## 1colea2022005 — Detailed Assessment Report (selected findings)

## Source details

**Canonical URL:** [1colea2022005 — Detailed Assessment Report (selected findings)](https://www.imf.org/-/media/files/publications/cr/2022/english/1colea2022005.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2022/english/1colea2022005.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2022/english/1colea2022005.pdf.json)

---

### Key improvements to legal framework and supervision
- SFC: integrated supervisor covering banks, finance companies, insurance, securities, and other financial intermediaries; also the bank resolution authority.
- Financial Conglomerates Law (FCL) 1870: grants SFC supervisory authority over financial conglomerates (CF) and strengthens consolidated supervision by including holding companies as supervised entities.
- FCL scope: standards on risk management, adequate capital, corporate governance, and minimum requirements for managing concentration risks and conflicts of interest in intragroup and related party exposures.
- Cross-border cooperation: signed MOUs with foreign supervisors; authority to request information from parent companies and ultimate beneficial owners.

### Supervisory approach, tools, and governance
- Supervision-by-risk (SBR) approach instituted; guidance is principles-based.
- Draft regulation on integrated risk management (SIAR) and URF technical paper on large exposures and related parties to align with BCBS standards.
- Supervision supported by onsite/offsite manuals, analytical and risk measuring tools, and collaboration with external/internal auditors.
- Supervision plan: significant activities (AS) → analyze AS risks → net risk indicator (N1, N2, N3).

### Enforcement, resolution, and regulatory reform priorities
- SFC enforcement tools include cease-and-desist orders, ringfencing, sanctions, and fines; enforcement extends to bank, management, Board, and parent FH.
- URF/URF proposal objectives on related parties:
  - consolidate exposures with subsidiaries;
  - ensure homogeneous treatment of groups of related parties;
  - consolidate various limits and reduce exemptions.
- Draft regulation on country risk to include transfer risk provisioning, require tolerance limits, and supervisory expectations.

### Market structure — key statistics and concentration
- TOTAL FINANCIAL SYSTEM: 2,200,188 billion COL$; 218 (% of GDP); 100 (Percent of total financial sector assets)
- Credit institutions: 768,724 billion COL$; 76.2 (% of GDP); 34.9 (Percent of total financial sector assets); 46 (No. of entities)
  - Commercial banks: 701,990 billion COL$; 69.6 (% of GDP); 31.9 (Percent of total financial sector assets); 24 (No. of entities)
  - State-owned bank: 27,851 billion COL$; 2.8 (% of GDP); 1.3 (Percent of total financial sector assets); 1 (No. of entities)
  - Other: 38,883 billion COL$; 3.9 (% of GDP); 1.8 (Percent of total financial sector assets); 21 (No. of entities)
- Pension funds: 383,761 billion COL$; 38.1 (% of GDP); 17.4 (Percent of total financial sector assets); 5 (No. of entities)
- Mutual funds: 135,027 billion COL$; 13.4 (% of GDP); 6.1 (Percent of total financial sector assets); 279 (No. of entities)
- Trust services: 660,546 billion COL$; 65.5 (% of GDP); 30.0 (Percent of total financial sector assets); 23,680 (No. of entities)
- Insurance: 94,820 billion COL$; 9.4 (% of GDP); 4.3 (Percent of total financial sector assets); 45 (No. of entities)
- State-owned Financial Institutions: 88,120 billion COL$; 8.7 (% of GDP); 4.0 (Percent of total financial sector assets); 11 (No. of entities)
- Concentration:
  - Financial conglomerates dominate; seven Colombian CFs account for nearly 81 percent of total conglomerates’ assets.
  - Cross-border exposure of Colombian CFs in Latin America: US$41 billion in 2012 → US$93 billion in 2020.
  - Central American exposures: Panama (US$29 billion), El Salvador (US$11 billion), Costa Rica (US$10 billion), Guatemala (US$8 billion).
  - Cross-border exposures can be as high as 25 percent of the assets of the respective CF.
  - Subsidiaries’ share of host-market assets: from 17 percent (Guatemala) to over 50 percent (Costa Rica and El Salvador).

### Impact of Covid-19 on banking sector — selected indicators
- Capitalization:
  - Average CET1 ratio: 12.8 percent at end-2020, up from 10.7 percent the year before.
  - Average total capital ratio: 17.2 percent at end-2020, up from 15.5 percent the year before.
- Liquidity:
  - Short-term liquidity indicator (IRL): 219 percent at end-2020, up from 188 percent one year earlier.
  - Structural liquidity indicator (CFEN): between 109.3 percent and 175.6 percent.
- Asset quality:
  - Past-due loans increased by 18.9 percent in 2020 and account for 5 percent of the total loan portfolio.
  - Coverage ratio of past-due loans: 141.8 percent → 152.6 percent.
- Profitability:
  - Average ROA decreased from 1.8 percent to 0.8 percent.
  - Average ROE fell from 12.64 percent to 5.86 percent.
- Supervisory view: credit risk greatest vulnerability, followed by operational, liquidity and market risks.

### Capital, liquidity, and Basel III alignment
- Since 2012 progressive convergence toward Basel III; majority of changes enforced in January 2021 with phase-in Jan. 2021−Jan. 2024.
- SFC estimates (implementation impact):
  - CET1 ratio increase from 10.7 percent to 16.4 percent.
  - Total solvency ratio increase from 16.4 percent to 21.3 percent.
  - Alternate estimate (all credit institutions): CET1 11.7 percent → 18.2 percent; total solvency 17.3 percent → 22.9 percent.
  - Improvement driven by RWAs density reduction from 75.9 percent to 66 percent.
- Mandatory capital ratios since January 2021:
  - CET1 ≥ 4.5 percent;
  - Tier 1 ≥ 6 percent;
  - Total capital ratio ≥ 9 percent;
  - Leverage ratio ≥ 3 percent.
- Buffers:
  - Capital conservation buffer: 1.5 percent (Colombia) vs 2.5 percent (Basel).
  - Additional buffer for DSIBs: 1.0 percent.
  - Transition regime Jan. 2021–Jan. 2024; end-state DSIB total CET/T1 = 7.0; T1 = 8.5; T1+T2 = 11.5 (percent).

### Deviations from Basel III (selected)
- Lighter risk weighting for certain assets:
  - zero risk-weight for cash deposits in entities supervised by the SFC;
  - zero risk-weight for Colombian government debt (local and foreign currency);
  - mandatory investments irrespective of issuer rating: 0 percent;
  - exposures to a clearing house: 0 percent.
- Operational risk: standardized approach introduced Jan. 2021 with marginal coefficients 12 percent and 15 percent (two coefficients vs three in Basel III).
- Authorities estimate aggregate effect of deviations reduces total capital ratio by less than 1 percent; new regulatory regime expected to decrease average RWAs between 10 percent and 16 percent.

### ICAAP, stress testing, recovery and resolution
- ICAAP: early stage; pilot launched in 2019; submission of stress test results postponed until July 2021.
- SFC to formalize comprehensive approach linking risk appetite, ICAAP, ILAAP, stress tests, recovery and resolution plans.
- Resolution enhancements:
  - Law 1870 (2017) and decree 521 (2018): FOGAFIN powers to transfer assets/liabilities to private buyer or bridge bank without shareholder consent.
  - Four supervised entities designated systemic in 2020–2021 required to establish resolution plans from 2022.
  - CIR created in 2018 to coordinate SFC and FOGAFIN resolution planning.

### Large exposures, concentration risk, and related parties (Principles 19–20)
- Current large exposure limits based on total capital; limits include:
  - 10 percent of total capital for credit transactions not covered by admissible guarantee;
  - 25 percent of total capital for transactions covered by admissible guarantee.
- Key deficiencies and findings:
  - Principle 19 assessment: Materially Non-compliant.
    - Large exposure limits based on total capital not Tier 1 as per 2014 BCBS standard.
    - Decree 2555 recognizes affiliated guarantees and letters of credit as risk mitigation increasing intra-group exposures.
    - URF 2020 study and CE13 (2019) aim to update large exposure requirements.
  - Principle 20 assessment: Materially Non-compliant.
    - Related-party framework fragmented; regulators and guidance dispersed; last BCP-identified deficiencies not fully addressed.
    - URF objectives: consolidate subordinate exposures, homogeneous groups of related parties, simplify limits, reduce exceptions.
- Recommendation: consider guidance thresholds on concentration levels and supervisory expectations when enhanced risk management thresholds exceeded.

### Country and transfer risk (Principle 21)
- Country and transfer risk not fully addressed; SFC has enhanced supervisory process and drafted regulation.
- Draft regulation to require transfer risk provisioning, tolerance limits, supervisory expectations for policies/procedures, semi-annual reporting to SFC and stress testing.
- Noted concentration: significant portion of Colombian banks’ assets booked in Central America.

### IRRBB (Principle 23)
- SFC carried out IRRBB supervisory exercises since 2018; largest banks assessed; 2021 plan to include medium and small banks.
- No prudential requirements or detailed IRRBB guidelines issued to date; mandatory stress testing program (EPR) does not explicitly refer to IRRBB.
- SFC considers issuing External Circular on IRRBB in second half of 2021, methodology to consider earnings-based measures and changes in Economic Value of Equity (EVE).
- Principle 23 assessment: Materially non–compliant (due to absence of formal requirements and incomplete coverage of medium/small banks).

### Liquidity risk (Principle 24)
- Short-term liquidity indicator (IRL) aligned toward LCR; CFEN (Net Stable Funding Ratio equivalent) introduced in 2019 (External Circular 19-2019).
- CFEN phase-in:
  - March 2020: 80 percent → March 2022: 100 percent for banks with ≥ 2 percent of total banking sector’s assets;
  - Smaller banks: 60 percent → 80 percent thresholds.
- Misalignments with Basel:
  - Run-off factors and eligible asset treatments differ; many run-off factors more favorable than LCR; authorities justify adaptations to local market behavior.
  - CFEN computed at individual level only; SFC considering consolidated NSFR calculation.
- Supervisory tools: system-wide and individual dashboards, top-down liquidity stress tests.
- Principle 24 assessment: Largely compliant.
- Recommendation: further align LCR/NSFR parameters and require NSFR consolidated calculation.

### Operational risk, cybersecurity, internal control and audit (Principles 25–26)
- Operational risk capital requirement in force since January 2021 (Basel III standardized approach-derived).
- SFC strengthened operational risk management and cybersecurity requirements; 2018–2019 maturity evaluations; 2020 proactive pandemic-related instructions.
- Outsourcing: expanded requirements in July 2020; critical outsourced activities require defined selection, contractual and monitoring standards.
- Internal audit and internal control:
  - SCI objectives: improve efficiency, prevent fraud, ensure adequate risk management, reliable information, compliance.
  - SFC assessed internal audit in 2020 across 35 entities; promoted risk-based audits.
- Principle 25: Compliant. Principle 26: Compliant.

### Financial reporting, external audit, disclosure (Principles 27–28)
- Since December 2015 credit institutions prepare consolidated financial statements under IAS/IFRS; external auditors follow ISA.
- Exception: individual bank-level statements do not fully follow IAS 39/IFRS 9 on impairment/classification; SFC instructions apply for individual statements.
- Statutory auditors (revisor fiscal) appointed and authorized by SFC; rotation required every five years at individual person level; firm rotation recommendation noted.
- Principle 27: Compliant (with noted exception re individual IFRS 9 application).
- Principle 28: Compliant; SFC publishes monthly bank-by-bank and aggregate financial information.

### AML/CFT framework (Principle 29)
- Legal framework: SARLAFT (CBJ Chapter 4, Title 4, Part 1) and EOSF Articles 102–107; UIAF coordination; multiple inter-agency agreements.
- Supervisory approach: risk-based MIS incorporating ML/FT vulnerability across product, client, jurisdiction and distribution channel; annual supervisory planning; onsite/offsite reviews.
- Compliance requirements:
  - CDD: periodicity at least every three years, annually for higher-risk customers; retention period five years.
  - Compliance officers required; appointments subject to SFC approval.
  - Training, screening, reporting procedures, and technological infrastructure mandatory.
- Resources: Office of Deputy Superintendent of AML/CFT had 41 officials end-2020 (up from 25 in 2016).
- Principle 29: Compliant.

### Supervisory powers, remedies, and implementation metrics
- SFC powers include access to information (Law 1328 of 2009, Art. Article 67), onsite inspections (EOSF, Art. 326.4), preventive and corrective measures, administrative orders, sanctions, removal/disqualification, and taking possession (EOSF, Art. 114–116).
- Supervisory activity (selected years, source: SFC):
  - 2018: Offsite 160; Onsite 36; Total 196.
  - 2019: Offsite 114; Onsite 30; Total 144.
  - 2020: Offsite 79; Onsite 6; Total 85. (Note: many exercises cancelled in 2020 due to COVID-19.)
- Corrective/sanction actions (2016–2019 totals): 36 (2016); 21 (2017); 22 (2018); 26 (2019).

### Assessments summary (selected Principles and ratings)
- Principle 1: Compliant.
- Principle 2: Largely compliant.
- Principle 3: Compliant.
- Principle 15: Largely compliant.
- Principle 16: Largely compliant.
- Principle 19: Materially non‑compliant.
- Principle 20: Materially non‑compliant.
- Principle 23: Materially non‑compliant.
- Principle 24: Largely compliant.
- Principle 25: Compliant.
- Principle 27: Compliant.
- Principle 28: Compliant.
- Principle 29: Compliant.

### Selected supervisory recommendations (verbatim where provided)
- Principle 2:
  - Specify in the law that the Superintendent is appointed for a minimum term and is removed from office during his/her term only for reasons specified in it.
  - Strengthen formal safeguards to prevent SFC staff from being involved in lawsuits for actions taken and/or omissions made while discharging duties in good faith.
- Principle 6:
  - Describe in an internal guideline the minimum criteria to be analyzed in each case.
- Principle 7:
  - Consider lowering the 100 percent cumulative limit on banking investments in authorized financial subsidiaries and some real sector companies and/or conditioning the above-mentioned investments to a prior supervisory approval.
- Principle 15:
  - Develop additional guidance to support the “principles-based” approach to communicating supervisory expectations.
- Principle 16:
  - Consider removing the remaining deviations from international standards on capital adequacy (e.g., credit risk weighting of some assets, treatment of minority interests).
  - Proceed with planned regulation linking risk appetite, ICAAP, ILAAP, stress tests, and recovery/resolution plans.
- Principle 19:
  - Increase guidance on concentrations (geographic, industry, sourcing, supply lines).
  - Eliminate intra-group guarantees or letters of credit as risk mitigant to increase limits.
- Principle 20:
  - Develop comprehensive related-party transaction framework.
- Principle 23:
  - Proceed with planned regulation on IRRBB pursuant to Basel III standards.
- Principle 24:
  - Consider readjusting or determining parameters used in computation of local LCR and NSFR ratios and require NSFR to be calculated at consolidated level.
- Principle 28:
  - Consider strengthening forward-looking loan loss provisioning and review exception to IAS 39/IFRS 9 for individual statements; consider mandatory firm rotation for statutory auditors.

*Source: EXECUTIVE SUMMARY and selected chapters of the Detailed Assessment Report (Financial Sector Assessment Program), International Monetary Fund and World Bank; assessment performed June 1 through June 21, 2021.*

### EXECUTIVE SUMMARY ____________________________________________________________________________ 5

### EXECUTIVE SUMMARY

### Key improvements to legal framework and supervision
- Since the last Basel Core Principles (BCP) review, significant improvements to the legal framework and supervisory process have occurred; additional recommended enhancements are highlighted in this assessment.
- The Superintendency of Financial Institutions (SFC) is an integrated supervisor covering banks, finance companies, insurance, securities, and other financial intermediaries; the SFC is also the bank resolution authority.
- Congress passed Financial Conglomerates Law (FCL) 1870 granting the SFC supervisory authority over financial conglomerates (CF) and strengthening consolidated supervision by including holding companies as supervised entities.
- The FCL defined scope of CF supervision, setting standards on risk management, adequate capital, corporate governance, and minimum requirements for managing concentration risks and conflicts of interest in intragroup and related party exposures.
- The SFC has strong coordination and cooperation arrangements with foreign supervisors (through signed Memoranda of Understanding (MOUs) and coordination mechanisms derived from the CCSBSO) and the authority to request information from parent companies and ultimate beneficial owners.

### Supervisory approach, tools, and governance
- The SFC has instituted a supervision by risk (RBS) approach and issued external circulars (CE), guides, and manuals communicating supervisory expectations; expectations are principles based and generally avoid setting benchmarks or limits.
- As part of ongoing communication of supervisory expectations, the SFC issued a draft regulation on integrated risk management; the URF issued a technical paper on large exposures and related parties to consolidate risk management guidance and align with BCBS standards on corporate governance, large exposures, and related parties.
- Ongoing supervision is supported by onsite/offsite procedure manuals, analytical and risk measuring tools, and close collaboration with banks’ external and internal auditors. Supervisory nucleus (NS) teams monitor a number of banks and perform both onsite and offsite activities.
- The SFC requests information from external/internal auditors on an ad hoc basis; external auditors maintain permanent staff at the large banks.
- A supervision plan is developed for each bank/CF after reviewing the risk profile, determining significant activities (AS) and analyzing AS risks to arrive at a net risk indicator for the entity (N1, N2, or N3).

### Enforcement, resolution, and regulatory reform priorities
- A strong enforcement and follow-up process supports preventive and corrective actions. The SFC, as resolution authority, has a broad range of tools including cease-and-desist orders, ringfencing, sanctions, and fines. Enforcement extends to the bank, its management and Board, and to those of the parent financial holding (FH).
- The Financial Regulation Unit (URF), with SFC technical support, is working on legislative reforms to address deficiencies noted concerning transactions with related parties. The URF proposal aims to consolidate exposures with subsidiaries, ensure homogeneous treatment of groups of related parties, consolidate various limits, and reduce exemptions.
- The supervisory process to monitor country risk has been enhanced; a draft regulation on country risk has been prepared that will include transfer risk provisioning, require banks to set tolerance limits, and set supervisory expectations for policies and procedures to identify, measure, and monitor country and transfer risks.

### Large exposures, concentration risk, and alignment with Basel standards
- The URF has a project to update and simplify large exposure requirements and align with Basel Committee on Banking Supervision (BCBS) standards. External Circular (CE) 13, issued in 2019, requires financial conglomerates to address concentration risk in their appetite statement and provides a high-level definition of concentrations and general risk management requirements for conglomerates.
- As new requirements are drafted for banks, the assessment recommends considering guidance thresholds on concentration levels and supervisory expectations when enhanced risk management thresholds are exceeded.

### Capital, liquidity, and risk frameworks
- Since 2012, authorities have progressed in converging regulations on capital adequacy, liquidity and operational risks toward the Basel III framework. Definitions of capital and risk coverage, including operational risk, are broadly aligned with relevant Basel III standards; short- and long-term liquidity ratios have been determined based on the LCR and NSFR standards.
- Remaining differences are highlighted in this assessment and were justified by authorities as adaptations to particularities of the Colombian market.

### Interest rate risk and accounting/auditing standards
- Leveraging supervisory exercises on interest rate risk in the banking book (IRRBB) carried out since 2018, the SFC is considering establishing a formal standard on IRRBB. The contemplated methodology considers both earnings-based measures and changes in the Economic Value of Equity (EVE), pursuant to BCBS principles.
- International Standards on Financial Reporting (IFRS) and International Standards on Auditing (ISA) have been incorporated into the Colombian regulatory framework and are fully applicable to all banks supervised by the SFC, except for some IFRS 9 provisions relating to loan portfolio impairment and classification and measurement of financial instruments for individual financial statements.

### Assessment context and methodology
- The assessment of implementation of the BCP by the SFC is part of the Financial Sector Assessment Program (FSAP) undertaken by the IMF and the World Bank. The assessment was performed June 1 through June 21, 2021, and is based on the regulatory and supervisory framework in place at the time of the visit.
- The mission was conducted totally offsite due to the prevailing virus situation; the authorities provided a detailed self-assessment and answers to additional questionnaires, including a specific “COVID-19” questionnaire.
- Compliance was measured against BCBS standards issued in 2012; the assessment focused on the “essential” criteria and followed guidance in Annex 2 of the BCP. The assessment is based solely on laws, supervisory requirements, and practices in place at the time, while noting regulatory and supervisory initiatives not yet completed or implemented.

### Institutional setting and coordination
- The SFC acts as licensing, supervisory, and resolution authority for a broad range of financial institutions and has adopted an integrated risk-based framework; it is also in charge of financial consumer protection.
- The SFC coordinates with other institutions in multiple areas:
  - Bank resolution and deposit insurance: SFC decides when to resolve a bank and works closely with the Guarantee Fund for Financial Institutions (FOGAFIN); a Resolution Cross-sectoral Commission (CIR) was created in 2018 to foster information sharing and analysis between the two authorities.
  - Financial stability: The SFC is a member of the Financial Stability Monitoring Committee (CCSSF) alongside Banco de la República (BR), Ministry of Finance (MHCP), and FOGAFIN; the CCSSF aims to harmonize policies and coordinate macroprudential policies.
  - Anti-money laundering and combating financing of terrorism: The SFC works closely with the Unit for Financial Information and Analysis (UIAF), an autonomous unit within the MHCP.
  - Design of financial regulation: The Colombian constitution gives the President power to issue financial regulations; in practice, regulation is delegated to the URF (created in 2011) and the SFC; the Financial Superintendent is part of the URF’s governing Board and the SFC contributes technical input to URF decrees.

*Source: EXECUTIVE SUMMARY, Detailed Assessment Report (Financial Sector Assessment Program), International Monetary Fund and World Bank; assessment performed June 1 through June 21, 2021.*

### 21. The SFC works jointly with other superintendencies, such as the Superintendency of the

### 1colea2022005 - 21. The SFC works jointly with other superintendencies, such as the Superintendency of the

### Coordination with other superintendencies
- The SFC works jointly with:
  - the Superintendency of the Solidary Economy for control and surveillance of nonfinancial cooperatives;
  - the Superintendency of Industry and Commerce, responsible for supervising and regulating competition issues;
  - the Superintendency of Corporations to have comprehensive knowledge of companies linked to the financial conglomerates it supervises.

### Market Structure — key findings
- Colombia has a large and sophisticated financial system that has grown steadily over the past decade.
- Financial sector assets increased to 218 percent of GDP in 2020 from 105 percent in 2010.
- Credit institution assets (primarily held by commercial banks) grew to 76 percent of GDP in 2020 from 50 percent in 2010, and control 35 percent of sector assets.
- Assets held by pension funds and trusts doubled in the past decade to 17 percent and 30 percent of GDP, respectively, and together represent 47 percent of total system assets.
- Mutual fund assets grew to 13 percent of GDP in 2020 and represent 6 percent of system assets.
- Insurance sector premiums were equivalent to 3 percent of GDP in 2020 (up from 2.2 percent in 2010).
- Other credit institutions collectively control assets equivalent to 4 percent of GDP.
- One state-owned bank and a number of development finance institutions have total assets equivalent to 9 percent of GDP.
- In terms of asset size, commercial banks account for 95 percent of total assets held by credit institutions.
- Financial conglomerates (CFs) dominate the system and are large and diversified, offering banking, financial services, and pension and assets’ wealth management.
  - The seven Colombian CFs account for nearly 81 percent of total conglomerates’ assets; six CFs with a foreign financial holding company own the rest.
- Cross-border exposure of Colombian CFs in Latin America rose from US$41 billion in 2012 to US$93 billion in 2020.
  - Colombian CFs operate in 14 jurisdictions in Latin America.
  - Central American exposures: Panama (US$29 billion), El Salvador (US$11 billion), Costa Rica (US$10 billion), Guatemala (US$8 billion).
  - Outside Central America: Peru (US$2 billion), Chile (US$0.6 billion), Mexico (US$0.3 billion).
  - Cross-border exposures can be as high as 25 percent of the assets of the respective CF.
  - As a share of host-market assets, subsidiaries of Colombian banks in Central America range from 17 percent of assets in Guatemala to over 50 percent in Costa Rica and El Salvador.

