by the BCBS in September 2012.
- The Peruvian authorities chose to be assessed and rated on the Essential Criteria (EC); Additional Criteria were not considered in the final rating.
- Compliance grading uses: compliant; largely compliant; materially noncompliant; noncompliant; non-applicable.
  - "Compliant" — all ECs met without significant deficiencies.
  - "Largely compliant" — only minor shortcomings; clear intent to achieve full compliance within a prescribed period.
  - "Materially noncompliant" — severe shortcomings despite formal rules; evidence supervision has not been effective.
  - "Noncompliant" — not substantially implemented; several ECs and ACs not complied with; supervision manifestly ineffective.
  - "Non-applicable" — criteria do not relate to the country’s circumstances.

### Institutional and market structure — supervisory organization and resources
- Legal basis:
  - Peru’s General Financial System Law (Ley General del Sistema Financiero, or LGSF) assigns responsibility for approval and supervision of banks and other nonbank financial intermediaries to the SBS.
  - The LGSF and SBS resolutions provide a comprehensive legal and normative framework for banking supervision.
- SBS organization and supervisory resources:
  - The SBS is a large organization with seven deputy superintendents.
  - Day-to-day supervision carried out by Superintendeces for Private Pension Funds Administrators, Banking Sector (incl. microfinance companies) (SABM), and Insurance.
  - SABM has two General Intendances: Banking Supervision (BSD) and supervision of microfinance institutions.
  - The Superintendence for Financial Risks (SAR) supports supervision; "about 55 percent of its resources are spent on bank supervision."
  - Combined BSD and SAR staff imply "about 130 staff are involved on a day-to-day basis in prudential supervision of the twenty (sixteen commercial and four state-owned) licensed banks."
  - Standing committees include the Internal Classification of Financial Institutions (Rating Committee) and Consolidated Supervision; there is also a Supervision Policies Committee and an internal Financial Stability Committee.
  - SAEE provides input on stress-testing, conducts biannually a top-down stress test for the banking system and prepares a quarterly (internal) financial stability report.

### Market structure — key features and concentration
- System size and composition:
  - Total financial system assets are "95 percent of GDP."
  - Banking sector is concentrated: "the four largest banks accounting for more than 83 percent of commercial banks assets."
  - Two large Peruvian conglomerates with foreign holding companies exist for which the SBS is operating de facto as the home supervisor.
  - Foreign presence: eleven of the sixteen banks are foreign-owned and they account for "about 48 percent of commercial bank assets."
  - Banks generated high levels of profits with system return on equity (ROE) "at around 19 percent in 2016."
- Microfinance institutions and cooperatives:
  - A wide range of MFIs operate, including finance companies, savings and loans (cajas municipales and cajas rurales de ahorro y crédito), entidades de desarrollo de la pequeña y microempresa, and COOPACs.
  - MFIs represent "about 6 percent of the total financial sector assets."
  - SBS has allocated significant supervisory resources to MFIs given risk management and corporate governance practices.
  - A contemplated three-tier regulatory framework for COOPACs: top 8-10 COOPACs supervised by SBS; Tier 2 by FENACREP; Tier 3 registered with basic monitoring.

### Selected system-level figures (from table)
- Total financial system assets:
  - 2011: 351,340 Millions of Soles; 75.6% of GDP.
  - 2017: 669,476 Millions of Soles; 98.6% of GDP.
- Banks — total assets:
  - 2011: 224,639 Millions of Soles; 48.3% of GDP; 63.9% of total system assets; 19 institutions.
  - 2017: 425,375 Millions of Soles; 62.6% of GDP; 63.5% of total system assets; 21 institutions.
- Commercial banks:
  - 2011: 193,056 Millions of Soles; 41.5% of GDP; 54.9% of total system assets; 15 institutions.
  - 2017: 371,303 Millions of Soles; 54.7% of GDP; 55.5% of total system assets; 16 institutions.
- Four largest commercial banks:
  - 2011: 160,820 Millions of Soles; 34.6% of GDP; 45.8% of total system assets; 4 institutions.
  - 2017: 309,539 Millions of Soles; 45.6% of GDP; 46.2% of total system assets; 4 institutions.
- Foreign-owned commercial banks:
  - 2011: 92,212 Millions of Soles; 19.8% of GDP; 26.2% of total system assets; 11 institutions.
  - 2017: 181,998 Millions of Soles; 26.8% of GDP; 27.2% of total system assets; 12 institutions.
- Pension funds:
  - 2011: 81,881 Millions of Soles; 17.6% of GDP; 23.3% of total system assets; 4 institutions.
  - 2017: 156,247 Millions of Soles; 23.0% of GDP; 23.3% of total system assets; 4 institutions.
- Insurers:
  - 2011: 19,786 Millions of Soles; 4.3% of GDP; 5.6% of total system assets; 14 institutions.
  - 2017: 45,146 Millions of Soles; 6.6% of GDP; 6.7% of total system assets; 21 institutions.
- Non-bank MFIs:
  - 2011: 16,345 Millions of Soles; 3.5% of GDP; 4.7% of total system assets; 35 institutions.
  - 2017: 28,218 Millions of Soles; 4.2% of GDP; 4.2% of total system assets; 28 institutions.

*Source: cr18366-perufsap — assessment reflects the regulatory and supervisory framework as of November 1, 2017.*

### 39.      High financial dollarization continues to be a source of vulnerability. Although financial

### cr18366-perufsap - 39.      High financial dollarization continues to be a source of vulnerability. Although financial

### Financial dollarization: current state and drivers
- Financial dollarization has declined substantially from its peak level of around 80 percent in the early 2000s.
- Current levels of credit and deposit dollarization are around 29 and 40 percent, respectively.
- The strong exchange rate depreciation between May 2013 and February 2016 led to some reversal of the dedollarization of deposits.
- Policy measures to disincentivize lending in foreign currency contributed to a sustained decline in credit dollarization:
  - dedollarization repos
  - FX credit reduction targets
  - additional capital surcharges on dollar lending

### Framework for the Formulation of Financial Stability Policies
- Institutional arrangements and coordination:
  - No designated macroprudential authority.
  - SBS Superintendent attends quarterly BCRP Board of Directors meetings.
  - High-level staff of the MEF, BCRP, and SBS meet on a regular informal basis to discuss financial sector developments and policy issues.
- Systemic risk analysis and reporting:
  - Systemic risk analysis is fragmented among the BCRP, SBS and Superintendencia del Mercado de Valores (SMV).
  - Information gaps exist.
  - Both BCRP and SBS prepare regular Financial Stability Reports; only BCRP publishes its report semiannually.
- Macroprudential tool ownership:
  - Bulk of macroprudential tools are with the SBS, including:
    - capital surcharges for systemically important financial institutions
    - capital conservation buffers
    - countercyclical capital requirements
    - dynamic provisioning
    - liquidity requirements
    - capital surcharges for a range of risks
  - BCRP uses reserve requirements and repo operations as monetary policy and macroprudential tools.
  - Recent policy focus: reducing dollarization levels of the economy, particularly household borrowing.

### Public infrastructure: corporate, accounting, supervision, and market institutions
- Relevant corporate and consumer protection laws:
  - General Law on Societies (GLS), Law 26887.
  - General Financial System Law, Law 26702 (LGSF).
  - Consumer Defense Code, Law 29571.
- Accounting and audit:
  - SBS issues accounting rules and financial statement structure for supervised financial institutions.
  - Accounting standards are based on the International Financial Reporting Standards (IFRS).
  - SBS establishes external audit requirements; audit firms conduct reviews in accordance with the International Standards on Auditing and Related Services issued by the IAASB of IFAC, as approved by the Council of Deans of the Association of Public Accountants of Peru, and with SBS provisions.
- Market and payments oversight:
  - Stock Market Superintendence (SMV) regulates and supervises the securities market.
  - Law 29440: Central Bank regulates payment systems; SMV regulates security settlement systems.
  - National Institute for the Protection of Competition and Copyright (INDECOPI) protects consumer rights and ensures adequacy of financial services based on provided information.
- Risk Registry:
  - SBS, as established by the LGSF, manages the Risk Registry.
  - The Risk Registry is an integrated system for registering financial, credit, commercial and insurance risk, containing information on debtors of supervised institutions.
  - Primary purpose: bank supervision—permits internal analysis of credit risk evolution, rating of debtors and provisions, verification of individual credit limits, and supports credit management by supervised entities.

### Framework for Crisis Management, Recovery and Resolution
- Legal and operational framework:
  - Resolution legal framework is an administrative process with the potential for judicial review.
  - LGSF grants SBS power to place a troubled financial institution under surveillance and/or in an intervention regime, culminating in recovery or dissolution and liquidation.
  - Surveillance regime duration: limited to 45 days but renewable for another 45 days under certain circumstances.
  - In the surveillance regime SBS does not take control but permanently positions SBS personnel in the entity; in the intervention stage SBS takes control and the operations of the entity cease by law.
- Resolution authority and roles:
  - SBS is the resolution authority; it triggers the resolution process and decides the tools to be used.
  - Fondo de Seguro de Depositos (FSD) is not involved in resolution decisions or tool selection; it provides financial support for the resolution tool selected by the SBS.
  - BCRP can provide Emergency Liquidity Assistance (ELA).
- Deposit insurance (FSD):
  - Peru’s deposit insurance system, administered by the FSD, is a “paybox plus” arrangement.
  - Articles 144 through 157 of the LGSF govern the FSD and establish it as a special private legal entity, while providing that the SBS shall supply the FSD with personnel, premises, equipment, and installations.
  - Membership and premiums:
    - All deposit-taking financial institutions authorized by the SBS are compulsory members of the FSD.
    - Currently, there are 44 institutions that are members: 16 banks, 10 financial companies, 12 municipal savings and loan institutions, and 6 rural savings and loan institutions.
    - The deposit insurance premium institutions must pay is determined on their external rating (the LGSF requires these institutions to have at least two external ratings).

*Source: cr18366-perufsap (excerpt provided).*

### 51.      The SBS establishes the information disclosure standards to be applied by the

### cr18366-perufsap - 51.      The SBS establishes the information disclosure standards to be applied by the

### Information disclosure and public reporting
- The SBS establishes the information disclosure standards to be applied by supervised institutions.
- The Accounting Manual published by the SBS establishes the periodicity with which the information of supervised companies must be disclosed.
- The LGSF requires all banks to be listed in the stock exchange; as a result, all commercial banks are also subject to the disclosure requirements of the SMV.
- The qualitative and quantitative disclosures required by the SMV are available per institution on its website.
- The SBS publishes extensive quantitative information of the banks and banking system on its website.

### Legal framework, responsibilities and objectives (EC1, EC2)
- The Banking and Insurance Superintendence (Superintendencia de Banca Y Seguros - SBS) is the banking supervision authority in Peru.
- SBS responsibilities and objectives are defined through Law 26702, the General Law of the Financial and Insurance Systems and Organic Law of the Superintendence (General Law), and by the Political Constitution of Peru (Article 87).
- General Law Article 345: SBS objective is to protect the public interest in what is related to the financial and insurance system.
- General Law Article 347: SBS responsibility to defend the public interest, safeguarding economic and financial soundness of supervised institutions, ensuring compliance with legal, regulatory and statutory rules, and exercising monitoring and control of business and activities. Article 347 also empowers SBS to file criminal charges against unauthorized individuals and corporations practicing banking-related activities and to request dissolution and liquidation of those operations.
- The General Law grants the Superintendent or SBS regulatory, inspection, control and sanctioning powers (Articles 349 to 362). Financial entities are also governed by resolutions and circulars issued by SBS per Article 349.
- SBS coordinates with:
  - the Central Reserve Bank of Peru (BCRP);
  - the Superintendence of the Securities Market (SMV);
  - the National Institute for the Defense of Competition and Protection of Intellectual Property (INDECOPI).
- On AML/CFT: Article 3 of Law No. 27693, as amended by Legislative Decree No. 1106, establishes that SBS has function and power to regulate general and specific guidelines, requirements, precisions, sanctions and other aspects related to AML/CFT prevention systems.
- Consumer protection: Consumer Protection Code (Law 29571), Article 81, establishes that matters related to consumer protection for financial service providers under SBS supervision are regulated by the Consumer Protection Code and Law 28587, while Article 81 reiterates the principle of regulatory specialty through Law 26702.

### Prudential framework and supervisory standards (EC3, EC4)
- The General Law and regulations issued by SBS provide a framework of minimum prudential standards for banks and, to a certain extent, banking groups.
- General Law (Articles 184 to 220) set prudential limits relating to capital requirements, related party lending, and penalties.
- Article 349(9): Superintendent can issue necessary regulations for application of the law and financial operations.
- Article 349(19): Empowers the Superintendent to perform all acts necessary to safeguard the public interest in context of its functions.
- Legal and regulatory framework covers licensing, capital components, capital requirements, provisioning, liquidity, concentration risk, related party lending, risk management, corporate governance, AML/CFT, prudential requirements on a consolidated basis from the bank downwards.
- Consolidated supervision:
  - General Law Article 138: requires necessary financial information on the conglomerate through the supervised entity on an individual and consolidated basis; SBS can require prudential measures based on consolidated supervision.
  - Resolution SBS No. 11823-2010 - Regulation for Consolidated Supervision of Financial and Mixed Conglomerates - and amendments establish capital requirements for conglomerates and financial groups (articles 5th to 14). These requirements are indirectly applicable to the financial group; non-compliance allows supervisory measures regarding the licensed entity only. Financial groups are not subject to corporate governance and risk management regulation requirements but are expected to implement adequate risk management mechanisms.
- Mandatory capital buffers are applied to supervised entities and take into account risk profile and systemic risk.
- Since 2010 banks are required to submit an ICAAP report on an annual basis.
- Regulatory updates and public consultation:
  - Notable regulatory changes cited: subordinated debt (2016); regulatory capital requirements to credit risk (2012); introduction of the LCR (2012); additional capital buffers (2011); enhancement of Comprehensive Risk Management Regulation with corporate governance requirements (2017); significant legal amendment in 2008 incorporating the Basel II framework.
  - The 32nd Final and Supplementary Provision of the General Law: SBS will publish in advance any proposed regulations of general application relating to matters pertaining to the General Law, including information on purpose, and offer time for comments.
  - Article 14 of Supreme Decree No. 001-2009-JUS: public entities shall release draft general regulations at least thirty (30) days before scheduled entry into force, except in exceptional cases.

### Supervisory powers, access, and scope (EC5)
- The legal framework empowers SBS to have full access to banks’ and banking groups’ Boards, management, staff and records to review compliance with internal rules and external laws.
- Article 39: all General Law provisions apply to foreign banks incorporated in Peru.
- Article 349 powers include:
  - exercise integral supervision of financial entities (item 3);
  - examine under oath any person whose testimony may clarify facts during inspections and investigations (item 5);
  - perform all acts necessary to safeguard public interests (item 19).
- Article 350: Superintendent may examine books, accounts, archives, documents, correspondence and any other necessary information; entities must provide facilities; refusal or resistance can result in sanctions. Article 350 empowers requests for background on financial situation, resources, administration, management, representatives’ actions, degree of security and prudence of investments, and other matters to be clarified.
- Article 77: Superintendent entitled to attend any session of the General Meeting of Shareholders of supervised companies in person or via delegate.
- Article 356: Superintendent entitled to have one or more representatives of the companies appear when instability or faults are indicated.
- Limitations: General Law grants powers for unrestricted access to Boards and records of supervised companies, but not directly to unsupervised companies that form part of financial or mixed conglomerates, including holding companies. Article 138 empowers SBS to require necessary financial information through supervised entities for consolidated supervision.
- In practice, SBS has access to board and senior management, and board minutes from holding companies and cross-border financial entities that are part of conglomerates.

### Corrective actions, sanctions, and resolution powers (EC6)
- Article 349(19): empowers SBS to take necessary actions to protect the public interest; SBS requires banks to take corrective actions including requiring capitalization, limiting growth, and requiring board members to step down.
- Article 355 (profit distribution and entities with financial stability and management deficiencies) empowers SBS to:
  - require capital adjustments to reflect actual capital ratios;
  - request cash capital increases;
  - forbid entities, for six months (renewable for six months), from:
    - taking additional risks of any kind with any related party;
    - renewing for over 180 days any operation that implies any risk;
    - executing operations that generate new market risk;
    - purchasing, selling or encumbering fixtures or real property corresponding to fixed assets or permanent financial investments;
    - transferring financial instruments from their credit portfolio;
    - granting credits without collateral;
    - granting Powers of Attorney for execution of the operations set forth above.
- Characterization of infractions: Article 356 defines infractions (including legal or regulatory breaches), all subject to sanctions.
- Article 361: SBS can impose sanctions depending on severity, including (exact list and wording preserved):
  1. admonition;
  2. fine in an amount not less of ten UITs or larger than two hundred, unless the present law indicates in a specific way, a different amount;
  3. fine director or staff, not less than five points UIT or bigger than one hundred.
  4. suspension of the director (board member) or staff in charge, for a term not less than three days or larger than fifteen, and removal in case of relapse.
  5. Destitution.
  6. Ineligibility of the director or staff in the case they were responsible of the intervention or liquidation of the institution under their charge.
  7. prohibition of distributing dividends.
  8. Intervention.
  9. Suspension or cancelling of the operations authorization.
- One UTI is currently 4,000 soles.

*Source: cr18366-perufsap - 51. The SBS establishes the information disclosure standards to be applied by the supervised institutions.*

### 10.  Dissolution and liquidation.

### 10. Dissolution and liquidation

### Supervisor powers over dissolution, liquidation, intervention and sanctions
- SBS has established a Sanctions Regulation (Resolution 816/2005) and further provisions on fines.
- The General Law (Article 95) empowers SBS to put banks under a “surveillance regime” in circumstances such as:
  - failure to meet capital requirements for over three months;
  - grant loans to its own shareholders in order for them to capitalize the bank;
  - incurring notorious or repeated violations of the General Law;
  - as well as other serious reasons.
- Under the surveillance regime, SBS has ample powers to require a recovery plan and to require immediate recapitalization, among others.
- Articles 104 to 107 deal with intervention, which can be triggered based on:
  - failure to complete a recovery plan established under the surveillance regime;
  - reduction in 50 percent of its regulatory capital;
  - among others.
- Article 381 of the General Law establishes SBS power to deny, suspend or cancel the operating license of financial entities.

### EC7 — consolidated supervision over parent and affiliated companies: description and findings
- SBS does not have the explicit power to review the activities of parent companies and of companies affiliated with parent companies (including its subsidiaries) to determine the impact on the bank and the banking group.
- Article 138 of the General Law elaborates on consolidated supervision relying on the supervised entities to provide the necessary information for supervisory purposes; there is no explicit reference to holding/parent companies.
- For affiliates of parent companies, Article 138 addresses mixed conglomerates and places the obligation to provide necessary information on the supervised entities.
- In practice:
  - SBS has access to parent companies balance sheets, board and senior management.
  - Information on non-financial affiliates depends on requiring it through the supervised entities.
- SBS can assess the impact of activities of companies directly under its supervisory perimeter but lacks explicit full powers to monitor parent company activities.
- SBS has established mechanisms that minimize the impact of legal constraints on assessing the risk profile of companies and conglomerates.

### Legal provisions on consolidated reporting and definition of conglomerates
- Article 138 requires presentation of balance sheets and other relevant financial information on a consolidated and individual basis from entities subject to supervision.
- For non-supervised entities, SBS may request information from them through the supervised entities and obtain such information via inspection visits and other on-site procedures (to supervised entities).
- Paragraph b) of Article 138: for companies not domiciled in Peru that form a financial conglomerate whose main activities are carried out in Peru, supervised entities must provide SBS with all necessary information, including general information on the banking group.
- Article 11 of the Special Rules on related parties and economic groups (Resolution SBS No. 5780-2015) defines legal persons/entities that can integrate a financial conglomerate and explicitly includes the holding company; it defines legal entity broadly (autonomous assets managed by third parties without legal personality, associations, investments in mutual funds, securities, trust funds, consortiums, etc.).

### Assessment of Principle 1
- Assessment: Materially Non-Compliant
- Key comment:
  - SBS responsibilities and powers are clearly defined; SBS can authorize banks, conduct ongoing supervision, address compliance, and undertake timely corrective actions.
  - Significant shortcoming: supervisory powers are limited regarding direct access to parents and affiliates (including their subsidiaries and other affiliates) outside the direct supervisory perimeter.
  - Concern is acute because two Peruvian conglomerates (in terms of main shareholders, activities and management) with foreign holding companies, for which SBS operates de facto as home supervisor, are systemic.
  - Although SBS has gathered information, monitored activities and required prudential controls through supervised entities and moral suasion, legal limitations impair SBS’ ability to effectively regulate and supervise these conglomerates on a consolidated basis.
  - The General Law grants powers for unrestricted access to the Board but not for unsupervised companies forming part of financial or mixed conglomerates, including holding companies.

- Recommendation:
  - Amend the legal framework to grant SBS powers to exercise full consolidated supervision.

### Principle 2 — Independence, accountability, resourcing and legal protection: overview
- High-level summary:
  - Supervisor possesses operational independence, transparent processes, sound governance, budgetary processes that do not undermine autonomy and adequate resources, and is accountable for discharge of duties and use of resources.
  - The legal framework includes legal protection for the supervisor.

### EC1 — operational independence, governance and public disclosure: findings
- Constitutional and legal basis:
  - Article 87 of the Political Constitution: organization and functional autonomy of SBS to be established under the law.
  - Article 345 of the General Law: SBS is a constitutionally independent public entity with purpose to protect public interests in financial and insurance systems; control and supervision powers over financial system and insurance system entities and others incorporated by the General Law or special laws.
- Decision responsibility:
  - Sole responsibility for decisions lies with the Superintendent and staff to whom responsibilities are delegated; Article 363 establishes the Superintendent as highest-ranking official.
- ROF and public disclosure:
  - Rules of Organization and Functions (ROF) detail SBS operation and are available on SBS website.
  - SBS is required to publish an annual report (Article 353); the 2016 annual report included on-site examinations, loan volumes, financial indicators, summary of actions taken, supervisory enhancements, new regulations, special themes, AML/CFT initiatives, budget actions and training.
  - Public administration entities must disseminate organizational, procedural, legal framework and budget information on their websites (Articles 5 and 25 of Supreme Decree No. 043-2003-PCM).

### EC2 — appointment and removal of head: findings
- Appointment and term:
  - Process of appointment and term of Superintendent are defined in the Constitution and General Law.
  - Article 87: Executive branch appoints the SBS Superintendent for the constitutional term; Congress ratifies the appointment.
  - Article 363: Superintendent holds office for the constitutional term of the government, may be appointed for one or more successive periods and will continue until successor appointed.
- Removal:
  - Article 366 establishes grounds and procedures for removal by Congress (on its own initiative or at Executive’s request) in circumstances: (1) serious misconduct duly verified and substantiated, or (2) definitive order of detention issued against him.
  - Serious misconduct examples include:
    - a) not taking necessary measures to punish unauthorized regulated activities;
    - b) violation of impediments to being named Superintendent;
    - c) not applying sanctions referred to in Article 361 when information clearly establishes the offense.
- Public disclosure:
  - General Law does not require reasons for removal to be publicly disclosed, but Congress procedures are public through the Permanent Commission except in national security/internal order cases.
- Historical note:
  - No removals in the last twenty years.

### EC3 — publication of objectives and accountability: findings
- Strategic planning and reporting:
  - SBS has a Strategic Plan, action plan, and annual compliance report; internal directive sets criteria for preparing, monitoring, evaluating and updating the action plan.
- Information publicly available on SBS website includes:
  - a) the General Law and regulations issued by SBS;
  - b) institutional vision and mission of SBS;
  - c) action plan’s quarterly compliance report (with summary of number of actions);
  - d) the annual report;
  - e) the ROF;
  - f) accountability report sent to the Comptroller when a Superintendent leaves office.
- The annual report presents main supervisory goals and regulatory changes; the accountability report is detailed but issued only when a Superintendent leaves office (usually every 5 years).

### EC4 — internal governance and decision processes: findings
- Organizational frameworks:
  - ROF and the Organization and Functions Manual (MOF) detail structure, functions and responsibilities.
  - No executive board; Article 363 establishes Superintendent as highest-ranking official.
  - Major decisions concentrated at Superintendent and Deputy Superintendent level with active staff-to-management communication for timely emergency decisions.
- Senior Committees:
  - a) Senior Management Committee — consultative body composed by Superintendent and Deputy Superintendents; responsibilities include opinions/recommendations on strategic and administrative management, institutional budget increases of at least 5 percent, remuneration policy, international relationships, career development, and modifications to organizational structure as of third organizational level.
  - b) Supervisory Policies — proposes supervision policies and coordinates projects to enhance supervision, authorization and sanctioning processes.
  - c) Information Technology — policies and prioritization of IT projects.
  - Financial Stability Committee and International Standards Committee recently created; Financial Stability Committee created in September 2017 to be comprised by Superintendent (chair) and Deputy Superintendents of Banks and Microfinance, Economic Studies (secretariat), Risks and Legal.
- Fit and proper and conflict avoidance:
  - Article 364: criteria for Superintendent include irreproachable conduct and recognized solvency and moral suitability.
  - Impediments (Article 365): i) direct or indirect equity share of any company subject to SBS supervision; ii) capacity as director, advisor, officer or employee of supervised entities.
  - SBS has a Code of Ethics.

- Internal audit:
  - SBS currently does not have a full-fledged Internal Audit function and acknowledges need to strengthen it.

### EC5 — staff professionalism, conflicts of interest and confidentiality: findings
- Internal rules and Code of Ethics:
  - Article 371: staff rights and obligations fixed in Internal rules approved by Superintendent, establishing prohibitions to avoid conflicts of interest and misuse of information.
  - SBS Code of Ethics (Administrative Resolution SBS No. 4343-2012) mandatory for all employees; notable prohibitions include:
    - a) disclose supervisory works or provisions without authorization;
    - b) be shareholder, adviser, director, official, employee or any binding/related party with supervised entities;
    - c) receive/solicit benefits, gifts or attention from supervised entities affecting independence.
  - Internal Working Rules (Resolution SBS No. 5769-2013) further prohibit:
    - a) providing advisory or consultancy to entities controlled by a supervised entity;
    - b) requesting loans from supervised entities without prior written authorization;
    - c) receiving sums of money, gifts or hospitality from supervised entities or their stakeholders;
    - d) misuse of office for personal benefits;
    - e) transactions with SBS service providers/customers/suppliers for personal gain.
- Confidentiality and penalties:
  - Article 372: prohibition to disclose details of reports or information obtained through SBS capacity.
  - Article 360: breach of duty of confidentiality is a serious and punishable offense under Article 165 of the Penal Code (violation of professional secrecy), punishable by fines and incarceration up to two years.
- Post-employment incompatibilities:
  - Law 27588 establishes prohibitions and incompatibilities for public officials (including Superintendent and Deputy Superintendents) with respect to companies within scope; impediments extend until a year after leaving the SBS.

### EC6 — adequacy of resources: findings and quantitative data
- Legal and budgetary autonomy:
  - Articles 367 and 373 empower Superintendent to program, develop, adopt, implement, expand, modify and control the annual budget.
  - Budget funded through fees paid by supervised entities; fees determined quarterly by the Superintendent (for deposit taking institutions based on average assets without exceeding one fifth of one percent). Only in exceptional cases may SBS increase such contributions.
  - Budget reported to public controlling bodies for statistical purposes without undermining autonomy.
- Human resources and compensation:
  - Article 367 (8): Superintendent power to appoint, hire, suspend, remove or dismiss staff, and set salaries.
  - Article 371: SBS staff subject to private sector labor regime allowing flexibility for salaries, promotions and training.
  - Wage bands based on 2015 opportunity cost analysis using Peruvian financial system benchmarks with no major differences to market; design considers higher percentiles at career start and convergence to average in highest categories.
  - SBS reports turnover around four percent in recent years.
  - Number of staff has grown with over 10 percent over the last two years.
- Use of external experts:
  - Article 357 allows use of audit firms for examinations; SBS reports it has never been done with banks.
  - SBS can hire individual consultants/firms; Article 372 prohibits disclosure by persons performing services to SBS.
  - SBS has not made use of external experts for banking supervision except Technical Assistances by multilateral organizations or trust funds (e.g., SECO).
- Training and development:
  - Training Department assesses annual training requirements and prepares Annual Training Plan.
  - Training occurs at SBS “Centro de Formación”; in 2016 average training time per worker in supervision areas was 78 hours on average.
  - SBS provides e-learning via FSI Connect; 250 SBS employees are FSI Connect users (approximately over half from financial supervision and regulation areas).
  - Training Department prepares quarterly performance reports for FSI Connect used in biannual performance evaluation, which affects promotions and salary increases.
  - SBS supports master degrees; since 2012, 45 employees received financial support to study a master degree in Peru and 42 people received leave of absence to study a master degree abroad.
  - Outreach Program: 14-week program for young professionals from Peruvian universities; top students are hired.
- Equipment and inspections:
  - No shortage of equipment; systematically updated.
  - SBS performs inspections abroad and reports no budget constraints.
- Quantitative staff allocation and units:
  - Deputy Superintendence of Banks and Microfinance (SABM) has 173 staff, half dedicated to banks.
  - Deputy Superintendence of Risks (SAR) has 86 staff, with roughly 60 percent of the time allocated to Banks.
  - SAR covers Banks, Microfinance, Insurance and Pensions.
  - Within SABM, half of staff is dedicated to banks and other financial institutions (General Intendance of Banks) and the other half to Microfinance (General Intendance of Microfinance).
  - Within the General Intendance of Banks, each of the four systemic banks is under a dedicated unit; examinations for systemic banks are longer and use a higher number of staff.
- Supervisory methodology:
  - SBS has an internal rating system used to determine supervisory programs and allocate resources, taking into account risk profile and systemic importance.

### EC7 — resource planning and skills development: findings
- Annual budgeting includes assessment of staff numbers needed.
- SBS policy recruits from Outreach Program; Deputy Superintendents and Training Department assess and plan training needs.
- Legal hires on ad hoc basis only concern Legal functional area.

### EC8 — allocation of resources by risk and systemic importance: findings
- Resource allocation considers risk profile and systemic importance of individual banks and banking groups via the internal rating system (see CP 8).