### Financial sector structure — selected statistics (from Table 1)
- TOTAL FINANCIAL SYSTEM: 2,200,188 billion COL$; 218 (% of GDP); 100 (Percent of total financial sector assets)
- Credit institutions: 768,724 billion COL$; 76.2 (% of GDP); 34.9 (Percent of total financial sector assets); 46 (No. of entities)
  - Commercial banks: 701,990 billion COL$; 69.6 (% of GDP); 31.9 (Percent of total financial sector assets); 24 (No. of entities)
  - State-owned bank: 27,851 billion COL$; 2.8 (% of GDP); 1.3 (Percent of total financial sector assets); 1 (No. of entities)
  - Other: 38,883 billion COL$; 3.9 (% of GDP); 1.8 (Percent of total financial sector assets); 21 (No. of entities)
- Pension funds: 383,761 billion COL$; 38.1 (% of GDP); 17.4 (Percent of total financial sector assets); 5 (No. of entities)
  - Pension funds (subrow): 325,138 billion COL$; 32.2 (% of GDP); 14.8 (Percent of total financial sector assets)
  - Other retirement funds: 47,927 billion COL$; 4.8 (% of GDP); 2.2 (Percent of total financial sector assets)
  - Prima media: 10,696 billion COL$; 1.1 (% of GDP); 0.5 (Percent of total financial sector assets)
- Mutual funds: 135,027 billion COL$; 13.4 (% of GDP); 6.1 (Percent of total financial sector assets); 279 (No. of entities)
  - Collective investment funds: 76,039 billion COL$; 7.5 (% of GDP); 3.5 (Percent of total financial sector assets)
  - Private equity funds: 19,412 billion COL$; 1.9 (% of GDP); 0.9 (Percent of total financial sector assets)
  - Other: 39,577 billion COL$; 3.9 (% of GDP); 1.8 (Percent of total financial sector assets)
- Trust services: 660,546 billion COL$; 65.5 (% of GDP); 30.0 (Percent of total financial sector assets); 23,680 (No. of entities)
  - Management and Payment: 179,000 billion COL$; 17.8 (% of GDP); 8.1 (Percent of total financial sector assets); 11,986 (No. of entities)
  - Social Security Resources: 88,000 billion COL$; 8.7 (% of GDP); 4.0 (Percent of total financial sector assets); 103 (No. of entities)
  - Real Estate Development: 76,000 billion COL$; 7.5 (% of GDP); 3.5 (Percent of total financial sector assets); 8,572 (No. of entities)
  - Secured Finance and Collateral Management: 72,000 billion COL$; 7.1 (% of GDP); 3.3 (Percent of total financial sector assets); 3,010 (No. of entities)
  - Investment: 15,000 billion COL$; 1.5 (% of GDP); 0.7 (Percent of total financial sector assets); 404 (No. of entities)
  - Securities custody: 222,173 billion COL$; 22.0 (% of GDP); 10.1 (Percent of total financial sector assets)
  - Other: 8,373 billion COL$; 0.8 (% of GDP); 0.4 (Percent of total financial sector assets)
- Insurance: 94,820 billion COL$; 9.4 (% of GDP); 4.3 (Percent of total financial sector assets); 45 (No. of entities)
  - Life: 58,358 billion COL$; 5.8 (% of GDP); 2.7 (Percent of total financial sector assets); 20 (No. of entities)
  - General: 33,137 billion COL$; 3.3 (% of GDP); 1.5 (Percent of total financial sector assets); 25 (No. of entities)
  - Other: 3,326 billion COL$; 0.3 (% of GDP); 0.2 (Percent of total financial sector assets)
- State-owned Financial Institutions: 88,120 billion COL$; 8.7 (% of GDP); 4.0 (Percent of total financial sector assets); 11 (No. of entities)
  - Other: 69,191 billion COL$; 6.9 (% of GDP); 3.1 (Percent of total financial sector assets)

(Source: SFC.)

### Competition in the financial sector
- Interconnectedness increased due to mergers and acquisitions; financial conglomerates control at least 75 percent of the industry with presence in banking, insurance, and asset management.
- Concentration measures (HHI, C3) have increased in key segments such as banking and pension funds.
- The Superintendency of Industry and Commerce (SIC) is the competition authority and coordinates with the SFC under an MoU:
  - SIC can sanction anti-competitive practices (collusive practices, abuse of market power).
  - For mergers in the financial sector, the SFC authorizes transactions following a (nonbinding) analysis by the SIC.
- The SFC has developed supervisory tools to promote competition:
  - Revised authorization process to promote efficiency, adequate preparedness, and proportionality for new entrants.
  - Issued guidelines to facilitate licensing and fit-and-proper assessments and standardized processes and criteria.
  - Strengthened financial consumer protection, including a comparative pricing tool and regulation of bundled product sales.
  - Introduced a sandbox mechanism for promoting financial innovation and adoption of new technologies in financial activities.

### Impact of the Covid-19 crisis on the banking sector
- Capitalization and solvency:
  - Average CET1 ratio: 12.8 percent at end-2020, up from 10.7 percent the year before.
  - Average total capital ratio: 17.2 percent at end-2020, up from 15.5 percent the year before.
  - Top-down stress tests showed some small credit institutions vulnerable; five institutions in 2020 were required to strengthen capital via direct capitalizations, conversion of bonds into equity, or speed-up of bond issuances.
- Liquidity:
  - Short-term liquidity indicator (IRL, based on Basel III LCR): 219 percent at end-2020, up from 188 percent one year earlier.
  - Structural liquidity indicator (CFEN, based on Basel III NSFR): between 109.3 percent and 175.6 percent.
  - Larger banks benefited from a “flight-to-stability phenomenon” in March 2020 with resource transfers into short-term and demand deposits.
- Asset quality and provisions:
  - Past-due loans increased by 18.9 percent in 2020 and account for 5 percent of the total loan portfolio.
  - Coverage ratio of past-due loans by all types of provisions increased from 141.8 percent to 152.6 percent.
- Profitability:
  - Average return on assets (ROA) decreased from 1.8 percent to 0.8 percent.
  - Average return on equity (ROE) fell from 12.64 percent to 5.86 percent.
- Risks and outlook:
  - Macroeconomic analysis by the SFC identifies credit risk as the greatest source of vulnerability, followed by operational risk, and liquidity and market risks.
  - The extent to which risks will reduce profitability depends on banks’ ability to sustain performance of best-qualified loans, achieve greater administrative efficiency, and maintain income from banking fees and trading revenues.
- Cautionary note:
  - Despite regulatory incentives, the impact of deterioration in credit risk and Covid-19 relief measures may not have been fully reflected in banks’ balance sheets yet (forbearance products allowed until end-June 2021 in some jurisdictions). All figures in this section should be read with caution.

### Preconditions for effective banking supervision
- Sound macroeconomic and financial sector policies:
  - Key components: full-fledged inflation-targeting regime; flexible exchange rate; Fiscal Rule (2011) for the central government; medium-term fiscal framework.
  - Monetary policy maintained inflation within the central bank’s targeted range (between 2 percent and 4 percent) until July 2020.
  - Main interest rate progressively relaxed between March and September 2020.
  - Authorities’ COVID-19 response included fiscal transfer programs, prudential regulations for relief measures for debtors, and central bank money injection.
- Liquidity system and market functioning:
  - The BR adjusts liquidity through open market repurchase operations against government securities and intraday repurchase operations; access to OMOs by non-systemic counterparties has been limited following 2013 FSAP advice.
- Macroprudential policy and institutional coordination:
  - Macroprudential policy has been implemented on an occasional basis in a decentralized regulatory context.
  - MHCP holds bulk of financial regulation; BR sets monetary policy, foreign exchange regulations, controls on foreign indebtedness, and reserve requirements; SFC supervises financial intermediaries.
  - Resolution responsibilities shared by the SFC and FOGAFIN, coordinated through the CIR (created in 2018).
  - CCSSF established in 2003 as an information-sharing and coordination forum, but it is not a decision-making body and lacks predefined tools or a clear objective variable to target financial stability.
  - Recommendation: set up an explicit macroprudential policy framework with a clear mandate for the lead authority, well-defined objectives, adequate powers, and strong accountability.

### Public infrastructure and supporting frameworks
- System of business laws:
  - Enforcing contracts remains lengthy and costly: on average three to five years; typical cost amounts to 45.8 percent of the claim value.
  - Insolvency proceedings governed by Law 1116 of 2006, amended by Law 1676 of 2013; treatment of secured creditors remains an important issue.
- Accounting and auditing:
  - Comprehensive accounting framework based on IAS and IFRS standards; SMEs subject to IFRS for SMEs; micro businesses apply simplified principles derived from IFRS for SMEs.
  - Last accounting update: December 2020 (decree 1432 (2020)).
  - External audits required for stock corporations, branches of foreign companies and companies above asset/income thresholds (thresholds in 2020: Col$4.140 million of total assets and Col$2.484 million of income).
  - Since 2016, International Standards on Auditing (ISA) are mandatory for external auditors of large companies and those publishing consolidated financial statements.
- Payment and clearing systems:
  - Private sector owns the stock exchange (BVC) and associated infrastructures: CRCC, CCDC, BVC-Renta, Deceval.
  - BR owns the large value payment system (CUD) operating on a real-time gross settlement basis and operates the public debt depository and settlement platform (DCV); BR oversees payment systems.
- Credit bureaus:
  - Two major credit bureaus (Datacredito and Transunion) with wide coverage: over 82 percent of economically active individuals in 2019.
  - Operation under Law 1266 of 2008 (habeas data act) which regulates data rights, types of information collected and consumer protection measures.
- Public statistics:
  - DANE publishes national accounts, prices and costs indexes, population and demography.
  - BR publishes exchange and interest rates, external sector statistics, economic surveys, and a biannual financial stability report.
  - SFC releases bank-by-bank and aggregated monthly financial information and a monthly report including aggregate information on banking profits, assets (quality and provision coverage), liabilities, capital ratios and liquidity risk indicators.

*Source: SFC; COLOMBIA INTERNATIONAL MONETARY FUND.*

### 46. A voluntary pilot assessment carried out in 2015 concluded that the Colombian

### A voluntary pilot assessment carried out in 2015 concluded that the Colombian authorities have strong powers to manage weak and failing financial institutions

### Resolution regime and recent enhancements
- 2015 pilot assessment: identified strengths and key shortcomings in Colombia’s recovery and resolution regime. Shortcomings included the need:
  - (i) for additional powers to transfer assets and liabilities to a private sector buyer or a bridge bank without requiring consent from shareholders or other interested parties;
  - (ii) to introduce an assessment of nonviability, based on clear criteria, as a trigger for timely resolution;
  - (iii) to implement rules to minimize the exposure of public and deposit insurance resources in resolution, including additional bail-in powers with regard to unsecured or uninsured creditors; and
  - (iv) to start recovery and resolution planning as soon as possible.
- Enhancements implemented over the past four years:
  - FOGAFIN granted explicit powers by law to transfer assets and liabilities to a credit institution, or a bridge bank, without requiring consent from shareholders or other interested parties (Law 1870 (2017) and decree 521 (2018)).
  - Four supervised entities designated as systemic in 2020 and 2021 (Bancolombia, Banco de Bogotá, Banco Davivienda, and BBVA Colombia) will have to establish and communicate to the SFC a resolution plan from 2022 onward.
  - The Conglomerate Law grants new supervisory powers to the SFC to require adjustments to the organizational structure of financial conglomerates, which can improve resolvability.

### Appropriate level of systemic protection (public safety net)
- Lender-of-last-resort (BR) facility:
  - Conditions for access set by the BR Board of Governors and laid out explicitly.
  - BR must lend to “solvent” credit institutions defined as either:
    - net equity of at least 50 percent, or
    - regulatory capital of at least 40 percent of the minimum amount,
    - and providing acceptable collateral, regardless of the BR’s or the SFC’s opinion on the firm’s viability.
  - Emergency funds cannot be used beyond pre-set periods and, in any case, cannot be used for more than nine months.
- Deposit insurance (FOGAFIN):
  - Current coverage limit: US$12,700 (Col$50,000,000) per depositor per institution.
  - All deposit-taking financial institutions required to participate (except cooperatives covered by FOGACOOP) and pay quarterly deposit insurance premiums.
  - Scheme covers 99 percent of the depositors in full.
  - As of October 2020, deposit insurance fund resources: US$7.1 billion (Col$ 27.5 trillion), accounting for 5.8 percent of insurable deposits.
  - If fund depleted, FOGAFIN may raise extraordinary contributions from the industry or ask for contributions from the national budget (EOSF art. 319).
  - FOGAFIN can begin to pay out insured deposits from eight days after the liquidation order; working to be able to pay out insured deposits within seven working days.

### Effective market discipline and corporate governance
- 2016 OECD review: concluded substantial reforms to strengthen corporate governance for listed companies and SOEs; noted challenges including low trading volumes, diminishing number of listed companies, and concentrated ownership via large conglomerates.
- Implementation and monitoring:
  - Updated Colombian Code of Best Practices and corporate governance framework for SOEs broadly compliant with international standards.
  - SFC monitors Code implementation; all issuers required to annually report adherence under a “comply or explain” methodology.
  - SFC publishes annual results to provide market with updated and comparable information; progress particularly among biggest stock companies.
  - Areas of lowest compliance: (i) enforcement of shareholder rights and equitable treatment; (ii) recognizing stakeholder rights; and (iii) duties, rights, and responsibilities of Boards.
- Foreign investment:
  - No restrictions on foreign investments in entities supervised by the SFC and no special conditions for foreign-financed takeovers, provided registration with the BR and compliance with Colombian law.
  - Currently seven banks in Colombia with a majority of foreign shareholders and six financial holdings domiciled abroad.

### Main findings — supervision framework, powers, and practices
- Responsibility, objectives, powers, independence, cooperation (CPs 1–3, and 13):
  - SFC is sole supervisor of the financial sector in Colombia, including insurance, with a broad range of preventive and corrective powers and a track record of using them.
  - Supervisory powers on financial conglomerates enhanced since 2017 and the adoption of the Financial Conglomerates Law.
  - SFC is a technical body affiliated to the MHCP, with separate legal personality, and administrative and financial autonomy; resources strengthened alongside sector growth and complexity.
  - Operational independence enhanced since 2015 by a decree on appointment and dismissal of the Superintendent, but additional formal safeguards recommended (e.g., statutory minimum term and limited removal causes; protections for SFC staff acting in good faith).
  - Domestic and cross-border cooperation:
    - Domestic: SFC participates in CCSSF with BR, MHCP, and FOGAFIN to monitor financial stability; through CIR, SFC and FOGAFIN coordinate possible resolution options and planning.
    - Cross-border: SFC participates in regional groups, supervisory colleges, signed MOUs (including with the Central American Monetary Council); home supervisor to seven conglomerates and host to six.
- Ownership, licensing, structure (CPs 4–7):
  - SFC processes for authorization of new credit institutions, ownership changes, and investments are well-designed, revised for efficiency and proportionality; draft guidelines issued to facilitate licensing and fit-and-proper assessments.
  - SFC actions against illegal deposit-taking:
    - Dedicated team of 26 officials performed 237 offsite and 215 onsite inspection visits between 2016 and 2020.
    - Resulted in 24 cases of illegal deposit-taking activity and 7 cases where controlling persons were conducting activities requiring SFC authorization.
    - SFC publishes public guidance on illegal deposit-taking practices.
- Methods of ongoing supervision (CPs 8−10, and 12):
  - Supervisory process overhauled: supervision-by-risk (SBR) approach, principles-based communication, and integrated supervisory framework (MIS) based on risk principles.
  - Risk assessment matrix (RAS) tailored to groups and individual banks:
    - RAS analyzes significant activities (SA), inherent risks, adequacy of risk management, assigns net risk ratings to each SA to assess global net risk (GNR).
    - Supervisors evaluate capital, liquidity, and profitability to compute overall risk profile and rating.
    - For financial holdings (HFs), RAS adds a layer focusing on contagion, strategic, and concentration risks.
  - SFC’s guidance is principles-based and high level; recommendation to provide more detailed guidance, benchmarks, and thresholds for enhanced monitoring.
  - Monitoring mix: onsite and offsite activities supported by extensive data collection; external auditors maintain full-time staff at larger banks responding to SFC information requests.
- Corrective and sanctioning powers (CP 11):
  - SFC actively employs a broad range of measures and tools, can require corrective action and apply sanctions on holding companies, banks, management, and boards; typically uses a ladder approach to allow remedies.
  - Preventive actions include orders and recommendations; SFC may request capital increases when capital is deemed inadequate relative to operating risks even if CAR meets minimums.
- Corporate governance (CP 14):
  - SFC issued External Circular 028 (2014) publishing the New Code of Best Corporate Practices—Country Code for stock and private debt-issuing banks; establishes Board duties, committees, internal controls, and reporting obligations.
  - Adoption voluntary but reporting required; once a bank adopts a recommendation, it becomes compulsory and must be incorporated into bylaws.
  - SFC has issued additional corporate governance guidelines and internal guides for assessing governance adequacy.
- Prudential requirements, regulatory framework, accounting and disclosure (CPs 15–29):
  - SFC requires comprehensive risk management processes and issued detailed guidelines for HFs, subordinates, and independent banks addressing Board roles, internal controls, risk appetite, and risk management policies.
  - Areas recommended for improvement: interest rate, liquidity, concentrations and large exposures, and country and transfer risk.
  - Basel III alignment since 2012 culminated in 2018 changes, with majority enforced in January 2021; Tier 1 and capital buffers to be progressively implemented over a three-year period (January 2021−January 2024). Key 2018 changes include:
    - introduction of new Tier 1 and leverage ratios calibrated as per Basel III;
    - introduction of a capital conservation buffer of 1.5 percent and of an additional buffer of 1 percent for DSIBs;
    - modifications to the list of instruments accepted as regulatory capital to harmonize with the international framework;
    - modifications to risk weights of assets to increase sensitivity to credit risk.
  - At the end of the transition period, capital requirements for a DSIB will reflect the introduced buffers and ratios.
  - Remaining differences between Basel III and Colombian capital requirements include:
    - lighter risk weighting for certain assets, such as a zero risk-weight for cash deposits in financial entities supervised by the SFC, Colombian government debt (both denominated in local and foreign currencies), mandatory investments irrespective of the credit rating of the issuers, and exposures to a clearing house;
    - recognition of minority interests above minimum capital requirements as eligible capital for entities subject to prudential standards equivalent to the Colombian ones.
  - Recommendation: complete alignment of regulatory capital requirements with relevant Basel III standards.

*Source: 1colea2022005 - 46. A voluntary pilot assessment carried out in 2015 concluded that the Colombian*

### 71. The implementation of the new capital requirements is expected to improve the

### 1colea2022005 - 71. The implementation of the new capital requirements is expected to improve the

### Capital requirements and solvency impacts
- Implementation of the new capital requirements is expected to improve the regulatory solvency of Colombian banks.
- SFC estimates:
  - CET1 ratio increase from 10.7 percent to 16.4 percent.
  - Total solvency ratio increase from 16.4 percent to 21.3 percent.
- Improvement mostly derives from:
  - Reduction in RWAs density from 75.9 percent to 66 percent.
  - Inclusion of results and reserves into CET1 capital instruments (to a minor extent).
- In 2020 the SFC authorized some credit institutions to adopt the new requirements early as a preparedness measure or to boost solvency of vulnerable entities.
- For all credit institutions (alternate estimate):
  - CET1 ratio increases from 11.7 percent to 18.2 percent.
  - Total solvency ratio increases from 17.3 percent to 22.9 percent.

### Internal capital adequacy assessment process (ICAAP) and stress testing
- ICAAP is at an early stage; a pilot exercise was launched in 2019 requiring each supervised entity to define scenarios that would result in noncompliance with capital and liquidity targets.
- Submission of stress test results was postponed until July 2021 due to the Covid-19 crisis.
- SFC expected actions:
  - Identify best practices and main shortcomings of techniques used.
  - Enhance regulation; draft regulation contemplates formalizing a comprehensive management approach linking risk appetite, ICAAP, ILAAP, stress tests, and recovery and resolution plans.
  - Require supervised entities to periodically report results of those exercises to the SFC.

### Accounting, provisioning, and auditing
- On consolidated financial statements, banks/FHs follow IFRS; individual bank-level statements follow prudential provisioning rules issued by the SFC.
- Prudential requirements result in higher provisioning requirements than under IFRS.
- Since December 2015, credit institutions are required to prepare and disclose financial statements pursuant to applicable IAS and IFRS standards, and external auditors perform engagements according to ISA standards.
- Exception: banks do not comply with IAS 39 and IFRS 9 standards for individual financial statements but follow SFC instructions.
  - Local rules for loan-loss provisioning are not totally aligned with IFRS 9 impairment principles; the main difference is the introduction of macroeconomic variables under IFRS 9, increasing provision requirements, especially for consumer loans.
  - Considerations:
    - Remove the difference in loss-provisioning method for individual statements.
    - Review the exception to IAS 39 and IFRS 9 in individual financial statements.
    - Consider completing regulatory requirements relating to the perimeter of external audits and imposing mandatory firm rotation.

### Lending limits, related-party transactions, and concentration risk
- Regulations establish connected-party and individual lending limits but do not fully address concentration risks to include other factors listed in the CP.
- Current guidance and Decree 2555 define large exposures, connected lending, and related parties, and set lending limits.
- Guidance gaps:
  - FCL requires conglomerates to address a broader scope of concentration risks, but existing guidelines focus on connected lending limits.
  - URF conducting a review to streamline lending limits and align guidance with BCBS large exposures standard.
  - URF study should review concentrations definition incorporating elements from external circular (CE) 13 of 2019 and consider guidance benchmarks to highlight exposures needing increased monitoring and risk mitigants.
- Related-party framework:
  - Regulations define related parties and apply lending limits but do not establish a consolidated body of requirements on related-party transactions.
  - Legal framework was judged deficient at the last BCP assessment and has not been amended.
  - URF project objectives:
    - Consolidate all exposures with subordinates.
    - Ensure clear and homogeneous application of groups of related parties concept.
    - Simplify scheme with fewer limits.
    - Reduce incidence of exceptions that generate arbitrage and complexities.

### Country and transfer risk
- Country and transfer risks are not fully addressed.
- SFC addressed some deficiencies from last BCP review by establishing requirements on risk management and controls for country risk at banks.
- Outstanding gaps:
  - Detailed guidance on measuring and provisioning country and transfer risks has not been issued.
  - Provisioning guidelines not provided.
- Risk concentration note:
  - Colombian banks have a significant portion of assets booked in Central America which may be subject to concentration and contagion risks.
- A regulation has been drafted on country and transfer risks to help address outstanding issues.

### Market risk and IRRBB
- Adequate regulatory standards are in place for management of market risks; SFC supervises implementation and has developed a robust framework to monitor market risk exposures and identify potentially vulnerable entities.
- Since 2018, SFC strengthened supervision of IRRBB for largest banks via dedicated offsite exercises; a similar exercise was planned in 2021 for medium and small banks and nonbank financial institutions.
- Gaps and planned actions:
  - No prudential requirements or detailed guidelines specifically dealing with IRRBB have been issued.
  - Mandatory stress testing program (EPR) does not explicitly refer to IRRBB.
  - SFC considers establishing a formal standard on IRRBB via an External Circular in the second half of 2021.
  - Contemplated methodology would consider both earnings-based measures and changes in the EVE, pursuant to BCBS principles.

### Liquidity risk management and alignment with Basel standards
- Framework for liquidity risk management is comprehensive and has converged toward international standards.
- Required ratios include:
  - Short-term liquidity ratio (IRL) aligned further with LCR in 2018.
  - Structural liquidity ratio (CFEN) derived from NSFR introduced in 2019.
- BR (as monetary and exchange authority) mandated in 2015 several new ratios relating to FX risk in the short term and currency mismatches.
- SFC uses system-wide and individual dashboards to monitor liquidity positions.
- Misalignments with Basel III:
  - Several regulatory parameters used in computation of ratios are not fully aligned with Basel III or are not yet determined.
  - Most run-off factors receive more favorable treatment than LCR standard prescribes.
  - Authorities justify parameters as reflecting local market conditions and client behavior.
  - Consequence: reduced comparability between subsidiaries of financial conglomerates across jurisdictions.
- Recommendation:
  - Further align local LCR and NSFR ratios with international standards.
  - Require NSFR ratio to be calculated at a consolidated level (as envisaged by the SFC).

### Operational risk and cybersecurity
- Since January 2021, banks must hold capital against operational risk; requirements derived from Basel III operational risk standardized approach.
- SFC enhanced operational risk management framework with instructions to strengthen:
  - Information security, cybersecurity, operational performance, recording of operational events, and outsourcing management.
- SFC actions:
  - 2018–2019: first evaluation of banks’ cybersecurity and business continuity maturity.
  - 2020: proactive specific instructions to improve operational risk management during the pandemic and follow up on implementation.
  - Monitored daily availability of online services via an automated connection test.

### Detailed assessment methodology and supervisory grading
- Assessment grading scale: compliant, largely compliant, materially non-compliant, and non-compliant; “not applicable” may be used in certain circumstances.
- Definitions summary:
  - Compliant: all essential criteria applicable are met without significant deficiencies.
  - Largely compliant: only minor shortcomings observed; overall effectiveness sufficiently good.
  - Materially non-compliant: severe shortcomings despite formal rules; supervision not clearly effective; practical implementation weak.
  - Non-compliant: no substantive implementation; several essential criteria not complied with; supervision manifestly ineffective.
- Countries may choose to be assessed against additional criteria; Colombia elected to be assessed on the additional criteria.
- Self-assessment template includes:
  - “Description” of the system (laws, prudential regulations, supervisory tools, institutional capacity, evidence of implementation).
  - Optional single-line “assessment” grade.
  - “Comments” section for assessors to explain gradings and required measures to achieve full compliance.

### Supervisory powers, responsibilities, and functions (Principle 1; EC1–EC3 findings)
- EC1: Responsibilities and objectives for authorities involved in banking supervision clearly defined in legislation and publicly disclosed.
  - Constitutional and legal framework:
    - President regulates via decrees, resolutions, and orders (Art. 189.11).
    - President exercises inspection, surveillance, and control over persons performing financial activities (Art. 189.24); exercised through the SFC.
    - SFC is sole supervisor of financial sector including insurance (Art. 11.2.1.3.1 of Presidential Decree 2555 (2010)).
  - SFC background:
    - Result of 2005 merger of superintendencies of banks and securities.
    - Technical body under MHCP with legal representation, administrative, and financial autonomy.
    - Objectives defined by law (EOSF, Art. 325 and 326): monitor financial system stability, promote securities market, protect investors/savers/policyholders.
    - New supervisory powers for financial conglomerates granted in 2017 (Law 1870 of 2017).
  - SFC responsibilities are stated in Part 11, Book 2, Title 1, Decree 2555 of 2010.
  - SFC conducts missions based on materiality principle and has right of access to necessary information (Law 1328 of 2009, Art. Article 67).
  - Administrative principles applicable include equality, morality, effectiveness, economy, celerity, impartiality and public disclosure (Colombian Constitution, Art. 209; Law 1437 of 2011, Art. 3).
  - Legal framework, mission, vision, and structure available on the SFC website.
- EC2: Primary objective of banking supervision is to promote safety and soundness; broader responsibilities subordinate to that objective.
  - SFC’s primary aim: preserve financial sector’s stability, security and confidence through supervision.
  - SFC also protects financial consumers and may adjudicate disputes related to contractual obligations (Law 1480 (2011)–Art. 57).
  - Independence between SFC’s jurisdictional and supervisory functions is established by law; distinct departments handle these functions in practice.
- EC3: Laws and regulations provide framework to set and enforce minimum prudential standards; supervisor can increase prudential requirements based on risk profile and systemic importance.
  - Legal framework mainly contained in EOSF (1993) and Decree Law 2555 (2010); both regularly updated.
  - SFC issues mandatory circulars and resolutions (CBCF, CBJ) on capital adequacy, risk management, loan classification and provisioning, accounting, and reporting.
  - Since 2015 SFC empowered to increase prudential requirements for individual banks and banking groups based on risk profile.

*From: 1colea2022005 - 71. The implementation of the new capital requirements is expected to improve the*

### 1. Based on its review of the ICAAP or on its process of supervision, the SFC may

### 1colea2022005 - 1. Based on its review of the ICAAP or on its process of supervision, the SFC may

### Powers to require corrective measures and higher capital
- Based on its review of the ICAAP or on its process of supervision, the SFC may order the entities to adopt measures to prevent or correct the deficiencies identified or require levels of regulatory capital superior to the minimum ones (DL 2555, Art. 2.1.1.1.15);

### Capital requirements for financial conglomerates
- The SFC can establish appropriate levels of capital for financial conglomerates considering for this purpose the activities carried out by the entities that are part of the financial conglomerate and the risks associated with them (law 1870 (2017), Art. 5);

*Source: 1colea2022005 - 1. Based on its review of the ICAAP or on its process of supervision, the SFC may*

### 3. Banks considered as systemic shall also maintain a systemic capital buffer

### 3. Banks considered as systemic shall also maintain a systemic capital buffer

### Systemic capital buffer and supervisory actions
- Decree 1477 (2018) redefines RWAs and technical capital (implementation in January 2021) and introduces a conservation buffer and a systemic buffer for DSIBs (full implementation in February 2024).
- In the last three years, as part of its regular monitoring, the SFC has ordered an increase of capital to two supervised entities, so that they achieve a capital adequacy ratio of 12 percent.
- Following a top-down stress test exercise in 2020, the SFC required five institutions to strengthen their capital positions through direct capitalizations, conversion of bonds into equity, or the speed-up of bond issuances in the market.
- For 2021, institutions are required to submit their dividend distribution project to the SFC prior approval, and the SFC may limit such distributions if it deems it necessary.

### Updates to laws, regulations, and prudential standards (EC4)
- Since 2009, progressive alignment toward IAS/IFRS and Basel III; important updates include:
  - Law 1314 (2009) on IFRS and related decrees, progressive implementation of IFRS since January 1, 2015;
  - Law 1870 (2017) and related decrees—SFC supervisory powers at conglomerate level, focus on risk management, capital adequacy, exposure limits, and conflicts of interest;
  - SFC external circular 031 (2017) on the implementation of stress tests;
  - SFC external circular 009 (2018) on the evolution of the Liquidity Risk Indicator (LRI), 019 (2019) on the implementation of a NSFR ratio since June 2019, and 002 (2020) on liquidity risk management;
  - Decree 1477 (2018), redefinition of RWAs and technical capital (implementation in January 2021) and introduction of conservation and systemic buffers for DSIBs (full implementation in February 2024);
  - Decree 1421 (2019), new capital requirements for operational risk to be implemented since January 1, 2021.
- Regulatory issuance process:
  - URF (under the MHCP) and the SFC are responsible; Financial Superintendent is part of URF Governing Board.
  - Draft decrees and SFC circulars/resolutions are published and subject to public consultation; industry and interested parties can send written comments.

### Supervisory powers and practices (EC5)
- Legal powers:
  - SFC has a general right of access to information needed for protection and stability of the financial system (Law 1328 of 2009, Art. Article 67).
  - Power to perform onsite inspections (EOSF, Art. 326.4). Directors, managers, legal representatives, external auditors, and staff must not obstruct supervisory actions (EOSF, Art. 72).
- Supervisory activity levels (source: SFC):
  - 2018: Offsite 160; Onsite 36; Total 196.
  - 2019: Offsite 114; Onsite 30; Total 144.
  - 2020: Offsite 79; Onsite 6; Total 85.
  - Note: A large number of supervisory exercises were cancelled in 2020 due to the COVID-19 crisis.
- Group and cross-border supervision:
  - SFC supervises at individual and consolidated levels; FCL (2017) grants new powers over financial conglomerates (request information, onsite inspections, including financial holding).
  - Since 2018, financial conglomerates must quarterly report: (i) capital adequacy at consolidated level (external circular 012 (2019)); (ii) intra-group exposures; (iii) exposures with related parties (external circular 030 (2020)).
  - SFC inspected subsidiaries in 7 foreign countries in 2018 (Costa Rica, Honduras, Paraguay, Nicaragua, Panamá, Peru and Guatemala); three onsite inspections in 2019 in Central America.

- Supervision of foreign banks:
  - Foreign bank subsidiaries/branches must be authorized by SFC; SFC seeks assurances regarding consolidated supervision and authorization/no objection of the home country (EOSF, Art. 53 no. 3).
  - Licensed foreign subsidiaries/branches have same rights and obligations as national banks (EOSF, Art. 45A).
  - If a foreign financial holding is not subject to an equivalent regime, SFC may ask for additional information (FCL, Art. 7).

### Corrective powers, sanctions, and resolution (EC6)
- Preventive and sanctioning powers:
  - SFC can issue administrative orders to suspend illegal, unauthorized or unsafe practices until remedial actions are implemented (EOSF, Art. 326 no. 5). Department directors can issue administrative orders within competences (DL 2555, Art. 11.2.1.4.33).
  - Preventive measures include enhanced surveillance, recuperation programs, prohibition to distribute dividends, mergers of failing institutions, recapitalization, fiduciary administration, partial or total transfer of assets and liabilities (EOSF, Art. 326 no. 5).
- Use of corrective and sanctioning powers (source: SFC):
  - Corrective:
    - Administrative Recommendation: 1 (2016); 4 (2017).
    - Administrative Order: 15 (2016); 12 (2017); 8 (2018); 13 (2019).
  - Sanctioning:
    - Sanctioning process: 20 (2016); 9 (2017); 10 (2018); 13 (2019).
  - Total corrective and sanctioning actions: 36 (2016); 21 (2017); 22 (2018); 26 (2019).
- Sanctions available:
  - Warnings, fines, suspension or disqualification up to five years for board members, legal representatives, auditors or high-level officers; removal of administrators, directors, legal representatives or external auditors; closure of representative offices of foreign financial institutions (EOSF, Art. 208 no. 3).
- License revocation and taking possession:
  - Licenses may be revoked under “Loss of Enforceability” (Contentious Administrative Code, Art. 66); no banking license withdrawal to date.
  - SFC may take over a supervised entity after Advisory Council opinion and MHCP acceptance if triggered by events (EOSF, Art. 114): suspension of payments, refusal to open books, failure to comply with SFC instructions, capital below 50 percent of issued capital, capital below minimum established in law, solvency ratio below 40 percent of required minimum, severe inconsistencies in information, failure to comply with recovery plan or ordered exclusion of assets and liabilities or progressive deleveraging. SFC must decide within two months and consult FOGAFIN beforehand.
  - Taking possession implies removal of directors/administrators/external auditors, suspension of payment of obligations (if decided), suspension of embargoes and processes (EOSF, Art. 116). SFC can transfer business and assets to FOGAFIN for liquidation (EOSF, Art. 326 no. 5).
- Coordination for orderly resolution:
  - Coordination through CCSSF and CIR (created in 2018) to facilitate resolution actions between SFC and FOGAFIN.
  - No bank closures or mergers as part of problem bank resolution in the last five years.

### Supervision of parent companies and affiliates (EC7)
- SFC has power to review activities and access records and Boards of supervised entities, including parent companies which are banks.
- SFC can inspect entities not subject to its control to determine risks to supervised entities; visits to real sector entities linked to financial conglomerates since 2008–2010.
- Powers over financial holding companies (FCL):
  - (i) Give instructions to the financial holding relating to risk management, internal control, reporting and corporate governance;
  - (ii) Authorize direct and indirect capital investments in financial entities contemplated by the holding;
  - (iii) Request the holding to change conglomerate structure when it impedes adequate reporting, comprehensive supervision, or identification of ultimate beneficial owners;
  - (iv) Request information and perform onsite inspections in entities part of a financial conglomerate;
  - (v) Revoke authorization granted to a supervised entity part of a foreign-based financial conglomerate where information is insufficient for supervision.
- Decree (August 2018) detailing rules for financial conglomerates on connected parties:
  - Parent company must establish intragroup and related parties’ exposure and risk concentration limits, present policies and limits to the SFC, and permanently update information on intragroup exposures and related parties (officially transmitted quarterly but can be required when needed).
  - SFC can require adjustments of limits when they are inappropriate given embedded risk or pose a risk to financial stability.

### Assessment: Principle 1 and Principle 2
- Assessment of Principle 1: Compliant.
  - There is a clear and comprehensive framework for banking regulation and supervision. SFC is the sole supervisor of the financial sector in Colombia, including insurance companies, with broad preventive and corrective powers and a track record of using them. Supervisory powers over financial conglomerates have been strengthened since 2017 and the FCL.
- Principle 2 (Independence, accountability, resourcing, and legal protection for supervisors):
  - The supervisor possesses operational independence, transparent processes, sound governance, budgetary processes that do not undermine autonomy and adequate resources and is accountable for the discharge of its duties and use of its resources. The legal framework includes legal protection for the supervisor.

### Governance, appointment, accountability, and internal processes (EC1–EC4)
- EC1: Operational independence and governance
  - SFC is a technical body affiliated to the MHCP with separate legal personality and administrative and financial autonomy (EOSF art. 325 no. 1; DL 2225, art. 11.2.1.1.1). It can regulate, supervise and take resolution actions (EOSF art. 325).
  - SFC does not require MHCP approval for general instructions to supervised entities or for most supervisory decisions. Prior consultation of an Advisory Council is mandatory for major supervisory decisions (EOSF art. 326 & 334; DL 2225, art. 9.1.1.1.1; 11.2.1.4.2).
  - Advisory Council: appointed by the president, chaired by the Superintendent, comprises five members including a MHCP representative and four independent members; director of FOGAFIN invited without vote. Members must populate annually a public register on conflicts of interest since 2019. The Council’s view is not mandatory and final decision rests with the Superintendent (Decree 422 (2006), Art. 2). The Superintendent has historically followed the Advisory Council’s opinion.
- EC2: Appointment and removal of Financial Superintendent
  - Presidential decree 1817 (2015) clarifies appointment/removal regime:
    - Appointment/dismissal by the president of the republic;
    - Appointment follows open application of qualified candidates (at least 10 years of relevant experience);
    - Financial Superintendent appointed for a period of four years, concurrent with presidential term;
    - Dismissals before term end must be motivated and publicly disclosed by decree.
  - The fixed-term provision was partly censured by the Council of State on May 14, 2020; a draft financial reform presented in March 2021 aims to reinstate the censured provision.
  - High turnover has decreased since 2012; over the last nine years only one change of Financial Superintendent (retirement due to appointment to the Central Bank's Board). Current Superintendent appointed in 2017 and ratified by decree in 2018.
- EC3: Published objectives and accountability
  - SFC missions and objectives published on its website and detailed in annual reports; annual public hearing discloses sector characteristics, achievements, supervisory priorities; strategic objectives, annual action plans, audited financial statements and budgets published.
  - SFC reports annually to Congress; sent two reports to Congress in context of Covid-19 on actions taken in 2020 and 2021.
  - Administrative acts and resolution decisions are publicly disclosed; appeal process does not suspend execution of decision.
  - SFC is subject to audits by the Comptroller General; last two audits took place in 2017 and 2020.
- EC4: Internal governance and decision processes
  - SFC directed by a Superintendent assisted by Delegate Superintendents (DL 2555, Art. 11.2.1.1.2). Superintendent appoints/dismisses senior staff (EOSF, art. 329).
  - Internal governance updated in 2019; internal resolution separates financial institutions into three groups by complexity, size, and materiality.
  - Joint Supervisory Teams (JST) composed of institutional and technical department staff are basic supervisory units, headed by a director (for the three most significant financial conglomerates—Sura Bancolombia, Bolívar, and Aval—or a relationship manager).
  - Supervised entities classified into N1, N2 and N3 categories considering quantitative criteria (size, interconnection, substitutability, complexity, global activity) and qualitative (risk profile and expert criteria).
  - There are three internal decision-making processes.

*Source: 1colea2022005 - 3. Banks considered as systemic shall also maintain a systemic capital buffer*

### 1. For entities categorized as N3 (least systemic importance), relevant Deputies

### 1. For entities categorized as N3 (least systemic importance), relevant Deputies 

### Approval for N3 entities
- For entities categorized as N3 (least systemic importance), relevant Deputies approve the results of supervision and administrative actions;

### Approval for other entities not covered by the Supervisory Committee
- For other entities not covered by the Supervisory Committee, a Review Panel approves the results of the supervision exercises and/or administrative supervisory actions, where appropriate;
- Deputy Superintendents and Deputies (Institutional and Risk) make up this panel;

*Source: https://www.imf.org/-/media/files/publications/cr/2022/english/1colea2022005.pdf*

### 3. For entities categorized as N1 or which are part of a financial conglomerate, a

### 1colea2022005 - 3. For entities categorized as N1 or which are part of a financial conglomerate, a

### Supervisory governance and decision-making
- Supervisory Committee:
  - Approves results of supervision and supervision measures.
  - Highest-level deliberative and decision-making body within the SFC in matters of supervision.
  - Composed of the Financial Superintendent, Deputy Superintendents and Deputies.
  - Expected to allow decision-making in times of crisis to be carried out in an agile and timely manner.
- Advisory Council:
  - Consulted prior to major supervisory decisions or resolution actions; formal decisions taken by the Superintendent.
  - Members required to populate a public register on conflicts of interest.
- Crisis processes and procedures:
  - Detailed in guidelines relating to the Integrated Supervisory Framework (MIS), the Safety Net Crisis Protocol, and SFC and FOGAFIN Resolution Handbooks.
  - All committees composed entirely of managers of the SFC, to whom rules to prevent conflicts of interest apply.

### EC5 — Supervisor credibility, professionalism and conflict-of-interest rules (Description and findings)
- Legal and internal frameworks:
  - Staff subject to general rules for Colombian civil servants (Law 734 (2002), Art. 36 to 41).
  - Decree 1170 of 1980: forbidden for SFC staff to hold position as shareholder, director or executive officer in a supervised entity.
  - Former SFC staff cannot take position in a supervised entity they controlled during a period of two years after quitting the SFC.
  - Internal provisions include obligation to maintain confidentiality of information; each member must sign a Confidentiality Charter (Corporate Governance Code).
- Sanctions for breaches:
  - Written admonition, fine, suspension, and destitution.
  - Breach considered a professional fault and, in some cases, a crime.
- Recent disciplinary record:
  - In the last five years, there has not been record of disciplinary actions against officials of the SFC for misuse of information or conflicts of interest.

### EC6 — Resources, financing and capacity (Description and findings)
- Budget and financing:
  - SFC budget included in general government budget, approved annually by the Congress.
  - Industry contributions cover around 95 percent of the SFC budget (EOSF, Art. 337.5.).
  - Contribution revenues supplemented by smaller amounts mainly from sanctions related to consumer protection.
  - Congress allocated additional funds once in 2011: US$2.3 million for claims related to pyramid schemes fallout.
- Expenses:
  - Expenses increased from Col$148,728 million in 2016 to Col$220,285 million in 2020.
- Staffing and composition:
  - The SFC had 1,075 employees as of January 2021.
  - 67.3 percent are focalized on supervision and 32.8 percent are part of the support areas for the supervision work.
  - In 2020 and so far in 2021, the SFC hired 220 new people.
  - More than three-fourth of the staff has more than three years of professional experience.
  - Turnover rate: 3 percent in 2020.
- Salary and retention:
  - Employee salary regime includes: (i) a special reserve equivalent to 65 percent of the annual compensation; (ii) technical bonuses associated to education profile and performance (up to 50 percent of the basic salary); and (iii) mid-year and end-year bonuses.
- External experts and cooperation:
  - Ability to commission external experts subject to confidentiality (example: inter-administrative agreement with Toronto Leadership Center; external experts hired since 2011 to help shift toward risk-based supervision).
- Training:
  - Focus areas: (i) Supervision; (ii) Legal; (iii) Management Support; and (iv) Technology and Innovation.
  - Training actions increased from 54 actions accounting for Col$850 million in 2016 to 137 actions accounting for Col$1.748 million in 2019.
  - For 2020, the budget for the regular training of staff is COL$2.317 million, with 50 management support, 14 legal, 54 supervision, and 11 technological activities trainings.
- Technology:
  - Since 2018, implementing a five-year program to improve IT platform with increasing dedicated budget allocations.
- Travel:
  - For 2020, the travel budget was Col$29.432 million.
- Supervisory coverage:
  - The SFC supervises and is the resolution authority for 410 diverse financial institutions.

### EC7 — Resource planning and skills assessment (Description and findings)
- Resource planning:
  - Planning stage of oversight strategy defined for a period of one year.
  - Allocation of human resources depends on objectives, assignment of JSTs, number of additional officials and duration of the exercise.

### EC8 — Risk-based resource allocation (Description and findings)
- Shift toward risk-based supervision:
  - Integrated Supervisory Framework (MIS) supported initially by the Toronto Centre.
  - Supervised entities categorized into three categories according to size, complexity, inter-connection, international activity, and risk profile.
  - More permanent and fully dedicated resources allocated to large, complex, and high-risk entities.
  - Supervisor exercise results presented in highest deliberative instances.

### EC9 — Legal protection for supervisors and staff (Description and findings)
- Legal framework:
  - No specific protections in law for the SFC, the Superintendent or staff against lawsuits for actions taken and/or omissions made while discharging duties in good faith.
  - Colombian Constitution: public servants responsible for infringing the Constitution or laws, as well as omissions or excesses in duties (Art. 6). Actions of public entities presumed to be in good faith (Art. 83). State may seek compensation from public servant when indemnity required for willful misconduct or gross negligence (Art. 90).
  - 2014 Council of State sentence: action against public servant under Art. 90 should be only in case of willful misconduct or gross negligence, and not for errors committed in good faith.
- Institutional protections and mechanisms:
  - Legal Department and external lawyers offer legal representation and defend administrative acts.
  - 2016 Budget Law explicitly authorizes Superintendencies to bear costs of legal processes brought against Superintendents for acts performed in course of duties; SFC has liability insurance contract for key staff covering decisions in performance of duties.
  - National State Legal Defense Agency charged with defending state interests; eventual participation regarding SFC to be defined.
- Court decisions (practice):
  - Very few court decisions ruled against SFC or its staff. Table of court decisions (Source: SFC):
    - 2016: Number of court decisions 140 — Negative rulings 1 — Positive rulings (in %) 99
    - 2017: Number of court decisions 60 — Negative rulings 0 — Positive rulings (in %) 100
    - 2018: Number of court decisions 86 — Negative rulings 1 — Positive rulings (in %) 98.83
    - 2019: Number of court decisions 167 — Negative rulings 0 — Positive rulings (in %) 100
    - 2020: Number of court decisions 39 — Negative rulings 0 — Positive rulings (in %) 100
    - 2021 (January to April): Number of court decisions 7 — Negative rulings 0 — Positive rulings (in %) 100
  - In practice, cases are first brought against the institution; no lawsuits filed against SFC employees related to performance of duties in the last five years.

### Assessment and recommendations — Principle 2 (Independence, resourcing and legal protection)
- Assessment: Largely compliant
- Key comments and recommendations:
  - SFC is a technical body, affiliated to the MHCP, with separate legal personality and administrative and financial autonomy.
  - Adequate financial and human resources, strengthened in recent years due to increasing complexity of financial sector.
  - Concern: composition and role of the Advisory Council could lead to interference in SFC decision-making, potentially undermining operational independence; Colombian authorities may consider additional safeguards.
  - Legal protections: constitutional, legal and institutional arrangements provide adequate protection for staff against financial consequences of actions taken in good faith. However, staff could be involved in lengthy and unpredictable legal proceedings even if liability is covered.
  - Recommended actions:
    - Strengthen formal safeguards to prevent SFC staff from being involved in lawsuits for actions taken and/or omissions made while discharging duties in good faith.
    - Specify in law that the Superintendent is appointed for a minimum term and is removed from office during his/her term only for reasons specified in it to achieve full compliance with the core principle.

### Principle 3 — Cooperation and collaboration (Assessment and key arrangements)
- Assessment: Compliant
- Domestic cooperation (EC1):
  - MOU signed to enhance inter-agency cooperation.
  - Coordination through participation in joint committees; evidence provided that arrangements work in practice.
  - Decree 2555 addresses sharing of information; Decree 2280 allows flexible mechanisms to formalize exchange in a timely manner.
  - Up to date, 19 agreements signed with 17 authorities.
  - Key domestic groups:
    - Advisory Group of Agencies Responsible for Preserving the Soundness and Stability of the Financial System (CCSSF).
    - Advisory Council (appointed by the president; five financial experts; Superintendent not obligated to accept advice; FOGAFIN Director participates without vote).
    - MHCP-URF Steering Committee (Article 8 of Decree 4172 of 2011); committee meets monthly.
- Cross-border cooperation (EC2):
  - Cross-border information sharing and cooperation agreements in place.
  - Types of arrangements and activity:
    - MOUs: 30 MOUs signed with 22 countries, and MOUs with multilateral agencies (1 non-public by request of counterparties).
    - International Internships: SFC staff participated, between 2016 and 2020, in a total of 49 internships with authorities and entities from 16 jurisdictions and 3 agencies.
    - Supervisory Colleges: Between 2015 and 2020, the SFC led 15 supervisory colleges; participates in colleges led by home supervisors (Itau, BBVA, Santander, and Scotiabank). Going forward, colleges will emphasize a comprehensive focus on Financial Conglomerates.
    - Central American Supervisors: Active involvement in CCSBSO since 2012; Superintendent re-elected as vice-chairman at September 2020 Assembly for two additional years, ending in 2022.
- Confidentiality protections (EC3 and EC4):
  - MOUs include confidentiality clauses: information received only for supervisory purposes; confidentiality provisions survive termination.
  - Parties must obtain prior written consent before disclosing received confidential information to third parties except where legally bound.
  - Home Supervisor inspection team members must sign confidentiality commitment for onsite visits.
  - Article 15, Colombian Constitution, allows denying provision of confidential information except when request comes from a tax, judicial or supervisory authority.
  - SFC must submit information to Criminal Authorities if required and keep it confidential; non-compliance may trigger administrative or criminal procedures.
- Support to resolution authorities (EC5):
  - Decree 923 of 2018, D2555 created the CIR, a technical body composed of officials designated by SFC and FOGAFIN.
  - SFC designed a Decision Tree to establish corrective actions and resolution mechanisms based on institution importance (systemic/non-systemic) and feasible solution alternative (public/private) to allow faster, more efficient decision-making.

### Principle 4 — Permissible activities (Assessment and key legal definitions)
- Assessment: Compliant
- EC1 — Definition of “bank”:
  - Defined in Art. 2, EOSF: banks (“establecimientos bancarios”) are financial institutions whose main function is to take deposits from the public (current account and other types) and place them through loans, discounts, advances or any other form of credit.
  - Banks are categorized as one type of “credit institutions” along with financial corporations, financing companies, financial cooperatives, and savings and housing corporations. All credit institutions are regulated and supervised consistently by the SFC and authorized to collect public deposits.
- EC2 — Permissible activities:
  - EOSF (Art. 7 to 9) authorizes banks to perform a list of operations including discounting commercial paper, taking current account, savings and time deposits, grant credit, issue letters of credit, custodian operations, invest in domestic and foreign public securities and other fixed income financial instruments, among others.
  - EOSF (Art. 10) prohibits certain operations and sets limitations, including: cannot hold more than 10 percent of another bank’s shares as collateral; cannot acquire or hold their own shares; cannot grant loans to finance acquisition of shares or preferred shares; cannot invest in corporate shares or bonds except in companies whose unique corporate purpose is innovation and technology related to the credit institution (DL 2555, Art. 2.26.1.4.1 to 2.26.1.4.3).
- EC3 — Use of the word “bank”:
  - Unauthorized use prohibited and penalized.
  - Commercial Code (Art. 606) prohibits misleading commercial denominations.
  - Article 108 EOSF prohibits unauthorized persons from using the word savings or equivalents or requesting/receiving unlicensed deposits.
  - Article 109 EOSF prohibits advertising as a bank without SFC license; exception for the Central Bank.
  - SFC publishes information and warnings on its website; recent enforcement examples include action against a beer company using the term “bank” and ordering two territorial entities to stop using the term.
- EC4 — Reserve of deposit-taking:
  - Colombian Constitution (Art. 335) requires authorization from the state to conduct financial activities including raising money from the public.
  - Article 108 EOSF grants SFC preventive powers with fines up to 1 million pesos, dissolution of entities and liquidation of illegal operations.
  - Decree 4334 (2008) granted Superintendency of Corporations extended powers to intervene establishments circumventing regulation.
  - Specialized SFC office for investigating illegal deposit-taking: 26 officials; performed 237 offsite and 215 onsite inspection visits between 2016 and 2020; concluded 24 cases involved illegal deposit-taking and 7 cases required authorization; SFC actions between 2016 and 2020 confirmed by courts: 198 confirmed in the first instance and 73 in the second instance.
- EC5 — Public list of licensed banks:
  - SFC maintains updated list of all licensed Colombian financial intermediaries and their branches, as well as licensed foreign banks operating in Colombia (publication on SFC website).