### EC9 — legal protection of supervisors against lawsuits: findings
- Legal framework does not provide adequate protection to supervisory staff against lawsuits for actions/omissions made in good faith.
- Article 366: criminal complaints against Superintendent or Deputy Superintendents must be filed directly with the National Prosecutor, who is sole owner of the criminal action; if complaint is awarded, Prosecutor of the Nation presents it before the Specialized Chamber of the Superior Court of Lima (first instance); judgment may be appealed to the Supreme Court.
- Procedure applies to former Superintendents and former Deputy Superintendents criminally denounced for alleged crimes in exercise of functions up to five years after leaving office.
- Prior to a civil lawsuit against SBS staff, SBS itself must be found guilty in civil court. The Twenty-ninth Final and Complementary Disposition of the General Law restricts precautionary measures for future enforced execution over SBS employees’ assets to cases where judgment declared civil liability of SBS for acts or omissions by the employee.
- SBS Resolution No. 629-1994: legal expenses and professional fees for judicial defense of SBS officials and employees in legal actions initiated by third parties as a result of professional decisions are to be paid by SBS, even after employment ceases.
- There have never been any banking supervisors declared personally liable by courts.

### Assessment of Principle 2
- Assessment: Largely Compliant
- Key comments:
  - SBS has operational independence, accountability and governance arrangements publicly disclosed; no budget constraints.
  - Allocation of resources takes into account risk profile and systemic importance, although proportion of staff allocated to banks versus microfinance may be too low.
  - Legal protection should be enhanced: current provisions provide some protection but do not shield SBS and SBS staff by a “good faith” test; current provisions extend only to Superintendent and Deputy Superintendents and cover only up to five years after leaving office.
  - Governance improvements recommended regarding assessment of supervisory effectiveness; Superintendent tenure coinciding with constitutional term of government may potentially undermine personal autonomy.

- Recommendations to authorities:
  - Amend the legal framework to further protect all SBS staff for acts or omissions in good faith including current and former staff (including senior management) even after leaving the SBS, irrespectively of the number of years of being out of the SBS;
  - Amend the legal framework so the Superintendence tenure does not coincide with the constitutional term of the government;
  - Review the allocation of resources to entities in relation to their systemic relevance and risk to ensure optimization of resources;
  - Enhance the Internal Audit Function, including the establishment of an Internal Audit Committee;
  - Operationalize the Financial Stability Committee;
  - Consider further elaborating on the discharge of supervision responsibilities relative to the objectives through the Annual Report.

### Principle 3 — cooperation and collaboration: EC1 findings (domestic)
- Legal basis for domestic cooperation:
  - General Law, Article 349 (Superintendent attributions, item 15) grants SBS powers to establish cooperation agreements with domestic supervisors.
  - First Final and Complementary Provision of the General Law requires BCRP and SBS to coordinate to fulfill constitutional obligations; Superintendent required to quarterly attend BCRP board meetings to exchange relevant information.
  - Second Final and Complementary Provision requires SBS and the Superintendence of Securities Market (SMV) to make relevant arrangements for supervision purposes; Superintendent to quarterly attend SMV board meetings.
  - Article 32 of the Consolidated Supervision Regulation allows SBS to establish coordination agreements with domestic authorities responsible for companies constituting financial groups, subject to confidentiality; agreements may include information exchange and coordinated in situ inspections.
- In practice:
  - Domestic cooperation agreements are currently in place (details not included in this content extract).

*Source: cr18366-perufsap - 10.  Dissolution and liquidation.*

### 1.        Coordination agreement with the BCRP - August 2007 – it covers several

### cr18366-perufsap - 1.        Coordination agreement with the BCRP - August 2007 – it covers several

### 1. Coordination agreement with the BCRP - August 2007
- Covers several aspects related to the relationship between the BCRP and SBS, including reinforcing the commitment to share all the necessary information for the fulfillment of their objectives.
- There are no specific provisions for the operationalization of those exchanges.
- The only information systematically shared by SBS with BCRP are prudential ratios.
- BCRP shares on a semi-annual basis macro scenarios for SBS stress testing.
- Other than that, information is shared upon request.

### 2. Cooperation agreement with SMV - March 2012
- Aims to facilitate the coordination for the fulfilment of their respective functions.
- The agreement makes explicit reference to exchange of data bases and other supervisory information.
- The agreement also makes reference to joint examinations, and coordination on consistency of regulations, in addition to exchanging information on ultimate beneficiary ownership.
- Currently there is no systematic sharing between SMV and SBS.

*cr18366-perufsap - 1.        Coordination agreement with the BCRP - August 2007 – it covers several*

### 3.        Agreement with the Superintendencia Nacional de Administration Tributaria -

### 3.        Agreement with the Superintendencia Nacional de Administration Tributaria -

### Coordination and information sharing (domestic)
- Agreements in April 2012 and February 2017 for sharing information on AML/CFT.
- Superintendent attends BCRP board meetings periodically, making presentations or discussing topics of common interest.
- A senior SBS representative seats at SMV Board, appointed by the Executive Branch at SBS request; currently the Deputy Superintendent General Counsel of SBS plays that role.
- Coordination mechanisms with other local institutions are reported to be activated as appropriate.
- Technical-level exchanges with BCRP occur on an ad hoc basis; topics have included over-indebtedness, stress-testing and dollarization.
- Exchanges with SMV have occurred at SMV request, including discussions on regulations and oral reports on findings.
- Internal information sharing within SBS between SABM, SAS, SAAFP (banking, insurance, pensions) and SAR is exchanged during quarterly meetings of the Consolidated Supervision Committee, which focuses on compliance with prudential limits and consolidated balance sheets and discusses conglomerate issues.
- EC2: Arrangements, formal or informal, are in place for cooperation, analysis and sharing of information, and collaborative work with relevant foreign supervisors of banks and banking groups; there is evidence these arrangements work in practice where necessary.

### EC2 — Cooperation with foreign supervisors (description and findings)
- Legal basis:
  - Article 349 (Superintendent attributions), item 14 of the General Law: authority to enter into cooperation agreements with foreign supervisors and related entities to better exercise consolidated supervision.
  - Article 367 (Superintendent abilities), item 10: empowers entering agreements with foreign government bodies or other supervisors for training and exchange of information in matters of supervision.
  - Article 32 of the Consolidated Supervision Regulation: SBS may establish coordination agreements with foreign supervisory authorities responsible for overseeing companies that constitute financial groups, subject to confidentiality; agreements may include exchange of information and coordinated in situ inspections.
- SBS has concluded cooperation agreements with foreign supervisors including: Colombia, Ecuador, Venezuela, Spain, El Salvador, Bolivia, Guatemala, Italy, Mexico, Nicaragua, Bahamas, Panama, Canada, Brazil, China.
- Informal coordination mechanisms used: emails, phone calls and official letters for exchange of information and on-site supervision in the scope of consolidated supervision; written exchanges provided to assessors confirm practice.
- SBS participates in supervisory colleges including Banco Santander, BBVA and Scotiabank, and organized its first supervisory college for Credicorp; plans to hold yearly colleges for both Credicorp and Intercorp, the latter starting in 2018.

### EC3 — Confidentiality provisions for information sharing (description and findings)
- Article 140 of the General Law: prohibits SBS staff from sharing information on banks clients’ assets (i.e. deposits etc.).
- Article 359 (reports): examination reports are confidential but can be shared with the BCRP in the context of fulfilling its objectives.
- Cooperation Agreements made available to assessors contain confidentiality clauses requiring information exchanged be used only to develop supervisory functions and only for lawful supervisory purposes; disclosure only as necessary to carry out legal responsibilities and must notify the originating supervisor if disclosure occurs.
- Article 16 of the Transparency Law: requests for information under framework agreements may be denied on grounds of public interest, national security or when disclosure would interfere with ongoing investigations.
- Directive 510-02: establishes classification, treatment and protection of information and defines "confidential" information to encompass on- and off-site reports produced by SBS, effectively not shared with other domestic authority or foreign supervisor.
- In practice, SBS reports have not been denied nor denied information under such provisions thus far; SBS shares summaries of reports. Files reviewed by assessors confirmed statements.

### EC4 — Use and protection of confidential information by receiving supervisors (description and findings)
- Article 360 of the General Law: SBS employees, representatives, agents or service providers prohibited from disclosing information obtained in exercise of functions; violation is serious misconduct and crime under article 165 of the Penal Code (violation of professional secrecy).
- Article 372: prohibits disclosure of details of reports or information obtained through exercise of office to persons outside.
- Article 143: information on clients’ assets with banks (i.e. deposits etc.) may be shared only with written permission of the client or when required by certain authorities (e.g., judges and courts, the Attorney General, the President of a Commission of Inquiry of Congress).
- Article 97 of the Political Constitution: grants Congress power to initiate investigations on matters of public interest, obliges those involved to appear before committees and grants committees power to access any information, including lifting bank secrecy and tax reserve; SBS cannot deny information requested by the President of a Commission of Inquiry of Congress under that authority.
- MoUs with foreign entities reviewed by assessors contain clauses requiring notification to originating supervisor when circumstances require release of supervisory information.

### EC5 — Support for resolution authorities (description and findings)
- SBS is the resolution authority in Peru and is in charge of recovery and resolution planning and actions.
- Deposit insurance (Fondo de Seguro de Depositos – FSD), per Articles 144 and 151 of the General Law, should provide deposit insurance (payoff) and, under exceptional circumstances, provide support to its members executing measures dictated by the SBS (with favorable opinion from the BCRP and MEF).
- Further details on the FSD are referenced in the Technical Note on Crisis Management.

### Assessment summaries and comments
- Assessment of Principle 3: Compliant.
  - Comments: Arrangements in Peru provide a framework for cooperation and collaboration with relevant domestic and foreign supervisors and reflect need to protect confidential information. SBS does not appear to need extensive exchange of information with domestic authorities to perform supervisory duties but provides information when requested.
- Principle 4 (Permissible activities): Compliant.
  - EC1: Article 282 of the General Law defines a banking company; Article 282 also defines other multi-transaction companies and notes which entities are authorized to collect deposits.
  - EC2: Articles 283 to 289 establish permitted operations for banking entities; Art. 283 allows transactions indicated in article 221 except commodity transactions and derivative financial products (forwards, futures, swaps, options, credit derivatives or other instruments or derivatives contracts), for which separate SBS authorization is required. Articles 223 and 224 specify operations requiring a separate department or subsidiaries.
  - EC3: Use of the word "bank" limited to authorized and supervised companies; Article 11 requires prior authorization to engage in financial system activities and prohibits use of names suggesting SBS-authorized activities; Article 15 requires authorized entities to include reference to activity in their name. SBS verifies proper use of social denominations and the Department of Contentious Affairs combats financial informality.
  - EC4: Article 11 requires prior authorization to take deposits; permitted deposit-takers besides banks include financial companies, rural loans and savings institutions and municipal savings and loans institutions; savings and loans cooperatives take deposits only from members unless licensed. Non-bank deposit taking institutions represent approximately 11 percent of the system. Article 351° empowers the Superintendent to order immediate closure of premises conducting unauthorized operations, with Public Ministry intervention and seizure of documentation; SBS may demand support of public force.
  - EC5: SBS website makes available a list of licensed banks (URL provided in source). At present there are no branches of foreign banks operating in Peru.
  - Comments: Permissible activities and control over the use of the word “bank” are clearly defined in Peru.
- Principle 5 (Licensing criteria): Compliant.
  - EC1: General Law Article 12 requires prior authorization from SBS to initiate operations; Article 19 empowers SBS to authorize organization and operation of companies in Articles 16° and 17. For banks, prior opinion of the BCRP is required but not a reason for denial. Article 349 lists powers including authorization of organization and operation; Article 381 empowers SBS to grant, deny, suspend or cancel authorizations.
    - Licenses provided for universal banking; regulations have no provisions regarding prudential conditions for licensing a bank.
    - SBS licensing process includes visiting premises, reviewing policies/procedures, systems and controls. SBS may impose conditions prior to authorization (e.g., shareholders to provide more capital than minimum, details in Bylaw). Changes in Bylaw require SBS approval.
  - EC2: General Law, SBS regulations and internal procedures state licensing criteria; SBS can refuse requests not meeting requirements and revoke licenses granted based on false information.
    - Title I of the General Law (Articles 12, 13, 15, 16, 19, 20, 21, 22, 23, 24, 25 and 27) set requirements; Article 21 requires applications to follow procedures and include specified information; Article 28 allows SBS to withdraw license due to very serious infractions; Resolution SBS 816/2005 lists dissolution and liquidation as measures for providing false information. Administrative Law (Law 27444), Article 32.3 provides for nullity of administrative acts based on misrepresentation or fraud.
    - Resolution SBS 10440/2008 (Licensing Regulation) sets requirements and criteria including feasibility studies, fit and proper criteria for organizers, shareholders and senior management. TUPAs contain the administrative procedure stages.
    - Licensing process phases: authorization (documentation analysis and authorization to establish operations, subject to on-site exam) and operation (assessment of policies, procedures, IT and accounting systems, business continuity). Once licensed the entity has three months to start operations. Files reviewed by assessors confirm practice.
  - EC3: Licensing criteria are consistent with ongoing supervision, including fit and proper criteria and validation of policies, corporate governance, risk management, AML, and adequate personnel and systems. On-site initial examination may result in required enhancements which become binding conditions.
    - Criteria for licensing do not explicitly reference prudential requirements, but General Law and regulations do not distinguish new banks from ongoing banks; banks are expected to meet prudential requirements when initiating operations.
  - EC4: Licensing Regulation (Article 6) requires shareholders to submit information to ascertain moral integrity and financial solvency, including related parties and concept of economic group and ultimate beneficiary shareholder (reference to CP 20). Annex 1 of the Licensing Regulation requires corporate governance, organizational and operational structure, personnel policies, and list of shareholders, board members and senior management.
    - Article 33 of the Regulation for Consolidated Supervision of Financial and Mixed Conglomerates (Resolution SBS No. 11823-2010 and amendments) states SBS may consider impediments to authorize establishment of companies in specified cases.

*3.        Agreement with the Superintendencia Nacional de Administration Tributaria -*

### 1. When the legal and administrative structure of the conglomerate prevents or

### cr18366-perufsap - 1. When the legal and administrative structure of the conglomerate prevents or 

### Key issue
- When the legal and administrative structure of the conglomerate prevents or hinders effective consolidated supervision;

*Source: cr18366-perufsap - 1. When the legal and administrative structure of the conglomerate prevents or*

### 2. When the conglomerate is not subject to effective consolidated supervision

### 2. When the conglomerate is not subject to effective consolidated supervision

### Context and supervisory practice
- Situations described where consolidated supervision is not effective include:
  - Parent company or a parent company located in countries where effective consolidated supervision is not performed.
  - In the country of origin or the country where the main financial and/or insurance activities of the conglomerate are carried out, there is no consolidated supervision.
  - The country of origin does not apply the minimum international standards for effective consolidated supervision.
- In practice, the SBS has authorized cases where the Home Supervisor does not perform consolidated supervision. In those cases SBS:
  - Set up additional information requirements to monitor the group.
  - Kept close contact with the home supervisor and submitted questionnaires to acquire further information regarding consolidated supervision and the overall supervisory approach.
  - Required additional monitoring of the local entity and information regarding the parent and ultimate beneficial shareholders.

### Licensing, ownership transparency and suitability (selected ECs)
- EC5 (licensing authority identifies major shareholders and ultimate beneficial owners):
  - Relevant legal provisions: Articles 19, 20, 22 and 52 of the General Law; Article 4 and Article 6 of the Licensing Regulation.
  - Requirements include resumes/annual reports, affidavits on impediments and pending legal proceedings, list of assets (with encumbrances), list of related parties, ownership structure up to ultimate beneficiary, list of shareholders, directors, managers and senior officials.
  - Legal-entity shareholders must provide:
    - Annual Report and audited financial statements for the last 2 years of the legal entity which is a shareholder and all companies forming the economic group, and where applicable consolidated financial statements of the conglomerate.
    - Information on shareholder equity.
    - For foreign legal persons: a renowned rating agency report, details on investments and annual report for the last 2 years, in case it is the parent.
  - SBS can require further information on shareholders owning over 4 percent up to the ultimate beneficial shareholder.
  - Significant Ownership Regulation (Resolution SBS 6420-2015) requires an annual affidavit from shareholders affirming identity of ultimate beneficiaries and their moral integrity and financial solvency, and ability to make cash contributions to cover any equity deficiency.
  - In practice SBS uses credit registry and international databases to gather further information.

- EC6 (minimum initial capital):
  - Article 16 of the General Law establishes minimum capital to be contributed in cash; updated quarterly according to the Wholesale Price Index (Article 18).
  - For commercial banks, the minimum capital stock for the period July - September 2017 is S/26,609,326.
  - Licensing process includes a feasibility study with financial projections; SBS assesses planned capital beyond minimum.

- EC7 (fit and proper assessment of board and senior management):
  - Article 79 requires banks to have at least five board members deemed fit and proper.
  - Article 81 lists unfitness criteria (insolvency, employees of the institution except CEO, staff from other banks, holders of past due loans over 120 days, former board members/senior management sanctioned).
  - Licensing Regulation Article 7 requires resumes, affidavits of no penal/police antecedents, affidavits on judicial processes, asset affidavits, etc.
  - Resolution 272/2017 requires boards composed to enable effective participatory performance and with relevant skills.
  - In practice:
    - SBS assesses adequacy of proposed senior managers and individual board members; interviews are not systematically used.
    - Changes to board members or senior management are subject to ex-post evaluations, not prior assessment.
    - Analysis has not systematically determined whether the Board has collective sound knowledge of material activities and associated risks.

- EC8 and EC9 (strategic/operating plans and pro forma financials):
  - Licensing Regulation (Annex I) minimum content of viability study includes:
    - Strategic planning (group background, mission, objectives, marketing strategy, branch expectations).
    - Organization (corporate governance, structure, staffing).
    - General policies and procedures (risk management across credit, market, operational, liquidity; internal control and auditing; AML/CFT; related parties).
  - Financial requirements include:
    - Capital – initial capital, opening balance sheet, budget and financing structure.
    - Financial projections: balance sheet, income, cash flow, breakeven, VAN and TIR and sensitivity analysis.
    - Projection assumptions: macro variables (exchange rate, economic growth rate, sector), pricing, transaction sizes, number of customers, financial and administrative expenses; loan portfolio projection by risk category; projected capital ratio with detailed calculation of risk-weighted assets and regulatory capital.
  - SABM leads licensing with Superintendence of Economic Studies analyzing financial projections.
  - Outsourced functions require separate authorization.

- EC10 (foreign banks — home supervisor no-objection and consolidated supervision):
  - Article 18(7) of the Licensing Regulation requires a certificate from the home supervisor that the parent is authorized to establish operations abroad and is subject to consolidated supervision.
  - Article 6(8-f) requires a statement of no-objection from the home supervisor for potential foreign financial entity shareholders and a list of administrative sanctions over the last three years.
  - Article 33 of the Consolidated Supervision Regulation (Resolution 11823-2010) allows SBS to consider as impediments for authorization where legal/administrative structure prevents effective consolidated supervision or where parent/controller is located in countries without effective consolidated supervision or where minimum international standards are not applied.
  - Consolidated supervision is considered effective if it meets minimum international standards including analysis of risk management at consolidated level, regulatory capital and capital requirements, related party and concentration limits, and analysis of consolidated financial statements to the satisfaction of the Superintendence.

- EC11 (monitoring new entrants):
  - No policies/processes specifically to monitor progress of new entrants in meeting business and strategic goals.
  - Article 94 requires CEOs to submit to the board at least quarterly reports comparing performance with projections; Circular B-1899-92 requires those reports to be sent to SBS.
  - Entities are subject to on-site examinations at least once a year and ongoing off-site monitoring.
  - Implementation periods for supervisory requirements are generally 12 months (and entities required to open business up to three months after being granted a license); follow-up occurs through regular examinations.

### Key legal thresholds, timeframes and numeric values (preserved exactly)
- Minimum capital stock for commercial banks for July - September 2017: S/26,609,326.
- Shareholding notification and authorization thresholds:
  - Prior authorization required for transfers of ownership over 10 percent (or that would result in holdings over 10 percent).
  - Significant owner defined as direct or indirect stake above ten percent (10 percent).
  - SBS can require information on shareholders owning over 4 percent up to the ultimate beneficial shareholder.
  - Notification obligations: acquisition of 1 percent in 12 months requires providing information; reaching 3 percent or more within 12 months triggers additional reporting requirements.
  - Circular G-152-2010: CEO and Head of Internal Audit must inform SBS within five business days of learning of facts affecting moral fitness or economic solvency of shareholders owning directly or indirectly 3 percent or more.
  - Related Parties Regulation: modifications to composition of economic group must be communicated in no more than 15 calendar days following the month in which the change occurred.
  - SBS Resolution 1913-2004: supervised companies must inform SBS on election of directors and appointment of managers and internal auditors within one (1) business day.
  - Licensing implementation timeframe: entities are generally granted a 12-month period for implementation and required to open business up to three months after license grant.
  - Penalties/time to divest: sale of holdings required within thirty (30) days if fined for violations; fine doubles if period expires without correction.
  - Article 54 forbids public servants and their spouses to hold over five percent in a supervised entity.
  - Article 55 forbids controlling shareholders holding over five percent in another entity of the same nature.

### Findings, limitations and supervisory gaps highlighted
- Strengths and practices:
  - SBS has a comprehensive licensing process assessing ownership structure, governance, strategic and operating plans, internal controls, risk management and projected financial conditions.
  - SBS requires non-objection from home supervisors for foreign parents and has procedures to liaise with home supervisors.
  - Practical arrangements in cases where home consolidated supervision is lacking include additional information requirements and closer monitoring.
- Weaknesses and limitations:
  - The General Law does not explicitly define “significant ownership” and “controlling interest” (though regulations clarify).
  - The definition of “significant owner” relies on a quantitative 10 percent threshold and may not capture persons exerting significant influence with holdings below 10 percent.
  - No systematic prior assessment of whether a board has collective sound knowledge of material activities and associated risks.
  - Changes to board and senior management are subject to ex-post rather than prior assessment.
  - Resolvability of banks is not currently part of SBS supervisory approach: no procedures to assess banks’ resolvability; banks are not required to develop recovery plans; no resolution planning for Peruvian systemic banks.
  - SBS supervisory rating does not produce a rating for conglomerates, though group-wide characteristics can override individual entity ratings downward.
  - SBS ability to evaluate cross-border acquisitions and consolidated risks is constrained by limited legal powers regarding holding companies and consolidated supervision of groups (legal limitations vis-à-vis CP 1 and CP 12).
  - The affidavit requirement for significant owners does not fully address cases where ultimate beneficiaries cannot be identified (e.g., NYSE-traded shares; only holdings above 5 percent through a single entity are required to be notified to the SEC).

### Policy recommendations and supervisory actions (as noted in source)
- Recommended to amend legal/regulatory framework to:
  - Adequately incorporate significant influence as a qualitative indicator for significant ownership in the regulatory framework (to capture situations where influence exists with holdings below 10 percent).
- Recommended supervisory enhancements:
  - Establish a process for assessing resolvability of systemic banks.
  - Consider establishing a rating for conglomerates and establishing a lead supervisor for the conglomerate responsible for the overall view of operations and risks.
  - Further enhance interactions with senior management and particularly the Board of supervised entities to better understand strategy, operations, controls and risks.
  - Lower the maximum percentage allowed to be held in a non-financial company to ensure there is no controlling interest/influence (noting current concerns that limits may allow banks to have controlling interest/influence).
  - Streamline off-site surveillance reports through further coordination between SAR and SABM.
  - Speed up the process of establishing an off-site surveillance IT platform.

### Relevant supervisory powers and enforcement tools cited
- Articles and regulations cited granting SBS powers:
  - General Law Articles: 16, 18, 19, 20, 22, 52, 57, 58, 59, 87, 90, 92, 94, 136, 138, 200, 221, 349, 350, 356, 357, 359, 381 (b).
  - Licensing Regulation Articles: Article 4, Article 6, Article 7, Article 17, Article 18(7), Article 28, Article 33.
  - Consolidated Supervision Regulation (Resolution 11823-2010) Article 33.
  - Significant Ownership Regulation (Resolution SBS 6420-2015).
  - Related Parties Regulation (Resolution 5780-2015).
  - Internal rules and directives: Resolution 272/2017; Circulars G-152-2010, G-165-2012, G-164-2012; Directive No. SBS-SBS DIR-SBS-342-01; Directive SBS No. SBS-DIR-SBS-578-01.

*Source: cr18366-perufsap - 2. When the conglomerate is not subject to effective consolidated supervision*

### Appendix 12-I: Control of Capital Instruments (monthly); Appendix 12-I I:

### Appendix 12-I: Control of Capital Instruments (monthly); Appendix 12-I I: Control of subordinated debt (monthly)

### Reporting framework and frequency for risk types
- Capital instruments: Appendix 12-I (monthly); Appendix 12-II: Control of subordinated debt (monthly).
- Credit Risk:
  - Report 2 A: Risk-weighted assets for Credit Risk (monthly).
  - Annex 5: Debtors classification and Provisions Report (monthly).
  - Annex 6: Credit Debtors Report (monthly).
- Market Risk:
  - Annex 1: Investment (monthly).
  - Annex 8: Positions on Derivative Financial Instruments (weekly).
  - Annex 9: positions subject to FX Risk (monthly).
  - Report 2-B: Capital Requirement components for Market Risk (monthly).
  - Appendix 7: Interest Rate Risk Measurements - local and foreign currencies (monthly).
- Liquidity Risk:
  - Annex 15-A: Treasurer's Report and Daily Liquidity Position (daily).
  - Annex 15-B: Liquidity Coverage Ratio (daily).
  - Annex 15-C: Monthly Liquidity Position (monthly).
  - Annex 16-A: Liquidity maturity table (monthly).
  - Annex 16-B: Stress Test and Contingency Plan (quarterly).
- Operational Risk:
  - Report 2-C: Capital Requirements Calculation (monthly).
- Economic Group and Related Parties:
  - Report 19-I and 19-II: Information on the economic group (semi-annual).
  - Report 19-A: Information on legal entities that compose the economic group (semi-annual).
  - Report 21: related party lending (quarterly).
- Limits:
  - Report 13: Control of Global and Individual Limits Applicable to Financial System Companies (monthly), including large exposures.
- ICAAP:
  - Since 2010, banks are required to provide an ICAAP report on an annual basis.
- Periodic collection of economic sector and geography data: collected periodically by the Economic Department and forwarded to the Supervision Department.

### EC2 — Accounting and reporting standards
- Legal basis and powers:
  - Article 349 (13) of the General Law empowers the SBS to set regulations for the elaboration, presentation and disclosure of financial statements and complementary information, as well as consolidation criteria, based on general accepted accounting principles.
  - Articles 354 authorizes SBS to:
    - require establishment of provisions and reserves for off-balance sheet items that bear credit or market risk;
    - require that investments and other exposure subject to market risk are marked to market according to a methodology to be established;
    - require that fixed and other assets are adjusted to their market value according to a methodology to be established;
    - forbid entities to pay dividends or distribute profits until they comply with the previous requirements;
    - require the amount of provisions it deems necessary in cases where there is not enough information to properly value it.
- Accounting Manual:
  - Provides reporting instructions and formats.
  - Prepared in accordance with International Financial Reporting Standards (IFRS) issued by the International Accounting Standards Board (IASB), which have been established in Peru by the Accounting Standards Board.

### EC3 — Valuation methodologies, governance and validation
- Regulatory instruments:
  - Regulation for Trading and Accounting of Derivatives (SBS Resolution 1737-2006) aligns broadly with IAS No. 39; Article 8 establishes initial measurement at fair value and subsequent changes affect income statement; conservative price points (bid/ask) must be used depending on long/short positions; offsetting positions may use average market prices.
  - Regulation for the Classification and Valuation of Investments (Resolution 7033-2012) establishes a standard methodology for identifying impairment in accordance with international standards.
  - Asset Classification and Provisioning Regulation (Resolution 11356-2008) sets criteria for calculation of loan exposures taking into account valuation of collateral and provisioning.
- Supervisory requirements and practices:
  - Accounting Manual requires entities to have valuation methodologies periodically tested and calibrated.
  - Annual valuation required for intangibles such as goodwill; valuations must be available to the SBS.
  - SBS may require special reports by independent professionals for complex products.
  - Circular B-2087-2001 requires independent validation of interest rate risk calculations (Annex 7 – Interest Rate Risk Measurement).
  - On-site examinations assess policies and procedures related to valuation of collateral.
  - IFRS implemented in Peru with some minor deviations (see CP 27); annual external audits validate valuations.

### EC4 — Frequency and use of supervisory information
- Collection frequency:
  - SBS collects information on a daily, monthly, quarterly and yearly basis (see EC1 details).
  - ICAAP reports are distinct for local systemic banks.
  - Yearly Corporate Governance Questionnaire tailored for systemic banks.
  - Ad-hoc requests more frequent for systemic banks; periodic information mostly homogeneous for all banks.
- Use:
  - Data is systematically used producing daily, monthly and quarterly reports, and for ongoing monitoring.
  - Certain reports may be requested at shorter intervals or earlier (e.g., liquidity) depending on concerns.

### EC5 — Comparability and consolidated reporting
- Coverage and comparability:
  - SBS collects data periodically from all supervised entities and certain information from holding companies and financial affiliates.
  - The Accounting Manual, Annexes and Reports apply to all core financial sector entities with varying levels depending on company nature.
  - Insurance firms subject to a different Accounting Manual with daily, monthly and yearly submissions.
- Financial conglomerates reporting (Article 20 of the Consolidated Supervision Regulation) required on consolidated basis:
  - balance sheets/income statements (quarterly),
  - cash flow statement (annually),
  - statement of changes in equity (quarterly),
  - financial eliminations (quarterly),
  - regulatory capital (quarterly),
  - capital ratio calculations (quarterly),
  - global risk management report (annually),
  - information on related and connected parties (quarterly).

### EC6 & EC7 — Powers to request information and access records
- Legal powers:
  - Article 350 of the General Law: Superintendent may examine books, accounts, records, documents, correspondence and any other information necessary; may require records to inquire about financial situation, resources, administration, performance of representatives, degree of safety and prudence, and other matters.
  - SBS can receive testimony from third parties and request display of books and documents.
- Mixed conglomerates:
  - SBS does not have direct access to information but has powers to indirectly require them.
  - Article 138(2) of the General Law: SBS entitled to request information to determine effects of the financial situation of non-financial entities on supervised entities; supervised entities must provide such information.
- Access in practice:
  - SBS generally has no difficulties accessing records, Board, management and staff.
  - Legal limitation exists for cross-border bank records due to secrecy issues; SBS coordinates with local authorities and may require specific reviews of information protected by secrecy law.