### Principle 5 — Licensing criteria (Assessment and key requirements)
- EC1 — Authority:
  - SFC is the sole licensing and supervisory authority for all institutions in the Colombian financial system (EOSF, Art. 326).
  - License can be limited to activities the applicant declares or activities SFC determines can be supported with the applicant’s technical and operative infrastructure (EOSF, Art. 53, no.7).
  - SFC may impose prudential conditions where appropriate (DL 2555, Part II).
- EC2 — Licensing steps and criteria:
  - Two steps: 1) constitution licensing; 2) operation licensing.
  - Constitution licensing criteria (EOSF, Art. 53 no.3) and internal process described in SFC Integrated Management System (SGI) and public checklist.
  - Verifications before granting banking license include:
    - Organizational structure of the intended institution.
    - Statutory laws.
    - Compliance with capital requirements and verification of origin of capital, including owners’ income statements and identification of ultimate beneficiaries.
    - Pro forma financial statements—and five years detailed projections of such statements and main financial indicators.
    - Fit-and-proper test for managers, directors, statutory auditors, and legal representatives.
    - Risk Management Systems’ manuals (credit, market, operational, anti-money laundering, terrorism financing, conglomerate risk, corporate governance).
    - Strategic and operational plans and feasibility studies.
  - Advisory Council issues a concept to advise the Superintendent on authorization or rejection.
  - If criteria not fulfilled, SFC can require additional information within one month and may deny authorization if requirements remain unmet; if false information discovered, SFC would reject authorization immediately and may inform other competent authorities.
  - Examples of reviewed authorization technical studies: conversion of a local financing company into a bank; establishment of a Colombian subsidiary by a foreign financial conglomerate.
  - Operating license requirements (EOSF, Article 53, no.7):
    - Formalization of public deed highlighting constitution capital value.
    - Formal payment support of the constitution capital.
    - Demonstration of technical and operative infrastructure to operate daily.
    - Registration certificate of the Deposit Insurance Institution, if required.
  - Operational Risk Office performs onsite examination to validate technical and operative infrastructure.
  - SFC published draft detailed guideline on expectations at each stage of licensing.
  - Licenses are administrative acts and can be revoked if based on false information (Code of Administrative Acts, Art. 91, no.2).
- EC3 — Consistency with supervision:
  - Licensing criteria consistent with ongoing supervision via MIS; Authorization Group coordinates with Joint Supervisory Team (JST) for consistent evaluation.
- EC4 — Structures and supervisory effectiveness:
  - SFC evaluates transparency and adequacy of legal, managerial, operational and ownership structures of bank and wider group; can require changes or mitigation measures.
  - For financial conglomerates, SFC has legal power to order the financial holding company to change the conglomerate’s structure if it hinders supervision (FCL, Art. 6).
  - Once operating license granted, SFC grants office to Board members, legal representatives, statutory auditors and others; without SFC approval they cannot hold positions.
  - Fit-and-proper guideline draft published on SFC website.
- EC5 — Suitability and ownership transparency:
  - Prospective shareholders, administrators and directors must send CV and documentation proving suitability and financial position (certificate of legal existence, financial and income tax statements, justification of origin of funds, other investments).
  - SFC entitled to require information on real beneficiaries at licensing or any time thereafter (EOSF, Art. 53 no.3).
  - When checking solvency of prospective shareholders and administrators, SFC pays particular attention to the net worth of real beneficiaries of at least 10 percent of shares (continued in source).

*Source: https://www.imf.org/-/media/files/publications/cr/2022/english/1colea2022005.pdf*

### 1.3 times the investment they intend to make; and that

### 1colea2022005 - 1.3 times the investment they intend to make; and that

### EC6 — Minimum initial capital amount
- A minimum initial capital amount, subject to annual inflation indexation, is stipulated by law for all kinds of credit institutions (EOSF, Art. 80).
- The 2020 minimal initial capital requirements are the following (COL in millions; USD1 in millions):
  - Banks: 100,492; 30.7
  - Financial corporations: 36,553; 11.2
  - Financial companies: 25,893; 7.9
  - Financial cooperatives: 4,191; 1.3
  - Companies specialized in electronic deposits: 7,631; 2,3
- Footnote: Converted to U.S. dollars using the official exchange rate as of December 31, 2019 ($3,277.14 Colombian pesos per dollar).

### EC7 — Fit-and-proper assessment at authorization and ongoing
- Fit-and-proper criteria include:
  - (i) skills and experience in relevant financial operations commensurate with the intended activities of the bank;
  - (ii) no record of criminal activities or adverse regulatory judgments rendering a person unfit.
- Description and findings:
  - Pursuant to EOSF, Art. 53 no.3, at authorization the SFC requires CVs of future legal representatives and administrators, including prior investigations and sanctions, and an authorization for criminal background checks.
  - SFC proactively runs verifications in social networks and news.
  - SFC seeks Board independence from management and complementary backgrounds among members.
  - A special committee (Comité de Posesiones) composed of the Superintendent, senior deputy Superintendents, and SFC Institutional Delegates evaluates and approves or rejects nominations (EOSF, Art. 326 no.2).
  - Between January 2020 and May 2021, some applications were rejected, mostly for lack of professional experience or availability, less often for criminal record or conflict of interest.
  - Proposed directors and senior managers must meet fit-and-proper criteria at all times; SFC can remove them if they cease to meet criteria.
  - SFC evaluation process includes:
    - (1) pre-application meetings and workshops;
    - (2) licensing-phase CV review;
    - (3) nomination-phase assessment of Board collective ability;
    - (4) supervision phase.
  - Assessors were informed of one case where SFC required strengthening of a prospective bank’s Board.

### EC8 — Review of strategic and operating plans
- Licensing authority reviews proposed strategic and operating plans, including:
  - corporate governance systems;
  - risk management and internal controls (including detection and prevention of criminal activities);
  - oversight of proposed outsourced functions.
- Description and findings:
  - Authorization requires a feasibility study with reasons for the business model, description of ongoing business, strategic and operational plans, governance structure, internal controls, oversight of outsourced functions, and draft risk management policies related to prevention of criminal activities.

### EC9 — Review of pro forma financial statements and projections
- SFC reviews pro forma financial statements and financial projections over a five-year period, including financial indicators for the proposed bank.
- Evaluation considers:
  - adequacy of financial strength to support the proposed strategic plan under different scenarios;
  - financial information on principal shareholders.
- SFC collects financial statements and tax records of proposed shareholders as required in the Check list for the constitution of supervised entities.

### EC10 — Foreign banks and home supervisor clearance
- Consistent with Art. 53 of EOSF, foreign entities submitting licensing requests must:
  - show they are subject to consolidated supervision by a competent authority in their country of origin;
  - explain the type and scope of supervision of the controlling entity;
  - attach a copy of authorization letter of their home supervisor to establish a bank in Colombia when required by applicable law.
- Financial conglomerate with cross-border holding: applicant must demonstrate home jurisdiction fulfills an equivalent regulatory and supervisory regime to Colombia (FCL, Art. 7).
- SFC has executed MoUs with different jurisdictions to guarantee information exchange; executed MoUs with home/host supervisors are considered a guarantee in the authorization process.
- SFC requests, before issuing the license, a declaration of no objection from the supervisor of origin, even if the applicant meets checklist requirements.

### EC11 — Monitoring new entrants
- SFC monitors first operational steps of new banks by reviewing:
  - information reported to the SFC;
  - tendency;
  - legal compliance;
  - compliance with prudential regulatory framework.
- Recommendations made during authorization are monitored through different information requirements.
- Supervision of new entrants is facilitated by information exchange between the Authorization Group and the JST; a knowledge document containing main activities, risk appetite, corporate governance descriptions, and supervisory considerations is handed over.

### Assessment of Principle 5
- Rating: Compliant
- Comments:
  - SFC is the sole authority for credit institution licenses and has a well-designed authorization process based on a complete set of criteria.
  - Technical studies supporting licensing decisions contain clear analyses.

### Principle 6 — Transfer of significant ownership (overview)
- Supervisor powers: review, reject and impose prudential conditions on proposals to transfer significant ownership or controlling interests in existing banks.

### EC1 — Definitions of significant ownership and controlling interest
- Law does not explicitly define “significant ownership” but SFC approval is mandatory for acquisition of 10 percent or more of a supervised institution (EOSF, Art. 88).
- “Subordination” defined (Code of Commerce, Art. 260) and presumed in cases listed in Art. 261, including situations where:
  - more than 50 percent of capital is owned by a parent company;
  - parent company or subordinate companies hold enough votes to constitute a majority of the general assembly or select majority of Board;
  - parent company exercises significant influence via contract or business deal;
  - a single person or group presents: (i) own 50 percent or more of capital; (ii) account for a majority in decision-making; or (iii) exercise influence in decision-making; and
  - control exercised by another entity through persons/entities mentioned above.

### EC2 — Requirements for supervisory approval/notification of ownership changes
- Any shareholder or investor acquiring at least 10 percent of capital of a supervised entity must obtain SFC authorization.
- Requirements summarized in public document Check list for the negotiation of shares of a supervised entity; internal procedures in SFC Integrated Management System.
- Technical studies reviewed by assessors in 4 recent cases included thorough analysis of proposed ownership structure and financial capacity of proposed shareholders; bank acquisition study extended to business plan, financial projections, and public interest.
- Recommendation: an internal guideline could describe minimum criteria to be analyzed in different cases, and material cases implying transfer of control should encompass corporate governance changes, management of material risks, financial projections under several scenarios, and operational resilience (or explain why not reviewed).

- Financial conglomerates: authorization required when holding company plans to acquire 10 percent or more of shares of a supervised entity or increase that percentage (FCL, Art. 6). If threshold not reached, holding company must notify SFC at least 15 days before acquisition; SFC may request additional information (CBJ, part 1, title 5, chapter 3).

### EC3 — Power to reject or reverse change in significant ownership
- SFC can reject any proposal for change in significant ownership or controlling interest, stating explicit reasons based on failure to demonstrate character, responsibility, fit-and-proper status, or adequate financial standing.
- Assessment of proposed changes uses similar criteria as for licensing banks; SFC analyzes direct and indirect proposed owners or real beneficiaries for fit-and-proper status.
- Depending on materiality, SFC may verify that proposed change is not detrimental to public interest.
- Number of applications for transfer of significant ownership or controlling interests over the past five years:
  - Total solicitations: 48
  - Authorized: 41
  - Conditioned authorizations: 0
  - Denied: 2
  - Desisted: 5
  - Source: SFC.
- If a change was based on false information, SFC has power to reject, modify or reverse the change.

### EC4 — Reporting of significant shareholders and beneficial owners
- Supervised institutions and financial holdings must report quarterly to SFC:
  - number of shares and shareholders;
  - names of shareholders;
  - percentage of shares in each entity (external circulars 035 (2016) and 018 (2018)).
- Required reporting levels:
  1. First ownership level: list and shares of all shareholders who own at least 1 percent of the ES capital (subscribed and paid-in capital).
  2. Second ownership level: list and shares of shareholders who own at least 5 percent of a first-level institution.
  3. Third ownership level: list and shares of shareholders who own at least 10 percent of a second-level institution.

### EC5 — Power to address unapproved change of control
- Any transfer of 10 percent or more without SFC authorization is invalid without need of a judicial mandate (EOSF, Art. 88 no.2).
- Assessors were informed of one case where SFC detected an unapproved change of capital and ordered its reversal.

### EC6 — Requirement for banks to notify supervisor of material information about major shareholders
- There is no requirement that banks must notify the supervisor as soon as they become aware of any material information that may negatively affect the suitability of a major shareholder.
- However, all banks are listed companies and are required to report relevant financial information to the public via the SFC website.

### Assessment of Principle 6
- Rating: Compliant
- Comments:
  - SFC must authorize acquisitions of 10 percent or more and has a well-designed authorization process focusing on ownership structure and financial capacity of proposed shareholders.
  - Given the range of situations covered, an internal guideline describing minimum criteria for analysis in each case could be valuable.
  - Colombian authorities could consider introducing a requirement for banks to notify the supervisor as soon as they become aware of any material information that may negatively affect the suitability of a major shareholder.

### Principle 7 — Major acquisitions (selected EC1 findings)
- Laws clearly define acquisitions and investments that are prohibited, require prior SFC approval, or do not require approval but are subject to limitations.
- Examples:
  - General rule: commercial banks not authorized to make capital investments in companies in the real sector, unless receiving shares as payment of debts (Paragraph h, Art. 10, EOSF).
  - Acquisitions and investments requiring SFC approval include:
    - Direct and indirect capital investments in financial entities contemplated by holding of a financial conglomerate (law 1870, Art. 6).
    - Merger with or acquisition of another financial entity (EOSF, Art. 326 no.1).
    - Investments in capital of financial institutions, insurance companies, capital markets institutions, and foreign subsidiaries (DL 2555, Art. 2.35.3.1.1). Authorization required also for indirect investments through foreign subsidiary when materiality criteria are met.
  - Materiality criteria (DL 2555; Art. 2.35.3.1.3):
    - (i) size of the investment (equal or higher than 10 percent of the capital of the buyer in case of an initial investment—to be calculated over a 12-month period—and 5 percent or higher of the capital when it is an increase of an existing capital investment);
    - (ii) coordination with foreign supervisors (when capital investment is to be made in a jurisdiction with whom the SFC does not have an MoU);
    - (iii) some acquisitions and investments do not require SFC approval but are subject to limitations and can be investigated by the SFC.

*Source: COLOMBIA — INTERNATIONAL MONETARY FUND (excerpts from the supplied chapter).*

### 1. Banks can invest in some corporate and government bonds, but each of those

### 1. Banks can invest in some corporate and government bonds, but each of those investments cannot exceed 10 percent of its paid capital and reserves (with the exception of investments in Colombian government bonds which are not limited; EOSF, Art. 9).

### Investment limits in bonds and equity
- Banks’ investments in some corporate and government bonds cannot exceed 10 percent of its paid capital and reserves.
- Exception: investments in Colombian government bonds are not limited (EOSF, Art. 9).
- Banks may invest in the capital of some nonbanking financial subsidiaries (financial services companies, stock brokers, online deposits and payment companies) provided:
  - those companies are constituted in accordance with the banking regulations; and
  - the shares are not less than 51 percent of the paid capital of the company directly or indirectly (EOSF Art. 119 no.1).
- A cumulative limit for capital investments in nonbanking subsidiaries of up to 100 percent of the sum of capital, reserves and the capital revaluation account minus cumulative losses is set (EOSF Art. 119 no.2).
- These banks’ subsidiaries cannot have investments in the capital of any kind of companies, with the exception of those listed in Art. 110, EOSF (EOSF, Art. 119 no.2).

### Investments in service entities
- Banks can invest in shares of entities whose sole purpose is to provide technical or administrative services necessary for the banking business, upon a general authorization issued by government regulation (DL 2555, article 2.1.7.1.1; EOSF, Art. 110).
- These investments are subject to the cumulative limit of 100 percent of capital.

### Financial corporations and material investments
- Financial corporations (investment bank-type entities) can invest in real sector companies without authorization of the SFC, even when they are a subsidiary of a bank (EOSF, Art. 12).
- Financial corporations can also invest in the capital of banks and nonbanking financial entities; those investments are subject to the 100 percent cumulative limit (EOSF, Art. 119).
- The SFC reports it supervises the material investments of financial corporations and investments which could compromise their financial condition, and that the cumulative limit can be adjusted.
- The SFC may request all necessary information without limitations from banking secrecy laws to assess capital investments (EOSF, Art. 326 no.3).
- The SFC monitors, through different supervision exercises, credit institutions’ investments when they constitute a material part of their business/strategy.

### Observations on the 100 percent cumulative limit
- The 100 percent cumulative limit on banking investments in other credit institutions, nonbanking financial subsidiaries and some real sector companies is noted as rather high in this EC.
- The limit includes investments in other credit institutions, which require prior authorization from the SFC where the investment is equal to or greater than 10 percent of the capital in circulation of the receiving entity or corresponds to an increase in this percentage (penalty of ineffectiveness).
- Consequently, only a fraction of banks’ total investments in other companies is not subject to prior supervisory approval; this fraction varies by bank depending on investment targets.
- Recommendation consideration: Colombian authorities could consider introducing a lower limit for investments not subject to supervisory approval and/or conditioning them to prior supervisory approval.

### Authorization process and evaluation criteria (EC2)
- The SFC has created an Authorization Group to harmonize visions and analysis regarding individual proposals (investments, mergers, acquisitions, fit-and-proper analyses).
- The SFC supervisory team and the Authorization Group can record procedures and processes in the Integrated Management System (SGI) to evaluate authorization requests.
- In practice, applicants may have preliminary discussions with the SFC to present the operation and receive initial feedback; preliminary steps include meetings and workshops with supervisors.

### Formal application requirements and main documents reviewed
- Checklists for: (i) merger of a supervised entity; (ii) acquisition of a supervised entity; and (iii) investments subject to supervisory approval are posted on the SFC website.
- Main documents reviewed in case of a merger or acquisition of a supervised entity include:
  - The requesting letter, which shall include: (i) names of the entities involved in the operation; (ii) number and share of the investment; (iii) indication of whether or not the supervised entity already participates in the company in which the investment is proposed; (iv) value, term and description of the payment associated with the transaction; (v) indication of whether or not the investment is funded partially or totally with borrowing; (vi) detailed explanation of the origin of the resources invested; (vii) indication regarding whether or not the investor already has investments on entities supervised by the SFC; and (viii) indication regarding common interests with other parties involved in the company in which the investment is done;
  - A report explaining the reasons why the investment does not cause any threat to public interest;
  - A report explaining the measures adopted by the investors to protect the small investors (minority shareholders) according with the regulation (EOSF, Art. 62);
  - A report explaining the mechanism to protect financial consumers of the entities involved in the transactions;
  - CVs of the legal representatives and members of the Board;
  - Financial projections for the next five (5) years: financial statements, financial ratios, solvency, and scenario analysis assuming different macroeconomic conditions;
  - Evaluations or manuals of risk management systems, detailing prospective changes and the timetable to implement such changes;
  - Description of changes in the organizational structure and the compliance of dispositions regarding corporate governance;
  - When the investment implies a conglomerate, there are additional requirements.

### Decision-making and supervisory practice
- The Advisory Council issues an opinion and advises the Superintendent regarding approval or rejection of the operation, including major acquisitions.
- Assessors reviewed multiple files: three files of investments in Latin America and two authorizations for a merger between credit institutions.
- Technical studies summarizing SFC analysis and supporting authorization decisions are well structured and typically include:
  1. An assessment of the corporate structure and governance arrangements of the entities involved in the operation;
  2. An analysis of the business plan of the acquiring institution, including financial projections;
  3. An estimation of the impact that the acquisition would have on the compliance with prudential requirements (solvency, legal limits, reserve requirements, and foreign exchange);
  4. An evaluation of the political and economic environment in the countries of operation and of the supervisory regime.

*1colea2022005 - 1. Banks can invest in some corporate and government bonds, but each of those investments cannot exceed 10 percent of its paid capital and reserves (source PDF).*

### 5. An evaluation of the capacity of the acquiring institution to manage the risks of

### 5. An evaluation of the capacity of the acquiring institution to manage the risks of the new acquisition

### Overview of recent authorizations
- Total solicitations: 27
- Authorized: 24
- Conditional Authorization: 1
- Denied: 1
- Desisted: 2
- Source: SFC

### EC3 — Evaluation criteria and supervisory powers regarding acquisitions
- Objective criteria used by the supervisor:
  - Ensure new acquisitions and investments do not expose the bank to undue risks or hinder effective supervision.
  - Ensure new acquisitions/investments will not hinder effective implementation of corrective measures in the future where appropriate.
- Analysis components prepared by the SFC for authorizations (reports/study documents, depending on materiality):
  - Financial implications of the acquisition for the acquiring bank.
  - Impact on compliance with prudential requirements (solvency, legal limits, reserve requirements, and foreign exchange position).
  - Evaluation of host country supervisors, including host country cooperation standards for consolidated and cross-border supervision, access limitations to information, and onsite inspection findings identifying significant differences with Colombian regulation.
  - Identification of all host supervisors and verification of MoUs; identification of supervisors requiring negotiation.
  - Evaluation of the political and economic environment in countries of operation.
  - Evaluation of the capacity of the acquiring institution to manage the risks of the new acquisition.
- Supervisory prohibitions and considerations:
  - Supervisor can prohibit major acquisitions/investments (including establishment of cross-border banking operations) in countries with laws/regulations prohibiting information flows deemed necessary for adequate consolidated supervision (EOSF, Art. 58 and 64).
  - Determination may consider whether the acquisition/investment creates obstacles to the orderly resolution of the bank.

### EC4 — Adequacy of financial, managerial, and organizational resources
- Evaluation enhancements include assessment of:
  - Adequacy of financial and organizational resources.
  - Capability of the acquiring entity to manage risks of the proposed acquisition.
- Information required from acquiring bank:
  - Financial projections for the next five years.
  - Information on compliance with prudential requirements.
  - Evaluations or manuals of risk management systems.
  - Details on organizational structure and compliance with corporate governance dispositions.

### EC5 — Nonbanking activities and financial conglomerates
- General rule: banks cannot invest in shares of nonfinancial entities unless through a subordinate constituted as a financial corporation (investment bank-type), with exceptions noted in EC1.
- Approval process includes assessment of:
  - Risks to which the nonfinancial entity is exposed.
  - Risk management capabilities of the acquiring bank.
- Post-FCL (February 2019) authorities for SFC regarding mixed conglomerates:
  - Request information and perform onsite inspections in entities that are part of a financial conglomerate.
  - Require changes in legal structure of a financial conglomerate if insufficiently transparent and posing a threat to financial stability.
  - Request adjustments in risk policies and exposure limits (intra-group and related parties) when inconsistent with underlying risks or threatening financial stability (decree 1486 (2018)).

### Additional criteria AC1 — Review of other group entities’ major acquisitions
- SFC approves investments of supervised entities and foreign subsidiaries in capital of financial institutions, insurance companies, and capital markets institutions when materiality criteria met; otherwise notification required prior to operation.
- SFC has reviewed acquisitions of financial institutions abroad made by foreign subsidiaries of CFs; scope of review as in EC2.

### Assessment and comments on Principle 7 (summarized)
- Assessment: Compliant
- Comments:
  - SFC performs thorough analyses including financial strength before authorizing acquisitions/investments.
  - Observation: The 100 percent cumulative limit on banking investments in other credit institutions, nonbanking financial subsidiaries and some real sector companies is noted as rather high relative to the EC. However, investments in other credit institutions equal to or greater than 10 percent of capital in circulation require prior authorization; consequently only a fraction of banks’ total investments in other companies is not subject to prior supervisory approval.
  - Recommendation noted: Consider introducing a lower limit for investments not subject to supervisory approval and/or conditioning them to prior supervisory approval.

### Principle 8 — Supervisory approach (key features)
- Assessment: Compliant
- SFC supervisory framework highlights:
  - Risk-based, forward-looking supervisory program with annual supervisory plans per bank identifying significant activities and measuring inherent risks (credit, market, operational, insurance, AML/TF, compliance and strategic).
  - Evaluation of risk and governance management (financial analysis, compliance, risk management, actuarial, internal audit, senior management and Board).
  - Net risk scoring for capital, profitability, liquidity (scoring, direction of risk and importance); classification as N1, N2, or N3 for supervision intensity.
  - Three supervision levels: Conglomerate level, Consolidated level, Individual level.
  - Use of quantitative and qualitative information, analysis of Emerging Risks, business model analysis, and permanent monitoring to identify trends and determine supervisory priorities.
  - Assessment of internal control system based on the three lines of defense and proportionality.

### EC6–EC8 — Resolvability and crisis framework
- EC6: SFC, as resolution authority, assesses resolvability considering risk profile and systemic importance; may require measures including changes to business strategies, structures, procedures; case-specific measures include intensified supervision, monitoring transactions, coordinated resolution options, ordered capitalizations, governance orders, restrictions on operations, deadlines for remedial measures, special audits.
- EC7: Clear framework/process for handling banks in times of stress; stress test results have been used (exercises in 2020) and SFC issues instructions, recommendations, orders for preventive/corrective measures (Article 113 EOSF). Triggers for resolution include failure to recover or circumstances in Article 114 (EOSF); for conglomerates, cross-border disclosure that prevents SFC performing supervisory functions may trigger resolution.
  - SFC created Resolution Mechanisms and Plans Group (GR) in 2018; GR coordinates with Intersectoral Resolution Commission (CRI) and presents resolution study to Financial Superintendent; Advisory Council consulted for resolutions.
- EC8: Constitutional and legal provisions (Article 335) prohibit financial activity without prior authorization; SFC acts on bank-like activities outside regulatory perimeter as illegal exercise of financial activity.