### EC8 — Enforcement of timely and accurate submissions
- Submission system and responsibilities:
  - SUCAVE: automated system for banks submitting prudential returns.
  - Article 87 and 92 of the General Law deem Board members and senior management responsible for failure to submit information; such failure is an infraction.
  - Sanctions Regulation (Resolution 816-2005) treats failure to follow accounting manual and failure to submit periodic information as infractions.
- Practice and remedies:
  - SBS reports that failure to submit information and delays are rare; quality overall good except when new information is requested, which can take time for full implementation.
  - For systematic delays or need to resubmit, SBS can submit a written request and may ask for a correction plan.

### EC9 — Validation and integrity of supervisory information
- Components of validation:
  - External auditors, software validations, and on-site examinations complement each other.
  - External Audit Regulation (Resolution 17026-2010) Article 6 and Annex I require External Audits to review compliance with prudential ratios and reconcile prudential returns with trial balance and appropriate approvals.
  - SUCAVE has internal validation against trial balances preventing submission until inconsistencies are corrected.
  - On-site examinations include direct validations, focusing on risk-weights calculation for credit risk and provisioning, conducted on an as-needed basis.
  - Since 2016, on-site examinations include IT modules that evaluate generation processes of prudential returns (audit style), particularly related to capital adequacy, provisions and liquidity.
- Use of external experts:
  - SBS has not made use of external experts thus far.

### EC10 & EC11 — Use and requirements for external experts
- Practice:
  - SBS does not make use of external experts for performing supervisory work.
  - On occasion, SBS has hired experts with support of SECO for capacity building on liquidity stress testing, internal models for credit risk, and risk data aggregation.
- Implication:
  - EC10 and EC11 duties regarding formal roles, scope, suitability assessment, conflicts of interest, and prompt reporting of material shortcomings are not exercised because SBS does not use external experts for supervisory tasks.

### EC12 — Periodic review of information collected
- Process and recent changes:
  - SBS collects a broad range of periodic information and changes in regulations are reflected in submission changes as needed.
  - Recent enhancements include liquidity funding gap and yearly information on individual’s income to monitor over indebtedness.
  - A major past review on credit risk submissions occurred; currently a task force established to perform an overall review of information received aiming at eliminating overlaps.
- Assessment:
  - The SBS periodically reviews and updates the information collected to satisfy supervisory needs.

### Assessment — Principle 10
- Assessment: Compliant
- Comment:
  - SBS has an adequate approach for collecting, reviewing and analyzing prudential reports and statistical returns from banks on both a solo and a consolidated basis, and independently verifies these reports through on-site examinations.

### Principle 11 — Corrective and sanctioning powers; EC1 findings on early intervention
- Legal and procedural basis:
  - Article 90 of the General Law requires communications from SBS related to on-site examinations or investigations or containing recommendations to be submitted to the Board at its next meeting under the responsibility of the Chairman of the Board.
  - Article 359 requires SBS to inform findings from on-site examinations through a written report so the Board can adopt corrective measures within an appropriate time frame.
- Practical process:
  - On-site examinations include an exit meeting with the CEO; initial findings presented and submitted in written form; bank has five days to react; final inspection report submitted to the Chairman of the Board with findings and recommendations.
  - Internal Audit Regulation (Resolution 11699-2008) Article 18: Internal Audit required to submit the SBS quarterly reports (20 days after the end of the quarter) on implementation of recommendations; these reports are closely monitored by SBS.
  - All communications delivered through SABM; follow ups consolidated via a web-based tool for on-site examination items; off-site surveillance items monitored separately.
- Observations and prioritization:
  - Inspection reports contain significant numbers of observations encompassing major issues and regulatory non-compliance.
  - In 2017, SBS adopted an approach to prioritize observations ranked high, mid and low priority to help banks plan responses.
  - Banks generally take timely measures to address supervisory concerns; IT enhancements often take longer and banks may request extended implementation time.
  - Yearly examinations include on-site verification of the effectiveness of major measures taken.

### EC2 — Range of supervisory tools (availability and operationalization)
- Legal powers:
  - Article 349 (19) of the General Law empowers SBS to perform all acts necessary to safeguard public interests.
  - Article 355 empowers SBS, in case of entities with financial instability or management deficiency, to:
    - require capital adjustments to reflect actual capital ratios;
    - request cash capital increases;
    - forbid entities, for six months (renewable for six months), from:
      a) taking additional risks of any kind with any related party;
      b) renewing for over 180 days any operation that implies any risk;
      c) executing operations that generate new market risk;
      d) purchasing, selling or encumbering fixtures or real property corresponding to fixed assets or permanent financial investments;
      e) transferring financial instruments from their credit portfolio;
      f) granting credits without collateral;
      g) granting Powers of Attorney for execution of the operations set forth in preceding points.
- Sanctions and infractions:
  - Article 356 characterizes infractions, including legal or regulatory breaches, all subject to sanctions.
  - Art. 361 grants SBS powers to impose sanctions depending on severity (further provisions on sanctions in regulations).
- Operationalization gap:
  - While SBS can require a range of corrective actions (including requiring capitalization, limiting growth, requiring board members to step down), SBS has not operationalized these powers into a regulation or procedures comprising a range of supervisory tools to be used depending on severity.

*Source: IMF country report content provided in the input.*

### 1. admonition;

### 1. admonition;

### Sanctions regime and available measures
- Sanctions enumerated include:
  - admonition;
  - fine in an amount not less of ten UITs 33 or larger than two hundred, unless the present law indicates in a specific way, a different amount;
  - fine director or staff, not less than five points UIT or bigger than one hundred;
  - suspension of the director (board member) or staff in charge, for a term not less than three days or larger than fifteen, and removal in case of relapse;
  - destitution;
  - ineligibility of the director or staff in the case they were responsible of the intervention or liquidation of the institution under their charge;
  - prohibition of distributing dividends;
  - intervention;
  - suspension or cancelling of the operations authorization;
  - dissolution and liquidation.
- One UIT is currently 4,000 soles.
- SBS has established a Sanctions Regulation (Resolution 816/2005) and further provisions on fines.
- Article 381 of the General Law establishes among the powers of the SBS the power to deny, suspend or cancel the operating license of financial entities.

### Surveillance, intervention, and recapitalization powers
- General Law (Article 95) empowers the SBS to put banks under a “surveillance regime” in circumstances such as:
  - failure to meet capital requirements for over three months;
  - grant loans to its own shareholders in order for them to capitalize the bank;
  - incurring notorious or repeated violations of the General Law;
  - other serious reasons.
- Under surveillance regime, SBS can require a recovery plan and immediate recapitalization among other measures.
- Articles 104 to 107 deal with intervention, which can be triggered by:
  - failure to complete a recovery plan established under the surveillance regime;
  - reduction in 50 percent of its regulatory capital;
  - other listed grounds.
- Article 63 requires that any deficit of the minimum capital needs to be addressed within the next trimester, which can be extended twice if reasonable efforts are being made.
- Resolution 8425-2011 on capital buffers (Article 16) establishes that any reduction on capital below the supervisory buffer requires SBS authorization and a recapitalization plan; failure to comply will result in sanctions.
- Breaches to consolidated capital requirements trigger presentation of a capitalization plan and other measures (Article 12 of the Consolidated Supervision Regulation).
- Breaches of limits related to concentration risk (Articles 200 to 211) are considered infractions (Article 219).

### Practical use of powers and enforcement approach
- In practice, SBS heavily relies on moral suasion; files indicate successful early-stage action, particularly on capital requirements and risk management.
- Examples reviewed by assessors where actions were taken (including non-bank deposit-taking institutions):
  - limiting asset growth;
  - requiring Tier 1 capitalization;
  - request for replacement of the CFO;
  - denial of authorizations.
- Cases of non-compliance with recapitalization plans are dealt with either through moral suasion or by making use of Article 349.
- SBS does not have a framework that operationalizes all legal powers into an ordered range of measures by gravity, although in practice it has been able to tackle issues successfully thus far.

### Early intervention thresholds and measures (EC3 and EC4 findings)
- Breaches and thresholds:
  - breach to the minimum regulatory capital ratio (10 percent) for three consecutive months or five alternate months within a year → bank is put under the surveillance regime (Art. 95(2g));
  - a decrease in 40 percent of regulatory capital → bank under the surveillance regime (Art. 95(2h));
  - a 50 percent decrease in regulatory capital → triggers intervention (Article 104).
- EC3 finding: supervisor has power to act where a bank falls below established regulatory thresholds, and can intervene at an early stage to require corrective action; in practice, SBS acts early and effectively, primarily through moral suasion.
- EC4 finding: supervisor has a broad range of measures to address early-stage scenarios, which may include:
  - restricting current activities of the bank;
  - imposing more stringent prudential limits and requirements;
  - withholding approval of new activities or acquisitions;
  - restricting or suspending payments to shareholders or share repurchases;
  - restricting asset transfers;
  - barring individuals from the banking sector;
  - replacing or restricting powers of managers, Board members or controlling owners;
  - facilitating a takeover by or merger with a healthier institution;
  - providing for interim management of the bank;
  - revoking or recommending revocation of the banking license.
- Article 355 empowers SBS, in case of entities with financial instability or management deficiency, to require capital adjustments and cash capital increases, and to suspend for six months (renewable for another six months) entities from performing specified risky operations, including:
  a) to take additional risks of any kind with any related party;
  b) to renew for over 180 days, any operation that implies any risk;
  c) to execute operations that generate new market risk;
  d) to purchase, sell or encumber fixtures or real property corresponding to their fixed assets or to their permanent financial investments;
  e) to transfer financial instruments from their credit portfolio;
  f) to grant credits without collateral;
  g) to grant Powers of Attorney for the execution of the operations set forth in the preceding points.

### Sanctions applied to individuals (EC5 findings)
- The General Law characterizes infractions (Article 356); Art. 361 grants SBS powers to impose sanctions depending on severity, encompassing board members and staff.
- Sanctions applicable to directors and staff include:
  1. fine director or staff, not less than five points UIT or bigger than one hundred.
  2. suspension of the director (board member) or staff in charge, for a term not less than three days or larger than fifteen, and removal in case of relapse.
  3. destitution.

*Source: cr18366-perufsap - 1. admonition;*

### 4. ineligibility of the board member or staff in the case they are deemed

### 4. ineligibility of the board member or staff in the case they are deemed responsible for the events leading to intervention or liquidation.

### Corrective powers, ring-fencing and resolution (EC6, EC7; Principle 11)
- Legal basis and powers:
  - Article 349 (19) of the General Law gives the SBS ample powers to take necessary actions to ensure the safety and soundness of the system.
  - Article 134: SBS attribution to perform consolidated supervision of financial and mixed conglomerates.
  - Article 138 °: as a result of consolidated supervision, SBS can require supervised entities to adopt prudential measures to mitigate inappropriate risks related to transactions with other entities of the group including situations resulting from lack of information where risks cannot be properly assessed.
  - The Consolidated Supervision Regulation (Resolution 11823-2010) establishes capital requirements and limits applicable to conglomerates.
- Findings:
  - SBS has applied sanctions, including ineligibility, over the last several years.
  - SBS is the resolution authority in Peru.
- Assessment (Principle 11): Largely Compliant
- Comments:
  - SBS acts at an early stage to address unsafe and unsound practices; broad legal powers plus a moral suasion culture have enabled effective supervisory action.
  - SBS has experienced senior staff ensuring consistency in corrective actions.
  - SBS would benefit from documenting operational procedures and frameworks for corrective action to assure consistent application.
- Recommendation:
  - Operationalize legal powers into a regulation or procedures comprising a range of supervisory tools to be used depending on the severity of the situation, encompassing its full range of powers including withdrawing a license.

*Source: cr18366-perufsap - 4. ineligibility of the board member or staff in the case they are deemed responsible for the events leading to intervention or liquidation.*

### Consolidated supervision (Principle 12) — overview and EC findings
- Systemic conglomerates and legal perimeter:
  - Peru has two systemic domestic conglomerates.
  - These conglomerates hold on a gross basis 23 and 21.8 percent and on a net basis 6.3 and 13 percent respectively of total assets abroad.
  - Legal framework empowers SBS to exercise full consolidated supervision only from the bank downwards; holding companies are outside the supervisory perimeter.
- EC1 (understanding group structure and activities):
  - SBS gathers information on affiliates (banking and non-banking), domestic and cross-border.
  - SBS has used moral suasion to take action when risks arise from wider group entities.
  - Legal limitations on access to parent and affiliates may jeopardize consolidated supervision in the future.
- EC2 (prudential standards on a consolidated basis):
  - SBS imposes prudential standards on a consolidated basis via the Consolidated Supervision Regulation, including capital requirements and prudential limits (related party exposures and concentration risk).
  - There are no liquidity requirements on a consolidated basis.
  - Corporate governance and risk management framework are not applied at the holding level.
  - Consolidated Supervision Regulation specifics:
    - Shortfalls < 20 percent of consolidated capital requirement: supervised entities must ask authorization to distribute dividends.
    - Shortfalls > 20 percent: suspension of dividends.
    - Breaches of concentration or related party limits: require authorization prior to dividend distributions.
    - Article 20 requires supervised entities to submit consolidated information including financials, capital requirement calculations, related party transactions and concentration limits.
  - A special unit within SAR compiles and monitors consolidated information and submits to the Consolidated Supervision Committee (including insurance and pension fund supervisors).
- EC3–EC5 (oversight of foreign operations, visits, and parent company activities):
  - SBS reviews oversight of foreign operations; cross-border operations are part of supervisory approach.
  - SBS performs on-site examinations abroad every year, meeting local supervisors; these entities are legally outside the supervisory perimeter but examined de facto.
  - Effectiveness of host-country supervision is considered when setting supervisory approach and depth.
  - SBS has gathered significant information on parents and affiliates via information requests, meetings with holdings, and public information; supervisory actions have focused on ensuring consolidated capital levels.
- EC6 (limiting group activities and locations):
  - SBS does not have legal power to limit the range of activities or locations for consolidated groups (supervisory perimeter is the entity downwards only).
  - SBS may use moral suasion to limit activities if needed.
- EC7 (supervision of individual banks in the group):
  - SBS supervises individual banks on a stand-alone basis and gathers extensive individual-level information; relationships with other group members are examined via contracts and meetings.
- Assessment (Principle 12): Largely Compliant
- Comments:
  - SBS acts “de facto” as home supervisor and conducts systematic examinations of financial subsidiaries outside its legal perimeter.
  - Key shortcomings stem from legal limitations: inability to enforce requirements directly on holding companies; significant cross-border operations held via holdings.
  - Holding companies can invest in non-financial entities whose risk management and controls are not under SBS formal scrutiny.
  - Governance, liquidity, and overall risk management supervision at the holding/group level needs enhancement (see CPs 14, 15, 16 and 24).
- Recommendation:
  - Amend the legal framework to enable full exercise of consolidated supervision.
  - Enhance consolidated supervision approach to governance, overall risk management, capital and liquidity risk management as detailed in CPs 14, 15, 16 and 24.

### Home-host relationships (Principle 13) — EC findings and assessment
- Cross-border exposures and supervisory colleges:
  - Cross-border operations concentrated in the two systemic conglomerates represent almost on a net basis 11 and on a gross basis 22 percent of total assets.
  - For one conglomerate, SBS conducted its first supervisory college in June 2017 (participants: SBS, SMV, FED, Cayman Islands, Panama, Colombia and Chile); all participants signed a confidentiality agreement.
- EC2 (information sharing):
  - MoUs and informal arrangements exist with multiple jurisdictions (listed in source).
  - MoUs in place include Canada, Colombia, Ecuador, Spain, Mexico, Panama, Bahamas, China, El Salvador, Venezuela, Bolivia, Guatemala, Italia, Nicaragua and Brazil.
  - There are no formal arrangements with the US, Chile, Panama, Cayman Islands; informal arrangements are used effectively.
  - SBS systematically participates in colleges of Scotiabank and BBV.
  - SBS conducts joint examinations abroad and shares inspection summaries with host supervisors.
- EC3 (coordination of supervisory activities):
  - Joint examinations are common; cross-border visits include branches, subsidiaries and affiliates with preliminary and final meetings with host supervisors.
  - Inspection reports with recommendations are submitted to entities and copies of summaries shared with host authorities.
  - As a host supervisor, instances of home supervisors examining in Peru are rare but coordination occurs when they do.
- EC4 (communication strategy):
  - Communication strategy is anchored on cross-border examinations; summaries of findings are shared between supervisors; communication to banks is done separately.
  - First college on CrediCorp was conducted in 2017.
- EC5 (cross-border crisis cooperation):
  - SBS is yet to develop a framework for cross-border crisis cooperation and coordination.
  - Recently signed MoUs include clauses related to crisis management; SBS plans to incorporate such clauses into other MoUs.
- EC6 (group resolution plans):
  - SBS is yet to develop group resolution plans for its two systemic domestic conglomerates.
- EC7 (host treatment of foreign banks):
  - Foreign banks operating in Peru are subject to the same legal and regulatory framework as domestic banks.
  - Currently no cross-border operations of foreign banks operating in Peru.
  - Article 6 of the General Law forbids SBS to issue regulations that provide different treatment for companies of same nature.
- EC8–EC10 (on-site access, booking offices, consequential action coordination):
  - SBS reports no impediments to home supervisors’ access to local offices when coordinated under MoUs.
  - Legal/regulatory framework does not allow booking offices or shell banks; establishment of banks/branches requires SBS authorization (Licensing Regulation – Resolution 10440-2008) including feasibility study and fit and propriety checks.
  - SBS coordinates with domestic and foreign supervisors, to the extent possible, before taking consequential actions based on information from another supervisor.
- Assessment (Principle 13): Compliant
- Comments:
  - SBS actively cooperates with home and host supervisors.
  - Cross-border operations concentrated in two systemic conglomerates represent on a net basis 11 and on a gross basis 22 percent of total assets.
  - SBS acts de facto as home supervisor despite legal perimeter limitations.
  - Resolvability and crisis handling aspects have been considered in the rating of CP 8.
- Recommendation:
  - Establish Crisis Management Groups for the two systemic conglomerates.

### Corporate governance (Principle 14) — EC1–EC5 findings
- Legal and regulatory framework:
  - Peruvian companies have a two-tier governance structure: Supervisory Board oversees Executive Management; CEO can be part of the Board; Chair can perform executive functions.
  - LGSF (Articles 84, 87, 90, 93, 94) establishes Board and CEO basic responsibilities and requires monthly Board meetings; CEO must inform Board at least quarterly and monthly on credit and investment portfolio developments and violations of SBS limits.
  - GIR (Comprehensive Risk Management Regulation - Resolution SBS No. 37-2008) applies to all Supervised Institutions (SIs) and details Board and senior management responsibilities, Board Committees, CRO role, outsourcing, internal/external audit, whistleblowing and compliance.
  - Corporate Governance & GIR (Resolution SBS No. 272-2017) issued February 2017 will replace GIR per April 2018; it enhances independent Board member requirements, Board committee composition, introduces Remuneration Committee, succession planning, and Board effectiveness self-assessment.
  - The GIR and Corporate Governance & GIR do not apply to the holding or the financial group of conglomerates for which SBS is the home supervisor; Consolidated Supervision Regulation (Resolution SBS 11823) has less detailed group requirements.
- EC1 (responsibilities and guidance):
  - GIR Article 8 enumerates Board responsibilities (a)–(k) including approving risk policies, selecting suitable managerial staff, approving resources for risk management, establishing incentive systems, approving manuals/policies, establishing business objectives, ensuring capital sufficiency, and obtaining reasonable assurance that main risks are under control.
  - Article 9 requires Board members to individually declare compliance with regulation and include deficiencies and planned actions.
  - The Corporate Governance & GIR will require independent Board members (minimums) and Board regulations (Article 5) and will apply proportionality across SIs.
  - Supervised banks, particularly top four, are largely compliant and expected to be fully compliant by April 2018.
  - SBS guidance on group-wide corporate governance is less developed.
- EC2 (assessment and corrective action):
  - SBS rating methodology uses 7 building blocks: i) Solvency; ii) Credit risk; iii) Liquidity risk; iv) Market risk; v) Operational risk; vi) Profitability and efficiency; and vii) Management and control.
  - Governance elements are assessed per risk type and overall under “Management and control” which covers strategic management, suitability of Board and senior management, quality of internal audit, AML/CFT, transparency, and compliance function.
  - SBS uses a Self-assessment Questionnaire of Good Corporate Governance Practices sent two months before annual on-site exams; results are input to on-site examination.
  - On-site supervision manual No. B.1.PS – GC01 details assessment criteria; interaction with Boards has mostly been limited to an annual meeting with one independent Board member.
  - Corporate governance of groups (for which SBS is home supervisor) is not explicitly covered but SBS is gradually incorporating group aspects into self-assessment and inspections.
- EC3 (nomination and Board composition):
  - Article 79 LGSF: at least 5 Board members; Article 81 provides suitability and impediment rules.
  - Corporate Governance & GIR (effective April 2018) details Board regulations, independent member minimums, and Board Committee structure; Audit Committee must be chaired by an independent member but Risk Committee is not required to have an independent chair or majority.
  - Banks expected to apply international best practices and largely comply with new regulations.
  - Procedures for nominating/appointing Board members at group level are not reviewed by SBS.
- EC4 (duties of Board members; suitability and approval process):
  - LGS Article 171 contains duty of care and duty of loyalty.
  - Article 81 LGSF requires suitability (technical and moral) and absence of legal impediments.
  - Article 82 LGSF: elections and vacancies must be reported to SBS within one business day with certified minutes.
  - Supplementary Rules (Resolution SBS No. 1913-2004) require notifying SBS of Board members, senior managers and Internal Auditors with CVs and affidavits; reporting done via REDIR.
  - Corporate & GIR Article 4 requires Board composition with specialisms and competencies; independent members can serve at group and subsidiary levels.
  - REDIR information is reviewed off-site; SBS evaluates knowledge and experience and cross-checks external sources (Public Prosecutor, Judicial Branch, Worldcheck).
  - SBS does not as standard inquire with foreign supervisors about adverse information on appointees who worked abroad.
  - Interviews of proposed Board members are not standard; engagement with independent Board members is largely limited to one meeting per year.
- EC5 (Board oversight of strategy, risk appetite, culture, conflicts):
  - Self-assessment questionnaire includes Board responsibilities alignment with GIR Article 8, formalization in regulations, compliance, Board sign-off, oversight of senior management performance, approval of policy/strategy modifications, establishment of corporate values and Code of Ethics and Conduct.

*Source: cr18366-perufsap - 4. ineligibility of the board member or staff in the case they are deemed responsible for the events leading to intervention or liquidation.*

### section 5.2 contains self-assessment questions on the establishment of a mechanism

### cr18366-perufsap - section 5.2 contains self-assessment questions on the establishment of a mechanism

### Mechanism for dealing with conflicts of interest
- Section 5.2 contains self-assessment questions on the establishment of a mechanism for dealing with conflicts of interest.
- The corporate governance on-site examination manual evaluates the institution’s mechanisms for dealing with conflicts of interest in procedure 2.12.
- Review of the minutes of the Board and its main Committees plays an important role in the evaluation of these procedures.
- The results of this assessment feed into the used rating methodology.

### Board responsibilities, fit-and-proper standards, and related supervisory tools (EC6–EC9)
- Regulatory framework and instruments:
  - GIR (article 8) assigns Board responsibility for selecting senior management with technical and moral suitability and for ensuring effective management of risks.
  - New Corporate Governance & GIR (SBS Resolution No. 272-2017), effective per April 1, 2018, includes more specific Board responsibilities regarding succession planning and requires approval of the risk appetite system (article 7 sub h).
  - LGSF articles 93 and 94 require the CEO to inform the Board monthly on credit and investment risk developments and at least quarterly on general business developments.
  - Articles 381 and 199 of the LGSF: article 381 gives the SBS power to take necessary measures to prevent/avoid unqualified persons controlling or participating in the Board, management and operation of SIs; article 199 requires institutions to have a process for evaluating adequacy of capital considering the institution’s risk profile and requires the Board to maintain effective capital above the minimum required level.
- Supervisory tools and procedures:
  - Self-evaluation Questionnaire of Good Corporate Governance Practices for Financial System Companies includes:
    - Section 7: self-assessment questions on establishment of suitability standards for selection of senior management and succession planning.
    - Sections 1.2.a and 1.3: self-assessment questions on Board oversight of senior management performance and Board approval of policy/strategy modifications.
  - Corporate governance on-site examination manual (In situ No. B.1.PS – GC01) procedures:
    - Procedure 2.2: evaluation of the Board’s compliance with responsibilities and functions (article 8 of the GIR).
    - Procedure 2.3 and 2.20: evaluate Board oversight on monitoring/evaluation of senior management performance and existence/substance of criteria for moral and technical suitability and succession planning.
    - Procedure 2.4: evaluates the Board’s involvement in approval of strategy and related policies.
    - Procedure 2.5: evaluates whether Board has approved and is promoting compliance with a Code of Ethics and Conduct.
    - Procedure 2.12: evaluates institution’s mechanisms for dealing with conflicts of interest.
  - Review of Board and Committee minutes is systematically used in on-site examinations.
- Findings and supervisory practice:
  - Supervisory practice mainly focuses on checking appointed Board members are not subject to impediments in the LGSF; cases were reviewed where SBS formally required removal of Board members due to impediments.
  - For other deposit-taking institutions, SBS provided examples of realized Board changes via informal communication.
- Assessment and comments on Principle 14:
  - Assessment: Largely Compliant.
  - Key observations:
    - SBS governance requirements do not apply on a group-level for groups for which SBS is home supervisor; group Board members are not subject to formal fit and propriety review by the SBS and are not required (GIR, article 9) to sign-off on responsibilities as required for Board members of supervised institutions.
    - Two of the four systemically important commercial banks are part of groups for which the SBS is the home supervisor.
    - SBS places significant emphasis on corporate governance of licensed institutions, but actual engagement with Boards and individual Board members could be further enhanced; current engagement mainly relies on review of minutes.
    - New Corporate Governance & GIR sets expectation of periodic Board effectiveness self-assessment, but SBS has not developed clear expectations on standards, internal framework for assessing collective suitability, or assessment criteria for expected seniority and experience for key Board positions.
    - Independent Board members at group level may also act as independent members at subsidiary level, which could lead to divided loyalties in certain situations.

### Risk management process and supervisory assessment (Principle 15; EC1–EC2)
- Overarching framework:
  - Comprehensive Risk Management Regulations (“GIR” - SBS Resolution No. 37-2008) require supervised institutions to have comprehensive risk management processes and Board-approved policies and procedures to identify, measure, monitor, control and report risks. The GIR will be replaced per April 2018 by Corporate Governance & GIR (SBS Resolution No. 272-2017).
  - Corporate Governance & GIR emphasizes Board responsibility for principal objectives and strategy (article 7 sub a) and Board approval of the risk appetite system (article 7 sub h).
  - Corporate Governance & GIR (article 17 sub a) establishes senior management responsibilities to assure activities are consistent with strategy, risk appetite, corporate culture and values, market conduct and Board-approved policies, and to periodically inform the Board on alignment status.
- Specific risk regulations issued by the SBS (as referenced):
  - SBS No. 3780-2011 on Credit Risk Management
  - SBS No. 041-2005 on the Administration of Foreign Exchange Induced Credit Risk
  - SBS No. 6941-2008 on the Administration of Over-Indebted Retail Clients
  - SBS No. 7932-2015 on Country Risk Management
  - SBS No. 0509-98 on Market Risk Management
  - SBS No. 1455-2003 on the Administration of Foreign Exchange Risk
  - Circular B 2087-2001 on Interest Rate Risk Management
  - Resolution SBS No. 9075-2012 on Liquidity Risk Management
  - SBS No. 2116-2009 on Operational Risk Management
  - Circular SBS No. 139-2009 on Business Continuity Management
  - Circular SBS No. 140-2009 on Information Security Management
  - Resolution SBS No. 2660-2015 on AML/CFT Risk Management
  - SBS No. 11823-2010 Consolidated Supervision Regulation
- Application and scope:
  - These regulations contain requirements for organization and responsibilities of the risk management function, Board oversight, risk identification, evaluation, mitigation, control, monitoring, and reporting requirements set by the SBS.
  - The regulations apply to licensed/supervised institutions and not on a group-wide basis. The Consolidated Supervision Regulation (article 26) requires the supervised institution to assure that the financial group implements adequate risk management strategies and policies and refers in article 27 to the GIR.
  - Some terminology across regulations predates the Corporate Governance & GIR and may need standardization, but this has not affected practical effectiveness.
- Supervisory assessment methods:
  - SBS rating methodology consists of 7 building blocks: Solvency, Credit risk, Liquidity risk, Market risk (incl. IRRBB), Operational risk, Profitability and efficiency, and Management and control.
  - Overarching risk management requirements are part of the assessment of management and control; credit, market, liquidity and operational risk rating methodology also assess Board oversight and risk management for specific risks.
  - Management and control, credit risk and profitability and efficiency are standard components of on-site examinations; liquidity, market and operational risk follow a risk-based approach and cycle. Capital is annually reviewed as part of the supervisory review of the ICAAP.
  - The SBS sends a self-assessment (Self-assessment Questionnaire of Good Corporate Governance Practices for Financial System Companies) in advance of annual on-site examinations and requires banks to finalize it one month before the on-site inspection. The self-assessment includes Board oversight, senior management responsibilities and risk management and control questions and feeds into on-site inspection (manual GC01).
  - Section 2 of GC01 contains procedures for evaluation of the Board regarding integrated risk management; section 3 contains procedures for evaluation of organization and risk culture of the risk management unit.
  - Detailed risk management regulations correspond with other on-site examination manuals and procedures that review Board oversight and management of each material risk.
- ICAAP and supervisory expectations:
  - SBS requires banks to submit an ICAAP through an Office Multiple since 2010.
  - The ICAAP guidance is annually updated, including prescribed standard stress test parameters banks must use for ICAAP.
  - The SBS requires that at a minimum the ICAAP report covers specified elements (the source text indicates the list follows).

### Recommendations (extracted from assessment comments)
- Apply at a group-level, for groups for which the SBS acts as home supervisor, the same governance and fit and propriety requirements as applied to licensed institutions.
- Enhance the requirements regarding the composition of the Board committees (number of independent Board members and having an independent Board member as Chair).
- Board engagement needs to be further intensified.
- The SBS should develop a framework for assessing the collective suitability of the Board and assessment criteria in terms of expected seniority and experience for key Board positions (e.g. Chair, Chair of the Risk Committee, Chair of the Audit Committee).

*Source: cr18366-perufsap - section 5.2 contains self-assessment questions on the establishment of a mechanism*

### 1. Capital planning and monitoring process

### 1. Capital planning and monitoring process

### 2. Capital adequacy level of the institution
- a) Base scenario
- b) Calculation of capital requirements for all material risks
  - (1) Credit risk
  - (2) Market risk
  - (3) Operational risk
  - (4) Additional capital buffers (by regulation)
    - (a) Countercyclical buffer
    - (b) Credit concentration risk
    - (c) D-SIB buffer (see also CP 16)
    - (d) Interest Rate Risk in the Banking Book
    - (e) Propensity to risk (comparing general provisions with average historic impairment losses)
  - (5) Other material risks
- c) Projections of indicators
- d) Aggregation of capital requirements
- e) Access to capital and quality of capital
- f) Determination of internal capital target
- g) Projection of available capital

### 3. Stress-testing
- a) Description of assumptions and methodology
- b) Evaluation of results

### 4. Sensitivity analysis
- (Item listed: Sensitivity analysis)

### 5. Conclusions
- (Item listed: Conclusions)

*Source: cr18366-perufsap - 1. Capital planning and monitoring process*

### 6. Evaluation of the previous ICAAP

### 6. Evaluation of the previous ICAAP

### Evaluation procedures and supervisory review
- The supervisory review of the ICAAP largely takes place off-site; on-site follow-up is performed if pertinent issues arise.
- The ICAAP needs to be signed off by the CRO and the Head of the Unit responsible for the preparation and approved by the Board.
- In the supervisory review, the SBS compares ICAAP results against the top-down stress-test performed by the SAEE, the institution’s risk profile, and SBS’ internal risk rating.
- The SBS monitors banks’ actual regulatory capital ratio against banks’ internal targets in its quarterly off-site report.
- Detailed procedures for the supervisory review of the ICAAP are documented in a separate manual.

### EC3—Risk management strategies, policies, processes and limits
- Supervisor determines that strategies, policies, processes and limits are:
  - (a) properly documented;
  - (b) regularly reviewed and appropriately adjusted to reflect changing risk appetites, risk profiles and market and macroeconomic conditions;
  - (c) communicated within the bank.
- Exceptions to established policies, processes and limits require prompt attention and authorization by appropriate management and the Board where necessary.
- Findings:
  - All Board members must sign-off on compliance with responsibilities in the GIR and Corporate Governance & GIR, including approval of risk appetite and policies.
  - GIR/Corporate Governance & GIR do not explicitly require periodic updating, internal communication, and exception reporting, but these are incorporated in more detailed risk management regulations.
  - SBS on-site examination manuals and review of Board minutes and underlying documentation verify that policies and procedures for material risks are established, regularly updated, communicated and implemented.
  - Assessors reviewed on-site examination documentation substantiating actual use of on-site procedures.

### EC4—Board and senior management information and understanding
- Supervisor determines that Board and senior management obtain sufficient information on and understand risks and how they relate to adequate capital and liquidity, and that they regularly review implications and limitations of risk information.
- Findings:
  - SBS verifies through review of minutes and supporting documentation that business and risk management functions provide timely, adequate and permanent information to the Board and Committees.
  - SBS verifies implementation of Board-approved policies and limits during on-site examinations.
  - Regulations/procedures do not explicitly require the Board or senior management to regularly review implications and limitations of risk management information.

### EC5—Internal capital and liquidity adequacy processes (ICAAP/ILAAP)
- Supervisor requires banks to have appropriate internal processes for assessing capital and liquidity adequacy and reviews these assessments and strategies.
- Findings:
  - Banks are required since 2010 to submit an annual ICAAP.
  - SBS provides detailed and annually updated guidance on ICAAP expectations; supervisory review procedures are in a separate manual.
  - Assessors reviewed sample ICAAPs, supervisory review reports, and formal supervisory communications.
  - ICAAP review results currently feed qualitatively into assessments of management and control and solvency; they are not yet part of the existing rating methodology.
  - Inclusion of ICAAP in the rating methodology is foreseen in the next version expected to be implemented in 2019.
  - There is no Internal Liquidity Adequacy Assessment Process (ILAAP) requirement.
  - For liquidity assessment, SBS relies on the on-site liquidity risk supervision manual; banks report liquidity positions and ratios daily to the SBS.
  - Quarterly, banks must submit results of a standardized stress-test and their liquidity contingency plan.
  - Off-site liquidity monitoring and on-site liquidity assessments feed into the liquidity risk rating, one of the 7 components of the rating methodology.

### EC6—Use and governance of risk models
- Supervisor determines banks comply with supervisory standards on models, Boards and senior management understand model limitations and uncertainties, and banks perform regular independent validation and testing.
- Findings:
  - SBS allows internal models for credit, market and operational risk and has set standards: Resolution SBS 14354-2009 (credit), Resolution SBS No. 6328-2009 (market), Resolution SBS No. 2115-2009 (operational).
  - Currently none of the banks are using advanced models; SBS has no application in process.
  - Other models requiring SBS approval exist (e.g., country risk provisioning using banks’ own country classification methodologies).
  - Banks use internal credit scoring, regulatory VaR for FX risk, and regulatory methodologies to assess liquidity and IRRBB.
  - The SAR has specialized units and on-site procedures for reviewing these models.
  - GIR/Corporate Governance & GIR do not provide an expectation that the Board or senior management regularly review model output limitations and uncertainties.
  - Clarifying this expectation and improving model governance for internal models (other than those used for regulatory capital) would enhance the framework.

### EC7—Information systems and reporting
- Supervisor determines banks have adequate information systems to measure, assess and report exposures across all risk types and that reports reflect risk profile, capital and liquidity needs and are timely for Board and senior management.
- Findings:
  - SIs must periodically send standardized prudential reports and annexes; information systems must support this.
  - Debtors Credit Overview Report (“RCD” Annex 6) requires banks to report standardized information on borrowers with exposures above PEN 1.00; validated data feeds into the Credit Registry.
  - SBS applies controls to assess validity and consistency of credit risk and asset quality reports, and selectively reviews reported information during annual on-site examinations.
  - On-site examinations verify provision of timely, adequate information to senior management and the Board via review of Board Risk Committee minutes and supporting documentation.
  - SBS has a Department of Information Systems and Technologies Supervision to evaluate reliability and integrity of information under normal and stress conditions.
  - SBS indicated data quality of prudential reports is relatively high; required corrections in recent years have not resulted in material changes to initial reported positions.

### EC8—New products and major initiatives
- Supervisor determines banks have policies and processes to ensure Boards and senior management understand risks of new products, material modifications, and major initiatives, and that major activities require Board approval.
- Findings:
  - Article 18 of the GIR (Article 25 of Corporate Governance & GIR) requires the risk unit to inform the Risk Committee about risks associated with new products and important changes prior to launch, and proposed mitigation measures.
  - Circular No. G-165-2012 requires SIs to report to SBS their assessment of risks of new products or important changes, specifying minimum content including types of associated risks (credit, ML/FT, liquidity, market, technical, reassurance, strategic and operational risks) and mitigation measures.
  - Off-site, SABM and SAR evaluate risk reports for new products/changes; on-site, SBS verifies Board/Risk Committee approvals via minutes.
  - Specialized SBS units selectively verify compliance with regulatory requirements for product launch risk assessments.
  - SAR evaluates ML/FT risk assessments for new products; compliance officer reports semiannually to the chairman of the board.

### EC9—Risk management function resources, independence and reporting
- Supervisor determines banks have risk management functions covering all material risks with sufficient resources, independence, authority and access to Boards, segregated from risk-taking functions and subject to internal audit review.
- Findings:
  - Article 3 of the GIR (article 20 Corporate Governance & GIR) requires comprehensive risk management identifying all risks and ensuring management within risk appetite.
  - GIR and Corporate Governance & GIR require Board Risk Committee, independent centralized integrated risk unit, and a CRO reporting directly to the Board Risk Committee.
  - Internal Audit Regulation (Resolution SBS No. 11699-2008) requires internal audit to review the risk management function with minimum requirements in the Annex.
  - SBS issues a self-assessment questionnaire for good corporate governance practices; banks must finalize one month before on-site inspection.
  - On-site evaluation procedures (GC01) include assessment of Board integrated risk management and organization/risk culture of the risk management unit.
  - On-site results feed into the assessment of management and control in the internal rating methodology.
  - SBS requires remediation of deficiencies in risk governance and resources when needed.

### EC10—CRO and senior manager appointment/removal and disclosure
- Supervisor requires larger/complex banks to have a dedicated risk management unit overseen by a CRO; removal of CRO should be with Board approval and discussed with supervisor.
- Findings:
  - All banks are required to have a dedicated risk management unit overseen by a CRO per GIR/Corporate Governance & GIR.
  - Article 187 of the LGS (Law No. 26887) establishes senior management (including CRO) may be removed only by the Board or general meeting of shareholders; provisions making managers irrevocable or harder to remove are void.
  - Resolution SBS No. 1913-2004 requires supervised institutions to inform SBS of elections/appointments/vacancies of Board members, senior managers and internal auditors within no more than one day, including certified minutes excerpts.
  - Although SBS regulations do not contain explicit disclosure requirements for removals, listed banks must meet disclosure requirements in Regulation of Facts of Importance and Reserved Information (Resolution SMV No. 005-2014-SMV / 01) as issued by SMV, which covers appointment, removal and changes in Board and senior management.

### EC11—Standards for material risk types
- Supervisor issues standards related to credit risk, market risk, liquidity risk, interest rate risk in the banking book and operational risk.
- Findings:
  - SBS has issued detailed risk management regulations per material risk type and capital requirements for credit, operational and market risk.
  - SBS has additional capital requirements for large exposures, sectoral and geographical concentration risk, interest rate risk in the banking book and propensity to risk.

### EC12—Contingency arrangements and recovery planning
- Supervisor requires banks to have contingency arrangements and assesses their adequacy; recovery plans expected for systemically important banks where warranted.
- Findings:
  - ICAAP requires banks to provide an overview of capital planning and contingency capital plan; SBS reviews stress scenario results (SBS prescribes parameters), assumptions, capital quality and additional sources.
  - SBS requires contingency plans for operational, business continuity and liquidity risk; evaluated off-site and on-site.
  - SBS established a working group for market-wide business continuity stress testing in 2012; exercises: 2014 (12 banks, earthquake scenario) and 2017 (23 institutions).
  - Banks must submit quarterly liquidity stress-testing results and contingency plans (Annex No. 16-B); specialized SBS unit verifies reasonableness and consistency with funding sources and resources.
  - When warranted by risk profile, FIs must submit action plans to redress capital or other deficiencies; plans are evaluated in- and off-site.
  - There are currently no formal requirements for recovery plans as described in the Key Attributes for Effective Resolution Regimes (FSB, October 2014).

### EC13—Forward-looking stress testing
- Supervisor requires forward-looking stress testing commensurate with risk profile and assesses bank programs for capture of material risks and scenario plausibility.
- Findings:
  - GIR/Corporate Governance & GIR do not contain explicit stress-testing requirements, but Article 349 of the LGSF and article 8 of the GIR require banks to perform a comprehensive severe stress test with SBS-prescribed parameters as part of ICAAP.
  - SBS compares banks’ ICAAP stress results with SAEE stress-test results during supervisory review.
  - Specific regulations require risk assessments and stress tests for credit, FX-induced credit risk, country, market, IRRBB and liquidity risks; results reported to SBS and methodologies reviewed on-site.
  - On-site supervision verifies reporting and discussion of stress test results at Board/Risk Committee level and recommends corrective actions where needed.

### EC14—Risk accounting in pricing, performance and product approval
- Supervisor assesses whether banks account for risks (including liquidity impacts) in internal pricing, performance measurement and new product approval.
- Findings:
  - On-site supervision manuals by business lines include sections for evaluation of pricing methodology, procedures, granting preferential rates, and tools for calculating prices and profitability.
  - Circular G-165-2012 requires risk reports for new products or major changes, to be sent to SBS and approved by the Risk Committee or specialized committee; these reports must include applicable risks including operational risk.

### Assessment of Principle 15 (Risk management)
- Overall assessment: Largely Compliant.
- Comments:
  - Regulatory framework is tailored to Peru’s circumstances and sets clear expectations for material risks.
  - GIR and its successor do not apply on a group-wide basis; Consolidated Supervision Regulation partially addresses this but indirect regulation is not optimal.
  - SBS reviews models in practice but could enhance the framework with model governance guidelines; SBS is working on a proposal covering: i) relationship between model management and risk appetite; ii) responsibilities in model management; iii) development, validation, approval and monitoring processes; iv) supporting documentation; v) processes of outsourcing and system support.
  - No formal requirements for recovery and resolution plans for D-SIBs; capital and liquidity contingency plans based on stress-testing provide a starting point.

- Recommendations:
  - Develop and issue guidelines for model governance including the expectation for the Board and senior management to review the limitations and uncertainties relating to the output of the models and the risk inherent in their use;
  - Implement requirements for recovery and resolution planning for D-SIBs.

### Principle 16—Capital adequacy (introductory findings)
- Principle summary: Supervisor sets prudent and appropriate capital adequacy requirements reflecting risks; supervisor defines components of capital with emphasis on loss-absorbing elements.
- EC1—Laws, regulations or supervisor require banks to calculate and consistently observe prescribed capital requirements and define qualifying components of capital.
- Findings:
  - Minimum capital requirement is 10 percent and is based on the Basel II definition for capital and the Basel II risk weights (with some conservative amendments) for credit (Resolution SBS No. 14354-2009), market (Resolution SBS N° 6328-2009) and operational risk (Resolution SBS No. 2115-2009).
  - Article 16.A of the LGSF establishes minimum entry capital for deposit-taking institutions.
  - Article 199 of the LGSF establishes that the capital adequacy ratio must always be equal to or greater than 10 percent of the sum of: (1) capital requirements for market risk multiplied by ten; (2) capital requirements for operational risk multiplied by ten; and (3) risk-weighted assets for credit risk including off-balance sheet items.
  - Article 199 also establishes the Board’s responsibility to ensure buffers above minimum requirements to absorb economic cycle fluctuations considering the institution’s risk profile.
  - Article 184 of the LGSF provides the capital definition (Basel II based and includes Tier 3 capital); Article 185 provides Basel II based limits for Tier 2 capital, subordinated debt and Tier 3 capital.
  - Resolution N. 975-2016 provides criteria for subordinated debt to qualify as Tier 1 (perpetuity and loss absorption), and introduces a 1000 percent risk weight for Deferred Tax Assets (when more than 10 percent of available capital) and for intangible assets (excluding goodwill, which is deducted from regulatory capital); transitional period from 2017 to 2026 with risk weights gradually increasing from current Basel II risk weight to 1000 percent.
  - Additional Capital Requirements Regulation (Resolution SBS No. 8425-2011) requires banks to hold non-cyclical and counter-cyclical capital buffers; methodology differs from Basel but aims for similar objectives as Basel III.
  - Instead of the 2.5 percent Capital Conservation Buffer (CCB) in Basel III, SBS implements a CCB composed of five specific risk elements; actual buffer varies by balance sheet composition and risk profile. The CCB comprises:
    - Single name concentration risk maximum add-on of 0.4 percentage points (of RWAs);
    - Sector concentration risk maximum add-on of 1.6 percentage points;
    - Geographical concentration risk maximum add-on of 0.4 percentage points;
    - Interest Rate Risk in the Banking Book (IRRBB) add-on required if the Economic Value of Equity changes by more than 15 percent after a prescribed interest rate shock;
    - Propensity to risk buffer for banks with high historic specific provisions.
  - For D-SIBs, SBS methodology requires banks with assets larger than three percent of GDP to hold an additional buffer calculated as a function of: i) external rating; ii) assets to GDP; iii) assets to total assets of deposit taking institutions. In practice the resulting buffer varies from 0.1 to [text truncated in source].

*Source: 6. Evaluation of the previous ICAAP (cr18366-perufsap).*

### 0.6 percentage points for the 4 dominant commercial banks.

### cr18366-perufsap - 0.6 percentage points for the 4 dominant commercial banks.

### Countercyclical buffer (CCyB) and capital framework
- The implemented Counter-Cyclical Buffer (CCyB) is a function of per asset class differentiated additional credit risk weights varying from zero for governments exposures to 55 percent for revolving consumer loans. Thus, and unlike the Basel III CCyB, the buffer varies across institutions depending on their balance sheet composition.
- Activation rule:
  - The countercyclical buffer is activated if the moving average of the annual GDP growth over a period of 30 months is higher than 5 percent.
  - Financial institutions must comply within 12 months after the buffer is activated.
  - After deactivation, banks may use the buffer only after they have used their countercyclical provisions (see CP 18); they can use 60 percent of the buffer. For using the remaining 40 percent, a capital plan and the approval of the SBS is needed.
- Supervisory discretion:
  - The Additional Capital Requirements Regulation provides the SBS the power to not release the countercyclical buffer when deactivated in case of observed weaknesses in governance and risk management.
  - The SBS expects banks to establish in their ICAAP internal capital targets above the additional required buffers, including the countercyclical buffer, even while currently deactivated.

### Capital requirements — table (as provided)
- Capital Requirements Peru Compared to the Basel III framework (Jun-2017)
  - Peru - All Banks (Min / Max): Min. Req. 10.0% / 10.0%; CCB 0.8% / 4.3%; CCyB* 0.7% / 5.0%; D/G-SIB 0.0% / 0.6%; Total** 11.8% / 16.6%
  - Peru - D-SIBs (Min / Max): Min. Req. 10.0% / 10.0%; CCB 1.0% / 1.1%; CCyB* 1.7% / 2.0%; D/G-SIB 0.1% / 0.6%; Total** 13.0% / 13.3%
  - Basel III (Min / Max): Min. Req. 8.0% / 8.0%; CCB 2.5% / 2.5%; CCyB* 0.0% / 2.5%; D/G-SIB 0.0% / 2.5%; Total** 10.5% / 15.5%
- Notes:
  - Source: SBS
  - * Considers the numbers of CCyB if the cyclical rule was activated.
  - ** Corresponds to the total required capital considering as the cyclical rule was activated.

### Domestic systemically important banks (D-SIBs) and additional capital charges
- Methodology:
  - Additional capital requirements for D-SIBs are a function of external rating, total assets divided by GDP, and total assets divided by total assets of the financial system.
  - All banks with total assets more than 3 percent of GDP attract an additional capital charge under this methodology.
- Current outcomes:
  - Using this methodology currently 5 banks attract a capital charge for systemic risk.
  - The top 4 commercial banks (accounting for approx. 75 percent of the assets of deposit taking institutions) attract an addition capital charge of well below 1 percentage point (explicitly cited elsewhere as 0.6 percentage points for the 4 dominant commercial banks).
- SBS recognition:
  - The SBS recognizes the methodology results in very limited additional capital requirements for the D-SIB buffer and for single name concentration risk and is in the process of reviewing and recalibrating these methodologies.

### Definition and quality of capital; capital assessment practices
- Main differences with Basel:
  - The definition of capital is still based on Basel II rather than the full Basel III capital definition.
  - In practice the average Common Equity Tier 1 ratio of the banking system is more than 10 percent.
  - SBS Resolution N. 975-2016 provides criteria for subordinated debt to qualify as Tier 1 and introduces a risk weight of 1000 percent for Deferred Tax Assets and intangible assets.
- Supervisory review:
  - SBS reviews the quality of capital in the SREP/ICAAP review and considers capital quality in supervisory actions; has required increases in high quality capital where needed.
  - In case of (non-operating) holding companies, minimum capital requirements are only indirectly applicable to the financial group via the subsidiary.
- Improvements suggested:
  - Consolidated capital adequacy assessment could be improved by also considering:
    - i) capital adequacy of the holding on a solo level (to determine if excess capital is available on the holding level);
    - ii) the location of capital within the conglomerate, including the risk of ringfencing/non-transferability of capital allocated to entities supervised by authorities abroad;
    - iii) the extent to which excess capital at a group level can be completely allocated to support the financial activities of the conglomerate.
  - Current consolidated assessment does not adequately account for adjustments related to differences in accounting standards between solo financials (SBS accounting) and consolidated financials (IFRS).

### Supervisory powers and intervention thresholds
- Legal powers:
  - Article 349 of the LGSF empowers the SBS to perform all acts necessary to safeguard solvency of the financial system and savings of the public.
  - Article 355 allows SBS to determine real value of assets and, if necessary, require regulatory capital adjustments and immediate shareholder cash capital contributions.
- Grounds for special supervisory regime (Article 95 of the LGSF):
  - a) Failure to comply with reserve requirements for three consecutive periods, or in more than 5 months over a period of 12;
  - b) Need to resort to financing of obligations indicating structural financial insufficiency for fulfillment of the reserve (in the opinion of SBS);
  - c) Need to resort to liquidity support from the Central Bank for more than 90 (ninety) days in the last 180 (one hundred and eighty) days;
  - d) A breach of the different large exposure limits established in articles 206, 207, 208 and 209 for a period of 3 months over a 12-month period;
  - e) Infringement of other individual or global limits with a frequency or magnitude that reveals inadequate business conduct together with omission in approval/execution of corrective measures;
  - f) Repeated failure to comply with customer service requirements in Article 139;
  - g) When available regulatory capital is lower than established in the first paragraph of article 199 (10 percent) for a period of 3 consecutive months or 5 alternate months in a period of one year;
  - h) Loss or reduction of more than 40 percent (forty percent) of available regulatory capital (over a period of one year).
- Consolidated supervision thresholds (Consolidated Supervision Regulation, SBS Resolution No. 11823-2010, article 12):
  - i) If a consolidated group has a deficit, the supervised entity must submit a capital restoration plan;
  - ii) If a consolidated group has a deficit of less or equal than 20 percent of the required regulatory capital, all supervised companies in the group shall submit dividend proposals for prior authorization to the SBS;
  - iii) If the deficit exceeds the 20 percent threshold, supervised companies belonging to the financial group must allocate all net profits to regulatory capital to overcome the deficit.

### ICAAP, forward-looking capital management and stress testing
- ICAAP requirements and supervisory review:
  - Since 2010 all banks are required to submit annually an ICAAP.
  - Guidelines (Guia de Autoevaluacion de Suficiencia de Capital 2017-2019) clarify minimum standards and annually updated parameters for a standardized comprehensive stress-scenario.
  - ICAAP must be linked to strategy and capital planning on a 3-year horizon; since 2015 it must include a sensitivity analysis of credit risk of the loan portfolio.
  - In 2017 ICAAP submissions banks were for the first time required to include a section on the group (group structure, risk appetite, risk management, a 2-year projection, ability to generate additional capital, quality of capital, and approach towards stress-testing).
- Supervisory tools and integration:
  - ICAAP review is not yet formally integrated in the internal rating process but is used as an override when needed.
  - Specialized risk units of the SAR are not on a standard basis part of the ICAAP review process.
- Stress testing:
  - Liquidity contingency planning and stress testing required by Liquidity Risk Management Regulation (Resolution SBS No. 9075-2012), with quarterly submission of results and review during on-site examinations.
  - Internal rating methodology considers solvency as separate element and includes stressed capital position calculations that consider alignment with worst classifications, full provisioning of adverse classified exposures, and corrections for adverse occurred events not fully provisioned.

### Credit risk and problem assets — regulatory and supervisory framework (Principles 17 & 18)
- Credit risk governance and regulation:
  - GIR sets overarching governance and risk management requirements; Credit Risk Management Regulation (SBS Resolution No. 3780-2011) sets specific credit risk management requirements.
  - Article 8 of GIR: Board responsible for approving policies, limits, processes, procedures, roles and responsibilities for risk management.
  - Article 35 of Credit Risk Management Regulation: FIs must perform, at least annually, a credit risk stress-test considering macro- and micro-economic events that could affect credit quality.
- Specific risk regulations:
  - Foreign Exchange Induced Credit Risk Management Regulation (Resolution SBS No. 041-2005) requires internal procedures to qualify, grant and monitor loans in foreign currency and annual measurement of the effect of FX shocks (10 percent and 20 percent depreciation scenarios).
  - Retail Over-Indebtedness Risk Management Regulation (Resolution SBS No. 6941-2008) requires a risk management system to identify over-indebted retail borrowers; non-compliance may require additional general provisions of 1 percentage point over exposures classified as Standard.
- Classification and provisioning (SBS Resolution No. 11356-2008)
  - Five borrower categories: Standard; Watch; Substandard; Doubtful; Loss.
  - Specific provisioning rates table (as provided):
    - Without Collateral / With preferred collateral / With preferred highly quality collateral
    - Watch: 5.00% / 2.50% / 1.25%
    - Substandard: 25.00% / 12.50% / 6.25%
    - Doubtful: 60.00% / 30.00% / 15.00%
    - Loss: 100.00% / 60.00% / 30.00%
  - If exposures have preferred self-liquidating guarantees the FI must establish specific provisions for the covered portion of 1 percent.
  - Write-off policy: Board must write-off fully provisioned Loss category exposures when there is real and verifiable evidence of non-recoverability; backstop rules for long-dated Loss/Doubtful classifications remove collateral recognition after specified time limits (Loss >24 months; Doubtful >36 months).
- Supervisory review and tools:
  - FIs must report monthly classification and provisioning via Annex 5; Annex 6 (Credit Report of Debtors (RCD)) reports individual borrower exposures above PEN 1.00.
  - Classification alignment rule: align to highest risk category assigned by any FI whose credit represents a minimum of twenty percent (20 percent) of total exposure of the client to all FIs of the system (only one category difference allowed); retail alignment only when the other FI’s classification is Doubtful or Loss.
  - Internal Audit Unit must include credit risk management evaluation in its Work Plan and review a representative sample of non-retail portfolio at minimum every 4 months; retail procedures require permanent controls and annual sample integrity analyses.
  - External auditors required to review asset classification and report discrepancies under External Audit Regulation (Resolution SBS No. 17026-2010).
  - As standard procedure FIs must submit entire loan database (Base de Datos) prior to on-site exam; SBS uses ACL, IDEA and STATA to review asset classification and adequacy of provisions across the entire retail portfolio; for non-retail reviews a file-by-file excel template (FECD) is used.
- Assessment:
  - Principle 17 (Credit risk): Compliant.
  - Principle 18 (Problem assets, provisions and reserves): detailed framework in place; supervisory reviews intensive and corrective actions applied where needed.

### Findings, comments and key concerns
- Overall capital requirements including those set by the Additional Capital Requirements Regulation appear broadly in line with overall Basel III standards (including conservation, countercyclical and G-SIB buffers) though implemented through different approaches.
- Concerns and areas for improvement:
  - The D-SIB capital buffer and additional capital requirement for single name concentration risk are currently very limited and need recalibration; SBS is reviewing methodologies.
  - The definition of capital remains based on Basel II; adjustments toward Basel III definition are in progress via supervisory review and resolution measures.
  - Activation trigger of the CCyB is based only on GDP growth and may not be effective in situations with excessive credit growth when GDP growth is below 5 percent.
  - Supervisory group capital adequacy assessment should better account for: solo holding capital adequacy, capital location and ringfencing risks, and allocation feasibility of excess group capital.
  - Consolidated assessment does not adequately account for differences in accounting standards (SBS accounting at solo level vs IFRS at consolidated level).
  - ICAAP and its supervisory review are not yet formally integrated in the SBS rating methodology (ICAAP used as override); planned integration in a revised rating methodology to be rolled-out in 2019.
  - The SBS could consider involving the expertise of the SAR in the supervisory review of banks’ ICAAP.

### Recommendations (as listed)
- Incorporate as planned ICAAP and the related supervisory review in the revised supervisory rating methodology.
- Finalize the review of the current methodology for the calculation of the additional capital requirements as planned, taking into account the observations above.
- Enhance the group capital adequacy assessment by extending the current approach with analysis of:
  - i) the capital adequacy of the holding on a solo level (to determine if excess capital is available on a holding level);
  - ii) the location of capital within the conglomerate, including the risk of ringfencing/non-transferability of capital allocated to entities supervised by authorities abroad;
  - iii) the extent to which excess capital at a group level can be completely allocated to support the financial activities of the conglomerate.
- Review and revise the current group capital assessment methodology to assure that necessary adjustments to account for differences in accounting standards between solo and consolidated levels are properly taken into account.
- Formalize the developed risk-based supervisory cycle for assessing credit risk and incorporate it in the revised rating methodology and supervisory approach expected to be rolled-out in 2019.

*Source: SBS*

### Chapter III, Subsection 3 of the Classification of Borrowers and Provisioning

### Chapter III, Subsection 3 of the Classification of Borrowers and Provisioning

### Off-balance sheet exposures and Credit Conversion Factors (CCF)
- Regulation requires FIs to make general and specific provisions for direct exposures and the exposure equivalent of off-balance sheet items.
- Two types of off-balance sheet exposures recognized:
  - Those that can be unilaterally cancelled by the bank (based on contractual arrangements and therefore may not be subject to provisioning).
  - Those that cannot be unilaterally cancelled.
- Credit Conversion Factors for Provisioning Purposes (Source: SBS):
  - a) Irrevocable letter of credit confirmations with a maturity of up to a year, when the issuing financial institution is part of a first level foreign financing system — 20%
  - b) Letters of guarantee that guarantee the performance of a customer — 50%
  - c) Endorsements, letters of credit and guarantees not included in the “b)”, and confirmed letters of credit not included in “a)”, as well as banker acceptances — 100%
  - d) Undisbursed granted credits and unused lines of credit — 0%
  - e) All other items — 100%
- Note on deviation from Basel II alignment:
  - The CCF for undisbursed granted credits and unused lines of credit (0%) deviates from the factors used for credit risk capital requirements (Resolution SBS No. 14354-2009), which follow Basel II: commitments with an original maturity up to one year and commitments with an original maturity over one year receive CCFs of 20 percent and 50 percent, respectively.
  - Only commitments unconditionally cancellable at any time by the bank without prior notice, or effectively providing for automatic cancellation due to deterioration in a borrower’s creditworthiness, receive a 0 percent CCF.
  - The current blanket approach assigning 0% to all undisbursed and unused lines of credit is considered to underestimate exposure at default and general provisioning requirements for this type of off-balance items. This was also noted in the 2011 BCP assessment.