### Principle 9 — Supervisory techniques and tools (key processes)
- Assessment: Compliant
- EC1–EC4 highlights:
  - Appropriate mix of onsite and offsite supervision; supervision plan based on risk profile, planning, onsite and offsite execution.
  - Supervisory plan (ASP) prepared semiannually and approved by Financial Superintendent; ASP details objectives, team members, specialists, number of days, deliverables, and is adjustable.
  - Information sources include regulatory reports, presentations, meetings with banks, reports by BR, home/host supervisors, IMF, rating agencies.
  - Tools: analysis of financial statements, business model analysis, horizontal peer reviews, stress test outcomes, corporate governance analysis.
  - Horizontal reviews conducted on topics including over-indebtedness analysis, cybersecurity management implementation, concentration analysis, and supply chains in residential construction and housing sectors.
- EC6–EC12 highlights:
  - Internal audit evaluated for independence, authority, resources, and audit quality; SFC engages with internal audit and may request annual internal audit plans.
  - Frequent contacts with Boards, senior and middle management; meetings at start/end of onsite exercises; supervisor challenges assumptions in strategies/business models.
  - Formal communication of findings via Official Letter; supervisory reports and, where necessary, mandatory corrective action instruments; follow-up until remediation.
  - SFC may use independent third parties (statutory auditors, external experts) with clear mandates; may order external auditors at ES expense for specialized analyses.
  - Information systems and MIS support the supervisory process; Analytics Division manages data governance; collaborative analytical cells produce reports and validate data.
  - Periodic independent review framework implemented (internal control unit, Supervisory Methodologies division quality reviews, external assessments e.g., Toronto Center 2016).

### Principle 10 — Supervisory reporting (collection, validation, and use of data)
- Assessment: Compliant
- EC1–EC7 key points and mandatory reports:
  - SFC has power to require solo and consolidated information on financial condition, performance, and risks.
  - Major reporting instruments and periodicities:
    - Financial Statements: IFRS standard (quarterly); CUIF (monthly and quarterly, on a solo and consolidated basis).
    - Capital Adequacy: Prior to 2021: Report 110 (monthly/quarterly solo and consolidated); Report 301 (monthly/quarterly solo and consolidated). In 2021 replaced by Report 239 (monthly and quarterly, solo and consolidated). Web service of Capital adequacy of financial conglomerates (quarterly).
    - Credit Risk: Report 341 (Individual report by debtor - Active credit operations) (quarterly); Report 88 (Weekly report - active interest rates) (weekly); Report 453 (Distribution of the balance by product) (monthly); Report 454 (Amounts and number of credits approved or disbursed for vintage analysis) (weekly); Report 536 (Individual Report of Modified and Restructured Active Credit Operations) (monthly).
    - Market Risk: Report 351 (Composition of the investment portfolio) (daily); Reports 468–472 (Valuation of derivative financial instruments) (daily).
    - Liquidity Risk: Report 458 (Contractual cashflows and standard measurement of liquidity risk) (weekly); Report 473 (Interest rate structure of balance sheet) (weekly); Reports 401 and 402 (Information related to temporary liquidity supports (ATL)) (occasionally).
    - Operational Risk: Report 444 (Transactions through distribution channels).
    - Economic Group and Related Parties: Report 261 (Intergroup Consolidated Reciprocal Operations) (quarterly); Report 406 (Report of related parties to the Financial Conglomerate and Operations for the control of aggregate exposure limits) (quarterly); Report 403 (Report on exposure limits and risk concentration between entities of the financial conglomerate and their related parties) (quarterly).
  - Financial conglomerates report foreign subsidiaries on a quarterly basis (main accounts, risk management indicators, credit portfolio). Quarterly IFRS9 portfolio report required (exposures and provisions by portfolio, stage, days in arrears, economic sector) covering Colombian Main Office and subsidiaries.
  - SFC issues reporting instructions and technical standards; IFRS adopted by all credit institutions in 2015.
  - Valuation controls: Fair Value principles (IFRS 13) applied; price vendors supervised; independent price vendor used; valuation methodologies tested/calibrated; internal auditor and statutory auditor involvement required; SFC can require adjustments for prudential reporting.
  - Data collection frequency: daily, weekly, monthly, quarterly, yearly depending on data nature. Ad-hoc and more frequent requests for banks under enhanced monitoring; certification by legal representatives/statutory auditor required where applicable.
  - Supervisory verification: automatic consistency validations in SFC systems; signed and endorsed returns by legal representative, accountant and statutory auditor; on-going monitoring and onsite examinations for validation.
  - Powers to request any relevant information from banks and wider group, irrespective of activities; MoUs and exchanges with other supervisors; updated MoU with Colombian Superintendency of Companies (December 2020) to reinforce oversight of nonfinancial affiliates.
  - Enforcement for timely and accurate reporting: EOSF provisions (Article 208) sanction reluctance or inaccurate information; SFC requests amendments when inconsistencies noted.
  - Analytics Division and collaborative analytical cells manage data governance and produce validation controls; major template review in 2017 derogated more than 40 mandatory templates to refine information.

### Principle 11 — Corrective and sanctioning powers
- Assessment: Compliant
- EC1 — Early engagement and follow-up:
  - SFC raises supervisory concerns early with management/Board; requires corrective measures and written responses; requires Board resolution addressing SFC requirements and action plan; compliance monitored by SFC.
  - Tracking includes periodical reports, statutory auditor certification, and onsite verification. Non-compliance may lead to administrative or sanctioning processes (Articles 209, 210 and 211 EOSF).
- EC2 — Range of supervisory tools:
  - Legal basis: enforcement powers under EOSF, Article 326 and Article 113.
  - Available supervisory tools include:
    - Issue cease-and-desist orders to suspend illegal, unauthorized and unsafe activities.
    - Impose sanctions on companies or persons acting on behalf of the ES.
    - Impose special supervision to closely monitor the ES.
    - Take possession measures to avoid dissipation of assets and normalize operations.
    - Order suspension of unfair competition among ES.
    - Conduct onsite inspections, investigations, require information from individuals/institutions/nonfinancial entities, and inspect irregular exercise of financial activity including in subsidiaries and other companies not under SFC scope if they expose the ES.
    - Require increased provisions and recapitalization, including on a consolidated basis (FH/CF).
    - Impose measures/sanctions including removal of ES directors, legal auditors, or employees for violations or non-compliance with SFC orders.
  - Delegation and approval:
    - Application of supervisory tools delegated to Deputy Superintendent; Financial Superintendent may approve depending on risk situation.
  - Application approach:
    - Gradual and sequential application from preventive to corrective measures; measures formulated considering concentration risk, complexity, systemic importance, and overall risk profile.

*Source: 1colea2022005 - 5. An evaluation of the capacity of the acquiring institution to manage the risks of the new acquisition (PDF).*

### 3.2 Mid Measures before sanctioning regime: Issue cease-and-desist orders to

### 3.2 Mid Measures before sanctioning regime: Issue cease-and-desist orders to

### Purpose of cease-and-desist orders
- Issue cease-and-desist orders to stop unsafe activities.
- Order may address unsafe related parties' operations, inadequate provisions, and in general, activities that inhibit transparency and the ability of the SFC to accurately determine the financial condition of the bank.

### Scope and targets of orders
- Orders may address:
  - unsafe related parties' operations,
  - inadequate provisions,
  - activities that inhibit transparency and the ability of the SFC to accurately determine the financial condition of the bank.

### Additional supervisory powers
- SFC may also remove or suspend management, or statutory auditors, that are not observing their duties in compliance with corporate governance and regulation.

*Source: https://www.imf.org/-/media/files/publications/cr/2022/english/1colea2022005.pdf*

### 3.3 Sanctioning powers: Simultaneously and/or independently from other

### 3.3 Sanctioning powers: Simultaneously and/or independently from other preventive/ corrective measures, the SFC can impose sanctions against the ES/CF, their administrators, statutory auditors, employees, and other related persons to their activity.

### Supervisor powers and early intervention (EC3, EC4)
- The supervisor can act where a bank falls below established regulatory threshold requirements, including prescribed regulatory ratios or measurements, and can intervene at an early stage to require a bank to take action to prevent it from reaching its regulatory threshold requirements.
- The SFC has the powers to take administrative action proactively to prevent a bank from breaching minimum operating indicators, specifically against minimum capital, solvency and/or liquidity, loan provisions, and when the equity indicator is close to the minimum level (loss of equity) or when fraud, embezzlement, failures in administration, and/or resignation of members of the Board of directors of the ES/CF are identified.
- The SFC provides clear prudential objectives and a range of options applied according to the gravity of a situation, including restricting activities, imposing more stringent prudential limits and requirements, withholding approval of new activities or acquisitions, restricting or suspending payments to shareholders or share repurchases, restricting asset transfers, barring individuals from the banking sector, replacing or restricting powers of managers/Board members/controlling owners, facilitating a takeover or merger with a healthier institution, interim management, and revoking or recommending revocation of the banking license.

### Credit risk measures
- SFC may require higher level of loan provisions, perform reclassifications and/or adjustments in the credit risk rating, and suspend the use of internal portfolio rating models and use the SFC reference model. These evaluations and follow-up are done through the supervisory process.
- When the ES/CF does not comply or remains non-compliant, the SFC will issue an Administrative Order to increase the level of provisions.

### Liquidity risk measures
- When not meeting regulatory requirements, the ES must submit an action plan to improve liquidity levels and include options such as reducing loans, increasing capitalization, selling assets, raising loan/deposit ratio.
- Based on risk, the SFC may impose different minimum limits of the IRL indicator.
- If the ES does not comply, the SFC may: prohibit cash market; portfolio placements, disbursements and leasing operations; making investments.

### Solvency measures
- To enhance solvency the SFC may impose operating restrictions and require submission of a capital plan addressing asset sales, reduction or elimination of new lending, issuing subordinated debt or convertible bonds.
- The SFC may limit or prohibit the distribution of profits and increase loan loss provisions.
- An ES must present an adjustment plan with clear actions that permits the ES to solve capital ratios weaknesses within 12 months.
- If the ES does not comply with the plan, the SFC will issue an Administrative Order to raise the capital level. When an ES does not comply with an Administrative Order, the SFC will intervene (Taking possession measures).

### Corrective supervision and resolution powers (EC4)
- Preventive or prudential measures include:
  - Recommendations/orders to correct weaknesses (e.g., risk management, corporate governance, internal control system, AML/CFT risk management).
  - Mandating an increase in provisions.
  - Adopt measures to preserve capital, even above regulatory minimum and limiting dividends.
- Corrective supervision and resolution measures the SFC may require in recovery:
  - Recapitalization.
  - Confirm capital valuation.
  - Mandatory placement of shares without subject to the right of first refusal.
  - Forced sale, assignment, or any other disposition of assets, whether earning or non-earning.
  - Portfolio write-downs.
  - Increase loan provisions.
  - Prohibition of profit distribution.
  - Creation of temporary administration mechanisms with or without legal status.
  - Adoption of specific programs to improve asset recovery.
  - Adjust liability mix.
  - Adjust credit activity, or of the operational or administrative structure.
  - Removal of administrators.
  - Any other measure aimed at producing institutional changes to prevent future financial deterioration and improve efficiency and effectiveness of management.
- Resolution mechanisms and takeover measures:
  - Once an institution has triggered any of the clauses included in Article 114 (EOSF) the SFC must take immediate possession of its assets and business, after receiving the opinion of the Advisory Council of the SFC.
  - Causes for taking possession include: suspension of payments, refusal to open its books and other documents, failing to comply with the SFC instructions and orders, persisting in conducting business in an unlawful or an unsafe manner, capital is below 50 percent of the issued capital, capital is below the minimum capital established in the law, solvency ratio is below 40 percent of the required minimum, severe inconsistencies in submitted information, failure to comply with the recovery plan or progressive deleveraging ordered by the SFC.
  - The SFC has two months to decide whether to liquidate or restore operability, but may order immediate liquidation if circumstances arise.
  - Measures to expedite resolution include: (i) Purchase of assets and assumption of liabilities and Bridge bank; and (ii) Revocation of the authorization certificate of an ES that belongs to a Financial Conglomerate.
  - Liquidation involves transferring the business and assets of the institution to FOGAFIN.

### Sanctions on management and individuals (EC5)
- The SFC can impose sanctions on directors, statutory auditor or employees. Sanctions depend on seriousness or materiality and recurrency of the transgression.
- Administrative sanctions the SFC may impose:
  (a) Warning or call for attention.
  (b) Fines in favor of the National Treasury, whose limit will depend on whether it is a personal sanction or institutional.
  (c) Suspension or disqualification for up to five (5) years.
  (d) Removal of administrators, directors, legal representatives, or Statutory Auditors.
  (e) Closure of representative offices of foreign financial and reinsurance institutions.

### Ring-fencing and measures vis-à-vis parent/subsidiaries/related entities (EC6)
- The SFC may adopt measures to isolate a bank's operation from its parent, subsidiaries, or parallel banking structures if operations may adversely impact the bank or the banking system.
- Possible measures:
  (a) Require fiduciary administration of the assets and business by another authorized institution.
  (b) Require partial or total transfer of assets, liabilities or contracts or sale of commercial establishments to another institution.
  - Install temporary administration mechanisms.
  - Require that management and decision-making be carried out independently of its parent and/or related parties.
- With the issuance of FCL authorization, supervision and sanctioning powers were strengthened for financial conglomerates (HF), including power to require HF to change the structure of the CF, to identify beneficial owners, and to revoke operating authorization of a supervised entity in Colombia that is part of a conglomerate whose controlling entity is in a different jurisdiction when information provided does not allow proper supervision.

### Cooperation, coordination and crisis preparedness (EC7, AC2)
- The SFC is a member of inter-institutional coordination bodies for crisis preparation and management, including the CCSSF (Financial Safety Net) and the CIR.
- CCSSF functions include sharing information, taking coordinated measures, and conducting financial crisis simulation exercises.
- CCSSF members adopted preparedness documents:
  (a) Recovery and Resolution Manuals, prepared by the SFC and FOGAFIN.
  (b) Crisis Protocol, approved by the CCSSF.
  (c) Policy of Crisis Simulation Exercises, approved by the CCSSF.
  (d) Crisis External Communications Protocol, approved by the CCSSF.
- The SFC has signed inter-administrative agreements with nonbank supervisors and entities to share information or supervision experiences, including:
  - Superintendency of Companies
  - Family Subsidy Superintendency
  - Superintendency of Ports and Transportation
  - Solidarity Economy Superintendency
  - Office of National Taxes and Customs (DIAN), the Ministry of Information Technology and Communications (MinTic), and the Financial Information and Analysis Unit (UIAF)
- Law 1328 empowers the SFC to exchange confidential information with foreign supervisory entities, subject to confidentiality commitments by the receiving agency.

### Consolidated supervision, group-wide powers and cross-border oversight (Principle 12 and 13)
- The SFC maintains information on holding companies, banks, banking groups and financial conglomerates, including business lines and ownership up to ultimate beneficial owner.
- EOSF, Article 325, requires the SFC to supervise on a consolidated basis, with emphasis on foreign branches and subsidiaries.
- The FCL established definitions of Financial Conglomerate and Financial Holding Company (HF) and conferred additional supervisory and intervention powers. The HF and its direct financial affiliates are within the SFC’s supervisory perimeter.
- There are 13 financial conglomerates: seven domestic and six with cross-border HF.
- SFC authority includes:
  (a) Regulate appropriate capital levels for financial conglomerates.
  (b) Give instructions regarding risk management standards for subsidiaries.
  (c) Define criteria to identify related parties and limit exposure and concentration of risks.
- Additional FCL powers:
  (a) Give instructions to HF on risk management, internal control, information disclosure and corporate governance.
  (b) Authorize direct or indirect capital investments by HF in financial activity entities.
  (c) Require HF to change conglomerate structure when it hinders disclosure, consolidated supervision or identification of ultimate beneficial owner.
  (d) Revoke operating authorization of a supervised entity part of a conglomerate whose controlling entity is in a different jurisdiction when information provided does not allow proper supervision.
- Since 2019 the SFC has been following implementation of secondary regulation derived from the FCL, including the MGR and exposure and risk concentration limits between intra-group entities and related parties; the SFC expected a final version of the risk profile of financial conglomerates by the end of 2021.
- The SFC imposes prudential standards and collects/analyzes consolidated information on regulatory capital, liquidity exposures, lending limits, large exposures and related parties; information is generally signed by the Statutory Auditor, the accountant, and the legal representative.
- The SFC methodology for financial conglomerates focuses on contagion, concentration, and strategic risks and supervises financial analysis, risk management and corporate governance to assess: the level of risk exposure; the level of compliance with regulation; and the corporate governance to determine the risk profile.
- The SFC conducts supervisory colleges and cross-border cooperation:
  - The SFC has held 22 supervisory colleges in the last 8 years.
  - The SFC conducted the first supervisory colleges for Financial Conglomerates in 2021 involving Grupo Aval Acciones y Valores S.A., Grupo Bolivar S.A., Grupo de Inversiones Suramericana S.A., and Grupo Bancolombia S.A.
  - The SFC has been host supervisor for colleges involving Santander, BBVA, Itaú and Scotia Bank.
  - The SFC has participated in more than 49 training sessions for host supervisors in Central and South America.
- Home-host cooperation and information exchange:
  - The SFC has signed MOUs for exchange of information and cooperation with foreign supervisors and multilateral authorities; MOUs enable exchange of confidential information and conducting onsite inspections of cross-border establishments.
  - In July 2014 the CCSBSO signed an MOU with the Central American Monetary Council (CMCA) for regional financial stability; applies to the SFC as a CCSBSO member.
  - Host and home supervisors participate in onsite inspections according to host jurisdiction regulation; inspection results and reports are shared with host supervisors and incorporated into supervisory processes.
  - The SFC has promoted/participated in more than 49 international internships to share information and practical experiences.
- Crisis cooperation frameworks and protocols:
  - The CCSSF prepared Recovery and Resolution Manuals (SFC and FOGAFIN), Crisis Protocol, Drills Policy, and “External Communications Protocol in Times of Crisis.”
  - MOUs with foreign supervisors describe procedures for crisis management events.
  - The CCSBSO established a joint committee and issued a “Communication Protocol for Crisis Management and Entity Resolution in Problems of the Central American Council of Superintendents of Banks, Insurance and Other Financial Institutions,” approved in 2019, guiding coordination, contact points, minimum required information, local and regional repercussions, and public communication strategy.

### Additional safeguards and governance (AC1, AC2)
- Laws/regulations guard against undue delays in corrective actions; SFC has a risk matrix that includes corruption risk defined to include unduly delaying appropriate corrective actions.
- Law 734 establishes duties/prohibitions for SFC officials as public servants and contemplates faults and sanctions.
- The SFC, as the single supervisory authority for financial and insurance institutions and the stock market in Colombia, does not require MOUs to inform other domestic financial superintendencies, but has signed inter-administrative agreements with specified nonbank supervisors and authorities (listed above) to share information or supervision experiences.
- At international level, Law 1328 empowers the SFC to establish mechanisms for exchanging confidential information with foreign supervisory entities (referenced in BCP 3-EC3).

### Assessments
- Assessment of Principle 11: Compliant. Comment: Broad range of enforcement tools and evidenced by frequent application by SFC.
- Assessment of Principle 12: Compliant. Comment: SFC under the Financial Conglomerates Law has supervision powers over the consolidated entity and individual subsidiaries and affiliates. The supervisory process focuses on understanding the consolidated entity.
- The SFC’s supervisory process includes individual, consolidated and conglomerate layers; risk profiles are evaluated independently in each layer with corresponding supervision strategies.

*Source: 3.3 Sanctioning powers section of the provided IMF chapter PDF.*

### 1.      Operationalize what is established in the Guidelines for the “Treatment and

### 1colea2022005 - 1.      Operationalize what is established in the Guidelines for the “Treatment and

### Cross-border cooperation, crisis preparedness, and supervisory colleges
- Operationalize the Guidelines for the “Treatment and Evaluation of Clusters and Weak Financial Groups,” of the Multilateral Memorandum of Information Exchange and Mutual Cooperation for Consolidated and Cross-Border Supervision among CCSBSO members (MOU 2016).
- Activate cooperation, communication and information exchange mechanisms when an extraordinary event occurs in any of the countries of the region that merits the activation of the protocol for crisis management and resolution.
- Protocol’s Principle 7: supervisory colleges and crisis management structures are different but complementary; the work of financial group supervisors should serve as one of the pillars for crisis management planning.
- CCSBSO’s MOU: signatory authorities permanently share relevant facts of interest for the region’ stability, and allow decisions regarding preventive supervision measures, authority interventions, and reputational threats.

### EC6 — Group resolution planning and information sharing
- Where appropriate, due to the bank’s risk profile and systemic importance, the home supervisor, working with its national resolution authorities and relevant host authorities, develops a group resolution plan.
- The relevant authorities share any information necessary for the development and maintenance of a credible resolution plan.
- Supervisors alert and consult relevant authorities and supervisors (both home and host) promptly when taking any recovery and resolution measures.
- Description and findings re EC6:
  - The SFC works with other Colombian national resolution authorities and relevant host authorities regarding resolution plans.
  - Resolution Plans require that selected entities present an individual resolution plan which must take into account the foreign subsidiaries and all cross-border activity.
  - The SFC requires the RP to be strategic, feasible and current.
  - Through the CBJ, in terms of conglomerates and cross-border relations, the RP must have the following:
    - Organizational and operational structure: The organizational, operational and shareholding structure, including real beneficiaries. If the supervised entity belongs to a CF, in addition to the above, it must include the relationship of all entities belonging to the CF and its hierarchical organization, as well as the structure of the shareholding property.
    - Description of the resolution regimes applicable in the jurisdiction in which each CF’s subsidiary is located.
    - The corporate governance of the ES and those that comprise the CF.
    - Description of the relevant agreements reached with other entities of the CF, including the quantification of exposures, services, funding, guarantees and capital flows, among to terminate said agreements others. Likewise, a description of the existing legal and operational restrictions and, those existing in relation to the free flow of resources between the entities belonging to the CF.
    - Identification and description of the economic, legal, operational, and corporate governance impact of any affected entity belonging to the CF, if the monitored entity enters into a resolution stage and any mitigation mechanisms proposed to reduce the impact.
    - Operations abroad: Description of the cross-border operations of the supervised entity, detailing their nature, sources of financing, main risks and supervisory authorities of said operations, within the scope of this supervision.
    - Resolution strategy: A strategic analysis that describes the procedure to be followed by the monitored entity in the presence of a situation of material financial stress and the entry into a resolution stage, indicating the period required for the execution of each one of the stages that constitute this procedure. This strategic analysis should indicate the way in which the stability of the entities belonging to the CF can be compromised as a result of the implementation of the resolution strategy.
  - Domestically, the resolution authorities coordinate and guide the activities related to the Resolution Plans—RP—through the CIR—a body that also provides guidelines on the preparation, presentation, updating and adjustment of the RP.
  - At the cross-border level, the existence of MOUs allows home and host supervisors to exchange necessary information for the viabilities evaluation of the RP that involves cross-border relations, as well as to alert about situations that may affect the entities’ recovery or resolution.

### EC7–EC10 — Host/ home supervisor responsibilities and cooperation
- EC7: Host supervisor’s national laws or regulations require that the cross-border operations of foreign banks are subject to prudential, inspection and regulatory reporting requirements similar to those for domestic banks.
  - Description and findings re EC7:
    - The SFC as host supervisor requires that the cross-border operations of foreign banks be subject to prudential, inspection and regulatory reporting requirements similar to those for domestic banks.
    - Article 7 of the FCL states that financial conglomerates with a HF constituted abroad must accredit to the SFC that they are subject to a prudential regulation regime and to a comprehensive and consolidated supervision equivalent to the one performed by the SFC.
- EC8: Home supervisor onsite access to local offices and subsidiaries to facilitate assessment; home supervisor informs host supervisors of intended visits.
  - Description and findings re EC8:
    - MOUs facilitate the exercise of the comprehensive and consolidated supervision of the CFs. Consequently, those authorities have onsite access in Colombia to the subordinates of their supervised banking groups, upon fulfillment of the obligations contained in the MoU.
    - As home supervisor, the SFC informs the host supervisors about planned onsite visits scheduled to cross-border operations of the Colombian banks, and the results of those visits are shared with the host supervisor.
- EC9: Host supervisor supervises booking offices consistent with internationally agreed standards; no shell banks permitted.
  - Description and findings re EC9:
    - The SFC, as host supervisor, supervises booking offices in a manner consistent with internationally agreed standards.
    - SFC has the legal capacity to authorize the constitution and licensing of Booking Offices and Representation Offices of Financial Organizations and Foreign Reinsurance, and to exercise inspection, surveillance, and control over those structures.
    - The CBJ defines the general instructions that Representative Offices in Colombia must follow, including:
      - The authorized activities;
      - The obligations as a commercial entity; and
      - The duty of professional advice (give a complete information in relation to the products and services that it promotes, indicating that these are provided by the foreign institution, among others).
    - Licensing procedure includes verification of entities’ advertising activities, limited to products and services authorized by the SFC.
    - Opening a representative office, or executing a correspondent agreement to offer products, or services does not exempt foreign entities from having to comply with the Colombian regulations on public offering of securities.
    - The current regulatory framework does not allow the constitution of Shell Banks, and these have not been presented de facto.
- EC10: Supervisor that takes consequential action based on information from another supervisor consults with that supervisor, to the extent possible, before taking such action.
  - Description and findings re EC10:
    - The SFC coordinates with domestic and foreign supervisors, before taking consequential action based on information received from another supervisor.
    - This commitment is included in the MOUs subscribed by the SFC.
- Assessment of Principle 13: Compliant
  - Comments: The SFC actively engages in collaboration with domestic and foreign authorities.

### Principle 14 — Corporate governance (EC1–EC4)
- Principle 14: The supervisor determines that banks and banking groups have robust corporate governance policies and processes covering strategic direction, group and organizational structure, control environment, responsibilities of the banks’ Boards and senior management, and compensation. These policies and processes are commensurate with the risk profile and systemic importance of the bank.
- EC1: Responsibilities of Board and senior management; supervisor guidance on expectations.
  - Description and findings re EC1:
    - Colombia has a broad regulatory framework for corporate governance, established through a wide range of laws and decrees implementing the laws, SFC circulars, and a voluntary corporate governance code - Country Code.
    - Articles 71, 72, 73 (EOSF) establish aspects related to the bank ́s organization such as the responsibilities, obligations and suitability of the Board and senior management members.
    - 2014: SFC issued External Circular 028, which published the New Code of Best Corporate Practices (Country Code). Stock-issuing banks are required to report annually on their status regarding the Code. Once the bank adopts a Recommendation it will become compulsory incorporated in their bylaws.
    - The Country Code Implementation Report is a fundamental tool to evaluate corporate governance items in the Integrated Supervisory Framework.
    - Boards are responsible for: reviewing and approving corporate strategy, monitoring its compliance; monitoring management performance; developing a risk policy and overseeing the development of a risk management function; setting performance objectives and key performance indicators; establishing the implementation and supervising the performance of the Internal Control Systems; and reviewing and approving major capital expenditures and remuneration.
    - Board of financial holding companies must ensure transparency of the organization’s structure and that its strategic guidelines are complied with throughout its structure.
    - The SFC monitors policies, procedures, and methodologies established by the ES, through supervising processes (onsite and offsite) and dialogue with managers.
- EC2: Regular assessment of corporate governance and remediation of deficiencies.
  - Description and findings re EC2:
    - The Integrated Supervisory Framework guidelines provide directions on how to verify whether the bank has adequate corporate governance practices and policies, their relevance, and their effective implementation.
    - The guidelines address:
      1. Mandate.
      2. Organizational Structure.
      3. Resources.
      4. Methodologies and Practices.
      5. Reports.
      6. Supervision of the Board of Directors and Senior Management.
    - The SFC evaluates performance of the Board and Senior Management using onsite and offsite supervision and the significant activities assessment; reviews reports presented to those organs; includes comments in meeting minutes; conducts interviews with Board or Senior Management; analyzes independence, decision levels and reports.
    - Deficiencies and recommendations are communicated to the ES.
- EC3: Governance of nomination and appointment of Board members; committees.
  - Description and findings re EC3:
    - Governance structures and processes for nominating and appointing Board members are reviewed to determine appropriateness for the bank and banking group.
    - Supervisors verify Board members have adequate skills, diversity, and knowledge applicable for the size, complexity, and risk profile of the bank.
    - Board members must take an oath of office at the SFC pledging to diligently manage the bank's business, comply with legal obligations, and with rules, orders and instructions issued by the SFC.
    - SFC Guidelines for the evaluation of the Board of Directors recommend an odd number of Board members, appropriate academic profiles and experience, and a proportion of independent members (non-executive).
    - Selection, approval, reappointment, and replacement of Board members must be supported by internal regulations that establish profiles and qualifications and processes of nomination and removal.
    - Audit, risk oversight, and remuneration committees with experienced non-executive members are required for issuing banks.
    - SFC considers as good practice committees such as Appointments and Remunerations, and Corporate Governance; if a bank does not consider one necessary, functions must be assigned to others or assumed by the Board itself.
- EC4: Board members’ duties of care and loyalty; legal obligations and prohibited conducts.
  - Description and findings re EC4:
    - Under EOSF and Commercial law, "managers" (including Board members) must act (i) in good faith, with loyalty and with the diligence of a “good businessman”; and (ii) in the interest of the company bearing in mind the interest of the shareholders.
    - Commercial Code obligations for managers include: (i) protect confidentiality of proprietary information; (ii) refrain from undue use of insider information; and (iii) except otherwise authorized by the shareholders, refrain from participating in activities competing with the company or acts resulting in a conflict of interest.
    - EOSF legal obligations for managers to refrain from the following conducts:
      1. Concentrate the risk of assets above the legal limits.
      2. Perform operations with shareholders, related parties or people connected to them, above the legal limits.
      3. Invest in companies or associations in unauthorized amounts or percentages.
      4. Facilitate, endorse, or execute any practice that has as purpose or effect tax evasion.
      5. Fail to provide reasonable or adequate information to the public, users or client that allow them to take informed decisions.
      6. Fail to maintain accounts according to the applicable regulations, or to maintain it in such way that it is impossible to know in due course the statement of assets and liabilities or the statement of the operations conducted or to submit to the SFC false, inexact, or misleading accounting information.
      7. Inappropriate use of reserved information.

*International Monetary Fund — COLOMBIA (chapter excerpts).*

### 8.   Fail to fulfil the obligations and functions imposed by law, or incur in

### 8.   Fail to fulfil the obligations and functions imposed by law, or incur in conducts that are prohibited, constitute impediments or inabilities related to the exercise of their activities, among others.

### EC5 — Board approves and oversees strategic direction, risk appetite and strategy
- Legal framework: Financial regulation, commercial law, and the Country Code delineate Board responsibilities regarding strategy, risk appetite and strategy.
- SFC procedures require Board responsibility to:
  - Approve the objectives, strategies and business plans and supervise their implementation by Senior Management.
  - Approve the implementation and supervise the suitability of the Risk Governance Structure.
  - Approve the design and implementation and supervise the performance of the Risk Management Control Function.
  - In conjunction with Senior Management and the Risk Management function, define the entity's risk appetite considering the company's long-term objectives, exposure to risk and the ability to manage it effectively.
  - Supervise and ensure the implementation of the Risk Appetite Framework, and its articulation and dissemination through the Risk Appetite Statement.
  - Supervise the company's adherence to the policies and limits established in the Risk Appetite Framework.
  - Review and approve, at least once a year, the policies, and practices for managing significant risks, and ensure that they are being applied.
  - Approve the implementation and supervise the performance of the Internal Control Systems.
  - Promote corporate culture and values.
  - Approve policies and procedures to manage and disclose conflicts of interest.
- Code of Conduct, Section 4.1: establishes the control environment as foundation of the SCI; effectiveness depends on competent personnel and instilling integrity and control awareness throughout the organization.
- Footnote: “Risk appetite” definition and treatment (footnote 56).

### EC6 — Fit-and-proper standards, succession, and oversight of senior management
- Boards must:
  - Oversee senior management’s execution of Board strategies and monitor performance against established standards.
  - Establish fit-and-proper standards when selecting senior management and maintain succession plans.
- Supervisory Guide responsibilities for the Board:
  - Periodically determine number of Senior Managers, qualifications, knowledge, skills, experience and level of dedication.
  - Appoint the president, members of Senior Management, and those responsible for control functions.
  - Set performance and remuneration standards consistent with long-term strategic objectives and risk levels.
  - Supervise performance of Senior Management.
  - Ensure existence of succession plans.
- Country Code recommends Nomination and Remuneration Committee and disclosure of remuneration and economic benefits to Board members, CEO, and Auditor.
- Supervisory practices: interviews with Board and Senior Management, verification of minutes, internal processes, leadership succession plans, to strengthen corporate governance and issue instructions.

### EC7 — Board oversight of compensation systems and alignment with prudent risk-taking
- Supervisory Guide requires inspectors to evaluate whether the Board has a clear compensation system for management consistent with long-term strategic plans and risk appetite.
- MAR policies must establish adequate incentives aligned with prudent risk-taking, long-term objectives and financial strength of the CF entities.
- Parent/controlling entity’s Board responsibility: establish adequate corporate governance and ensure appropriate management and control policies consistent with structure, business, and risk profile.
- Supervisor role: determine existence of such policies and check effective application; SFC can require resolution of deficiencies (Section 4.7 of the Guideline).
- Country Code Recommendations 18.19, 18.21 and 18.22: Nomination and Compensation Committee supports Board on appointment and compensation of Board members and senior managers.
- SFC reviews Country Code Implementation Reports and requests clarifications where remuneration policies are unclear.

### EC8 — Board and senior management understanding of operational structure and non-transparent structures
- Supervisory procedures require review of Board policies related to Risk Governance Structure and Risk Management Policies, assessing whether they grant transparency in ES Governance.
- Supervisor evaluates performance by:
  - Checking effectiveness of policy communication.
  - Verifying Board oversight that all risks are managed.
  - Interviewing Board members and reviewing communication to committees.
  - Reviewing Board minutes, internal audit reports and onsite discussions.
- Where group structure impedes adequate information disclosure, SFC has requested structural changes; issuance of FCL strengthened power to require FH changes if structure prevents adequate disclosure, consolidated supervision or identification of real beneficiaries.

### EC9 — Power to require Board composition changes
- Article 326 (EOSF): Board members, administrators, legal representatives, reviewers, Prosecutors, etc., must assume positions before the SFC and meet objective requirements and subjective qualities established by the SFC, and maintain these qualities for the duration of service.
- When a Board member does not fulfil duties, SFC options:
  - Moral suasion: dialogue with owner or Board President requesting removal.
  - Personal sanction process under Article 209 (EOSF): (i) removal; or (ii) disqualification.
- Removal may be requested under "Vacancy" numeral 4 of Article 73 of the EOSF for failure to attend Board meetings for a period superior to three months.

### AC1 — Notification requirement for material information affecting fitness and propriety
- CBJ provision (sub-section 1.4.1.1.7, Number 1, Chapter II, Title IV Part I): supervised entities or official responsible must inform the SFC immediately of any situation known that affects the conditions and requirements considered by the SFC at time of Board member or senior management possession.
- Board responsibilities:
  - Periodically determine qualifications, knowledge, skills, experience and dedication of directors.
  - Evaluate performance of functions; SFC recommends annual assessment of Board collectively and individually using self-assessment or external advisors.
- Upon becoming aware of material and bona fide information that may negatively affect fitness and propriety, the bank must follow procedure to replace that member and initiate authorization process for the new member before the SFC.

### Assessment of Principle 14
- Assessment: Compliant
- Comment: SFC issued corporate governance guidance applicable to all banks to ensure Board and Senior Management establish risk assessment systems, risk appetite statements, Board committees and address duty of loyalty and ethics. Country Code is voluntary but SFC requires annual reporting on adoption and extent.

### Principle 15 introduction and EC1–EC2 — Risk management process (start)
- Principle 15: supervisor determines banks have comprehensive risk management process (Board and senior management oversight) to identify, measure, evaluate, monitor, report and control or mitigate all material risks timely and assess adequacy of capital and liquidity relative to risk profile and market and macroeconomic conditions; includes contingency arrangements and recovery plans where warranted; process commensurate with risk profile and systemic importance.
- EC1 — Board-approved risk management strategies and risk appetite:
  - SFC reviews risk management from CF to ES individual level; supervision at three levels: conglomerate, consolidated and individual.
  - Risk Management Framework (MGR) requirements for CF include:
    - Encouraging organizational culture of risk awareness in the CF;
    - Defining and monitoring exposures and concentration of risks among CF entities and related parties;
    - Defining risk appetite with exposure limits consistent with business plan, risk profile and financial soundness.
  - NS (supervisory teams) assess compliance via onsite reviews, discussions with management and staff, reviewing audit reports, sampling internal control activities, Board discussions and minutes review.
  - NSs determine ES/CF have integrated risk management framework with policies, procedures, exposure limits, and risk appetite.
  - Senior management responsibilities assessed through onsite/offsite reviews: (i) implementation and monitoring of policies and risk strategy; (ii) defining measures when limits are close to breach; (iii) keeping Board informed on monitoring results.
  - Regulatory framework requires risk management frameworks for credit risk, market risk, operational risk, liquidity risk, and AML/CFT addressing: (i) risk governance structure with assigned responsibilities; (ii) policies and procedures for identifying, assessing, mitigating, controlling, monitoring and reporting all risks with prior Board approval; (iii) internal limits aligned with risk strategy.
  - Banks required to implement internal control systems promoting risk control culture and business continuity plans with corrective and preventive actions.
  - Financial Conglomerate Law broadened scope from “legal entity” to “comprehensive supervision approach.”
- EC2 — Comprehensive bank-wide risk management policies and processes:
  - SFC requires Board-approved comprehensive and consolidated risk management system for all exposures, considering proportionality, nature of business, size and systemic importance.
  - Banks must develop specific policies, methodologies, and controls to:
    - (i) identify current and potential risks, including country risk;
    - (ii) measure, control and monitor risks within tolerable thresholds approved by the Board;
    - (iii) ensure (i) and (ii) are implemented by senior management and risk management function.
  - HF must identify and assess exposure levels of all subsidiaries with respect to same counterparty, business line, geographic location, economic sector, related parties, service providers, shared service centers, and natural disasters that may generate material change in CF risk profile.
  - SFC assesses risk management function features: (i) effectiveness for anticipating, identifying and measuring potential risks in dynamic environments; (ii) whether its oversight is consistent with Board-approved risk appetite statement.
  - Supervision considers specific criteria (continued in source).

*Source: 1colea2022005 - 8.   Fail to fulfil the obligations and functions imposed by law, or incur in conducts that are prohibited, constitute impediments or inabilities related to the exercise of their activities, among others.*

### 1. The Board has a defined risk culture, which includes the determination of a

### 1. The Board has a defined risk culture, which includes the determination of a

### Key principles and expected practices
- 1. The Board has a defined risk culture, which includes the determination of a risk appetite from which the policies, guidelines and risk limits are defined.
- 2. Proactively updates its policies, practices, and limits in response to changes in the industry and in the EC's strategy, business activities and risk appetite.
- 3. Integrates its policies, practices, and limits to the day-to-day business activities, to the entity's strategy and to the capital and liquidity management policies.
- 4. Quantitative risk modelling aimed at strengthening procedures for identifying, monitoring, and mitigating risks, including early warning systems, back testing techniques and robust data bases.
- 5. Monitors risk exposures against approved limits and ensures that material deviations are dealt in a timely manner.
- 6. Proactively and effectively addresses events that may arise due to internal or external shocks.
- 7. Makes regular and exhaustive reports to the Board (or its committees) and AG on the effectiveness of the risk management processes and ensures problems are identified and escalated to the corresponding decision-making instances in a timely manner.
- 8. Participate effectively in the Board of directors’ committees.
- 9. Ensure unity of language and understanding between the risk management function and the business areas in the day-to-day activities.

### Supervisory proportionality and ratings
- The assessment acknowledges the proportionality principle; ES/CF are rated in accordance with their nature, scope, complexity, and risk profile.
- Rating levels correspond to 4 buckets: (i) strong; (ii) adequate; (iii) needs improvement; or (iv) weak.
- Each ES at the corresponding supervision level (individual and/or consolidated) must perform an assessment and prospective analysis to mitigate possible negative consequences in normal operations and to report to the HF.
- The NS must rate the risk management functions performed by each ES, considering effectiveness in exercising functions and responsibilities in accordance with the nature, scope, complexity and risk profile of the CF.
- The NSs determine supervisory strategies and priorities according to the supervisory importance of the ES/CFs and their risk profile.
- There are 3 levels of importance for ES: High (N1), Medium (N2) and Low (N3), which means the SFC applies proportional supervisory effort; supervisory effort is more intense in Banks with N1 of importance than with N2 or N3.

### EC3 — Documentation, review, communication, and exceptions
- Supervisor determines that risk management strategies, policies, processes and limits are:
  - (a) properly documented;
  - (b) regularly reviewed and appropriately adjusted to reflect changing risk appetites, risk profiles and market and macroeconomic conditions; and
  - (c) communicated within the bank.
- Exceptions to established policies, processes and limits receive prompt attention and authorization by appropriate management levels and the bank’s Board where necessary.
- Description and findings re EC3:
  - Through the NS the SFC assesses compliance with the Risk Management Systems supported by supervisory framework criteria.
  - At a minimum, the HF must have:
    - (i) Risk Management Framework (MGR) handbook that includes policies, procedures, methodologies, exposure limits and functions assigned to managerial bodies; and
    - (ii) periodic reports that allow the Board and senior management to establish and monitor the risk profile of the Bank and parent and evaluate coherence with risk appetite, capital levels, business plan and market conditions, and the measures implemented per the early warning system.
  - All limits, policies, procedures, and methodologies must be reviewed at least once a year and updated when necessary.
  - For consolidated and individual supervisory levels, the SFC requires credit institutions to adopt and document policies (including limits), processes, and procedures for adequate risk management and timely decision-making and information provision.
  - The Board of the ES/CF must define exceptional situations under which approved limits can be breached and any other body authorized for this purpose.
  - The NS evaluates the coherence of policy exceptions and deviations against risk profile and applicable standards, hierarchical approval levels, monitoring, controls and communication to AG and JD.

### EC4 — Board and senior management information and understanding of risk
- Supervisor determines that Board and senior management obtain sufficient information on, and understand, the nature and level of risk being taken and how this relates to capital and liquidity; they regularly review and understand implications and limitations (including measurement uncertainties) of risk management information.
- Description and findings re EC4:
  - The SFC requires periodic reports from the risk management supervision function to allow Board and senior management to understand and monitor capital and liquidity levels and the ES/CF risk profile and its consistency with risk appetite, business plan, complexity and market conditions.
  - The NS verifies that corporate governance bodies perform in-depth review and evaluation of commercial objectives, strategies, events and transactions that may pose significant risks, aligning objectives with controls and assessing consistency of risk exposures with defined tolerance.

### EC5 — Internal capital and liquidity adequacy processes
- Supervisor determines banks have appropriate internal processes for assessing overall capital and liquidity adequacy in relation to risk appetite and risk profile; supervisor reviews and evaluates these assessments and strategies.
- Description and findings re EC5:
  - HFs must have a risk appetite statement consistent with appropriate capital levels and risks (contagion, concentration and strategic). The framework must be reviewed at least once a year or when circumstances require further review.
  - NSTs consider CFs; HFs determine a basis for technical and adequate equity determination of the CF and the bank and make corresponding deductions to avoid double gearing.
  - NS verify via MAR assessment that banks have integrated principles and measures guiding determination of amount and types of risks to assume; MAR is forward-looking and consistent with business plan, capital and liquidity internal thresholds, remuneration system and risk management framework on a business-as-usual basis.
  - NS verify development and permanent monitoring of MAR components (capacity, tolerance and risk appetite) are consistent and effectively disclosed across the entity—Board (approves), senior management (proposes and implements), risk management functions (identify, measure, manage and mitigate), operational management (operations and reports)—in accordance with the risk appetite monitoring guide.

### EC6 — Models governance, understanding limitations, and validation
- Supervisor determines banks comply with supervisory standards on model use; Boards and senior management understand limitations and uncertainties of model outputs; banks perform regular and independent model validation and testing; supervisor assesses whether model outputs appear reasonable.
- Description and findings re EC6:
  - The SFC evaluates internally developed risk management models to ensure compliance with minimum regulatory standards; models must be approved by ES/CF governing bodies.
  - Model performance must be internally evaluated by the risk management function through back-testing techniques.
  - For CFs, NS assesses whether HF designs procedures, methodologies, controls, and early warning systems for managing CF risks (concentration, contagion and strategic) and that the Board through the Risk Committee supervises implementation.
  - Each risk has guidelines to standardize quantification methodologies; NS oversees them as a whole and places recommendations/supervisory measures to the CRO regarding comprehensive and consolidated risk management.

### EC7 — Information systems and reporting adequacy
- Supervisor determines banks have information systems adequate under normal and stress conditions for measuring, assessing and reporting exposures across all risk types, products and counterparties; reports reflect risk profile and capital/liquidity needs and are timely and suitable for Board and senior management.
- Description and findings re EC7:
  - NS reviews banks’ technological infrastructure, information systems and data architecture, and the reports produced.
  - Banks must have a reporting system in accordance with size, nature and complexity, and develop procedures for information storage guaranteeing confidentiality, security, quality, availability, integrity, consistency and consolidation.
  - NSs evaluate that the risk management function prepares periodic reports for Board and senior management to monitor operations and compliance with the risk appetite statement and business plan.
  - NSs assess whether the risk management function uses risk measurement and monitoring tools to provide early warning indicators on trends and adverse conditions that could negatively affect risk profile, capital, liquidity and profitability.

### EC8 — New products, major changes and Board oversight
- Supervisor determines banks have adequate policies and processes to ensure Boards and senior management understand risks inherent in new products, material modifications and major initiatives; such activities require Board or specific committee approval.
- Description and findings re EC8:
  - Board is responsible for approving policies, procedures, methodologies, and controls for managing risks to which business models/lines are exposed.
  - SFC requires banks to have a risk committee to monitor compliance with the risk appetite statement, risk profile, capital, liquidity and profitability levels; advise the Board on operations, events or activities including entry into new markets that may affect risk profile or deviate from thresholds, business plan or risk appetite.
  - NSs verify adequacy of policies and practices to report exposure analysis results timely, accurately and understandably to Board and senior management (entity risks, stress test or scenario analysis results, risk-return relationships, risk-appetite and limits).

### EC9 — Risk management function resourcing, independence, and reporting
- Supervisor determines banks have risk management functions covering all material risks with sufficient resources, independence, authority and Board access; duties are segregated from risk-taking functions and report directly to Board and senior management; risk management is regularly reviewed by internal audit.
- Description and findings re EC9:
  - Risk Management function required to:
    - Set clear functions and responsibilities and interlinkages with Board, senior management, risk committee and internal audit.
    - Have enough authority and hierarchy to carry out functions and responsibilities independently and access records, information and personnel of the ES/CF.
    - Demonstrate independence from operational management; risk manager is not in charge of any control function or business unit.
    - Have necessary physical, human, economic and technological resources and suitable qualifications and competencies of human capital.
    - Deliver timely, accurate and understandable reports to JD and AG with results of risk exposure assessments, stress test results, vulnerabilities (including environmental conditions) and recommendations for decision making according to ES/CF risk profile.
  - NSs assess whether Internal Audit methodologies and practices establish effectiveness and efficiency of the risk management function and suitability of such results.

### EC10 — CRO requirement for larger and more complex banks
- Supervisor requires larger and more complex banks to have a dedicated risk management unit overseen by a Chief Risk Officer (CRO) or equivalent; removal of CRO should be recorded and, for issuers, changes must be disclosed.
- Description and findings re EC10:
  - NSs assess that large banks (individual and consolidated level) with complex/diverse structures, issuers or systemically important have a Chief Risk Officer Manager (CRO).
  - SFC requires Board decisions, including appointment and removal of the CRO, be recorded in meeting minutes.
  - SFC maintains frequent contact with senior management and risk units to discuss reasons for changes or removals of risk committee members including the CRO.
  - ES which are securities issuers must reveal to the market appointments, changes or removals of senior management or Board members.

### EC11 — Standards for key risk types and noted deficiencies
- Supervisor issues standards related to credit risk, market risk, liquidity risk, interest rate risk in the banking book, and operational risk.
- Description and findings re EC11:
  - The SFC has issued regulations with instructions for proper risk management.
  - Deficiencies are noted at the individual CP for liquidity, interest rate risk, concentrations.

### EC12 — Contingency arrangements and recovery planning
- Supervisor requires banks to have appropriate contingency arrangements as part of risk management to address risks that may materialize and actions for stress conditions; for entities with risk profile/systemic importance, contingency arrangements include robust and credible recovery plans; supervisor assesses adequacy and seeks improvements if deficiencies identified.
- Description and findings re EC12:
  - The NS, in evaluating the risk management function, verifies that risk positions are controlled against approved limits and ensures that once thresholds are exceeded, any potential breach is dealt with in a timely manner.

*IMF staff summary based on the supplied chapter content.*

### Chapter 28 of the CBCF (bottom-up stress testing framework)

### Chapter 28 of the CBCF (bottom-up stress testing framework)

### Stress testing framework and governance
- Credit institutions must perform stress tests at two levels:
  - Internal stress tests for financial planning, covering a three-year horizon of projections.
  - Stress tests submitted to the supervisor under two macroeconomic and financial scenarios: the baseline and adverse.
- The latest exercise required ECs to perform a reverse stress test considering two main scenarios and to adopt recovery actions in terms of liquidity, capital, and profitability when needed.
- The SFC runs a top-down stress test to assess resilience of financial institutions against potential shocks.
  - The CCSSF carries out stress test exercises every six months; frequency increases to a quarterly basis when macro-financial conditions require it (as happened during the Covid-19 outbreak).
  - The top-down approach has allowed the SFC to: (i) prioritize supervision; (ii) require EC to strengthen their internal stress test framework; and (iii) design measures to withstand the shock.
- Coordination and information-sharing:
  - Coordination between Supervisory units and the SFC’s Resolution Group aids assessment of stress outcomes and identification of entities that may give rise to vulnerabilities or face resolution; monitored regularly when needed.
  - Results of stress exercises are presented to the CIR to assess whether recovery and resolution mechanisms may be required and to assess triggering thresholds of resolution plans, considering systemic importance and market environment.