### Classification, provisioning triggers, and write-offs (EC4)
- Retail borrower classification is based on the number of days past due.
- Non-retail borrower assessment requirements:
  - Assess repayment capacity, including total indebtedness to other FIs in Peru and abroad, and compliance with obligations on those exposures.
  - Consider risks related to foreign currency, maturity of exposures, interest rates and derivative exposures.
  - Evaluate repayment capacity considering possible variation in the economic and regulatory environment, and vulnerability to changes in contractual relationships and composition of client and supplier portfolios.
  - Consider days past due and classification of the borrower by other financial institutions (available in the Credit Registry) in determining final classification.
- Write-off rules:
  - An exposure needs to be written off when:
    - It has been classified as a Loss loan and has been provisioned for 100 percent, and
    - Evidence exists that the exposure has become non-recoupable, or the exposure is too small to justify initiation of legal or arbitration procedures.
  - As a backstop:
    - If an exposure has been classified as a loss loan for more than 24 months (or for 36 months as doubtful), the collateral no longer can be considered for provisioning purposes and the exposure needs to be provisioned for 100 percent.
  - Approval requirements for write-offs:
    - All write-offs need to be approved by the Board.
    - If a write-off exceeds 3 tax units (PEN 4,050), it also needs to be approved by the SBS (SBS approval is needed for tax deduction purposes).
- SBS on-site review:
  - Adequacy of non-retail borrower assessments is reviewed by the SBS on a sample basis during on-site examinations (see EC2).

### Early identification, oversight of problem assets, and treatment of restructured/refinanced loans (EC5)
- Classification of retail borrowers is determined by days past due.
- SBS review tools:
  - Uses ACL, IDEA and STAT software to review adequacy of classification and provisioning levels for the entire retail portfolio.
  - Uses sampling approach for non-retail portfolio.
- On-site examination evaluation focuses include:
  - Whether credit policies and/or credit risk manuals clearly establish the credit evaluation and approval process.
  - Whether organizational structure establishes functional independence of the area responsible for evaluation and classification of non-retail loans relative to business and operating units.
  - Whether the classification area has sufficient and adequate computer tools.
  - Whether officials responsible for evaluation and classification have a high workload or perform other tasks that impede main responsibilities.
- Requirements and practices for refinanced/restructured loans:
  - The borrower’s asset classification at signing of refinancing contract or approval of rescheduling must be maintained.
  - Exception: borrowers classified as Standard must be reclassified to Watch upon refinancing/rescheduling.
  - Only after 6 months of full compliance with new terms and conditions can the loan be reclassified (1 category).
  - For grace periods, the six-month period starts after the end of the grace period.
  - Review of refinanced and restructured loans is part of the on-site loan classification review process.

### Reporting, supervisory access, and documentation (EC6)
- SBS receives extensive off-site information on loan classification and loan-loss provisioning.
- Prudential returns submitted monthly by FIs:
  - Annex 5: “Report on Classification of Borrowers and Provisions”
  - Annex 5-A: “Summary of Procyclical Provisions”
  - Annex 5-B: “Loan Portfolio Transfers”
  - Annex 6: “Borrowers’ Credit Report – RCD”
- Annex 6 is the data source for the Credit Registry and contains information on the complete loan portfolio.
- Article 15 of the Credit Risk Management Regulation requires that all information necessary for compliance (including for classifying and loan-loss provisioning) be available to the SBS physically and on magnetic media.
- Not submitting required periodic reports is a grave infraction and subject to sanctions under Resolution SBS No. 816-2005 – Sanctions Regulation.
- SBS indicates it has full access to necessary information in practice.

### Supervisor enforcement powers and corrective actions (EC7)
- Chapter IV, Subsection 4 of the Classification of Borrowers and Provisioning Regulation:
  - SBS will regularly review adequacy of loan portfolio classification.
  - SBS can require reclassification of exposures and/or higher provisions.
  - FIs are required to immediately reclassify exposures after receiving SBS instruction.
  - If institution does not comply, SBS will immediately deduct required additional provisions from the institution’s regulatory Tier 1 capital.
- Additional supervisory requirements:
  - SBS requires banks to make additional provisions for retail clients if Retail Over-Indebtedness Risk Management Regulations’ risk management requirements are not met.
  - For non-retail exposures, the FX Induced Credit Risk Management Regulation requires reclassification if repayment capacity is significantly affected by currency depreciation shock (assessed using two supervisory prescribed stress test scenarios).
- Legal basis and procyclical provisioning:
  - Article 132 of the LGSF establishes that provisions mitigate risks for depositors; SBS has used this to implement pro-cyclical provisioning requirements within the Classification of Borrowers and Provisioning Regulation.
  - Activation trigger aligns with the countercyclical capital buffer (see CP 16), but FIs must comply with pro-cyclical provisioning requirements within 6 months after activation (instead of 12 months).
  - Additional general provisioning for loans classified as Standard varies per asset class:
    - 0.4 percent for corporate exposures
    - 1.5 percent for revolving consumer loans
  - Regular general provisions vary from 0.7 to 1.0 percent depending on business line.
  - Objective: build an additional general provisioning buffer in benign circumstances to absorb losses when loan portfolio quality deteriorates.
- Evidence from on-site reports: SBS requires FIs to reclassify loans (and increase provisioning) when necessary following portfolio review.

### Valuation of collateral and risk mitigants (EC8)
- Classification of Borrowers and Provisioning Regulation distinguishes, for provisioning purposes:
  - Preferred collateral
  - Liquid preferred collateral
  - Self-liquidating collateral
- SBS requires banks to have appropriate mechanisms for regularly assessing the value of risk mitigants, including guarantees, credit derivatives and collateral.
- Valuation of collateral must reflect net realizable value, taking into account prevailing market conditions.

*Source: Chapter III, Subsection 3 of the Classification of Borrowers and Provisioning*

### Section 3 of Chapter IV of the Classification of Borrowers and Provisioning Regulation

### Section 3 of Chapter IV — Valuation of Collateral and Related Supervisory Requirements

### Valuation basis and professional appraisal
- Valuation of collateral must be based on the net realization value, reflecting sale value in the market minus additional expenses incurred for that purpose.
- Net realizable value in the market is the net value the FI expects to recover from an eventual sale or execution of the asset in its current state and location and should consider penalties and charges for taxes, commissions, freights, and losses.
- Commercial reference value must be calculated from reliable information; valuation must follow a strictly conservative criterion based on current market conditions and not on mere expectations of price improvement or speculative financial assumptions related to potential customers.
- Goods given as collateral must be valued by an appropriate professional duly registered in the Registry of Appraisers (REPEV) of the SBS.
- For mortgages and movable property, it must be verified that they have been effectively registered in the corresponding registers and that they have insurance covering loss of the property, duly endorsed in favor of the FI; otherwise they cannot be considered as preferred collateral for provisioning purposes.
- For real estate and personal property registered in the Legal Registry of Assets, valuation must be made through a commercial appraisal with sufficient backup records referring to the prices used, preferably relying on recent sales of similar goods; the considerations underlying the final valuation must remain in files available to the SBS.
- When collateral relates to securities or financial instruments, they need to be pledged in favor of the company observing the laws on the matter.
- Valuation of financial instruments will be carried out according to internal models developed by the company, subject to review by the SBS; such models must be consistent with the Regulation of Classification, Valuation and Provisions of the Investments of the Companies of the Financial System, and resulting prices must be equal for the valuation of collateral and investments.

### Definition and requirements for preferred collateral; updating values
- Preferred collateral must meet all of the following requirements:
  - (a) money or assets that allow conversion into money without significant costs;
  - (b) have adequate legal documentation;
  - (c) they do not present any prior obligations that could diminish their value or prevent the creditor company from acquiring a clear title;
  - (d) its value is permanently updated.
- To keep preferred collateral values permanently updated, FIs may use value updating systems based on market performance indicators, built on reliable commercial, economic and statistical reference information.
- The value of preferred collateral must be updated by valuation performed by an expert registered in the REPEV, when applicable and when there is a change that could have a significant impact on the valuation of the asset.

### Types of accepted collateral for provisioning purposes
- Preferred collateral (o.a. first mortgages);
- Preferred liquid collateral (o.a. financial instruments issued by the Government or Central Bank);
- Self-liquidating collateral (a.o. cash deposits).

### Collateral review, adjustments and supervisory file review
- Review of collateral is generally carried out on borrowers in the selected sample of the loan portfolio to determine whether collateral meets SBS criteria for credit risk mitigation purposes.
- If examination of credit files establishes adjustments in collateral values, the FI is obliged to make those adjustments and to establish additional provisions, if necessary.

### Identification and reclassification of problem assets (EC9)
- Laws, regulations or the supervisor establish criteria for assets to be:
  - (a) identified as a problem asset (e.g., a loan is identified as a problem asset when there is reason to believe that all amounts due, including principal and interest, will not be collected in accordance with contractual terms);
  - (b) reclassified as performing (e.g., a loan is reclassified as performing when all arrears have been cleared and the loan has been brought fully current, repayments have been made in a timely manner over a continuous repayment period and continued collection, in accordance with contractual terms, is expected).
- Retail borrowers and mortgage loans are assessed based on days past due.
- Non-retail borrowers are assessed based on repayment capacity, including total indebtedness to other lenders in Peru and abroad, and compliance with obligations on those exposures.
- Assessment must consider risks related to foreign currency, maturity of exposures, interest rates and derivative exposures, possible variation in economic and regulatory environment, vulnerability to changes in contractual relationships and composition of client and supplier portfolio.
- Days past due and the classification of the borrower by other financial institutions (available in the Credit Registry) must be taken into account.
- FIs must maintain a permanent record of all refinanced and restructured exposures that have been reclassified as current.

Reclassification conditions for refinanced and restructured exposures to be classified as performing (Normal or Watch):
- As a result of the satisfactory evaluation of their repayment capacity;
- The conditions of the exposure have not been changed more than once as a result of repayment capacity issues;
- The borrower has repaid at least 20 percent of the refinanced or restructured exposure;
- The borrower has demonstrated its repayment capacity for at least two consecutive quarters;
- If the refinanced or restructured exposure contains a grace period, the above conditions need to be complied with from the date the grace period ends.

- As standard practice, refinanced and restructured loans or borrowers with characteristics of refinancing are included in the sample of credit files reviewed during on-site examination for compliance with the Classification of Borrowers and Provisioning regulation.

### Board reporting and supervisory review of asset portfolio information (EC10)
- The “On-site Credit Risk Management Supervision Manual” contains procedures for review of the quarterly report on asset classification and provisioning to the Board (or its Risk Committee) as prepared by the Risk Unit of the FI.
- The manual In-Situ SABM No. GC-01-2010 Evaluation of Good Corporate Governance Practices in Companies of the Financial System contains procedures to review whether reports prepared by the Risk Unit are complete, comprehensive, easy to interpret and sufficient for the CEO and the Board (or its Risk Committee); it also reviews adequacy of the reporting system and is part of the governance self-assessment submitted in advance of the on-site examination.

### Individual assessment and thresholds for significance (EC11)
- The Classification of Borrowers and Provisioning Regulation requires that all borrowers are assessed and classified individually.
- For retail borrowers, days past due can be used as a criterion; non-retail borrowers face higher requirements.
- Clients with total loans in the financial system of less than PEN 300,000 in the past 6 months qualify as retail borrowers.
- Mortgage loans for housing are considered part of the retail portfolio. All other exposures are considered non-retail borrowers.

### Concentration risk: framework and supervisory monitoring (Principle 19; EC1–EC4)
- The Credit Risk Management Regulation requires FIs to set concentration limits for:
  - large exposures,
  - geography,
  - economic sectors,
  - asset classification category,
  - internal classification category,
  - exposure to foreign exchange induced credit risk,
  - retail clients exposed to the over-indebtedness risk,
  - country risk.
- In case of losses, FIs must compare and analyze estimated losses with realized losses and review potential corrective actions (articles 18, 34).
- The Credit Risk Management Regulation, Retail Over-indebtedness Risk Management Regulation and the Foreign Exchange Induced Credit Risk Regulation require FIs to assess risk capacity and ability to absorb adverse events using stress-testing.
- The Credit Risk Supervision Unit of the SAR prepares standard periodic reports on credit risk trends, including a Sectoral Credit Risk Report analyzing sectoral concentration risk per bank and system level.
- Additional capital requirements and prudential reporting have been implemented for individual, sectoral and geographical concentration risk (see CP 16).
- SAEE conducts stress-tests two times per year (considering macro-economic and structural developments); recent focuses included a possible mortgage asset bubble (2011-2012), expansion of credit card and consumer loans (2014-2015) and the impact of El Nino on FIs with major exposures in potentially affected regions.
- ICAAP requirements include assessment of all material risks over a three-year horizon, a comprehensive regulatory stress test and credit risk sensitivity testing; SAEE stress-testing results are used as a benchmark for FI ICAAP reports.

EC1 — policy and process requirements and findings:
- SBS has regulations for single name, sectoral, geographical, FX induced credit and country concentration risk and monitors funding concentration risk.
- Responsibility of the Board for approval and review of concentration risk policies is laid down in the GIR and Corporate Governance & GIR.
- Article 17 of the Credit Risk Management Regulation (Resolution SBS No. 3780-2011) requires SIs to define acceptance criteria of risk in credit policies and procedures and to consider potential loss of all credit risk exposures, on- and off-balance sheet (article 1).
- Article 18 requires inclusion of internal credit risk concentration limits at least for:
  - limits per counterparty, at the individual level and by economic group, considering linkage by single risk;
  - limits by economic sectors, by geographical location and other common risk factors.
- Limits must be consistent with prudential regulations and exceptions must be approved by the Board.
- Single name, sector and geographical credit concentration risk are part of the Additional Capital Requirements Regulation (Resolution SBS No. 8425-2011); FIs must report monthly Reports No. 4 B-1, 4 B-2 and 4 B-3 (top-20 exposures, total credit exposures per economic sector (19 sectors) and per region (8 macro regions) and calculation of corresponding capital charge as part of the CCB).
- Article 200 of the LGSF establishes that holdings of shares and certificates of participation in mutual funds and certificates of participation in investment funds are not allowed to exceed in total 40 percent of available regulatory capital, without prejudice to large exposure limits in articles 203 to 211 of the LGSF.
- Market Risk Management Regulation (Resolution SBS No. 509-1998) tasks the Board to establish policies and procedures for market risk; Article 13 requires the Risk Committee to establish internal limits for market risk exposures including derivatives.
- Regulatory requirements and prudential reports also exist for FX induced credit risk, country risk and funding concentration risk.
- Under ICAAP, FIs must assess single name, sectoral and geographical concentration risk and capital needed to cover these risks.

EC2 — information systems and supervisory review:
- SBS uses a rating methodology with 7 building blocks: i) Solvency; ii) Credit risk; iii) Liquidity risk; iv) Market risk (incl. IRRBB); v) Operational risk; vi) Profitability and efficiency; and vii) Management and control. Credit concentration risk is scored as part of credit risk.
- On-site supervision manual “No. CI-03, Global and Individual Limits” requires review of FI systems and whether concentrations as reported have been determined and calculated adequately.
- On-site examination evaluates monitoring systems, compliance with regulatory and internal operating limits, availability of reports to business and risk officials, presence of preventive alerts, and reporting to Risk Management, senior management and the Board.

EC3 — internal thresholds, communication and review:
- GIR and Corporate Governance & GIR set overarching responsibilities for Board and senior management regarding strategy, risk appetite, policies, procedures and operating limits.
- Regulations require FIs to establish internal limits in credit policies and procedures; on- and off-site supervision evaluates whether limits guarantee adequate diversification by single name, sector and geographical area considering size and nature of loan portfolio and risk appetite.
- SABM on-site supervision manual “No. GC01, Evaluation of Good Corporate Governance Practices in Companies of the Financial System" contains procedures to review whether Board and senior management responsibilities are well defined and aligned with strategy and risk profile, and whether the Board has established risk management policies; review of minutes is part of procedures.
- On-site credit risk examination includes procedures to review per business line: (i) effective monitoring of internal limits, (ii) consistency of limits with strategy and goals, (iii) reporting of monitoring results to Risk Committee and/or Board, (iv) actions defined and adopted in the event of breaches.

EC4 — supervisory information to review concentrations:
- The Accounting Manual for Companies of the Financial System sets information and formats companies must submit to the SBS and periodicity.
- The trial balance provides information on exposures in domestic and foreign currency by type of credit.
- Annex 3 "Credit Flow by Type of Credit and Economic Sector" presents credit balances by type and main economic sectors.

### Assessment and recommendation highlights
- Assessment of Principle 18: Compliant.
- Comment: The CCF (credit conversion factor) used for provisioning purposes for undisbursed granted credits and unused lines of credit deviates from factors used for credit risk capital requirements (Resolution SBS No. 14354-2009). The current blanket approach assigns a 0 percent CCF to all undisbursed and unused lines of credit, which is from a provisioning point of view less conservative compared with Basel II (where commitments with original maturity up to one year and commitments with original maturity over one year receive CCFs of 20 percent and 50 percent, respectively; only unconditionally cancellable commitments receive 0 percent).
- Considering the overall framework for credit risk, provisioning and capital requirements this is assessed as a minor issue and the criterion is overall assessed as Compliant.
- Recommendation:
  - Review the CCFs applied (for provisioning purposes) to undisbursed and unused credit lines.

*Source: Section 3 of Chapter IV of the Classification of Borrowers and Provisioning Regulation (cr18366-perufsap).*

### Annex 10 "Deposits, Loans and Personnel by Offices", provides information on the

### Annex 10 "Deposits, Loans and Personnel by Offices"

### Coverage and frequency
- Reports are sent monthly.
- Provides information on the balance of the portfolio of total loans and per currency per geographical area at the district level.

### Key data elements (Annex 10)
- Balance of the portfolio of total loans.
- Balances per currency.
- Balances per geographical area at the district level.

### Related dataset: Annex 6 "Credit Report of Borrowers (RCD)"
- Sent monthly.
- Includes all loans above PEN 1.00.

### Key data elements (Annex 6 RCD)
- Borrowers' main economic activity.
- The office where the disbursement was made.
- Borrowers' credit risk classification.
- Detailed balances by currency.
- Accounting status.
- Type of credit.
- Other borrower-level information enabling detailed analysis.

### Analytical uses and ad hoc reporting enabled by Annex 6
- Generation of ad hoc reports such as:
  - Balances by type of credit.
  - Balances by economic sectors.
  - Balances by geographical area.
  - Balances by currencies.

*Source: Annex 10 "Deposits, Loans and Personnel by Offices" and Annex 6 "Credit Report of Borrowers (RCD)".*

### Annex No. 01 (monthly) contains information on investments by instrument and

### Annex No. 01 (monthly) contains information on investments by instrument and issuer.

### Reporting framework and management reporting
- Annex No. 01 (monthly) contains information on investments by instrument and issuer.
- FIs must identify groups of debtors that are part of economic groups or connected in Report No. 20 and Report No. 20-A (covering at least the top 200 exposures).
- Report No. 23 "Exposure to Country Risk" provides information on all exposures (assets, contingent loans and derivatives) resulting from operations affected by country risk.
- FIs report monthly: large exposures and compliance with regulatory large limits (Report 13); top-20, sector and geographical concentrations (Reports 4 B-1, 4 B-2 and 4 B-3).
- The SAR prepares monthly and quarterly management reports on different risks, including concentration risk, per bank and for the banking system.
- Assessors reviewed Annexes and Reports and assessed the information provided through these reports as well as internal SBS management reporting as comprehensive.

### Groups of connected counterparties and definitions (EC5)
- Legal basis: Article 203 of the LGSF defines when exposures are considered a single counterparty exposure (group of connected counterparties) if:
  - (i) there is direct or indirect common control;
  - (ii) financial problems of one party may affect others due to common ownership, control or administration, reciprocal guarantees or direct business dependence which cannot be replaced in the short term;
  - (iii) exposures granted to one party are presumed to be used for the benefit of others; and
  - (iv) the nature of the relationship is such that they can be considered a single economic unit.
- Resolution SBS 5780-2015 (Connected Parties and Economic Groups Regulation) issued in 2015 introduced stricter criteria and adopts international standards.
- Article 8 definition: economic group comprises all legal persons and/or legal entities, national or foreign, made up of at least two members, of which one exercises control over the other or others, or when control is exercised by one or more natural persons acting jointly.
- Article 3 definition: connected parties are those where the financial or economic situation of one affects the other or others; presumption of single risk link includes spouses and persons/entities with ownership and/or management relationships per articles 4 and 5.
- Article 4: ownership relationship presumed when shares or voting shares held directly or indirectly represent 4 percent or more of shares or voting shares.
- Article 10: SBS may, for prudential reasons, apply additional presumptions to determine economic group membership.
- Reporting: supervised companies must submit semiannually Report No. 20 (top-200 exposures to economic groups/connected clients) and Report No. 20-A (detail of connected persons and type of linkage).
- Finding: definitions and guidance are comprehensive; ownership definition (4 percent or more) is conservative.

### Large exposures and concentration limits (EC6)
- Legal/regulatory references: Articles 198 to 216 of the LGSF; Circular B-2148-2005 provides detailed guidance.
- Exposure calculation per Circular B-2148-2005: consider limits granted to counterparty, direct credit exposures (drawn/disbursed amounts), accounts receivables, financial leases, investments, credit equivalent of derivatives and contingent exposures; except unused and undisbursed credit lines.
- LGSF large exposure limits:
  - Article 206 establishes a large exposure limit of 10 percent.
  - Depending on collateral quality, limit can be exceeded up to 15 (article 207) or 20 percent (article 208).
  - Limit can be exceeded up to 30 percent (article 209) if collateral consists of deposits held at the same FI or financial instruments issued by the Central Bank.
- Resolution SBS No. 11823-2010 requires limits applied on a consolidated basis by financial or mixed conglomerates.
- Supervisory practice: SBS determines via prudential returns and on-site exams that FIs have adequate monitoring, senior management reports to Board, and compliance with regulatory limits.
- Assessment note: large exposure limit of 10 percent for uncollateralized exposures is conservative compared to international standards. Large exposure includes on- and credit equivalent (using Basel II CCFs) of off-balance exposures.

### Stress testing for concentration risk (EC7)
- Single name, sector and geographical credit concentrations are part of the Additional Capital Requirements Regulation; FIs must assess adequacy under ICAAP and consider these exposures in regulatory stress-tests.
- SBS internal stress-testing (SAEE) includes concentration exposures; example: 2017 stress-test estimating impact of el Nino using geographical loan portfolio distribution.
- Assessment: supervisor requires inclusion of significant risk concentrations into stress testing programs.

### Assessment of Principle 19
- Assessment: Compliant.
- Comments:
  - New rules on related parties and economic groups issued in 2015 (Resolution SBS N° 5780-2015) with stricter criteria.
  - Regulations do not consider a combined limit for large exposures but the large exposure limit (maximum 10 percent for uncollateralized exposures) is conservative.
  - Additional Capital Requirements Regulation imposes additional capital for single name concentration risk considering top 20 exposures; SBS reviewing adequacy of this capital charge (see CP 16).

### Transactions with related parties — Principle 20 (overview)
- Supervisor requires arm’s length treatment, monitoring, mitigation, and write-off of related-party exposures in accordance with standard policies.
- Related party concepts include subsidiaries, affiliates, parties with control relationships, major shareholders, Board members, senior management, close family, and corresponding persons in affiliated companies.
- Transactions include on- and off-balance exposures, service contracts, asset transactions, leases, derivatives, borrowings, and write-offs; concept interpreted broadly.

#### EC1 — Definition and limits for related parties
- LGSF establishes limits for related party exposures; related party exposures subject to a limit of 30 percent (see CP 19).
- LGSF establishes a limit of 7 percent for loans to Board members and employees; no Board member or employee may receive more than 5 percent of the overall limit (this limit includes spouses and relatives).
- Resolution SBS N° 5780-2015 provides definitions and grants SBS discretion (article 10).

#### EC2 — Arm’s length terms
- Article 202 prohibits credits to Board members or employees on terms more advantageous than best clients, except first home mortgage loans.
- Resolution SBS No. 472-2006 requires affiliates to be properly identified, risks evaluated, financing granted on no more advantageous terms, and Board approval of policies and procedures.

#### EC3 — Board approval and conflict-of-interest exclusion
- Article 180 of the General Company Law (LGS) requires Board members to disclose and refrain from participating in matters with conflicts.
- Corporate Governance & GIR (Resolution SBS No. 272-2017), effective April 1, 2018, requires senior management to report related-party transactions to the Board and Board Regulations to address conflicts.
- Resolution SBS No. 472-2006 (Article 6) stipulates prior Board approval for financing to related parties.
- Credit Risk Management Regulation (Article 4 and 21) requires structures preventing conflicts in decision-making; transactions with affiliates require Board or highest credit committee approval excluding conflicted members.
- Circular No. B-2185-2010: issuance of proof of non-recoverability requires certified Board agreement copy; Credit Transfer and Acquisition Regulation (Resolution SBS N° 1308-2013) requires Board approval for portfolio transfers/acquisitions.

#### EC4 — Policies/processes to prevent conflicted participation
- IAU and external auditor must review policies/procedures for avoiding conflicts (Resolution SBS No. 472-2006 Articles 9 and 10).
- On-site examinations aim to identify potential conflicts, particularly with related persons.
- SIs required to have a "Conflict of Interest Handbook".
- On-site inspection manual “No. GC-01" Evaluation of Good Corporate Governance Practices" provides procedures for conflict-of-interest review.

#### EC5 — Limits, deduction from capital, consolidated application
- Aggregate related party limit equals single counterparty/group limit; Board member & employee cap: total exposures cannot exceed 7 percent of available regulatory capital and no individual Board member/employee more than 5 percent of that overall limit.
- Prudential Rules (Article 7) exclude exposures already deducted from regulatory capital from limit calculations.
- Consolidated supervision (Resolution SBS No. 11823-2010): total related party exposure not allowed to exceed 30 percent of available regulatory capital of the consolidated group. The 7 percent Board/employee limit does not apply at consolidated group level.
- Sanctions on breaches (LGSF article 219): apply a sanction of 1.5 times the average interest rate margin over the amount in excess; average interest rate margin in local currency is currently 13.54 percent. If breach not remedied within a month an additional penalty increased by 50 percent each month the infraction continues. Breach of 7 percent Board/employee limit penalized with a fine of 100 percent of the excess.

#### EC6 — Identification, aggregation, monitoring, independent review
- FIs must aggregate exposures to related persons and report via Report No. 13; Report No. 13 must be signed by the General Manager and Head of the Risk Unit.
- Resolution SBS No. 472-2006 Article 5 requires banks to maintain a related parties database, permanently updated; validation via on-site and off-site supervision.
- Consolidated Supervision Regulation requires consolidated related parties database available to SBS and validated on-site.
- Internal Audit and External Audit Regulations require IAU and external auditors to verify reporting and compliance.
- On-site procedures (Annex No. 10, SC.01) validate mechanisms for calculation and compliance with legal limits and related parties database.

#### EC7 — Supervisor obtains aggregate related-party information
- Reports No. 19, No. 19-A, No. 21 and No. 21-A support off-site monitoring of related party exposures and compliance.
- Semiannual Reports No. 19 and 19-A list economic group companies and shareholders, directors, managers and senior officers; companies must notify SBS within fifteen (15) calendar days of composition changes.
- Regulation on Connected Parties and Economic Groups (Resolution SBS No. 5780-2015 Article 18) requires submission within fifteen calendar days after quarter-end of Reports No. 21 and 21-A detailing financing to related parties and exposure types, linkage type and total related party exposure as percentage of available regulatory capital.
- Consolidated groups submit quarterly Annex 10 “Related Party Exposure Limit”.
- Monthly Report No. 13 includes compliance with all regulatory limits including related parties, Board members and employees.
- Assessment: Principle 20 — Compliant.
- Comments: 2015 regulation strengthens linkage criteria and adopts international standards.

### Country and transfer risks — Principle 21 (overview & supervisory approach)
- Principle 21 assessment: Compliant.
- Regulatory framework:
  - Corporate Governance & GIR (Resolution SBS No. 272-2017) to replace GIR (Resolution SBS No. 037-2008) per April 2018.
  - Resolution SBS No. 7932-2015 sets specific risk management and provisioning requirements for country risk; requires a country risk manual (article 7) documenting policies, classification, internal limits, stress tests, contingency plans, exit procedures, etc.
  - Article 8 requires consolidation in line with Consolidated Supervision Regulation (Resolution SBS No. 11823-2010).
- Supervisory processes:
  - Country risk monitored by DSRCRE of the SAR; exposures and country risk management reviewed as part of credit risk and included in rating methodology.
  - Banks with exposures with expected losses higher than 1 percent of available regulatory capital are monitored more closely; exposures with expected losses more than 2 percent of available regulatory capital considered for on-site inclusion.
  - SAR prepares quarterly detailed country risk reports; June 2017 quarterly country risk report assessed as comprehensive.
- Information systems and reporting:
  - Reports No. 23 (monthly), No. 23-A and No. 23-B (quarterly) provide exposure consolidation and validation.
  - Procedures include cross-checking Annex 1 and Appendix 6 "Debtor Credit Report (RCD)" with Report No. 23 and monitoring evolution of exposures.
- Provisioning and stress testing:
  - Article 18 prescribes provisioning requirements per country depending on risk category and exposure tranche (marginal scheme). The regulation maps Moody’s, S&P and Fitch ratings to 8 risk categories; Categories III and above are investment grade (BBB and higher).
  - Article 14: use most conservative available external rating for sovereign bonds; countries without classification assigned risk category VIII.
  - Article 16 allows internal rating models for country risk classification subject to SBS authorization (no authorizations granted by end-June 2017).
  - Provisioning requirement to be compared with credit/investment provisioning; highest of the two applies.
  - Exemptions from country risk provisions listed (e.g., foreign trade ops with residual term < one year; investments abroad valued at market price monthly; exposures deducted from regulatory capital; certain derivative transactions; exposures with multilateral development banks listed in Article 16 of the Credit Risk Capital Regulation).
  - Article 20: FIs with exposure to a country exceeding ten percent (10 percent) of available regulatory capital must carry out at least an annual stress-test using FIs’ own methodology with scenarios including deviation of main assumptions, contagion exacerbation, liquidity restrictions, changes in market-credit risk relationships.
- Supervisory powers:
  - Article 21 requires monthly submission of Report No. 23 and quarterly Reports No. 23-A and No. 23-B; head of Risk Unit responsible for preparation and submission.
  - Article 350 of the LGSF empowers the Superintendent to request any information deemed necessary.
- Observed system state (June 2017):
  - Six banks had exposures exceeding 10 percent of available regulatory capital (thus required to conduct internal stress tests).
  - All banks were below the 1 percent monitoring threshold of expected loss divided by available regulatory capital as almost all exposures classified as investment grade (grade I – III).
- Comment: regulatory provisioning requirements for country risk are conservative.