### Bank requirements, recovery planning, and internal processes
- Based on EC scenarios, banks must:
  - Forecast main business lines and financial statements within a three-year horizon.
  - Assess recovery capacity in terms of credit, market and liquidity risk.
  - Identify financial vulnerability in terms of capital, profitability and liquidity.
  - If the adverse scenario triggers financial difficulties or regulatory breaches, submit a recovery plan detailing actions required to mitigate the risks.
- The SFC is drafting a regulation to formalize synergies between ICAAP, ILAAP, stress testing framework and recovery and resolution plans.
- NS supervision responsibilities:
  - Supervise that the risk management function measures, controls and monitors risks of the CF in line with tolerable thresholds approved by the JD.
  - Identify situations that could prevent the HF from fulfilling its strategic plan so the Board can act effectively.

### EC13 — Supervisor assessment of stress testing programs (requirements and findings)
- EC13 expectations:
  - Supervisor requires banks to have forward-looking stress testing programs commensurate with risk profile and systemic importance, integrated into risk management and decision-making, and used to assess capital and liquidity levels.
  - Scope of assessment includes whether the program:
    - (a) promotes risk identification and control on a bank-wide basis;
    - (b) adopts suitably severe assumptions and addresses feedback effects and system-wide interaction between risks;
    - (c) benefits from active involvement of the Board and senior management;
    - (d) is appropriately documented and regularly maintained and updated.
  - Supervisor requires corrective action if material deficiencies are identified or if results are not adequately taken into account.
- NS must assess Board approval and monitoring of policies/procedures for significant risk management, including stress test scenarios and contingency plans. Among aspects assessed:
  - Whether scenarios are consistent with the bank’s risk tolerance.
  - Whether scenarios are suitable for portfolios and include severe shocks and/or periods of prolonged recession; include high market volatility or liquidity shocks if relevant.
  - Whether frequency of stress tests supports timely decision-making.
  - Whether scenarios include situations in which the bank’s viability may be compromised.
  - Level of participation of the JD and AG: Board has final responsibility; AG implements, administers and supervises the program and ensures adequate contingency plans.
- After review, NS provides ES with recommendations for corrective or improvement measures.

### EC14 — Internal pricing, performance measurement and new product approval
- EC14 expectations:
  - Supervisor assesses whether banks appropriately account for risks (including liquidity impacts) in internal pricing, performance measurement and new product approval for significant business activities.
- Description and findings re EC14:
  - SFC assesses internal pricing elements including:
    - Characteristics: product/service type, target market, jurisdictions, comparative advantages.
    - Funding: resource gathering strategy, whether product/service is a source of funds, pricing process.
    - Strategic planning.
  - NS assesses effectiveness of Financial Analysis function to:
    - (i) carry out independent assessments of ordinary course of business; and
    - (ii) produce accurate, timely, understandable, independent operational and financial reports of business lines and key performance indicators to the AG and the JD.

### Additional criteria (AC1)
- Supervisor requires banks to have policies and processes for assessing other material risks (e.g., reputational and strategic risks).
- The FCL requires assessment of strategic, concentration and contagion risks.

### Assessment summary and supervisory initiatives
- Assessment of Principle 15: Largely Compliant.
  - Broad risk management framework in place; SFC actively monitors and evaluates risk management.
  - Areas for improvement: liquidity, interest rate risk, concentrations, related-party transactions.
  - SFC guidance is “principles-based” and lacks benchmarks or minimum requirements for clear supervisory expectations.
- SFC issued a draft regulation (SIAR) to integrate current risk management systems into a single framework aligned with Basel Corporate Governance principles; SIAR to be applied individual and consolidated, commensurate with risk appetite, nature, size, complexity, risk profile and business model. Final regulation expected to be published in 2021.

### Principle 16 — Capital adequacy (EC1 and EC2 findings)
- EC1: Laws/regulations require banks to calculate and observe prescribed capital requirements and define qualifying components of capital.
  - DL 2555 (2010) sets capital rules including:
    - CET1 ratio of 4.5 percent,
    - Tier 1 ratio of 6 percent,
    - Total capital ratio of 9 percent (DL 2555, Art. 2.1.1.1.1 and following).
  - Reporting requirements:
    - Mandatory monthly reporting for capital ratios calculated at individual level.
    - Mandatory quarterly reporting for capital ratios calculated at consolidated level (CBCF, chapter 13.16).
  - Non-compliance penalties:
    - Mandatory fine of 3.5 percent of the capital shortfall for each period of non-compliance (up to a limit of 1.5 percent of the required capital).
    - Banks must explain reasons and corrective measures to SFC.
    - If capital shortfall cannot be solved in less than two months and significantly hinders operational capability, a corrective action plan must be set up and supervised by the SFC (CBCF, chapter 13.16).
  - Qualifying components of capital follow three elements derived from Basel III: CET1, Additional Tier 1 and Tier 2.
    - CET1 instruments include paid-in shares, stock dividends, stock surplus, legal and occasional reserves, cash advances of less than 4 months aimed at increasing capital, irrevocable subordinated debts held by the FOGAFIN to foster issuer’s capital base, retained earnings, other comprehensive income (OCI), and qualifying non-controlling interests.
    - Decree 1477 (2018), in force January 2021, modified CET1 calculation further aligning with Basel III (suppression of irrevocable donations and adjustment account for foreign exchange, inclusion of all current and retained profits, and OCI). Deviations remain in treatment of non-controlling interests and recognition of cash advances and liabilities held by FOGAFIN as CET1.
    - Additional Tier 1 and Tier 2 qualification criteria broadly aligned with Basel III; Tier 2 includes general provisions up to 1.25 percent of credit RWAs.
- EC2: For internationally active banks the definition of capital, risk coverage, calculation method and thresholds are not lower than applicable Basel standards.
  - Since 2012 Colombia has been gradually aligning prudential regulations with Basel III; no difference between internationally active and non-internationally active banks regarding capital requirements.
  - Deductions from CET1 (DL 2555, Art. 2.1.1.1.11): cumulated and current losses, investments in capital/convertible/subordinated bonds of local and foreign non-consolidated financial institutions exceeding 10 percent of bank’s CET1 (subject to exceptions), net deferred tax asset, intangible assets, own shares, non-amortized value of pension liabilities determined by an actuarial calculation, and asset revaluation account.
  - Decree 1477 (2018) further aligned CET1 deductions with Basel III (e.g., full deduction of goodwill and intangible assets); deduction of non-amortized value of pension liabilities instead of net pension assets deviates from Basel III but deemed not material by authorities.
  - Risk coverage:
    - Decree 1421 (2019), in force January 2021, requires regulatory capital to be held against credit, market and operational risks (DL 2555, Art. 2.1.1.1.2).
    - Operational risk capital derived from Basel III standardized approach with adjustments:
      - Only two marginal coefficients of 12 percent and 15 percent are in force for the business indicator component instead of the three marginal coefficients in Basel III SA (12 percent, 15 percent and 18 percent).
      - The range to which the lowest marginal coefficient applies is set at less or equal to Col$3 billion (given prevailing COL/EUR exchange rate, more conservative than international standard less or equal to EUR 1 billion).
      - Some simplification in internal loss multiplier computation introduced without materially distorting results.
  - Credit risk — RWAs and deviations from Basel III standardized approach:
    - Decree 1477 (2018) introduced new rules aligning risk weighting of assets with Basel III standardized approach; some exposures receive less conservative risk weighting:
      - Cash deposits in entities supervised by the SFC and in foreign financial entities receive a risk weighting of 0 percent, irrespective of credit rating, whereas Basel III SA imposes a 20 percent floor; cash deposits account for 2.7 percent of credit institutions’ total assets as of June 2021.
      - Exposures to the Colombian government in local and foreign currencies receive a risk weighting of 0 percent, although Colombia’s credit rating (BBB- or BB+ in May 2021, depending on the credit ratings agency) would normally warrant a 50 percent or a 100 percent risk weighting; Colombian government debt denominated in foreign currencies accounts for less than 0.1 percent of credit institutions’ total assets as of June 2021.
      - Assets bought to comply with mandatory investments receive a risk weighting of 0 percent, irrespective of issuer rating; these account for about 1.2 percent of banks’ assets in June 2021.
      - Exposures to a clearing house set at 0 percent, whereas Basel framework sets a 2 percent risk weight for exposures to qualifying CCPs; this exposure is 0.1 percent of total assets.
      - Securitization exposures risk weights are less granular and overall less stringent than External Ratings-Based Approach; securitized assets account for 0.1 percent of total banking portfolio as of June 2021.
    - Other deviations:
      - Exposures to non-central government public sector entities rated between A+ and A- receive a credit risk weight of 30 percent against 50 percent in Basel III; this exposure is 0.1 percent of credit institutions’ total assets as of June 2021.
      - Unrated exposures to multilateral development banks receive a credit risk weight of 100 percent against 50 percent in Basel III; authorities noted credit institutions do not have exposures to unrated multilateral development banks as of June 2021.

*Source: Chapter 28 of the CBCF (bottom-up stress testing framework) — 1colea2022005*

### 0.4 percent of credit institutions’ total assets as of June 2021;

### 1colea2022005 - 0.4 percent of credit institutions’ total assets as of June 2021

### Deviations from Basel and estimated impact
- Specialized lending exposures rated BB- or below receive a credit risk weight of 100 percent against 150 percent in Basel III; according to Colombian authorities, this exposure represents 0.3 percent of credit institutions’ total assets as of June 2021.
- Equity securities that are not deducted from CET1 receive a credit risk weight of 100 percent against 400 percent (for speculative unlisted equity exposures), 250 percent (for all other equity holdings) or 100 percent (for investments in commercial entities below some thresholds) in Basel III; according to Colombian authorities, this exposure represents 0.5 percent of credit institutions’ total assets as of June 2021.
- Data obtained suggest that, taken individually, most of the above-mentioned deviations may not have a material impact on the level of credit RWA.
- Colombian authorities estimate that the aggregate effect of such deviations from the Basel standards represents a reduction in total capital ratio of credit institutions of less than 1 percent.
- Decree 1477 (2018) recognizes guarantees and other risk mitigation techniques as a way to reduce the EAD.
- Overall, according to the SFC, the new regulatory regime is expected to decrease the average amount of banks’ RWAs between 10 percent and 16 percent, respectively at consolidated and individual basis.

### Mandatory capital ratios and buffers (thresholds)
- Since January 2021, four capital adequacy ratios are mandatory:
  - a CET1 ratio of at least 4.5 percent;
  - A Tier 1 ratio of at least 6 percent;
  - A total capital ratio of at least 9 percent; and
  - A leverage ratio of at least 3 percent.
- Credit institutions have to comply with those minimum capital ratios both on an individual and consolidated basis (DL 2555, Art. 2.1.1.1.4).
- Decree 1477 (2018) introduced two additional buffers derived from the Basel III capital framework:
  - A capital conservation buffer of 1.5 percent; and
  - An additional buffer of 1 percent for DSIBs; the list of DSIBs is published every year on the SFC website.
- The capital conservation buffer is set at 1.5 percent, against 2.5 percent in the Basel framework, to compensate for the highest total capital ratio implemented in Colombia (9 percent) as compared with the one prescribed by the Basel framework (8 percent).
- No countercyclical buffer has been introduced in Colombia because credit institutions supervised by the SFC must already calculate and set aside countercyclical provisions to cover potential future losses on their loan portfolio (CBCF, chapter 2, Art. 1.3.4.1.). Those countercyclical provisions amounted to Col$4,098,243 million in December 2020 (i.e., 10.3 percent of total credit provisions or 0.8 percent of total loan portfolio).
- A transition regime is laid down for the gradual implementation of the Additional Tier 1 and buffers rules over a three-year period (Jan 2021–Jan 2024).
- In the end of the transition period, capital requirements for a DSIB will be as follows:
  - CET-T1 (in %) Minimum 4.5; Conservation buffer 1.5; Systemic risk buffer 1.0; Total 7.0
  - T1 (in %) Minimum 6.0; Conservation buffer 1.5; Systemic risk buffer 1.0; Total 8.5
  - T1 + T2 (in %) Minimum 9.0; Conservation buffer 1.5; Systemic risk buffer 1.0; Total 11.5
- Banks that will not have sufficient buffers will have to submit an adjustment plan to the SFC. Until full compliance is reached, there will be some limitations on the distribution of earnings and dividends, the suspension of bonus payment or any other discretional payment to related parties.

### Supervisor powers and actions (EC3)
- The supervisor has the power to impose a specific capital charge and/or limits on all material risk exposures, if warranted, including in respect of risks that the supervisor considers not to have been adequately transferred or mitigated through transactions (e.g., securitization transactions) entered into by the bank.
- Since December 2015, the SFC has had the power to impose a specific capital charge based on the assessment of the risk profile of banks (DL 2555, Art. 2.1.1.1.15). Two complementary processes can be used:
  - 1) SFC risk-based evaluation of adequacy of supervised entities’ capital, considering risk appetite framework and risk profile. Assessment is based on published criteria and an internal assessment guideline. Possible actions include requiring an additional level of capital.
    - The SFC leverages supervisory tools including: (i) periodic reports of minimum capital ratios on individual and consolidated basis; (ii) results of annual bottom-up stress tests carried out by supervised entities based on scenarios designed by the supervisor; (iii) results of onsite inspections; and (iv) results of the top-down stress test developed together with the Central Bank and presented to the CCSSF.
    - Based on this, the SFC has ordered in the last three years an increase of capital to two supervised entities, so that they achieve a capital adequacy ratio of 12 percent.
  - 2) The internal capital adequacy assessment process (ICAAP) of supervised entities. The ICAAP is at an early stage and may leverage on the annual stress tests performed since 2015. The SFC required each supervised entity in 2019 to define its own scenarios which would result in incompliance with their capital and liquidity targets. The SFC postponed the 2020 stress test exercise until July 2021 due to the Covid-19 crisis.
- Both on-balance sheet and off-balance sheet risks are included in the calculation of prescribed capital requirements. Off-balance sheet items are included after the application of a credit conversion factor of 10 percent, 50 percent or 100 percent (DL 2555, Art. 2.1.1.3.5).

### Capital adequacy framework and systemic importance (EC4)
- The prescribed capital requirements reflect the risk profile and systemic importance of banks in the context of the markets and macroeconomic conditions in which they operate and constrain the build-up of leverage in banks and the banking sector.
- Laws and regulations provide for adequate capital standards. The total capital ratio should be at least of 9 percent, which is stricter than the minimum one laid down by the Basel III capital standards even if there are some differences in how it is calculated.
- Colombian capital standards have been further strengthened with the introduction of a leverage ratio in January 2021 and will be better differentiated based on the systemic importance of banks, with an additional capital buffer gradually required for DSIBs over a three-year period (from Jan. 2021 to Jan. 2024).

### Use of internal assessments and models (EC5)
- Standardized approaches are mandatory for the measurement of capital requirements against credit, market and operational risks, unless the bank has developed internal models for calculating credit risk provisions and/or measuring market risk exposures which have not been objected by the SFC (CBCF, chap. 2 & 21). Currently, no credit institution use an internal model for these purposes.
- The use of internal models is subject to a prior approval of the SFC, whose assessment relies on a set of documents and on minimal quantitative and qualitative criteria defined by the SFC. For market risk, required documents include model descriptions, internal model for estimation of value at risk, back testing results for a period of six months, and information on people in charge of measuring and controlling risks.
- The SFC has the power to require the use of the standard model when quantitative criteria are not complied with or when the internal model does not adequately measure the market risk to which the supervised entity is subject.

### Forward-looking capital management and stress testing (EC6)
- Credit institutions shall maintain adequate capital levels to cover their current and potential risks exposure related to their business activities and strategic plan (DL 2555, Art. 2.1.1.1.15). The SFC may impose additional capital charges following a forward-looking approach.
- Entities must perform stress tests at two levels (CBCF, chap. 28):
  - (i) internal stress tests that entities must use within a three-year horizon of projections and use them for their financial planning; and
  - (ii) stress tests required by the supervisor (bottom-up scheme), in accordance with two macroeconomic and financial scenarios, the baseline and the adverse. Based on these scenarios, credit institutions must project their balance sheet within a three-year horizon, assess resilience in terms of credit, market, and liquidity risks, and identify financial vulnerability in terms of capital, profitability and liquidity.
- If a credit institution identifies financial difficulties from the adverse scenario, it must submit a recovery plan that incorporates actions to mitigate the risks that give rise to any potential breach to regulatory minimums.
- The MIS framework requires the SFC to assess credit institutions’ risk appetite statement, internal capital adequacy assessment and stress test, and the synergies across these three elements. Areas of special focus include:
  - (i) the stress test used to assess capital adequacy and capacity to meet capital requirements and internal targets;
  - (ii) Risk tolerance measures;
  - (iii) Internal Capital Plans;
  - (iv) The ability to gather capital to meet current and projected needs; and
  - (v) Contingency plans in case of stressed macroeconomic scenarios.
- When deficiencies are identified, the SFC might request measures including: supervisory recommendations, meetings with management, plans to overcome lacking practices, and direct requirements to Board members to implement best practices in capital management.
- The SFC can require contingency capital plans such as selling loan portfolios, stopping new loans, issuing subordinated debt or convertible bonds.
- The SFC is planning to reshuffle its regulation to promote a more inclusive approach between the stress testing framework, ICAAP/ILAAP, and contingency, recovery, and resolution plans.

### Additional criteria for non-internationally active banks and group allocation (AC1, AC2)
- AC1: For non-internationally active banks, capital requirements, including the definition of capital, the risk coverage, the method of calculation, the scope of application and the capital required, are broadly consistent with the principles of the applicable Basel standards relevant to internationally active banks.
  - Capital requirements are the same for both internationally active banks and non-internationally active banks. The only difference is an additional risk buffer for domestic systemically important banks (namely Bancolombia, Banco de Bogotá, Davivienda, and BBVA).
- AC2: The supervisor requires adequate distribution of capital within different entities of a banking group according to the allocation of risks.
  - Capital requirements are set both on an individual and consolidated basis. Financial conglomerates must have sufficient capital to bear the risks to which they are exposed (FCL, Art. 5). Supervised entities of a CF should comply with the applicable regulatory capital requirements on an individual basis.

*Source: 1colea2022005 - 0.4 percent of credit institutions’ total assets as of June 2021; PDF chapter/section.*

### 2. On a consolidated basis, financial conglomerates shall maintain eligible

### 2. On a consolidated basis, financial conglomerates shall maintain eligible

### Assessment of Principle 16
- Largely Compliant

### Comments on alignment with Basel III and implementation timeline
- Since 2012, Colombia has been gradually aligning its prudential regulations with the Basel III capital standards.
- Convergence culminated in 2018 with the following changes to the Colombian regime:
  - (i) introduction of new Tier 1 and leverage ratios calibrated as per Basel III;
  - (ii) introduction of a capital conservation buffer of 1.5 percent and of an additional buffer of 1 percent for DSIBs;
  - (iii) modifications to the list of instruments accepted as regulatory capital to further harmonize them with the international framework; and
  - (iv) modifications to the risk weights of assets to make them more sensitive to their credit risk.
- The majority of the changes entered into force in January 2021. However, Tier 1 ratio and capital buffers ratios will be progressively implemented over a three-year period (Jan. 2021−Jan. 2024).
- Operational risk was introduced in 2019 and entered into force in January 2021.

### Remaining differences and recommended actions
- Adjustments and discretionary choices made when translating Basel III into Colombian regulation may reduce capital requirements and improve regulatory solvency ratios of Colombian banks. These include:
  - i) lighter risk weighting of some assets, such as:
    - a zero risk-weight for cash deposits in financial entities supervised by the SFC;
    - Colombian government debt (both denominated in local and foreign currencies);
    - mandatory investments on financial institutions backed by the government, irrespective of the credit rating of the issuers;
    - exposures to a clearing house;
  - ii) recognition of minority interests above minimum capital requirements as eligible capital for entities subject to prudential standards equivalent to the Colombian ones.
- Recommendation: complete the alignment of regulatory capital requirements with the relevant Basel III standards.

### SFC supervisory powers and capital actions
- Since 2015, the SFC has the power to increase prudential requirements for individual banks and banking groups based on their risk profile.
- In the last three years, as part of its regular monitoring, the SFC has ordered an increase of capital to two supervised entities so that they achieve a capital adequacy ratio of 12 percent.
- The assessment of the SFC is based on published criteria and an internal assessment guideline.
- Recommendation: complement the guideline to give supervisors clear guidance on supervisory actions to consider when predetermined triggers or thresholds are reached, depending on supervised entity activities. One possible action is to require an additional level of capital where warranted.

### Internal Capital Adequacy Assessment Process (ICAAP) and related frameworks
- The ICAAP of credit institutions is currently at an early stage, at least for nonsystematic banks.
- A pilot exercise was launched in 2019 requiring each supervised entity to define scenarios that would result in incompliance with its capital and liquidity targets.
- Due to the Covid-19 crisis, the SFC postponed until July 2021 the submission of the stress testing results.
- Based on submissions, the SFC is expected to identify best practices and main shortcomings to enhance regulation.
- Recommendation: SFC should proceed with its draft regulation as planned to formalize the need for supervised entities to have a comprehensive management approach linking risk appetite framework with ICAAP, ILAAP, stress tests, and recovery and resolution plans. Supervised entities should be required to periodically report the results of those exercises to the SFC.

### Principle 17 — Credit risk (intro)
- Principle 17 requires that the supervisor determines banks have an adequate credit risk management process that takes into account risk appetite, risk profile and market and macroeconomic conditions, covering the full credit lifecycle (underwriting, evaluation, ongoing management), including counterparty credit risk.

### EC1 — Laws, regulations or the supervisor require banks to have appropriate credit risk management processes
- The credit risk framework and regulation are contained in Chapter II of the CBCF.
- Main purpose: provide principles, general criteria and minimum parameters that credit institutions (CI) must incorporate to design, develop, and apply an adequate credit risk management process (SARC).
- The SARC is the comprehensive reference framework for credit risk (CR) management and covers all stages of the credit cycle (granting, monitoring and recovery, including portfolio normalizations), as established in Section 1.2, Chapter II, CBCF.
- SARC main elements:
  - Policies and processes regarding the credit risk (CR) bank evaluation, rating, controls, and mitigation;
  - Organizational structure that assures a rightful segregation of functions (duties) and resolutions of potential conflict of interests;
  - Loan-provisioning system and methodologies to estimate and assess (quantify) expected losses.
- Loan provisioning system: Law 1314 of 2009 sets principles on accountability and financial information. Decree 2784 of 2012 requires Colombian issuers and financial institutions to follow IFRS standards. Since January 2015, those institutions have fully adopted IFRS, including IAS 39 and in January 2018 IFRS9 was adopted for consolidated financial statements. For unconsolidated financial statements, institutions must follow the credit risk framework and regulation contained in Section 1.3.4, Chapter II of CBCF.
- SARC covers current and prospective elements for assessing borrowers’ risk through the cycle and enables banks to establish risk limits and set provisions.
- Banks must permanently classify and reclassify portfolios by risk, considering objective conditions, sectorial factors, macroeconomic environment and prospective factors; each bank defines frequency and scope of monitoring (Sections 1.3.1.3 and 1.3.1.5, Chapter II, CBCF).
- Within SARC policies, banks must define collateral requirements and technical criteria for valuation (Section 1.3.1.4, Chapter II, CBCF).
- Sections 1.3.2.3.1 and 1.3.2.3.2, Chapter II, CBCF, require incorporation of macroeconomic and sectorial conditions in underwriting and monitoring stages.
- SFC monitors compliance and, via the Integrated Supervisory Framework, developed templates and guides defining relevant aspects for analysis, evaluation, documentation, and construction of banks’ risk profile.
- Supervision (onsite and offsite) evaluates credit risk appetite framework, reasonableness relative to bank size and risk profile, indicators for monitoring and control, policies and actions related to limits and early warning signs, and validation that the risk appetite framework has management and Board approval.
- For subsidiaries, supervision emphasizes the degree of direction and coordination from parent companies in policies, risk appetite guidelines, measurement and control, and transfer of best practices and methodologies.

### EC2 — Board and senior management responsibilities
- Supervisory review starts with bank submissions on credit risk management system and current policies; Board minutes are reviewed for approvals and involvement.
- SFC activities evaluate the role of the Board and Management regarding responsibilities and functions (Section 4.1 Chapter XVIII of CBCF).
- Supervisors evaluate controls and monitoring to determine whether products align with business lines and Board-defined risk appetite.
- Supervisory validation includes organizational structure for credit risk management, roles and responsibilities of management and Board in defining and approving the risk appetite framework, strategic business lines and risk management systems and policies.
- The "Board of Directors Guide" and "Senior Management Guide" provide guidance for supervisors to validate mandate, processes, tools and performance of controls; review scope may include coordination of credit risk lines with strategy, capital, and liquidity and their regular review and update.