### Market risk — Principle 22 (overview, findings, and recommendation)
- Assessment: Largely compliant.
- Regulatory framework:
  - Article 178 LGSF: SIs must establish asset-liability management process including liquidity risk, market risk, operational risk identification, measurement, control and reporting.
  - GIR (Resolution SBS 37-2008) and Corporate Governance & GIR (Resolution SBS No. 272-2017) set governance requirements.
  - Resolution SBS No. 0509-98 provides Market Risk Management requirements; Resolution SBS No. 6328-2009 provides Market Risk Capital Requirements including trading book definition.
  - Peruvian AFS sovereign bonds covered by market risk capital requirements (interest rate risk in trading book).
  - Resolution SBS No. 7033-2012 clarifies valuation of securities; Resolution SBS No. 1455-2003 provides Guidelines for Foreign Exchange Risk Management with regulatory FX limits.
- Market risk materiality:
  - Average capital requirement for banks’ market risk exposures is per mid-2017 less than 1 percentage point of banks’ regulatory capital ratio; mainly driven by open currency position and interest rate risk in trading book. Banks’ trading activities are limited.
- FX regulatory limits (Guidelines for Foreign Exchange Risk Management):
  - Net FX position limits (daily):
    - Long Open Position: 50 percent of regulatory capital
    - Short Open position: 10 percent of regulatory capital
  - Net FX derivatives position limits (daily):
    - Long position: Max (40 percent of regulatory capital, PEN 600 MM)
    - Short Position: Max (20 percent of regulatory capital, PEN 300 MM)
- Supervision and organization:
  - Market Risk Department (DSRMLI) within SAR has 12 staff; monitors daily market risk indicators, prepares monthly reports, performs on-site exams and scores market risk in rating methodology.
  - On-site procedures split into manuals: Foreign exchange risk management (Manual 1), Investment risk management (Manual 2), Treasury – derivatives (Manual 5), Independence of functions (Manual 6).
- Key supervisory findings:
  - Existing Market Risk Management Regulation (1998) is outdated; Draft revised regulation issued for consultation July 2017 (and later issued as SBS Resolution No. 4906-2017 after assessment — noted in recommendations).
  - Market Risk Management Regulation and FX Guidelines are not applicable on a financial group-wide level.
  - Supervisory procedures verify Board involvement, adequacy of policies, internal limits, model assumptions and parameters, and use of appropriate information systems.
- Valuation and model controls (EC4 & EC3):
  - Paragraph 2 of article 354 LGSF allows SBS to require market-value adjustments.
  - Article 11 Market Risk Management Regulation requires daily recording at market value; approximations allowed when market value unavailable.
  - Article 12 requires Risk Unit to use appropriate valuation methods and include retrospective analysis and worst future scenario.
  - Resolution SBS No. 7033-2012 aligns fair value accounting with IFRS; Regulation for Classification and Valuation of Investments (Resolution SBS No. 7033-2012) requires disclosure of models, assumptions and operational valuation records.
  - For non-active markets, valuation techniques/models must make most use of market data; Vector Price Regulation (Resolution SBS No. 945-2006) and other rules provide valuation sources.
  - Resolution SBS No. 1737-2006 prohibits contracting derivatives whose reasonable value cannot be determined reliably.
- Capital and valuation adjustments (EC5):
  - Market Risk Capital Requirements (Resolution SBS No. 6328-2009) based on Basel II framework cover interest rate (trading book and domestic AFS sovereign bonds), price, FX and commodity risk.
  - For interest rate risk in the banking book only the duration based method is allowed as standardized approach. The capital charge is 10 percent (compared to 8 percent under Basel framework).
  - Banks can apply to use Internal Model Method for market risk capital calculations; none currently use it.
  - FI reporting: Report No. 2-B1 with Annexes 1-A (Specific interest rate risk), 1-B (General interest rate risk), 1-C (Summary), Annex 2 Price risk, Annex 3 FX risk, Annex 4 Commodity risk.
  - DSRMLI prepares a quarterly internal supervisory report covering compliance, indicators, positions, IRRBB and FX risk, capital requirements, trading income, and market risk rating.
- Stress testing and model validation (EC6):
  - Article 12 Market Risk Management Regulation requires retrospective analysis and worst future scenario; Risk Committee to set policies for these results.
  - Draft Market Risk Management Regulation includes more detailed stress-testing governance.
  - Exchange Risk Management Regulations (Article 10) require scenario simulation and stress tests for FX risk; results should inform policies and be available to SBS.
  - On-site manuals include procedures to verify execution of stress analysis, scenario analysis, back-testing and methodology evaluation.
- Supervisory conclusion and recommendations:
  - Considering limited trading activities, the regulatory and supervisory framework is broadly adequate.
  - Existing Market Risk Management Regulation is outdated (1998); revised regulation consulted July 2017 and subsequently issued (see footnote in source).
  - Recommendation: Issue the revised and updated Market Risk Management Regulation.
  - Recommendation: SBS should evaluate to what extent current capital requirements need recalibration to bring them in line with the Basel III standard and whether the Basel III (simplified) standardized approach should be adopted.

### Interest rate risk in the banking book — Principle 23 (introductory points)
- Regulatory and supervisory requirements:
  - GIR and Corporate Governance & GIR set the overarching risk management framework.
  - Circular B 2087-2001 on Interest Rate Risk in the Banking Book (IRRBB) sets specific risk management and monitoring requirements and a regulatory limit: Earnings at Risk (EaR) must not exceed available regulatory capital by more than 5 percent.
  - Additional Capital Requirements Regulation requires banks to hold additional capital buffer for IRRBB above minimum if change in Economic Value of Equity (“EVE”) after applying a prescribed ... (source content ends here).

*Source: cr18366-perufsap - Annex No. 01 (monthly) contains information on investments by instrument and issuer (PDF).*

### Annex 7 of the Accounting Manual) interest rate shock exceeds 15 percent of

### cr18366-perufsap - Annex 7 of the Accounting Manual) interest rate shock exceeds 15 percent of

### Regulatory framework and scope
- The prescribed methodology for FIs to calculate capital is based on the methodology provided in the Basel Principles for the Management of IRRBB (July 2004).
- The outlier criterion: interest rate shock exceeds 15 percent of regulatory capital.
- Paragraph 3 of Circular B-2087-2001: banks must identify, measure, control and report adequately the level of interest rate risk they face.
- Paragraph 2 of Circular F-464-2003: establishes the same guidelines for non-bank companies.
- Wherever “interest rate risk” is used in this Principle the term refers to interest rate risk in the banking book; interest rate risk in the trading book is covered under Principle 22.
- Article 18 of the Circular: the SBS on a consolidated basis may require banks to apply the provisions of this regulation with respect to its economic group or part thereof, in accordance with Article 14 of the Consolidated Supervision Regulation (Resolution SBS No. 11823-2010).

### Supervisory responsibilities and resourcing
- The SAR risk unit DSRMLI is responsible for supervising the IRRBB, market and liquidity risk of SIs.
- DSRMLI staffing and allocation:
  - 12 staff.
  - Staff dedicate about two thirds of their time to banks.
- IRRBB is scored in SBS’ rating methodology as part of market risk; DSRMLI determines the rating.
- DSRMLI on-site inspection activities:
  - Verify the Board is informed in a timely manner of the level of interest rate risk via reports or presentations.
  - Review minutes to confirm the Risk Committee approves policies and procedures, establishes exposure limits, and sets communication and reporting lines.
- Required reporting: paragraph 19 of Circular B-2087-2001 requires a copy of the monthly Chief of the Risk Unit’s report on interest rate risk management to be sent to SBS.

### Corporate governance, Board and senior management roles (EC2)
- GIR and its successor (coming into effect per April 2018), the Corporate Governance & GIR, establish overarching responsibilities of the Board and senior management.
- Paragraph 3 of Circular B-2087-2001: the Board is responsible for approving policies and procedures for managing interest rate risk and ensuring senior management monitors and controls the risk.
- Article 9 of the GIR and article 8 of the Corporate Governance & GIR:
  - Board members must annually sign a declaration of compliance stating they have required management to have policies, processes and controls consistent with the SI's strategy, appetite levels and risk limits.
  - The declaration should indicate Board members have taken note of management information and decisions and reports of the Risks Committee.
  - The Risks Committee may, by delegation of the Board, approve policies and organization for integral risk management, propose risk limits, and propose improvements in integral risk management.
- Article 17 of the Corporate Governance & GIR: senior management must ensure SI activities are consistent with business strategy, risk appetite system and Board-approved policies; implement comprehensive risk management per Board provisions.
- Inspection verification:
  - DSRMLI staff confirm Board or Risk Committee approval of interest rate risk policies and procedures and that they are reviewed annually.
  - Review minutes of Board, Risks Committee, and Assets and Liabilities Committee to ensure alignment with Board-established strategies, policies and procedures and timely communication of deviations.

### Interest rate risk management requirements (EC3)
- Circular No. B-2087-2001 aims to ensure adequate management of positions affected by interest rate risk and covers:
  - Requirement for systems and models for measuring interest rate risk aligned with the degree of complexity of operations and level of risks.
  - Models should capture all material sources of interest rate risk and evaluate the effect consistently across activities, identifying and measuring impact of changes in interest rates on profits and equity value for all assets, liabilities and contingents.
- Specific model and system requirements:
  - 9.1: The assumptions required for elaboration of measurement systems and models should be clearly understood by the Chief in charge of the Risk Unit and by the Board or Committee.
  - 9.2: The initial validation of systems and models of measurement of interest rate risk and subsequent modifications must be carried out by an area independent of the area that develops or employs them.

### Documentation and procedural references
- Procedures and manuals referenced during inspections:
  - IRRBB Manual G4
  - Organizational Structure G6

*cr18366-perufsap - Annex 7 of the Accounting Manual) interest rate shock exceeds 15 percent of*

### 9.3 When the bank develops new internal models or makes modifications to them, it

### 9.3 When the bank develops new internal models or makes modifications to them, it must immediately notify the SBS, attaching a brief report evaluating the impact of these changes on the bank's risk analysis.

### Notification and internal model changes
- Banks must immediately notify the SBS when they develop new internal models or make modifications to them, attaching a brief report evaluating the impact on the bank's risk analysis.
- Independent validation of internal models of interest rate risk is performed during on-site examination.

### Interest rate risk limits and metrics
- Paragraph 15 of the Circular: banks must establish operating limits of exposure to interest rate risk as part of their internal control system; limits should focus on impact on profits (financial margin) and equity value under normal and stress conditions.
- EaR indicator (12-month horizon) is regulated to estimate impact on annual financial margin from specific interest rate changes.
  - Per paragraph 15 of Circular, banks must maintain an EaR indicator less than 5 percent of the regulatory capital.
- EVE indicator (change in economic value of equity from interest rate changes) must be reported.
  - Pursuant to Article 33 of the Additional Capital Requirements Regulation (Resolution SBS No. 8425-2011), if the change in EVE is more than 15 percent of regulatory capital, the entity must hold additional capital equivalent to the excess over this threshold.
  - Calculation of EVE is regulated and based on Basel Principles for the Management of IRRBB (July 2004); Basel Committee issued new standards for IRRBB in 2016.

### Monitoring and information systems
- SBS monitors IRR via prudential reports in annexes No. 7-A (Measurement of Interest Rate Risk - Gain on Risk) and No. 7-B (Measurement of Interest Rate Risk - Risk Value) to estimate EaR and EVE for domestic and foreign currency positions.
- Paragraph 11: at least monthly, the Chief of the Risk Unit must prepare a report on interest rate risk management for the Board, including:
  - degree of compliance with policies, procedures and exposure limits;
  - adequacy of interest rate risk measurement systems, policies and procedures.
  - A copy of this report should be sent to the SBS (paragraph 19); DSRMLI analyzes these reports off-site.
- On-site examinations verify adequacy of measurement systems, independent validation, appetite-dependent limits, timely exception reporting, internal reporting lines, and scope of audit reviews.
- Manuals referenced:
  - IRRBB Manual G4
  - Organizational Structure G6
- Assessors find Annex 7 prudential report and guidelines for EaR and EVE comprehensive; behavioral aspects (non-term deposits, mortgage early repayment optionality) are considered.
- DSRMLI staff demonstrated good knowledge of IRRBB, regulatory approach and banks’ internal management.

### EC4 — Stress testing for interest rate risk (description and findings)
- Circular No. B-2087-2001 paragraph 10: banks should simulate different scenarios and perform stress tests for interest rate risk, including non-compliance with assumptions and parameter variations used for Annexes No. 7-A and 7-B and internal models (paragraph 9).
- Stress test results should inform establishment and revision of policies, procedures and limits.
- Monthly, DSRMLI receives and analyzes the Risk Unit report including interest rate risk stress tests.
- On-site, DSRMLI verifies relevance and sufficiency of scenarios, robustness of models, independent validation, and communication of results to Risk Committee, Board and management.
- The prescribed ICAAP scenario includes an interest rate shock; DSRMLI is not directly involved in reviewing ICAAP stress test results.

### Assessment of Principle 23 and recommendations
- Assessment: Compliant.
- Comments:
  - Regulatory and supervisory approach and practices are adequate.
  - IRRBB is included in Additional Capital Requirements Regulation; additional capital buffer required if change in EVE is more than 15 percent of regulatory capital when applying a per maturity bucket prescribed interest rate shock.
- Recommendation:
  - The Basel Committee for Banking Supervision issued in 2016 standards for IRRBB. The SBS should review and consider the implementation of the Basel III standards for IRRBB.

---

### Principle 24 — Liquidity risk overview and supervisory framework

### EC1 — Liquidity requirements and supervisory tools (description and findings)
- SBS revised liquidity regulation in 2012 to include Basel III LCR (Resolution SBS No. 9075-2012).
- Article 30: companies must comply with limits:
  - a) Liquidity Ratio in Local Currency (LC): Liquid Assets / Short Term Liabilities in LC ≥ 8 percent. This limit is increased to 10 percent when the concentration of liabilities (of the 20 principal depositors with respect to the total deposits) in the previous month is higher than 25 percent
  - b) Liquidity ratio in Foreign Currency (FC): Liquid Assets / Short Term Liabilities in FC ≥ 20 percent. This limit is increased to 25 percent when the concentration in the previous month is higher than 25 percent
  - c) Liquidity Securities Ratio ≥ 5 percent of Liquid Assets
  - d) Ratio of liquidity coverage: LCR LC ≥ 100 percent and LCR FC ≥ 100 percent (per January 2019). Per the adjustment schedule, the requirement is 80 percent for 2017 and 90 percent in 2018.
- Compliance with a), b), c) evaluated on monthly average of daily balances; LCR must be complied with daily.
- Liquid assets definition for ratios a)–c) differs from HQLA used for LCR (includes balances with financial institutions).
- Liquidity Securities Ratio intended to assure portion of liquid assets held in high quality uncollateralized securities accepted at the BCRP discount window.
- Exemptions: limits c) and d) do not apply to companies with less than two years of operation; or with public deposits / total liabilities ratio < 15 percent, unless assets > 1 percent of total financial system assets. Currently only one bank does not have to comply but is monitored.
- SBS is implementing NSFR and already monitors banks against this ratio.
- Supervisory tools monitor contractual maturity mismatch; concentration of funding; available unencumbered assets; LCR required for significant currencies (PEN and USD); market-related monitoring tools included in internal monthly liquidity report.
- Sanctions and remediation:
  - Non-compliance with a) and b): monetary penalties (fine).
  - Non-compliance with c) and d): entity must send SBS a Liquidity Restoration Plan within a day after breach (breach should not last longer than 30 days). If plan inadequate or situation deteriorates, SBS has sanction and intervention tools.
- Required reports to SBS:
  - Annex No. 15-A: Report of treasury and daily position of liquidity (daily report);
  - Annex No. 15-B: Liquidity coverage ratio (daily report);
  - Annex No. 15-C: Monthly liquidity position (monthly report).
- Additional submissions:
  - Annex 16-A: Contractual liquidity maturity ladder and concentration indicators (monthly report);
  - Annex 16-B: Liquidity stress-test and liquidity contingency plan (quarterly report).

### EC2 — Calibration to market and macroeconomic context (description and findings)
- Liquidity requirements reflect Peruvian market and risk profile:
  - Minimum requirements applied separately for domestic currency and foreign currency (USD) because 40 percent of deposits are in dollars.
  - Exchange of liquidity between currencies accepted with a 5 percent haircut to reflect PEN-USD volatility.
  - Liquidity ratio minimums increased when 20 main depositors > 25 percent of total deposits.
  - LCR run-off rates reflect volatility of funding (stable (insured) deposit 7.5 percent; non-stable deposits 15 percent).
  - Twenty-five percent of minimum reserve requirement deducted from HQLA.
  - For LCR, corporate bonds issued by private companies considered HQLA if rated AA- or higher and eligible for repo with Central Bank.
  - LCR includes off-balance sheet accounts as part of 30-day outflow with a 5 percent weighting.
  - LCR and Liquidity Securities Ratio apply to entities with public deposits / liabilities ≥ 15 percent and/or assets > 1 percent of total financial system.
- Calibrations are more conservative than Basel III LCR framework.
- As of August 2015, SBS required FIs to establish internal loan-to-deposit limits due to increase in loan-to-deposit ratio system-wide.

### EC3 — Liquidity management framework (description and findings)
- DSRMLI (Department of Market Risk, Liquidity and Investments) within SAR supervises market risk; 12 staff dedicating ~ two thirds of time to banks.
- Off-site: DSRMLI reviews prudential liquidity reports and produces Daily and Monthly Liquidity Reports for bank-by-bank and system monitoring.
- DSRMLI participates in on-site examinations led by SABM and scores liquidity risk in SBS rating methodology.
- On-site verifies Board-approved policies, sufficiency of liquidity buffer, approved strategies/policies/procedures/manuals, periodic review at least annually.
- On-site procedures detailed in Guia de Supervision In-Situ de Liquidez.

### EC4 — Liquidity strategy, policies and processes (description and findings)
- Regulatory responsibilities:
  - Article 3: Board must approve tolerance levels to liquidity risk, risk limits, strategy and appetite.
  - Article 12: Board or Risk Committee to establish internal liquidity risk limits consistent with size, concentration and complexity.
  - Article 4: Management strategy (Board-approved) must include: composition and term of maturities, diversity and stability of funding, currency approach, intraday liquidity, off-balance sheet approach, asset liquidity assumptions, and stress considerations.
  - Article 26: FIs must have information systems and support tools; document automated processes/reports; ensure information security.
  - Article 9: Risk Unit must ensure adequate liquidity risk management and evaluate compliance permanently.
  - Article 24: liquidity contingency plan policies/procedures updated at least annually.
- Compliance:
  - Article 30: LCR compliance daily; liquidity ratio and securities ratio monthly (average of daily balances); FIs must calculate and report all indicators daily to SBS.
- On-site verification includes:
  - Board-approved tolerance levels;
  - Internal methodologies/models/indicators covering operational and structural liquidity;
  - Appropriate computer systems;
  - Board and Risk Committee oversight and corrective action approval when deviations occur;
  - Annual review of strategies/policies/procedures/manuals.
- Off-site data reliability for annexes and reports evaluated using DSSIT off-site manual ("Reliability of the Process of Generation of Attachments and Reports").

### EC5 — Funding strategies and monitoring (description and findings)
- Article 9: Risk Unit develops methodology for quantifying liquidity risk in normal and stress scenarios.
- Article 15: entity should simulate three scenarios: normal (liquidity by maturity), systemic stress, company-specific stress; larger entities should simulate additional scenarios.
- High-quality liquid assets buffer and minimum liquidity requirements mandated (Article 3 and Article 30).
- Article 22: Risk Unit must identify counterparties, currencies, markets, instrument types; establish anchoring strategy for diversification; verify access to resources and set internal concentration limits.
- Monthly concentration indicators submitted (Annex 16A):
  - Debt with 10 major creditors / Total creditors
  - Debt with 20 major creditors / Total creditors
  - Debt with 10 main depositors / Total deposits
  - Debt with 20 main depositors / Total deposits
  - Public sector deposits / Total deposits
  - Obligations from abroad with a maturity ≤ 360 days / Total liabilities
- Higher liquidity requirement for FIs where funding from 20 main depositors exceeds 25 percent of total deposits.
- Article 24: contingency plan requires continuous presence in financing markets and close relations with providers; periodic evaluation of capacity to obtain funds.
- Asset-sale capacity and committed lines:
  - Annex 16-B stress scenario applies haircuts: 10 percent for Central Government debt securities; 15 percent for representative foreign government debt securities; 30 percent for corporate bonds with A or lower risk rating and for equity instruments; 40 percent for other debt securities. Additional haircut applied on adverse classified loan portfolio per maturity band.
- Off-site and on-site monitoring include verification of:
  - Defined additional stress scenarios and periodic liquidity gap analysis;
  - Liquid instruments strategy and diversification of liquid assets;
  - Funding diversification strategies and funding structure review;
  - Indicators for concentration control;
  - Identification and monitoring of key counterparties, currencies, markets and instruments;
  - Asset and liability management strategies including asset sales and repo operations.

### EC6 — Contingency funding plans (description and findings)
- Article 24 requires Board-approved liquidity contingency plans, policies and procedures updated at least annually.
- Entities must simulate the regulatory stress scenario (reported in Annex No. 16-B) and keep institution-specific stress scenario simulations available for SBS review.
- Contingency plans should identify sources of financing (e.g., sovereign bonds, global bonds, BCRP deposit certificates) and committed liquidity lines; include sale of investment instruments or use in repo operations.

*cr18366-perufsap - 9.3 When the bank develops new internal models or makes modifications to them, it*

### Annex 16-B) and the action plan will be updated quarterly. The action plan must be

### cr18366-perufsap - Annex 16-B) and the action plan will be updated quarterly. The action plan must be

### Liquidity risk supervision (Principle 24; EC7, EC8)
- FIs must submit quarterly to the SBS Annex No. 16-B "Simulation of Stress Scenarios and Contingency Plan" with a simulation of systemic stress and a detailed strategy for dealing with systemic liquidity crisis, recording estimated cash inflows in each temporary band up to the six-month band.
- FIs must include in the Liquidity Contingency Plan the results of their specific stress scenario simulations, details of sources of financing and strategies, and keep methodologies used for simulations available to the SBS.
- DSRMLI reviews and monitors off-site Liquidity Contingency Plans submitted to the SBS; on-site examinations verify plans through procedures in the on-site supervision manual and include observations and recommendations when deficiencies are found, requiring corrective action within a certain period.
- Since 2012, SBS on-site supervision reviewed liquidity risk in 35 FIs, issuing 25 recommendations regarding FIs’ Liquidity Contingency Plans.
- For FIs belonging to financial or mixed conglomerates for which the SBS is the home supervisor:
  - Article 3 requires the FI’s Board to understand the liquidity risk profile of the financial group on a consolidated level.
  - Article 25 requires the Risk Unit to simulate biannual stress scenarios every six months and prepare a consolidated-level contingency plan considering limits to transfers or liquidity support among group entities.
- The Liquidity Risk Management Regulation applies to licensed FIs under direct SBS supervision and requires calculation and compliance with minimum liquidity requirements in USD and PEN; USD ratios are calibrated more conservatively. Foreign currency stress-testing must account for liquidity risk from foreign currency funding. There are currently no other currencies with material FI activities.
- Assessment of Principle 24: Largely Compliant.
- Comments:
  - SBS framework aligned with Basel III with inclusion of the LCR in 2012; SBS is working on NSFR implementation and monitoring.
  - No group-level liquidity requirements apart from semi-annual stress-testing and contingency plans; group requirement is indirectly enforced via the licensed institution in Peru — indirect regulation is not optimal.
  - Adoption of group liquidity contingency plans for the two groups where SBS is home supervisor is at an initial phase; SBS only recently pushed for more progress.
- Recommendations:
  - The approach towards liquidity risk supervision of financial groups should be intensified.
  - The SBS should continue its work on the implementation of the Basel III NSFR (tailored to the local circumstances) as planned.

*Source: cr18366-perufsap (Annex excerpt).*

### Operational risk (Principle 25; EC1–EC8)
- Regulatory framework and instruments:
  - GIR (Resolution SBS No. 37-2008) to be replaced on April 1, 2018 by Corporate Governance & GIR (Resolution SBS No. 272-2017).
  - Operational Risk Management Regulation: Resolution SBS No. 2116-2009.
  - Operational Risk Capital Requirements Regulation: Resolution SBS No. 2115-2009.
  - Circulars: G-191-2017 (criteria for recording loss events), G-139-2009 (business continuity), G-140-2009 (information security), G-164-2012 and G-180-2015 (reporting significant interruptions and business continuity indicators).
- Key duties and requirements:
  - Article 3 (Operational Risk Management Regulation): SIs must carry out and adequately manage operational risk.
  - Article 6: Board responsibilities include defining operational risk policy, approving the operational risk management manual, and establishing tolerance and risk appetite.
  - Article 11: Operational risk management methodology must be implemented consistently and integrated with SI risk processes; components aligned with COSO (internal environment, objectives setting, risk identification, risk assessment, risk response, control activities, information and communication, monitoring).
  - Article 13 and Circular G-139-2009: SIs must implement business continuity management systems; minimum elements include organization understanding, continuity strategy selection, development and testing, and integration into culture.
  - Circular G-140-2009: Information security management system consistent with ISO standards; minimum controls include logical, personal, physical and environmental security; asset inventory; backup procedures; incident management.
  - Article 12: SIs must implement a database to register all operational risk events of at least PEN 3,000.
  - Circular G-191-2017: additional criteria for recording, valuation and classification of operational risk loss events.
- Supervisory capacity and activities:
  - SAR specialized units: DSRO (operational risk) and DSSIT (IT risk). DSRO and DSSIT staff counts: 14 and 9 respectively; DSSIT foreseen to expand to 14 staff.
  - DSRO scores operational risk in SBS internal rating methodology and reviews Annual Operational Risk Management Reports, risk reports for new products/major changes, and reports of significant interruptions and business continuity indicators.
  - On-site examinations include manuals for "Operational Risk Management", business continuity and information security; DSRO and DSSIT assess whether stress-test results and contingency plans inform asset-liability management strategy adjustments.
- Sectoral business continuity exercises:
  - Initiated in 2013 to improve system preparedness for systemic operational interruptions; coordinated via "Business Continuity Work Team" with 28th meeting at end of July 2017.
  - Sectoral Exercises executed every three years:
    - First in 2014 involved 12 institutions (ASA users representing more than 90 percent of sector assets); led to action plans (e.g., acquisition of resilient communication means, public service hubs, alternative cash strategies, first SBS measures for systemic events).
    - Second in August 2017 had 23 participants including FIs, insurance system, SBS, BCRP and Ministry of Finance and Economics; scenario: large earthquake between 8 and 8.5 degrees Richter affecting Lima.
  - Assessors note participation limited to SIs with reasonably mature business continuity management; SBS still needs to implement recommendation to obtain satellite radio communication devices identified in first exercise.
- EC assessments:
  - EC1–EC3: Supervisory framework requires SIs to have operational risk strategies, policies and processes approved by Board and implemented by management; DSRO and DSSIT undertake off-site and on-site verifications.
  - EC4: Business continuity requirements and supervision in place; SIs must implement Crisis Management Plan and Business Continuity Plan(s), Emergency Plan and IT Recovery Plan(s).
  - EC5–EC6: Information security and IT risk frameworks mandated; DSSIT supervises IT implementation, information security, reporting reliability and data quality (prioritizing Credit RWA standard approach, liquidity risk reports, deposit insurance reports).
  - EC7: Reporting mechanisms required — Annual Operational Risk Management Report (Article 15), timely reporting of significant interruptions (Circular G-164-2012), quarterly key indicators of business continuity (Circular G-180-2015), and ASA-authorized SIs submit quarterly detailed loss-event data to Central Database.
  - EC8: Outsourcing requirements (Article 14 Operational Risk Management Regulation; Corporate Governance & GIR Articles 35–37); significant subcontracting requires risk analysis, Board approval, contractual SLAs, and, in some cases, prior SBS authorization for abroad processing.
- Assessment of Principle 25: Compliant.
- Comments:
  - SBS has a sound regulatory and supervisory approach toward operational risk via specialized SAR departments.
- Recommendations:
  - The SBS should follow up on the recommendations (and lead by example) from the industry-wide business continuity stress-test.

*Source: cr18366-perufsap (Annex excerpt).*

### Internal control and internal audit (Principle 26; EC1–EC5)
- Legal and regulatory framework:
  - GIR (Resolution SBS No. 37-2008) and Corporate Governance & GIR (Resolution SBS No. 272-2017, effective April 2018) define internal control as a Board, senior management and staff process to provide reasonable assurance on operations, financial reporting and compliance.
  - Internal Audit Regulation: Resolution SBS No. 11699-2008.
- Board and governance responsibilities:
  - GIR Article 9 and Corporate Governance & GIR Articles 7, 9, 14, 19: Board must approve organization and function manuals, delegation of powers, segregation of functions, and establish Audit Committee, Risk Committee, Compensation Committee (Audit Committee mandatory for FIs).
  - Audit Committee responsibilities include ensuring appropriate accounting and financial reporting processes and evaluating internal and external auditors’ activities.
  - Boards must establish whistleblowing and reporting mechanisms; Internal Audit Unit must notify SBS of significant adverse events per Internal Audit Regulation.
- Internal audit requirements and functions:
  - Internal Audit Unit (IAU) must be independent, have access to all information and powers needed, evaluate internal control design and operation, design audit plan, evaluate IT/system quality, verify compliance and follow-up implementation of recommendations, and verify AML/CFT systems.
  - IAU quality assurance and improvement program: internal evaluation annually and external evaluation at least every 5 years (Circular G-161-2012).
  - On-site supervision reviews Audit Committee minutes, IAU workpapers, reports, and compliance with internal audit standards; participation of Audit Committee Chair in supervisory interviews is unusual.
  - Internal Audit Regulation does not apply consolidated; Consolidated Supervision Regulation article 29 requires IAU of supervised entity to assess group risk management and accounting policies.
- Resources, independence and methodology:
  - Article 7 (Internal Audit Regulation): IAUs must have required knowledge and competencies proportionate to company complexity; each IAU must have an information systems audit service with competent personnel (may be subcontracted).
  - Professional certifications noted: CIA, CISA.
  - Article 8: Head of IAU must present training plan with main areas and number of hours required annually.
  - IAU reports to Audit Committee and has mechanisms to ensure independence and authority to access information (Article 5).
- Assessment of Principle 26: (implied from text) supervisory framework robust; elements evaluated via on-site manuals and incorporated into SBS internal rating methodology (qualitative indicator "Quality of the IAU").
- EC-specific findings:
  - EC1: Regulations require adequate internal control frameworks covering organizational structure, accounting policies, checks and balances, safeguarding assets.
  - EC2: On-site manuals verify separation of roles and independence of control bodies; SBS requests corrective actions when weaknesses found and evaluates specific criteria in internal rating (e.g., segregation of functions, veto capacity, compliance officer training, IAU staffing).
  - EC3: GIR Article 7-A requires Compliance Function with direct reporting line to Board, managerial level authority, periodic reporting; Corporate Governance & GIR Articles 29–30 expand Compliance Function responsibilities and Board approval of compliance policies; IAU must periodically review compliance activities.
  - EC4–EC5: IAU independence, responsibilities, staffing, access to information, methodologies, audit planning and authority over outsourced functions are mandated; IAU effectiveness reviewed during on-site examinations and factored into SBS internal ratings.
- Noted limitation:
  - Internal Audit Regulation not consolidated, implying indirect consolidated-level oversight; current indirect supervision appears to function because main group entities remain in Peru.

*Source: cr18366-perufsap (Annex excerpt).*

### conclusions, including that which is derived from minutes of the Board and its

### cr18366-perufsap - conclusions, including that which is derived from minutes of the Board and its

### Internal audit framework and methodology
- The Internal Audit Regulation establishes the minimum examinations to be carried out by the IAU, including evaluation of the management of the main risks to which the SIs are exposed.
- Article 9 of the Internal Audit Regulation establishes that, insofar as it does not conflict with the provisions of the regulations of the SBS, the International Standards for the Professional Practice of Internal Audit and the Code of Ethics issued by The Institute of Internal Auditors (IIA) apply, including standards on the planning of audit work.
- For system auditors, audit guidelines provided by the Information Systems Audit and Control Association (ISACA) shall be taken into account.
- The Internal Audit Supervision Manual analyzes whether the IAU has adequate infrastructure—human, technical and logistical resources—related to the magnitude and complexity of the operations of the company.

### Subcontracting, risk assessment, and contractual clauses
- Article 21 of the Risk Management Regulation (and Article 36 of the Corporate Governance & GIR, coming into force per April 2018) requires that, in cases of significant subcontracting, contracts with suppliers include clauses that facilitate adequate revision of the provision by the SIs, the internal audit unit, the external auditor, and the SBS or persons designated by it.
- Definition: Significant subcontracting means that, in case of failure or suspension of the service, it can put the SI at significant risk by affecting its income, solvency, or operational continuity. The subcontracting of one or more risk management functions will be considered significant.
- In operational risk supervision, the SBS reviews whether significant subcontracts have been subject to risk assessments and that clauses have been agreed to facilitate adequate review by Internal Audit, External Audit and SBS.

### Internal Audit Reporting System (SIRAI) and supervisory review
- Through SIRAI the IAU sends information to the SBS; based on this information the SBS evaluates off-site:
  - Whether the IAU is formally independent;
  - Whether the IAU reports to the Audit Committee;
  - Staff numbers and staff profiles;
  - Execution of the Audit Plan;
  - Number and time period of outstanding recommendations made by the SBS, external auditor, and the IAU itself.
- The SBS verifies IAU independence by evaluating:
  - Lines of reporting and responsibility established within the organizational chart;
  - Infrastructure conditions and assigned equipment;
  - Whether the internal audit function is directly accountable to the Board (in accordance with established standards);
  - Whether special assignments to the IAU have the conformity of the Audit Committee and/or Board and are compatible with monitoring and control functions;
  - Whether the internal auditor has unrestricted access to all information related to the activity and business of the company.
- Regarding the Work Plan (also sent through SIRAI), the SBS verifies:
  - Compliance with minimum activities established by current regulations;
  - Level of progress via quarterly reports sent through SIRAI;
  - In evaluating reports, the SBS considers scope and frequency of audit work, appropriate documentation, content of the audit program and conclusions in audit reports, ability to detect weaknesses or opportunities for improvement, and effective use through actions taken by the Board and management on IAU recommendations.
- The SBS may request additional activities to be performed by the IAU, according to identified risks, with predefined scope and procedures.
- Results of on-site assessments are incorporated into the internal rating methodology (qualitative indicator referring to UAI quality) and are taken into consideration when determining the SI’s risk profile and corrective measures, if needed.

### Assessment of Principle 26
- Assessment: Compliant
- Comment: The regulatory framework and supervisory approach and practices for internal control and audit are consistent with the scale and nature of the financial system.

### Principle 27 — Financial reporting and external audit: summary findings
- The supervisor determines that banks and banking groups maintain adequate and reliable records, prepare financial statements in accordance with accounting policies and practices that are widely accepted internationally, annually publish information that fairly reflects their financial condition and performance, and that such statements bear an independent external auditor’s opinion. The supervisor also determines that banks and parent companies of banking groups have adequate governance and oversight of the external audit function.

### EC1 — Board and management responsibility for accounting and records
- Legal basis:
  - Article 87 (sub 6) of the LGSF: Board’s responsibility to adopt measures conducive to timely completion of internal and external audits.
  - Article 92: holds senior management responsible.
  - Paragraph 13 of article 349 of the LGSF: SBS is the accounting standard setter for financial institutions.
- SBS powers: dictate general rules to specify preparation, presentation and publication of financial statements and consolidation rules in accordance with generally accepted accounting principles.
- Accounting Manual: accounting standards are based on and aligned with IFRS, with three main differences:
  - The provisioning requirements are those of the Classification of Borrowers and Provisioning Regulation (Resolution SBS Nº 11356-2008);
  - The revaluation of fixed assets for own use is not allowed;
  - Income of paid fees (closing commission) for loans are not recognized as part of effective interest rate, but they are amortized over the maturity of the loan.
- Conglomerates for which the SBS is the home supervisor seem to prepare Financial Statements on IFRS. Currently differences are limited, but with implementation of IFRS9 the difference is expected to increase.
- Accounting Manual provision: where accounting standard is not specified by SBS, IFRS as set by IASB and made official in the country by the Accounting Standards Board (Consejo Normativo de Contabilidad) apply.
- The SBS does not have plans to transition to IFRS9 for the financial sector at present.
- For the non-financial sector, Peru adopted IFRS in 2011 and IFRS9 will be implemented by the non-financial sector in 2018.
- Financial sector stakeholders indicated preference for application of IFRS9 to avoid increasing the gap with the international community.

### EC2 — External auditor opinion and auditing standards
- Legal and regulatory provisions:
  - Article 180 of the LGSF: SBS will establish requirements and standards for internal and external audit for FIs and insurers; financial institutions must submit financial statements for review to the external auditor, who must give its opinion.
  - Article 5 of the External Audit Regulation (Resolution SBS No. 17026-2010): Board or Audit Committee and management are responsible for providing the contracted audit firm with necessary information and facilities; management must report (as sworn declaration) to the Audit Committee that information access has not been limited.
  - Article 15: audits must be carried out applying the International Standards on Auditing and Related Services issued by the IAASB of IFAC and approved by the Board of Deans of the Association of Public Accountants of Peru, as well as SBS provisions.
  - Article 19: financial statements must contain the opinion of the audit firm on the reasonableness of the financial statements in accordance with SBS provisions, and in unforeseen situations by IFRS provisions.

### EC3 — Valuation practices and fair value
- There is no difference in the accounting standards banks are required to use for accounting and for prudential reporting.
- The Accounting Manual (Section E of Chapter I) indicates financial instruments measured at fair value must follow guidelines: value observed in market transactions under "normal" situations and mutual independence and will take into account the credit quality of the instrument.
- Regulation for Classification and Valuation of Investments of Companies in the Financial System (Resolution SBS No. 7033-2012) establishes guidelines consistent with:
  - IAS 32, IAS 39 and its Guide to Application, IAS 21, IAS 28, IAS 31, IAS 36, IFRS 3, and IFRS 7.
- Regulation for Trading and Accounting of Financial Derivative Products in Financial System Companies (Resolution SBS No. 1737-2006) establishes guidelines for accounting recording of derivative financial instruments for trading and hedging purposes.

### EC4 — Scope of external audits and risk/materiality approach
- Legal basis:
  - Article 367 (sub 7) of the LGSF: SBS power to issue provisions to coordinate work with internal and external auditors.
  - Article 6 of the External Audit Regulation: scope of external audits requiring FIs to contract external audit companies for:
    - a) the reasonableness of the financial statements and evaluation of aspects indicated in Annex I (supplementary reports);
    - b) evaluation of the internal control system in the field of external audit;
    - c) evaluation of the money laundering and prevention of terrorism prevention system (to be performed by a team independent from the financial audit team).
  - Article 7 (conglomerates): additional requirements include:
    - a) the annual review of reasonableness of consolidated financial statements of the conglomerate prepared in accordance with rules established by the Securities Market Regulator (SMV) and IAS 27, taking into account SBS accounting standards for supervised financial institutions;
    - b) evaluation of compliance with regulatory capital requirements and overall and concentration limits established in the Consolidated Supervision Regulation at a group level.
  - Article 8: SBS may arrange contracting of a different audit company or expand the scope/opportunity for examinations, at companies' expense, when:
    - a) results of audit examinations do not comply with External Audit Regulation provisions or are not satisfactory at SBS discretion;
    - b) SBS requires complementary audits.

### EC5 — Audit coverage areas
- Article 6 of the External Audit Regulation requires that companies contract external audit companies for:
  - a) the reasonableness of the financial statements and evaluation of aspects indicated in Annex I (supplementary reports);
  - b) evaluation of the internal control system;
  - c) evaluation of the money laundering and terrorism prevention system.

*Source: cr18366-perufsap - conclusions, including that which is derived from minutes of the Board and its*

### Annex I of the Regulations states that external audit companies will review all that

### cr18366-perufsap - Annex I of the Regulations states that external audit companies will review all that

### External audit scope and required supplementary reports
- Annex I of the Regulations requires external audit companies to review all that has been involved in the preparation of financial statements, including accounting records, policies, procedures, systems used and supplementary information associated with the main risks faced by the company, based on sampling criteria, as appropriate and in accordance with applicable auditing standards.
- The external auditor shall also prepare specifically for the SBS supplementary reports covering:
  - Review of the loan portfolio, considering the classification of debtors, constitution of required provisions, restructuring, refinancing or reprogramming of credits, as well as the criteria considered for the determination of the sample of the borrowers;
  - Review of compliance with global and individual limits;
  - Review of liquidity management;
  - Review of balance sheet and off-balance sheet risk management;
  - Review of the risk management of the interest rate in the trading book and banking book;
  - Review of operational risk management;
  - Review of the investment portfolio (on a sample basis);
  - Review of existing controls in the enterprise, the security and reliability of computer systems that produce financial statements.

- The SBS also verifies in its on-site examination the items covered by the required supplementary reports and only to a limited extent takes into account the assurance work conducted by the external auditor.

### Supervisor powers over auditor appointment and contracting (EC6)
- Article 18 of the External Audit Regulation:
  - SIs need to inform the SBS every year before May 31 of the external auditor company that has been preselected, indicating their registration with the Register of External Auditors of the SBS and the Register of the Colegios de Contadores Públicos Departamentales de la República.
  - Within 15 days after receiving the information the SBS has to inform the SI of any observations it deems pertinent.
- Article 8 of the External Audit Regulation permits the SBS, at the companies' expense, to arrange contracting of a different audit company or expand the scope of the audit and the timing of examinations when:
  - a) The results of the audit examinations carried out do not comply with the provisions of the External Audit Regulation, or are not satisfactory at the discretion of the SBS;
  - b) The SBS at its discretion requires the performance of complementary audits to those established in these regulations.

### Auditor rotation requirements (EC7)
- Article 12 of the External Audit Regulation:
  - The audit firm must rotate the partners responsible for issuing opinions on the reasonableness of the financial statements after five consecutive annual financial years of having performed audit in the same company.
  - Once said maximum period has expired, a period of at least two years must elapse before any such person can re-audit the company.
- Requirements for the report on the evaluation of the system for the prevention of money laundering and financing of terrorism:
  - It must be carried out by a different auditing company or a completely different team from the one that issued the opinion on the reasonableness of the financial statements.
  - The rotation required for the audit of financial statements is also applicable to the auditing company and the team preparing the report on the evaluation of the money laundering and terrorism financing prevention system.
- Supervisory follow-up:
  - As part of off-site procedures, the SBS verifies contracts to ensure rotation requirements per article 12 are met.
  - When non-compliance is identified, the SBS formally communicates to the FIs and requires corrective action.
  - The SBS has occasionally required rotation of individuals within the external audit firm via Official letters.

### Engagement and meetings with external auditors (EC8)
- The different teams within the SABM meet when needed with the external auditors of the banks they supervise; these are bilateral meetings.
- There is no standard practice of organizing trilateral meetings to discuss the management letter prepared by the external auditor, including for systemically important institutions or institutions with a higher risk profile.
- Formal meetings with external auditors on broader financial sector issues of common interest are not regularly scheduled.

### Reporting obligations and protections (EC9)
- Article 4 (e) of the External Audit Regulation:
  - Audit firms must include in the contract their obligation to make available to the SBS the working papers and other supporting documentation of the reports they issue and, if applicable, to support the report at the request of the SBS.
- Article 4 (g) of the External Audit Regulation:
  - The contract must contain a clause stating that the audit firm is obliged to disclose situations that demonstrate a lack of solvency, insufficient equity and/or accentuated financial or economic weakness of the audited company, and disclose any act or event that violates any provision which the SIs are required to comply with.
- Article 13:
  - Audit firms are required to notify the SBS in writing within ten working days of their knowledge of the significant adverse events they detect in the audit process, without prejudice to include them in the corresponding reports.
- Article 14:
  - In the event of problems that do not allow for adequate audits, the auditor must immediately notify the SBS and indicate in the respective reports the reasons.

### Assessment of Principle 27 and comments
- Assessment of Principle 27: Largely Compliant
- Comments:
  - The regulatory and supervisory framework are broadly adequate.
  - The SBS could improve its engagement with the external auditors.
  - The SBS could assess more in depth whether the current provisioning requirements are adequate when compared with the new IFRS9 standard, while also considering possible issues related to the resulting differences in accounting standards (as a result of not implementing IFRS9) between supervised institutions (using SBS standards) and consolidated financial groups (which may use IFRS standards).

- Recommendations:
  - Assess more in depth the potential impact of implementation of IFRS9 on FIs provisioning requirements, in particular to determine whether the current provisioning requirements are sufficiently prudent;
  - The SBS should discuss and engage with the different stakeholders on the implementation strategy of IFRS9;
  - The SBS should consider developing a structured (risk-based) approach for conducting trilateral meetings with the external auditor and the FIs to discuss the management letter;
  - Strengthen the engagement with the external auditor and the audit profession, as part of SBS’ supervisory approach.

### Disclosure and transparency (Principle 28) — Overview and EC1–EC3 findings
- Principle 28 summary:
  - The supervisor determines that banks and banking groups regularly publish information on a consolidated and, where appropriate, solo basis that is easily accessible and fairly reflects their financial condition, performance, risk exposures, risk management strategies and corporate governance policies and processes.

- EC1: Periodic public disclosures required
  - Article 135 of the LGSF:
    - FIs must keep their clients informed about the development of their economic and financial situation.
    - Notwithstanding annual reports, they are obliged to publish the financial statements in the Official Gazette and in a newspaper of extensive national circulation, at least four times a year in a prescribed format.
  - Chapter II of the Accounting Manual:
    - SIs must quarterly publish their Statement of Financial Position and Statement of Comprehensive Income in comparison with the previous year.
    - They are required to publish their capital requirement and the calculation of their capital ratio as well as disclosing assets granted as collateral in support of financing received.
    - A similar requirement applies to financial groups for which the SBS is the home supervisor.
  - Article 137 of the LGSF:
    - The SBS shall disseminate, at least quarterly, information on the main indicators of the situation of FIs.
    - The SBS may order supervised companies to publish any other additional information it deems necessary for the public; the SBS publishes extensive quantitative information of FIs on its website.
  - Banks are required by Law to be listed and are subject to SMV disclosure regulations, including:
    1. Individual information: quarterly financial statements approved by the Board are disclosed, including notes; annual financial statements audited and approved by the General Meeting of Shareholders, the day after having been approved, with deadline of 15 April.
    2. Companies supervised by the SBS must prepare their financial statements observing regulations of the SBS.
    3. Consolidated information of the conglomerate: scope of consolidation should be established in accordance with IFRS; quarterly financial statements including notes and audited annual financial statements.
    4. Annual report: presented in conjunction with the annual financial statements; the Principles of Good Corporate Governance and the Corporate Sustainability Report should be appended.
  - Material Events Regulation (Resolution SMV No. 005-2014-SMV / 01):
    - The issuer must disclose the material event as soon as such an event occurs or the issuer becomes aware of it, and in no case beyond of the day on which it has occurred or has been known.

- EC2: Scope and content of disclosures
  - SIs must quarterly publish their Statement of Financial Position and Statement of Comprehensive Income and year-end comparisons with the previous year.
  - They are required to publish their capital requirement and the calculation of their capital ratio; a similar requirement applies to financial groups for which the SBS is the home supervisor.
  - The Accounting Manual (chapter I) specifies the Annual Report should contain at least:
    a) The year-end financial statements (including notes to the financial statements);
    b) The report of the External Audit Company on the financial statements of the company;
    c) When applicable, the consolidated financial statements of the conglomerate, prepared in accordance with the standards established by the SMV (consolidate in accordance with IAS 27 "Consolidated and Separate Financial Statements");
    d) The report of the External Audit Company on the consolidated financial statements of the conglomerate;
    e) A state of the economic and financial situation of the company, including financial projections, as well as a summary evaluation of each of the most important events occurring in the period and subsequent events;
    f) Information on compliance with the Code of Good Corporate Governance;
    g) General description of the main characteristics of the entity's risk management;
    h) Other information required in specific regulations by this SBS.
  - Notes to annual financial statements must be prepared in line with IAS1 “Presentation of Financial Statements”, which covers information on financial position, risk management strategies and practices, risk exposures, aggregate exposures to related parties, transactions with related parties, accounting policies, business and management, and governance and remuneration.
  - Pillar 3 has not been implemented yet, and the SBS has so far not given any consideration to the recommendations made by the Enhanced Disclosure Task Force of the Financial Stability Board.

- EC3: Disclosure of group entities
  - Article 21 of the Consolidated Supervision Regulation:
    - Full and timely presentation of information corresponding to the unsupervised companies that are part of the conglomerate is the responsibility of the company supervised by the SBS.
    - When more than one supervised entity exists in the financial group, the entity responsible for submission is the one with the largest share of the assets of the financial group; if indeterminate, the SBS will determine the responsible company.
  - Article 22:
    - The entity responsible shall publish annually the Consolidated Financial Statements of the Financial Group as well as the amount of surplus or equity deficit in a newspaper of extensive national circulation; statements must correspond to the end of each year.
  - Article 23:
    - Consolidated financial statements for the fourth quarter should include general notes including: (i) identification of the financial group and companies included in consolidation and, if applicable, list of companies not included and reasons for exclusion; (ii) changes in the composition of the consolidated group.
    - Fourth quarter consolidated statements should include, as specific notes, the detail of each item of the financial statements.

*Source: https://www.imf.org/-/media/files/publications/cr/2018/cr18366-perufsap.pdf*

### Chapter I of the Accounting Manual states that, where appropriate, the company's

### cr18366-perufsap - Chapter I of the Accounting Manual states that, where appropriate, the company's

### Disclosure standards and consolidated financial statements
- Chapter I of the Accounting Manual: where appropriate, the company's financial statements should include the consolidated financial statements of the conglomerate, prepared in accordance with the standards established by the SMV.
- Financial statements must contain the report of the External Auditor on the consolidated financial statements of the conglomerate.

### EC4 — Supervisor review and enforcement of disclosure standards
- Finding: SBS’ supervisory approach is focused on assuring the quantitative quality of the financial statements; only the quarterly disclosure requirements (mainly quantitative) are in scope of its supervisory approach.
- Finding: Annual disclosures are covered by the regulations of the SMV.
- Finding: Assessors reviewed information on the website of the SMV; information is easily accessible and appeared complete.
- Limitation: Assessors did not have meetings with the SMV and did not assess the depth of SMV’s evaluation of qualitative disclosures.

### EC5 — Public dissemination of aggregate banking system information
- Legal basis:
  - Article 137 of the LGSF: SBS must disseminate, at least quarterly, information on the main indicators of the situation of companies in the financial system, linked to credit and marketable portfolios, investments and other assets, classification and evaluation according to degree of recoverability, and level of equity and provisions; SBS may order supervised institutions to publish additional information it deems necessary.
  - Article 353: SBS should periodically disseminate information on main indicators of SIs subject to its supervision and may order them to publish additional information it deems necessary.
- SBS publication practice:
  - Web Portal (www.sbs.gob.pe) publishes statistical and financial information for the system as a whole, by group of entities, and by financial system entity.
  - Monthly publications include: financial statements, risk-weighted assets, regulatory capital, the main financial indicators and statistics of the main operations of the institutions, structure of assets and liabilities, and variables and indicators reflecting main risks.
  - Quarterly publication: evolution report describing behavior of main variables and indicators by group of companies.
  - Financial Inclusion Indicators Report: published every six months, containing information on depth, access and use of financial services.
  - Additional statistical information on the exchange rate and market interest rates is published.
- Internal Directives used:
  - SBS Directive No. SBS-DIR-EEC-170-01, Rules for the preparation, publication and distribution of statistical information bulletins;
  - SBS Directive No. SBS-DIR-EEC-113-05, Rules for calculating and disseminating average interest rates;
  - SBS Directive No. SBS-DIR-EEC-142-04, Rules for calculating and disseminating the exchange rate.
- SBS Annual Report includes a section on evolution of main variables and indicators of companies in the financial system.

### Assessment of Principle 28
- Rating: Compliant
- Comment: Regulatory and supervisory approach and practices for disclosures and transparency is adequate for the level of development of the financial system.
- Comment: Regulatory framework assures required disclosures are easily accessible on the website of the SMV; required annual disclosures are based on IAS1 and are complemented by quarterly disclosures required by the SBS. SBS publishes detailed quantitative financial information of supervised entities and financial markets on its website.
- Recommendation:
  - Consider implementing the recommendations of the Enhanced Disclosure Task Force of the FSB and Pillar 3 of the Basel framework.

### Principle 29 — Abuse of financial services; legal and supervisory framework
- Principle: Supervisor determines banks have adequate policies and processes, including strict customer due diligence (CDD) rules, to promote high ethical and professional standards and prevent misuse for criminal activities.

### EC1 — Legal duties, responsibilities and powers related to supervision of internal controls and criminal activity
- Legal framework: General Law grants SBS broad powers; fifth section of the General Law dedicated to suspicious activities and SBS powers regarding verification and monitoring of effective compliance with obligations and programs requiring mandatory compliance.
- Article 381 (fifth section) empowers SBS to:
  - a) grant, deny, suspend or cancel licenses of financial entities;
  - b) take measures to prevent unsuitable persons from controlling or participating in board, management and operations of a financial entity;
  - c) examine, control and supervise financial entities and regulate and monitor fulfillment of registration and notification obligations related to suspicious transactions;
  - d) verify, through regular reviews, that financial entities have established and properly implemented programs for mandatory compliance;
  - e) provide other competent authorities with information obtained from financial entities in accordance with articles 375 and subsequent, including from SBS own examinations;
  - f) issue instructions and recommendations to help detect suspicious patterns in clients’ conduct, developed taking into account modern and safe techniques for asset management and serving as educational elements for staff;
  - g) cooperate and provide technical assistance to other competent authorities within investigations and prosecutions relating to illicit drug trafficking or related offenses.
- Role: Within banking supervision, SBS oversees risk management systems related to AML/CFT, in accordance with FIU Law and supervisory mandate.

### EC2 — Requirements for banks’ policies and processes to prevent criminal activity
- Legal/regulatory sources: General Law and Resolution 2660-2015 (AML Risk Management Regulation).
- Article 380 of the General Law requires financial entities to adopt, develop and implement programs, policies, procedures and internal controls to prevent and detect crimes as established by Article 296-B of the Penal Code. Required program elements include:
  - a) procedures to ensure high-level staff integrity and system for evaluating personal, employment and financial history of staff;
  - b) permanent training programs such as know your client and instruction on responsibilities in articles 375 to 378 (client identification and record keeping; availability of records; records and notification of cash transactions; communication of suspicious transactions);
  - c) an independent audit mechanism to verify compliance with the programs.
- AML/CTF Risk Management Regulation expectations:
  - Existence of procedures and controls; defined responsibilities of Board, senior management, Compliance Officer; requirement for AML/CFT Manual with minimum content; need for Code of Conduct; establishment of AML/CFT Risk Management Committee.
  - Article 3: entities must implement an AML/CFT System comprising compliance and risk management components; compliance component covers policies/procedures related to legal/regulatory requirements and confidentiality; risk management component includes procedures/controls for early detection and reporting of suspicious transactions.
  - Article 5: Board responsibilities to implement AML/CFT framework and foster internal environment; Article 6: senior management responsibilities to comply with controls and support compliance officers.
- Related regulations:
  - Internal Audit Regulation: role of internal audit in verifying compliance with AML/CFT framework; requires annual report to SBS with conclusions of assessment.
  - External Audit: required to assess AML/CFT systems and submit annually a report to SBS.
  - Corporate Governance and Risk Management Regulation: requires systems for timely reporting and investigation of non-authorized, illicit, fraudulent and questionable practices; reports to IAU or equivalent ensuring confidentiality; significant events communicated to SBS.
- SBS supervision manuals:
  - Updated in 2011 (full review), 2012 (correspondent banking), 2013 (transfer of funds and risk assessment); updates planned to cover AML Risks Management Regulation issued in 2015 and 2017.
  - Assessment scope includes:
    - a) AML/CFT Manual, Code of Conduct and other internal regulations against SBS minimum criteria;
    - b) Compliance Officer compliance with legal/regulatory requirements and adequacy of organizational resources;
    - c) procedures and tools for knowledge of client, market and personnel;
    - d) diligence and knowledge in Correspondent Banking and correspondent relations in fund transfer operations.
- Supervision methods:
  - Off-site supervision uses compliance office reports, internal audit, external audit, and questionnaires assessing exposure to money laundering and terrorist financing risks; results inform on-site examinations.
  - On-site examinations typically comprise two people and include targeted visits on KYC, correspondent banking, international transfers; special visits may be initiated for FIU-referred actions.
- Requirement: SBS requires banks to have procedures ensuring integrity and ethics of directors, managers and employees, compliance with Code of Conduct and AML Manual; banks must establish systems for timely reporting and investigation of unauthorized, illicit, fraudulent and other questionable practices; these are verified in supervision.

### EC3 — Reporting to FIU and supervisor of material suspicious activities
- Legal basis:
  - Article 8 of the FIU Law requires financial entities to report suspicious activities to the FIU (a specialized unit of the SBS, per Article 1° of Law N° 29038).
  - Article 378 of the General Law requires submission of suspicious transactions to the FIU.
- Finding: There are no specific requirements for banks to report to banking supervision suspicious activities when such activities/incidents are material to the safety, soundness or reputation of the bank.
- Chief Internal Auditor: required to report material events in general to the SBS two days after evaluation and production of a report; preliminary reporting prior to concluding assessment is possible (Art. 13 of the Internal Audit Regulations). No instances to date.

### EC4 — Supervisor informing FIU and other authorities upon detection
- Legal basis and practice:
  - Article 381 of the General Law enables SBS to provide other competent authorities suspicious transactions but does not create an explicit obligation to do so.
  - General Law explicitly requires informing the attorney general of criminal acts detected during examinations (not explicitly covering suspicious activities).
  - FIU Law, Article 10.2.3 (on External Audit), item b: supervisory bodies of entities required to report suspicious activities must issue reports and submit to the FIU when through supervisory functions they detect presumption of money laundering and/or terrorist financing.
- Practice: Each Deputy Superintendent has a compliance officer to report to the FIU electronically; SBS reports having reported a few cases.

### EC5 — CDD policies and processes (group-wide CDD elements)
- International criterion elements expected:
  - a) customer acceptance policy identifying unacceptable business relationships;
  - b) customer identification, verification and ongoing due diligence including beneficial ownership verification, understanding purpose and nature of relationship, and risk-based reviews;
  - c) policies/processes to monitor and recognize unusual or potentially suspicious transactions;
  - d) enhanced due diligence on high-risk accounts, including escalation to senior management for decisions on entering/maintaining relationships;
  - e) enhanced due diligence on politically exposed persons, including escalation to senior management;
  - f) clear record-keeping rules on CDD and individual transactions with at least a five-year retention period.
- Findings: In Peru, the legal and regulatory framework regarding CDD is overly prescriptive and does not encompass overall requirements laid out in this criterion to enable entities to develop their own internal policies and criteria, in addition to detailed requirements aimed at ensuring a more effective framework.

*Source: cr18366-perufsap - Chapter I of the Accounting Manual states that, where appropriate, the company's (PDF chapter).*

### Chapter V of the AML/CFT regulation is focused on CDD.

### cr18366-perufsap - Chapter V of the AML/CFT regulation is focused on CDD

### Definitions and scope
- Article 27 defines "customer" as the natural or legal person to which financial services are provided.
- CDD requirements apply irrespectively particular characteristic or frequency of operations and apply also to the beneficiaries in case of fund transfers.
- Article 28 requires verification of beneficial ownerships.
- Article 29 (2) states that if the entity does not have the capacity to take all necessary CDD measures it shouldn’t: initiate a commercial relationship with such client, perform any transactions and/or terminate the business relationship; and/or assess the possibility to report suspicious transactions in relation to such client.

### CDD process stages
- Article 29 establishes the CDD process stages:
  - Identification: procedures to obtain necessary information to determine the ultimate beneficiary.
  - Verification: verification procedures at the beginning of the contractual relationship ensuring customers have been duly identified and recorded in their personal documentation.
  - Monitoring: ensuring operations performed by customers are compatible with their profile, reinforcing and reaffirming the entity’s knowledge, and obtaining more information when doubts arise.
- Entities should determine monitoring frequency considering the LA / FT risks they face.

### CDD regimes: general, simplified, enhanced (Articles 30–32)
- General system:
  - Establishes minimum information to obtain from customers (individuals and legal entities).
  - Requires verification of such information.
  - Requires rating money laundering and terrorism finance risks through a scoring system.
  - Entities must keep monitoring procedures to ensure documents, data and information are kept up to date and in force.
  - Frequency of monitoring depends on identified risks.
- Simplified system:
  - Allows reduction of minimum identification information when ML/TF risk warrants it, according to treatment established by the SBS or authorization granted to certain products and/or services.
  - To apply simplified regime to a product, prior authorization from the SBS is required. Thus far those include basic accounts and simplified e-money accounts.
- Enhanced regime (Art. 32):
  - Entities must develop and implement enhanced CDD procedures.
  - Entities must identify and register customers whose business transactions show a pattern not matching their risk profile, and customers who could be highly affected by ML/TF risks.
  - Mandatory for several client types, including PEPs.
  - Listed enhanced measures include increasing transaction review frequency, updating customer information, and escalation of acceptance/maintenance decisions to senior management level.
- Gap noted: Although PEPs are under the enhanced regime, there are no explicit requirements regarding establishment of the source of funds or wealth or requirements of additional information on the intended nature of the business relationship.

### Risk factors to inform CDD (Article 4)
- Entities must take into account as risk factors: clients, products and services, and geographic zones (local and international).
- Aspects to be assessed:
  - a) Client: manage risks associated with customers, their behavior, history and activities at the beginning and throughout the business relationship, taking into account customers’ characteristics.
  - b) Products and/or services: manage risks during design, development and operation stages, including distribution channels and means of payment.
  - c) Geographical area: manage risks associated with jurisdictions, considering security features, economic and financial and socio-demographic aspects, provisions from competent authorities or the FATF, among others.

### Warning signs and AML/CFT manuals
- Annex 5 lists a significant number of warning signs related to unusual transactions; entities should define particular criteria depending on their operations.
- Each entity is required to establish procedures for evaluation of warning signs in the AML/CFT Manual or equivalent, available to the SBS.

### Records retention
- General Law, Article 375(6): entities must keep records to enable reconstruction of financial transactions above a certain amount in accordance with Superintendence provisions, for at least ten years after the conclusion of the transaction.
- Articles 54 and 55 of the AML/CFT Regulation further elaborate on CDD-related record retention.

### Supervisory verification procedures (SBS)
- Supervisory verification covers:
  - a) Effective implementation of the AML/CFT Manual; review visit reports to customers; lists of businesses and professions considered risky; listings of PEP.
  - b) Market knowledge procedures.
  - c) Establishment of customer risk profiles.
  - d) Review of reasons in case staff report to the Compliance Officer; review actions adopted when a client is reported (closing accounts, evaluating business relationship, among others).
  - e) Review of training materials used by Compliance Officers, focusing on CDD.
- CDD and market knowledge procedures examined include:
  - a) Verification of internal regulations proposing acceptance of risks associated with high-risk customers (PEPs, casinos, etc.).
  - b) Evaluation of product procedures enabling customer identification and understanding of activities and business sector, plus updates on information and documentation.
  - c) Verification that training materials include CDD.
  - d) Evaluation of measures in high risk areas (correspondent banking, transfer of funds, etc.).
  - e) Sample verification that cash transactions greater than $ 10 billion are stated in the corresponding control reports.

### Correspondent banking (EC6)
- Regulations establish broad requirements and some specific provisions, including prohibition of correspondent relationships with shell banks.
- Identified gaps:
  - No specific provisions requiring entities to gather sufficient information about respondent banks to fully understand their business, customer base, and supervision.
  - No explicit requirement for not establishing relationships with banks not effectively supervised by relevant authorities.
- Relevant legal provisions:
  - Article 14 of the AML Law and Article 43 of the AML/CFT Regulation require policies and procedures for correspondent banking; correspondent contracts must define obligations and responsibilities and be signed by senior management.
  - Article 43 requires satisfaction that the represented institution has complied with due diligence on customers with direct access to correspondent accounts and can, upon request, supply identification information on its customers.
  - Article 44: entities must implement due diligence procedures regarding correspondent entities, including AML/CFT frameworks; assessments kept in a separate file available to the SBS.
  - Article 45: if a correspondent has been investigated/sanctioned publicly or is licensed in a FATF non-cooperative country, entities must apply enhanced due diligence and record it.
  - Article 46 forbids relationships with shell banks and requires ensuring foreign entities do not allow use of accounts by shell banks.
- SBS procedures:
  - Specific examination procedures for correspondent banking exist.
  - Two Workbook types for inspections: general (basic analysis) and specific (deeper risk assessment).
  - Off-site review of compliance officer submissions with correspondent details (name, area, volume, prevention measures, opened accounts).

### Supervisory assessment of banks' controls (EC7)
- SBS relies heavily on internal and external audit reports and Compliance Officer Reports, and other information to determine if banks have sufficient controls and systems to prevent, identify and report financial abuse including ML/TF.
- On-site examinations include a module on the AML/CFT framework, including assessment of existence and effectiveness of communication channels.

### Supervisory powers and sanctions (EC8)
- Legal powers:
  - Article 381 (fifth section of General Law on Suspicious Financial Transactions) grants SBS powers including to deny, suspend or cancel a license.
  - SBS can inform the Public Prosecutor of criminal acts detected during inspections (Art. 358).
  - SBS lacks explicit additional powers such as suspending dividends, restricting asset growth, or restricting operations in certain business lines.
- Sanctions regime:
  - Serious infractions related to AML/CFT include failures in KYC, market knowledge, correspondent bank knowledge, integrity assurances, registration of operations, exclusion and review of customers, detection and reporting of unusual/suspicious transactions, AML/CFT manual/code of conduct deficiencies, and failure to implement AML/CFT framework.
  - Very serious infraction: transgressing duty of confidentiality in Article 12 ° of the AML Law (notifying any person/entity/body that information has been requested by or provided to the FIU).
  - Penalties:
    - Serious infractions: fines between 20 and 100 UITs.
    - Very serious infractions: fines between 30 and 200 UITs.
    - One UIT is equivalent to 4,050 soles.
    - The maximum fine (for very serious infractions only) is therefore around USD 250,000.
  - Sanctions to senior management or staff can result in fines, suspension or permanent disqualification.
- Enforcement record:
  - SBS has applied 14 sanctions to banks since 2010.
  - No sanctions have been applied to natural persons.

### Internal/external audit, compliance officer, screening, and training (EC9)
- Internal and external audit roles:
  - Title III of the AML Regulation establishes internal and external auditor roles in assessing the AML/CFT framework.
  - Article 62: the design and implementation of the AML/CFT framework should be assessed by the IAU; results submitted annually to the SBS as an Annex to the Compliance Report.
  - Article 6 of the Internal Audit Regulations: Internal Audit verifies AML/CFT compliance.
  - Article 19: annual evaluation report must consider adequate KYC policies, market knowledge, correspondent bank knowledge, AML/CFT Manual existence and compliance, periodic training programs, and compliance with AML/CFT regulations.
  - Article 63: external auditors required to submit an independent report assessing the AML/CFT framework.
  - External Audit Regulation (article 24): entities must hire an external audit to assess AML/CFT framework; article 25 lists minimum elements to be assessed (internal controls, warning signs, identification/knowledge of customers, record keeping, unusual/suspicious transaction records and procedures, disclosure mechanisms, exempted customers justification, staff propriety, staff knowledge/training, security procedures, Compliance Officer plan, internal audit plan and papers, internal sanctions, etc.).
- Compliance Officer:
  - Article 58: Compliance Officer responsible to communicate to the FIU activities deemed suspicious, irrespectively of the amount.
  - Article 7: Compliance Officer must be direct employment, full time and exclusive with the bank; appointed by the Board; communicate directly with the Board; enjoy autonomy and independence; have training and/or experience associated with AML/CFT; be at senior management level working with the CEO.
  - Article 48 of AML/CFT Risks Management Regulations: banks must have communication channels to report unusual activities detected by Board, management and staff to the Compliance Officer.
- Screening and recruitment:
  - Article 35: entities must implement due diligence for assessment of directors, managers and staff as part of recruitment and selection to ensure moral integrity; require and evaluate a wide range of information.
  - Article 36: entities must develop due diligence procedures with minimum criteria for selection of providers.
- Training:
  - Article 39: entities must develop annual training programs approved by the board for Directors, managers and staff on AML/CFT rules, policies, standards and procedures; compliance officer should review effectiveness.
  - Article 40: Compliance Officer and its staff subject to at least two (2) specialized trainings per year (different from those for staff, management and Board).
  - Article 41: entities must have annually updated information on training received; new Board members, senior managers and staff should receive training on the AML/CFT framework within 30 days of joining, at the latest.
  - Article 42: training should be tailored and include minimum topics (prevention model and risk management, risks exposure, typologies, external/internal rules, warning signs, procedure for communication of unusual transactions, responsibilities).

- SBS oversight of auditors and training:
  - SBS has unrestricted access to reports and worksheets from internal and external audit.
  - SBS reviews the quality of AML/CFT related work by internal and external auditors.
  - On-site examinations include review of personnel files and training provided.

### Reporting channels, IT systems and management information (EC10)
- Article 48: entities must develop and implement IT systems that enable management of ML/TF risks, including communication channels between the Compliance Officer, the Board, management and support and business lines staff, taking into account their role and powers.

*Source: cr18366-perufsap - Chapter V of the AML/CFT regulation is focused on CDD.*

### Annex 2 of the AML/CFT Regulation, on the minimum content of the AML/CFT

### Annex 2 of the AML/CFT Regulation, on the minimum content of the AML/CFT Manual

### Roles and responsibilities; internal procedures and communication
- Manual must contain:
  - All general obligations applicable to all employees.
  - Specific responsibilities related to duties as Board, Management, Compliance Officer and staff (business lines and support) taking into account their roles and responsibilities (item 2).
  - Establishment of internal procedures for consultation and communication of unusual or suspicious activities, as well as communication channels with the bank and with the various internal bodies (item 4).
- Examination procedures:
  - Verify if staff have tools to alert the Compliance Officer on possible unusual or suspicious transactions.
  - Review the list of reports used by the compliance officer to perform its controls activities.
  - Perform an overall assessment of communication channels.

### EC11 — Protection for reporting suspicious activity (description and findings)
- Legal framework:
  - The General Law provisions related to confidentiality of information pertaining to banks, banks’ Boards and staff (Art. 140) excludes from those provisions matters related to suspicious activities.
  - Banks are required to report suspicious activities to the FIU.
  - Banks and staff who, complying with such requirement, report suspicious activities to the FIU do not bear legal responsibilities.
  - Article 378 on communicating suspicious activities, item 4, states that entities, as well as staff, management, Board members and other representatives are exempt from penal, civil or administrative penalties when communicating suspicious activities irrespectively of the results of the communication.
- Gaps:
  - There are no provisions stating that internal communications in good faith should not be in anyway internally punished.
- Examination procedures:
  - Assess communication channels within supervised entities.
  - Verify that all staff have necessary tools to properly communicate to the Compliance officer and that unusual operations are timely reported.

### EC12 — Cooperation with domestic and foreign supervisors (description and findings)
- Institutional arrangements:
  - The AML/CFT Executive Multisectoral Committee (CONTRALAFT) was created in 2011 (Supreme Decree 057-2011-PCM).
  - Ministry of Justice heads the CONTRALAFT; it meets every two months.
  - The FIU is responsible for the Technical Secretariat.
  - CONTRALAFT is responsible for monitoring implementation, compliance and updating of the AML/CFT National Plan.
- SBS cooperation:
  - SBS cooperates with foreign supervisors under the MoUs detailed in CP3; MoUs have helped strengthen cooperation and collaboration.
  - Authorities shared cases of sharing information on sanctions and results of examinations.
  - SBS has a cooperation agreement with the SMV encompassing almost the entire spectrum of what is considered a financial institution under the FATF.
  - In practice, SBS reports sharing with SMV policies, procedures and manuals, upon request.

### EC13 — In-house specialist expertise and dissemination to banks (description and findings)
- No established procedures for disseminating overall information to banks on risks of money laundering and the financing of terrorism.
- In practice, SBS shares information with the bank association and compliance officers on particular themes and on changes on regulations.

### Assessment of Principle 29 — Largely Compliant
- Summary view:
  - SBS has a robust AML/CFT framework but limited sanctions can potentially curb its effectiveness.
  - Framework strengthened recently with the issuance of the AML/CFT risk management regulation and continuous enhancements in supervisory procedures.
  - Important limitation: sanctioning for banks is confined to fines up to USD 250,000, not enough to curb behavior.
- Other aspects for improvement:
  - Banks not explicitly required to report to banking supervision suspicious activities in cases where such activities/incidents are material to the safety, soundness or reputation of the bank; there is a general requirement to inform major events related to the bank which has never been used.
  - Current framework regarding CDD does not encompass the overall requirements for banks to develop their own internal policies and criteria, in addition to the detailed requirements aiming at ensuring and effective CDD.
  - No requirements that the CDD management program has, as one of its essential elements, a customer acceptance policy that identifies business relationships that the bank will not accept.
  - No specific provisions requiring entities to gather sufficient information about their respondent banks to understand fully the nature of their business and customer base, and how they are supervised; nor for not establishing relationships with those that are not effectively supervised by the relevant authorities.
- Recommendations to authorities:
  - Be able to impose sizable fines to banks. In addition, powers related to the possibility of suspending dividends, restrictions to asset growth, operating in certain business lines and others could also be useful tools to support banks’ compliance with the AML/CFT framework.
  - Explicitly require banks to report to the SBS suspicious activities and incidents of fraud in cases where such activities/incidents are material to the safety, soundness or reputation of the bank.
  - Require banks to develop their own internal policies and criteria for CDD beyond what is expressly prescribed in regulation.
  - Explicitly require entities to gather sufficient information about their respondent banks to understand fully the nature of their business and customer base, and how they are supervised.
  - Not allow banks to establishing relationships with correspondent banks that are not effectively supervised by the relevant authorities.
  - Require CDD management programs to have a customer acceptance policy that identifies business relationships that the bank will not accept.

### Summary compliance with the Basel Core Principles — selected findings and grades
- Overall summary remarks:
  - The report provides graded assessments across Core Principles; many are “LC” (Largely Compliant) or “C” (Compliant) with specific governance, supervisory perimeter and enforcement limitations noted.
- Selected Core Principle grades and key comments:
  - 1. Responsibilities, objectives and powers — MNC
    - SBS responsibilities and powers are clearly defined; legal limitation: supervisory powers limited regarding direct access to parents and affiliates outside the direct supervisory perimeter.
  - 2. Independence, accountability, resourcing and legal protection for supervisors — LC
    - Operational independence, accountability and governance arrangements in place; legal protection should be enhanced (no “good faith” test; limited temporal coverage; Superintendent mandate coincides with constitutional term of government).
  - 3. Cooperation and collaboration — C
    - Arrangements in place for cooperation with domestic and foreign supervisors; SBS does not routinely exchange much information with domestic authorities to perform supervisory duties.
  - 8. Supervisory approach — LC
    - Sound and comprehensive supervisory approach moving towards risk-based framework; elements related to conglomerates are taken into account for overriding purposes but not embedded in rating methodology.
  - 11. Corrective and sanctioning powers — LC
    - SBS acts at an early stage and uses moral suasion; would benefit from documenting in-practice procedures and framework for corrective actions.
  - 12. Consolidated supervision — LC
    - Legal framework empowers SBS to exercise full consolidated supervision only from the bank downwards; holding companies not formally regulated or supervised; SBS acts “de facto” as home supervisor for systemic conglomerates but weaknesses remain in group-level supervision.
  - 13. Home-host relationships — C
    - SBS actively cooperates with home and host supervisors; cross-border operations of two systemic conglomerates represent almost 22 percent of gross total assets; no Crisis Management Groups established for the two Peruvian financial conglomerates.
  - 14. Corporate governance — LC
    - Governance requirements do not apply on a group-level where SBS acts as home supervisor; engagement with Boards could be intensified; new Corporate Governance & GIR coming into effect per April 1, 2018 sets expectations for periodic Board effectiveness self-assessment.
  - 15. Risk management process — LC
    - Regulatory framework tailored to Peru; SBS reviewing models in practice and working on model governance guidelines; no formal requirements for recovery and resolution plans for D-SIBs though contingency plans required.
  - 16. Capital adequacy — LC
    - Significant progress implementing Basel III; ICAAP and supervisory review not yet integrated in SBS’ rating methodology; revised rating methodology including SREP results planned to be rolled-out in 2019.
    - Countercyclical buffer activation trigger based only on GDP growth and may not be effective where there is excessive credit growth when GDP growth is below 5 percent.
    - Supervisory group capital adequacy assessment could be improved by taking into account: i) capital adequacy of the holding on a solo level; ii) location of capital within the conglomerate, including risk of ringfencing/non-transferability of capital allocated to entities supervised by authorities abroad; iii) extent to which excess capital at a group level can be completely allocated to support the financial activities of the conglomerate.
    - Assessment of consolidated capital adequacy does not take adequately into account necessary adjustments for change in accounting standards; solo financials based on SBS accounting standards while consolidated financials might be based on IFRS, which could impact provisioning levels and therefore available capital on a consolidated basis.

*Annex 2 — AML/CFT Regulation: minimum content of the AML/CFT Manual (extracted findings and recommendations).*

### 17. Credit risk C The SBS has an adequate regulatory and

### cr18366-perufsap - 17. Credit risk C The SBS has an adequate regulatory and

### Credit risk framework
- The SBS has an adequate regulatory and supervisory framework for credit risk.
- The Credit Risk Management Regulation issued in 2011 and the Credit Risk Capital Requirements Regulation (Resolution SBS No. 8548-2012) address the comments made in the 2011 BCP assessment.

### Problem assets, provisions, and reserves
- The LGSF and regulations issued by the SBS provide a detailed framework for the identification and management of problem assets, the asset classification, provisioning and write-offs.
- Supervisory approach and practices to assure adequate policies and practices by FIs are sound.
- Supervisory action is undertaken when SBS observes deficiencies or weaknesses.
- Credit Conversion Factor (CCF) issues:
  - The CCF used for provisioning purposes for undisbursed granted credits and unused lines of credit deviates from the factors used for the credit risk capital requirements (Resolution SBS No. 14354-2009, which incorporates CCFs based on the Basel II capital requirements for credit risk).
  - Basel II framework: commitments with an original maturity up to one year and commitments with an original maturity over one year will receive a CCF of 20 percent and 50 percent, respectively.
  - Only commitments unconditionally cancellable at any time by the bank without prior notice, or that effectively provide for automatic cancellation due to deterioration in a borrower’s creditworthiness, receive a 0 percent credit conversion factor.
  - Current blanket approach assigns a 0 percent CCF to all undisbursed and unused lines of credit — from a provisioning point of view less conservative.

### Concentration risk and large exposure limits
- New rules on related parties and economic groups issued in 2015 (Resolution SBS N° 5780-2015) establish stricter criteria for determining a linkage and adopt international standards for defining an economic group.
- No combined limit for large exposures in regulations.
- Large exposure limit: at a maximum 10 percent for uncollateralized exposures (considered conservative compared to international standards).
- Additional Capital Requirements Regulation requires additional capital for single name concentration risk considering the top 20 exposures.
  - The additional capital charge may not be significant but has resulted in explicit attention to this risk in FIs’ risk management and ICAAPs.
- SBS is reviewing the Additional Capital Requirements Regulation including the adequacy of the capital charge for single name concentration risk.

### Transactions with related parties
- Resolution SBS N° 5780-2015 (2015) establishes stricter criteria for determining related parties and economic groups, relevant for FIs and financial conglomerates.

### Country and transfer risks
- Regulatory provisioning requirements for country risk are conservative.
- Assessors consider the regulatory framework and supervisory approach and practices to country risk adequate.

### Market risk
- Rating: LC (Limited Compliance) considering very limited trading activities; current regulatory and supervisory framework is broadly adequate.
- Existing Market Risk Management Regulation is outdated (1998).
- A revised and updated Market Risk Management Regulation has been issued to the industry for consultation; assessors did not perform an in-depth review of the revised regulation.
- Basel Committee is reviewing whether to issue a simplified Basel III standard approach for market risk.
- Recommendation: SBS should evaluate to what extent current capital requirements would need recalibration to bring them in line with the Basel III standard and whether the Basel III (simplified) standardized approach should be adopted.
- Note: The regulation (SBS Resolution No. 4906-2017) has been issued after the assessment and will come into force June 1, 2018.

### Interest rate risk in the banking book (IRRBB)
- Overall regulatory and supervisory approach and practices are adequate (C).
- IRRBB included in the Additional Capital Requirements Regulation:
  - Requires an additional capital buffer if the change in EVE is more than 15 percent of regulatory capital when applying a per maturity bucket a prescribed interest rate shock.
- Recommendation: Review and consider the implementation of the Basel III standards for IRRBB.

### Liquidity risk
- Rating: LC.
- SBS has a well-established regulatory and supervisory framework for liquidity risk.
- Inclusion of the LCR in 2012 aligned the framework with the Basel III framework.
- SBS is working on implementation of the NSFR and is already monitoring the banks on this ratio; given the primarily short-term nature of the assets and liabilities of the banking system the implementation of this ratio is less urgent.
- Semi-annual stress-testing and development of liquidity contingency plans are performed.
- No group level liquidity requirements; group requirement indirectly enforced via the licensed institution in Peru — this indirect form of regulation is not optimal.
- Adoption of group liquidity contingency plans by the two groups for which the SBS acts as home supervisor is in its initial phase; SBS has recently started to push for more progress.
- Recommendation: Intensify approach towards liquidity risk supervision of financial groups; continue work on implementation of the Basel III NSFR (tailored to local circumstances).

### Operational risk
- Rating: C.
- SBS has a sound regulatory and supervisory approach towards operational risk, performed by two specialized departments of the SAR.

### Internal control and audit
- Rating: C.
- Regulatory framework and supervisory approach and practices for internal control and audit are consistent with the scale and nature of the financial system.

### Financial reporting and external audit
- Rating: LC.
- Regulatory and supervisory framework broadly adequate.
- Improvements suggested:
  - Improve engagement with external auditors.
  - Assess more in depth whether current provisioning requirements are adequate when compared with the new IFRS9 standard, considering possible issues related to differences in accounting standards between supervised institutions (using SBS standards) and consolidated financial groups (which may use IFRS standards).

### Disclosure and transparency
- Rating: C.
- Regulatory and supervisory approach and practices adequate for the level of development of the financial system.
- Required disclosures are easily accessible on the website of the SMV.
- Required annual disclosures based on IAS1; complemented by quarterly disclosures required by the SBS.
- SBS publishes detailed quantitative financial information of supervised entities and financial markets on its website.
- Recommendation: Consider implementing the recommendations of the Enhanced Disclosure Task Force of the FSB and Pillar 3 of the Basel framework.

### Abuse of financial services (AML/CFT)
- Rating: LC.
- SBS has a robust AML/CFT framework but limited sanctions can potentially curb its effectiveness.
- Framework strengthened with AML/CFT risk management regulation and enhancements in supervisory procedures.
- Sanctioning limitation: fines up to USD 250,000 for banks — not enough to curb behavior.
- Other aspects for further improvement include:
  - Banks are not explicitly required to report to banking supervision suspicious activities material to the safety, soundness or reputation of the bank; there is a general requirement to inform major events related to the bank which has never been used.
  - Current CDD framework does not encompass overall requirements for banks to develop their own internal policies and criteria, in addition to detailed requirements to ensure effective CDD.
  - No requirement that CDD management program includes a customer acceptance policy identifying business relationships the bank will not accept, although banks are required not to have business relationships if they do not have the capacity to take all CDD measures.
  - No specific provisions requiring entities to gather sufficient information about their respondent banks to fully understand the nature of their business and customer base, and how they are supervised; nor provisions to prevent establishing relationships with correspondent banks that are not effectively supervised by relevant authorities.

### Recommended actions (high-level by Core Principle)
- Principle 1
  - Amend the legal framework to grant SBS powers to exercise full consolidated supervision.
- Principle 2
  - Amend the legal framework to further protect all SBS staff for acts or omissions in good faith including current and former staff (including senior management) even after leaving the SBS, irrespectively of the number of years of being out of the SBS.
  - Amend the legal framework so the Superintendence tenure does not coincide with the constitutional term of the government.
  - Review allocation of resources to entities relative to systemic relevance and risk.
  - Enhance Internal Audit Function, including establishment of an Internal Audit Committee.
  - Operationalize the Financial Stability Committee.
  - Consider further elaborating on discharge of supervision responsibilities relative to objectives through the Annual Report.
- Principle 6
  - Adequately incorporate significant influence as a qualitative indicator for significant ownership in the regulatory framework.
- Principle 7
  - Lower the maximum percentage allowed to be held in a non-financial company ensuring there is no controlling interest/influence.
- Principle 8
  - Establish a process for assessing resolvability of systemic banks.
  - Consider establishing a rating for conglomerates and a lead supervisor for the conglomerate.
  - Further enhance interactions with senior management and the Board of supervised entities.
- Principle 9
  - Streamline off-site surveillance reports through further coordination between SAR and SABM.
  - Speed up establishment of an off-site surveillance IT platform.
- Principle 11
  - Operationalize legal powers into regulation or procedures comprising a range of supervisory tools, including withdrawing a license.
- Principle 12
  - Amend legal and regulatory framework to enhance SBS’ powers for consolidated supervision.
- Principle 13
  - Establish Crisis Management Groups for the two systemic conglomerates.
- Principle 14
  - Apply at group-level, for groups where SBS is home supervisor, the same governance and fit and proper requirements as for licensed institutions.
  - Enhance Board committee composition requirements (number of independent Board members and independent Chair).
  - Intensify Board engagement.
  - Develop a framework for assessing collective suitability of the Board and assessment criteria for key Board positions.
- Principle 15
  - Develop and issue guidelines for model governance; set expectations for Board and senior management to review model limitations and uncertainties.
  - Implement requirements for recovery and resolution planning for D-SIBs.
- Principle 16
  - Incorporate ICAAP and related supervisory review in the revised supervisory rating methodology.
  - Finalize review of current methodology, particularly countercyclical buffer and single name concentration, for additional capital requirements.
  - Enhance group capital adequacy assessment by extending analysis to: i) capital adequacy of the holding on a solo level; ii) location of capital within the conglomerate, including ringfencing/non-transferability risks; iii) extent to which excess capital at group level can be allocated to support financial activities of the conglomerate.
  - Review and revise group capital assessment methodology to account for differences in accounting standards between solo and consolidated levels.
- Principle 17
  - Formalize developed risk-based supervisory cycle for assessing credit risk and incorporate into revised rating methodology and supervisory approach to be rolled-out in 2019.
- Principle 18
  - Review the CCFs applied to undisbursed and unused credit lines.
- Principle 22
  - Issue the revised and updated Market Risk Management Regulation.
  - Evaluate recalibration of current capital requirements to align with Basel III and consider adopting the Basel III (simplified) standardized approach.
- Principle 23
  - Review and consider implementing Basel III standards for IRRBB.
- Principle 24
  - Intensify liquidity risk supervision of financial groups.
  - Continue work on NSFR implementation tailored to local circumstances.
- Principle 25
  - Follow up on recommendations and lead by example for industry-wide business continuity stress-test.
- Principle 27
  - Assess potential impact of IFRS9 implementation on FIs provisioning requirements to determine sufficiency of current provisioning.
  - Discuss and engage stakeholders on IFRS9 implementation strategy.
  - Consider developing a structured (risk-based) approach for trilateral meetings with external auditors and FIs to discuss management letters.
  - Strengthen engagement with external auditors and the audit profession.
- Principle 28
  - Consider implementing recommendations of the Enhanced Disclosure Task Force of the FSB and Pillar 3 of the Basel framework.
- Principle 29
  - Amend legal/regulatory framework to:
    - Be able to impose sizable fines to banks; consider powers to suspend dividends, restrict asset growth, restrict operating in certain business lines and other tools to support enforcement of AML/CFT compliance.
    - Explicitly require banks to report to the SBS suspicious activities material to safety, soundness or reputation.
    - Require banks to develop internal policies and criteria for CDD beyond prescribed regulation.
    - Explicitly require entities to gather sufficient information about respondent banks to understand their business, customer base, and supervision.
    - Prohibit banks from establishing relationships with correspondent banks not effectively supervised by relevant authorities.
    - Require CDD management programs to have a customer acceptance policy identifying business relationships the bank will not accept.

### Authorities’ response (summary)
- SBS appreciates opportunity to comment and thanks IMF and WB assessors.
- Discussions were fruitful with practical recommendations; SBS will use them to enrich internal discussions on future regulatory and supervisory developments.
- Overall, assessment adequately reflects current status. SBS disagrees with grading of Principle 1, citing ample legal powers in Peruvian Banking Law for authorization, ongoing supervision and corrective actions; main weakness is limited legal powers for supervising holding companies, which SBS considers overweighted in the assessment of Principle 1.
- SBS notes indirect legal powers over holding companies via supervised banks have been effective for the two major banking groups; recognizes room for legal framework improvement but does not consider current limited powers a major source of risk.
- SBS will evaluate recommendations and develop a plan to continue strengthening the regulatory and supervisory framework of the Peruvian Financial System.

*Source: IMF Financial Sector Assessment Program — Peru (excerpt).*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2018/cr18366-perufsap.pdf_