### EC3 — Policies and processes to establish a controlled credit risk environment
- Regulatory requirements:
  - Banks must adopt a risk management system with policies and processes for CR management; senior management and internal control must adopt mechanisms for adequate implementation (Article 1.3.1, Chapter II of CBCF).
  - The CR management process must address organizational structure, adequate staff, internal policies to prevent/sanction conflicts of interest, and control of information use and reserve.
  - Board of Directors must approve SARC content and updates.
- Underwriting, monitoring and portfolio restructuring:
  - SFC requires continuous evaluation of credit risk at underwriting and throughout the loan cycle (Article 1.2, Chapter II of CBCF).
  - Supervisors validate approval requirements and delegation levels consistent with exposure and risk, through on-site and off-site activities.
  - Section 1.3.1.3 requires banks to consider borrower characteristics and risk tolerance (risk appetite framework) during underwriting.
  - Article 1.3.2.3.1 specifies minimum parameters: borrower’s risk profile, payment ability, loan financial conditions, collateral, sources of payment, and macroeconomic conditions.
  - Paragraph b, Article 1.2.2.3.1 requires methodologies for segmentation and discrimination of credit portfolios.
- Collateral:
  - Collateral is considered in estimation of expected losses; banks must have policies and procedures for classification, valuation and updating (see CP 18).
- Information and reporting:
  - “Risk Management Guide,” Paragraph b, Article 5.1: supervisors consider whether banks submit detailed, timely reports to the Board and Senior Management including exposures, stress tests and/or scenario analysis, risk-return analysis, risk appetite and limits.
  - Supervisors request examples of reports, objectives, frequency, and decisions taken; onsite processes validate automation and quality of information used to monitor exposure and credit quality indicators.
- Limits and exceptions:
  - Banks must set credit limits consistent with risk appetite, profile and capital strength and inform relevant staff regularly.
  - “Risk Management Guide” criteria for evaluating the Risk Management function include risk control culture, regular updating of policies, integration to daily activities.
  - Supervision evaluates suitability of credit limits, follow-up and monitoring to control compliance and identify early warning signals.
  - Board must assign responsibilities for credit risk management; supervision reviews exception granting processes, policies, limits, information systems, reports and compliance validation mechanisms.
- Internal models and validation:
  - Section 1.3.2.3.2 specifies minimum conditions for internal models and methodologies; methodologies must be reviewed at least twice (2) a year and tested under extreme scenarios (Stress Testing).
  - Supervisors evaluate consistency and maintenance of internal models, technical criteria, back testing results and documentation.
  - Offsite exercises in 2020 validated incorporation of new information and variables into rating methodologies to capture Covid-19 macroeconomic and sectorial conditions (e.g., portfolio measures applied by banks, emerging sectoral risks, variables measuring changes in debtor income).

### EC4 — Monitoring total indebtedness and significant risk factors
- Paragraph c, Article 1.3.2.3.1, Chapter II of CBCF, obliges CI to analyze current and expected repayment capacity, considering at least:
  - Borrower’s solvency (including global exposure level, quality and composition of assets, liabilities, equity, and contingencies), and historical and current payment history.
  - Borrower’s or financed project’s cashflow, considering all possible sources of risks and performing scenario analysis using macroeconomic variables (such as interest rates, exchange rates, GDP growth).
  - Financial and nonfinancial risks analysis, including market risk associated to possible “mismatches” of currencies, credits lifespan, interest rates, and contagion, legal, operational, and strategic risks.

*Italic: IMF assessment content from the provided PDF chapter.*

### Chapter II of CBCF

### Chapter II of CBCF

### Credit underwriting, follow-up, and monitoring
- The whole CR analysis must be done not only to debtors, but also to co-debtors, guarantors, joint debtors and in general, to any individual or legal entity acting or that may act directly or indirectly as a debtor.
- Follow-up process implies continuous monitoring and rating of credit transactions according to the underwriting process.
- Minimum information in follow-up: financial information or alternative information that allows knowing the financial situation of the borrower or financed project, sectorial and macroeconomic information that might affect debtors and can lead to potential changes in the loans’ conditions, as established in Article 1.3.2.3.2 of Chapter II.
- Supervision activities (on site or off site according to the annual supervision plan) evaluate methodologies and practices used by banks in credit underwriting, monitoring and recovery, including validation of all criteria defined by regulation to analyze borrower's payment ability.
- Cross-sectional analyses:
  - Measure debtors’ level of financial burden.
  - Identify variables with greatest impact on high financial burdens.
  - Generate alerts for banks with segments more sensitive to financial burdens.
  - Partnered with banks; some banks required to support their methodologies and indicators.
  - Best practice identified: use of differential levels of payment ability requirements when defining exposure granted to clients according to clients’ level of financial burden.

### Conflicts of interest and approval of major exposures (EC5, EC6)
- EC5: The supervisor requires that banks make credit decisions free of conflicts of interest and on an arm’s length basis.
  - Numeral 6, Article 98 of EOSF: directors, legal representatives, auditors, and any staff member with access to privileged information must abstain from transactions that give rise to a conflict of interest.
  - The SFC will impose appropriate penalties in accordance with the general sanctioning regime when a bank allows transactions that give rise to a conflict of interest.
- EC6: The supervisor requires that credit policy prescribes that major credit risk exposures exceeding a certain amount or percentage of the bank’s capital are to be decided by the Board or senior management; same for exposures that are especially risky or not in line with mainstream activities.
  - Article 122 of EOSF: transactions with managers and shareholders who own five percent (5 percent) or more of the subscribed capital require unanimous vote of Board members attending the meeting to be approved. Applies also to transactions with spouses and relatives within the second degree of consanguinity, affinity, and civilian.
  - SFC evaluates whether the Board opines on risk exposure and suitability of credit risk management when banks launch new products, enter new business lines or new markets.
- Assessment note: Requirements explicitly address conflicts of interest and arms’ length for related parties (EC5); however, they do not require all transactions to be at arm’s length, not just related parties. A threshold is not established as to large loans that must be approved by the Board (EC6).

### Supervisory access to information and personnel (EC7)
- EC7: The supervisor has full access to information in the credit and investment portfolios and to bank officers involved in assuming, managing, controlling and reporting on credit risk.
- Section 2.4.2, Chapter II of CBCF: instructions about management and availability of information corresponding to borrower’s credit files and databases, including qualitative or quantitative information supporting models and methodologies for underwriting, follow-up, and recovery. This information must be available to the SFC.
- Annex 1 of the CBCF requires CI to periodically submit standardized information allowing access and detailed analysis on credit and investment assets.
- The SFC has full access to staff responsible for managing, controlling, and reporting on credit risk and can request additional information, meetings, presentations and interviews during onsite or offsite supervision.
- Section 8, Article 326, EOSF empowers SFC to promote information exchange with foreign supervisors, enabling confidential information sharing with confidentiality commitment by the receiver.

### Standardized templates and reports (samples of regular submissions)
- Relevant templates submitted regularly by CIs to the SFC include formats numbered:
  - 88 Interest rates; disbursements and fundraising
  - 281 Active and liabilities Accounts of financial statements - weekly
  - 322 - 323 Loan exposures and fundraising by municipality
  - 341 Debtor Report – Individual Credit Loans
  - 343 Sale and/or Purchase of credit loan and/or write-off of uncollectable loans
  - 351 Investment portfolio
  - 453 Portfolio exposures per product
  - 454 Amount and number disbursements loans by product
  - 455 Disbursements of mortgage loan for vintage analysis
  - 456 Disbursements of microcredit loan for vintage analysis
  - 457 Disbursements of personal loan for vintage analysis
  - 466 Credit Card
  - 507 Write-off of uncollectable loans or loans recovery
  - 527 EPR (stress tests)
  - 536 Modification and restructuring of loans
- In March 2018, a quarterly report was developed for supervision of the portfolio’s main subsidiary accounts, required only from banks that consolidate financial statements.

### Stress testing and EPR (EC8)
- EC8: The supervisor requires banks to include their credit risk exposures into their stress testing programs for risk management purposes.
- SFC implemented EPR whose main objectives are:
  - (i) identify risks that may affect the bank ́s business viability;
  - (ii) facilitate the adoption of timely decisions when required;
  - (iii) examine the bank ́s consistency of capital, liquidity, assets, and liabilities.
- Chapter XXVIII of the CBCF establishes objectives, characteristics, responsibilities, and reporting duties related to EPR tests. Annex 1 provides guidelines and scenarios.
- Article 4.1 of Annex 1 details minimum aspects to be considered in development of such tests with respect to credit risk.
- Through supervision, SFC evaluates consistency of credit risk information, forecasts and assumptions used in tests. Supervision results give feedback to banks to strengthen tests and serve as input in financial planning and risk management.

### Assessment of Principle 17
- Overall assessment: Compliant.
- Rationale and evidence:
  - SFC places significant emphasis on credit risk and performs onsite verification of credit files and bank analysis of borrowers’ credit capacity.
  - Assessors were provided cases demonstrating file reviews and changes required of the bank on loan classifications.
  - Requirements explicitly address conflicts of interest and arms’ length for related parties (EC5); however, not all-inclusive for all transactions to be at arms’ length, not just related parties.
  - A threshold is not established as to large loans that must be approved by the Board (EC6).

### Principle 18 — Problem assets, provisions and reserves: EC1 to EC4 findings
- Principle 18 objective: supervisor determines that banks have adequate policies and processes for early identification and management of problem assets, and maintenance of adequate provisions and reserves.
- EC1: Laws, regulations or the supervisor require banks to formulate policies/processes for identifying and managing problem assets and require regular review of problem assets and asset classification, provisioning and write-offs.
  - Regulation related to portfolio classification and provisioning for individual financial statements is contained in Chapter II, CBCF. For consolidated financial statements, banks must follow IFRS9 standards.
  - Regulation requires CIs to formulate policies/processes to identify/manage doubtful assets and timely manage delinquent/nonperforming loans to maximize recoveries, including:
    - execution of collection tasks and those responsible;
    - evaluation of loan modifications and restructuring;
    - management of goods received as payment;
    - decision of loan write-offs.
  - Chapter II, CBCF contains minimum policies/processes for restructuring loans; policies must consider at least:
    - (i) requirements or conditions for a loan to be restructured;
    - (ii) mechanisms to identify and monitor restructured loans;
    - (iii) staff responsible for restructuring decisions;
    - (iv) mechanisms of borrowers’ disclosure about conditions for access to restructuring.
  - Processes must consider at least:
    - (i) conditions to establish actual deterioration of borrower's payment ability;
    - (ii) criteria for establishing restructuring financial viability;
    - (iii) rating of restructured portfolio;
    - (iv) identification and monitoring of restructured loans.
  - Modified loans subject to special monitoring until borrower makes regular and effective principal and interest payments for:
    - 9 consecutive months for microcredit loans;
    - 12 months for other portfolios (commercial, consumer and mortgage loans).
  - Modified loans with more than 30 days in arrears must be classified as restructured loans.
  - CI’s portfolio must be classified and provisioned from the moment loans are granted; follow-up stage requires continuous monitoring and rating updates consistent with underwriting.
  - Special monitoring/automation includes indicators: volume of modified and restructured portfolio by modality/product/sector, percentage of modified portfolio with early arrears, proportion of restructured portfolio with arrears greater than 30 days, due default rating.
  - Supervisory validations include that modifications apply only to debtors with early arrears and temporary impairment; curation times per regulation; migration rules to restructured; past-due disclosure for restructured portfolio with arrears greater than 30 days; and that portfolio normalization is not regular practice.
  - Recovery stage: rating must be consistent with risk analysis. Restructured loans have special rating rules.
  - Internal alignment process: bring loans of same type to same debtor to highest risk category and review credit behavior with other entities.
  - Individual provisions for mortgage and microcredit portfolios correspond to certain percentages given according to the rating (risk category), considering collateral’s value.
  - General provisions are 1 percent of the total value of mortgage and microcredit loans.
  - COLGAP standard provides minimum prudential aspects for estimating expected loss: i) evaluation of potential debtors’ risk profile since granting; ii) determination of default probabilities for a 12-month horizon; iii) integral evaluation of debtor's risk profile including loan’s length of arrears, economic sector, macroeconomic context, payment ability and financial information.
  - Annex 2, Chapter II, CBCF: rules for rating restructured portfolio with special characteristics such as business reorganizations (insolvency proceedings).
  - Annexes 3 and 5, Chapter II, CBCF: “Commercial Portfolio Reference Model” and “Consumption Portfolio Reference Model” provide classification rules for commercial and consumption portfolios as follows “AA,” “A,” “BB,” “B,” “CC," and “Default.”
  - Provisions for commercial and consumer portfolios cover expected losses via a formula considering:
    - (i) estimated probability of default for a 12-month period by segment and portfolio rating;
    - (ii) exposure at default;
    - (iii) loss given at default, considering collateral type and days after default.
  - Provisioning policies must consider countercyclical provision adjustments to build higher provisions in credit quality improvement periods.
  - Since implementation until Q1 2020, six CIs used countercyclical provisions to cover increased provision expenses. Between March and October 2020, nine CIs decumulated their countercyclical provisions.
  - Accounting recognition of losses is based on portfolio write-off; write-off must be approved by the Board of Directors per Chapter V, CBCF; write-off status does not relieve CI from continuing collection efforts.
- EC2: Supervisor determines adequacy of bank’s policies/processes for grading/classifying assets and provisioning; reviews may be conducted by external experts with supervisor reviewing external work.
  - SFC evaluates portfolio classification, rating processes, and correct constitution of provisions on an ongoing basis via onsite/offsite inspections or considering evaluations by external auditors (statutory auditor) and CI’s Internal Audit.
  - External auditors must report findings to SFC in collaborative duty, particularly relevant aspects regarding SARC management identified and communicated to CI management.
  - Year-end consolidated financial statements must have an opinion from the Statutory Auditor, including compliance verification with IFRS9 accounting and disclosure guidelines.
  - Title 6, D2555 gives SFC authority to order hiring of external audits paid by CI when:
    - When specialized analysis is required for technical reasons regarding CI operations or businesses.
    - When situations require specialized studies as they involve risks affecting public interest or stability, security and confidence of financial system and/or interests of financial consumers.
    - When situations require specialized study involving risks/circumstances affecting stability, security and public confidence related to a particular CI.
  - SFC has on rare occasions required CIs to hire external auditors for technical specialized opinions.
  - SFC evaluates Internal Audit performance and follow-up of results to establish deviations from SFC instructions and CI management definitions.
  - At consolidated level, supervision focuses on validating communication of guidelines and good practices regarding risk management from head office to branches and subsidiaries.
- EC3: Supervisor determines that bank’s classification/provisioning system takes into account off-balance sheet exposures.
  - Regulation (Section 1.3.3, Chapter II, CBCF) includes contingent rights as part of asset exposure.
  - For solvency margin under Basel III, contingencies (irrevocable/revocable credit letters, bank acceptances, guarantees, approved undisbursed loans, etc.) are included using conversion factors defined in regulation.
  - For IFRS9 expected losses, SFC performed cross-sectional analyses; supervisors identified incorporation of off-balance sheet assets when computing expected losses (e.g., suspended interests, bank guarantees, credit card quotas, revolving credit quotas).
  - Supervisors evaluated how internal models incorporate macroeconomic conditions on determination of risk and provisions.
- EC4: Supervisor determines banks have appropriate policies/processes to ensure provisions and write-offs are timely and reflect realistic repayment and recovery expectations, taking into account market and macroeconomic conditions.
  - SARC must include clear and precise policies and procedures defining criteria for CIs to cover credit risk, with management and control areas adopting special policies and mechanisms for adequate coverage through a system of provisions.

*Source: Chapter II of CBCF (excerpt).*

### Chapter II, CBCF).

### Chapter II, CBCF)

### Off‑balance sheet exposures & provisioning
- Two types of off‑balance sheet exposures: those that can be unilaterally cancelled by the bank (based on contractual arrangements and therefore may not be subject to provisioning), and those that cannot be unilaterally cancelled.
- Provisioning policies must explicitly consider counter‑cyclical adjustments so that in periods of credit quality improvement, higher provisions are constituted to compensate in some degree for those that should be constituted in periods of credit quality deterioration.
- Clause 13 of the CE 022 of 2020 establishes criteria to be met by the CI for reversed countercyclical provisions during the pandemic stress period; such criteria are validated monthly by the supervisor.
- When a CI fulfills decumulation conditions, it may decide whether to make use of reversed countercyclical provisions or not.

### Counter‑cyclical provision methodology and monitoring
- CIs must evaluate monthly four indicators to measure: 
  - i) deterioration (portfolio at risk provisions taken to expenses), 
  - ii) efficiency (ratio between net recovery provisions against portfolio interest), 
  - iii) fragility (ratio between net recovery provisions against gross financial margin), and 
  - iv) gross portfolio growth.
- Results of provisions calculated through reference models are submitted monthly by CIs to the SFC in interim financial statements.
- Supervisory evaluation covers portfolio rating methodologies (granting and monitoring stages) to ensure inclusion of risk variables such as sector, macroeconomic and market conditions, and to assess whether constituted provisions are sufficient.

### Provisioning system alignment with expected loss and IFRS9
- Sections 1.3.3 and 1.3.4, Chapter II, CBCF require CIs SARC to have a provisioning system reflecting the borrower’s credit risk (CR), and provisions must be calculated based on expected losses.
- For consolidated financial statements, the SFC has monitored how CIs update methodological parameters for estimating expected losses under internal IFRS9 models and performed horizontal analyses to identify incorporation of macroeconomic conditions into internal models.

### Early identification, oversight, and collection (EC5)
- CBCF requires development of policies and procedures approved by the CI’s Board of Directors and executed by management that define: 
  - (i) the development of collection activities; 
  - (ii) restructuring evaluation and approval; 
  - (iii) management of assets received as payment; and 
  - (iv) portfolio write‑off decisions.
- Chapter II defines criteria for classifying portfolio assets for each loan modality; risk categories must reflect borrower financial situation, payment ability and other information to establish compliance with current and future payments.
- Objective criteria include number of days in arrears at time of evaluation.

### Risk categories and days/months at default (objective minimum criteria)
- Mortgage / Microcredit risk categories:
  - A or “normal risk”: Less than 2 / Less than 1 (Months at Default)
  - B or “acceptable risk higher than normal”: 2 to 5 / 1 to 2
  - C or “appreciable risk”: 5 to 12 / 2 to 3
  - D or “significant risk”: 12 to 18 / 3 to 4
  - E or “risk of default”: More than 18 / More than 4
- Restructured credit transactions that are over 90 days in arrears for mortgage loans (with the exception of restructuring processes carried out under the adoption of Article 2 of Law 546 of 1999), and those that are over 60 days in arrears for commercial, consumer and microcredit loans, should be assigned risk category “D" or “significant risk."

### Commercial loans - risk categories by days at default
- Commercial loans:
  - AA: Up to 29 (Days at default)
  - A: 30 to 59
  - BB: 60 to 89
  - B: 90 to 119
  - C: 120 to 149
  - D: More than 149

### Definition of default and probability of default
- Default is the event that a credit meets at least the following conditions by modality:
  - (i) commercial: payments past due more than or equal to 150 days, or if restructured, greater than or equal to 60 days;
  - (ii) consumer loans: past due more than 90 days, or if restructured more than or equal to 60 days;
  - (iii) mortgage: past due more than or equal to 180 days; and
  - (iv) microcredit: past due more than or equal to 30 days.
- When the credit transaction is classified in the “default,” its PD (probability of default) is 100 percent (Annexes 3 and 5 of Chapter II of CBCF).

### Modified and restructured loans—conditions and monitoring
- A loan may be modified to allow the borrower to handle the obligation; criteria for "modified" loans:
  - (a) the new conditions must allow payment of the loan;
  - (b) the risk rating will be assigned according to the risk profile observed at the time of modification;
  - (c) these transactions will be monitored for a defined period per portfolio modality during which effective payments to principal and interest must be made;
  - (d) if the modified loan shows arrears of more than 30 days, it must be reclassified as restructured.
- Restructured transactions must be classified according to risk analysis and payment ability; rating cannot be higher than the category assigned before restructuring.
- To improve rating after restructuring, conditions include:
  - i) borrower’s payment ability improves and the new situation implies an improvement in the loan’s rating; and
  - ii) borrower made regular and effective payments of principal and interest for at least six months.
- CI must evaluate and re‑qualify the loan portfolio: 
  - (i) if loans incur payment delays after being restructured; 
  - (ii) at least twice a year in the months of May and November; and/or 
  - (iii) when it is known the borrower is in any legal or administrative process that may affect payment ability.

### Supervisory monitoring of restructured portfolio and normalization rules
- The SFC carries out continuous monitoring and control of CIs portfolio rating and provisioning policies to validate application of regulations and require adjustments where necessary.
- CE 026 of 2017 defined homogeneous rules for authorized strategies for normalization (credit restructuring and modifications) and portfolio recovery.
- Since CE 026 of 2017, the SFC has executed onsite and offsite supervision to validate normalization policies, determination processes for modifications/restructurings, information systems for marking, rating, and monitoring, and independence of approval/follow‑up areas.
- Template 536 was created to require detailed monthly information on modified and restructured loans for construction of early warning signs.

### Supervisory reporting, data access, and documentation (EC6)
- The SFC obtains regular reports to examine portfolio classification/rating and provisions. Major reports include:
  - Template 341 "Borrower’s Individual Credit Exposure." Compiles borrower’s individual credit exposure. Includes each borrower’s risk category, individual and counter‑cyclical provision, among others. For accounting and reporting purposes, the risk categories of the commercial and consumer portfolios. This report is submitted to the SFC and credit bureaus quarterly.
  - Template 453 “Balance exposure by products” compiles information about the portfolio’s exposure by type of product. The CIs report the portfolio’s balance by risk rating for each portfolio product and segment. The frequency of transmission of this information is monthly.
  - Template 477 “Consolidated Report on Individual Portfolio Provisions” Collects disaggregated information regarding individual portfolio provisions and their respective components. The frequency of transmission of this information is monthly.
  - Template 536 “Individual Report on the Modification and Restructuring of Credit” information on modified and restructured loans by borrower. Includes, among other information, the loan’s risk rating and provisions.
  - “Financial Statements” Chapters VII to X, CBCF, include information on the classification and provisions of the CIs portfolio. For intermediate financial statements, the information is received monthly, and for consolidated financial statements, it is received quarterly.
- The SFC requests portfolio data files to validate correct classification, rating, and provisioning. CIs must keep borrowers' credit files and databases supporting their models, including financial and socio‑demographic information, collateral information, and all quantitative and qualitative information supporting granting and monitoring models.

### Supervisor authority to require adjustments (EC7)
- The SFC determines through supervisory processes whether portfolio classification and provisioning are consistent with requirements and has authority to:
  - Order adjustments or modifications to risk ratings.
  - Order adjustments to the level of provisions if constituted provisions are insufficient or inadequate.
  - Order the suspension of practices through which provisions are reversed and the rating of restructured loans is improved.

### Valuation of collateral and risk mitigants (EC8)
- Paragraph d, Section 1.3.2.3.1, Chapter II of CBCF establishes minimum factors CIs must consider regarding collateral: nature, value, coverage, and liquidity.
- CIs must estimate potential costs to eventually sell the collateral and the legal requirements for enforcing collateral.

*Source: 1colea2022005 - Chapter II, CBCF).*

### Section III gives the instructions to determine the collateral’s value at granting and

### 1colea2022005 - Section III gives the instructions to determine the collateral’s value at granting and

### Collateral valuation, updates and supervisory role
- Section III provides instructions to determine the collateral’s value at granting and its update through time, including valuation methods at granting and follow-up stages, appraisal validity, and updates according to each collateral type.
- The SFC supervises that CIs carry out valuation and updating of collateral in the terms defined in the regulation and verifies compliance with collateral suitability characteristics.
- If collateral’s value is not updated in accordance with the regulatory guidelines, the collateral must be reclassified to the unsuitable category and cannot be considered for the calculation of the expected loss or portfolio provisions.
- At the consolidated level, the SFC verifies that CIs consolidating financial statements under IFRS9 guidelines incorporate analysis, valuation, and design of methodologies to consider collateral in the calculation of provisions.

### Asset identification and reclassification (EC9)
- EC9 requires criteria for assets to be:
  - (a) identified as a problem asset (e.g., when there is reason to believe that all amounts due will not be collected in accordance with contractual terms); and
  - (b) reclassified as performing (e.g., when all arrears have been cleared, repayments have been made in a timely manner over a continuous repayment period and continued collection is expected).
- Findings:
  - The SFC has established risk categories grouping loans with common characteristics; number of days in arrears is one criterion but not the only one.
  - Other risk factors evaluated include the borrower’s payment ability, level of exposure, quality and composition of assets, cashflow, among others.
  - For restructured portfolios, regulation requires:
    - (i) verification that the borrower's payment ability meets criteria for improving the rating; and
    - (ii) regular payments of principal and interest for six consecutive months.
  - For modified loans, rating must be updated according to the CI's risk analysis per Paragraph c, Section 1.3.2.3.2.1, Chapter II, CBCF. Modified portfolio is subject to special monitoring; release from such monitoring occurs after:
    - 9 consecutive months for microcredit; and
    - 12 months for other modalities.
- Regulation establishes guidelines regarding suspension of accrual interest according to loans’ length of arrears85; once client pays installments in arrears, obligation is reclassified as current and accrual of interest resumes.
  - Footnote 85: The suspension of accrual interest is defined according to the loan’s height of arrears by modality as follows: Commercial 3 months, Consumer 2 months, Mortgage 2 months and Microcredit 1 month.
- The SFC verifies assets are qualified per regulatory criteria and uses onsite, offsite, and cross-sectional analyses with frequency defined by the annual supervision plan.

### Board reporting and disclosures (EC10)
- EC10 expects the supervisor to determine that the bank’s Board obtains timely and appropriate information on asset portfolio condition, including classification, level of provisions and reserves, and major problem assets; information should include summary results of the latest asset review, comparative trends, and measurements of deterioration and expected losses.
- Findings:
  - The SFC evaluates and verifies the quality and completeness of information submitted by CIs and senior management’s knowledge and monitoring.
  - Required information includes portfolio current status, disaggregation by risk category, level of provisions and coverage, portfolio growth follow-up, disbursement evolution, past-due behavior, trends, forecasts, and results of management actions.
  - For CIs reporting consolidated financial statements, the SFC has validated quality of reports to Boards on performance of doubtful assets and expected losses.

### Individual valuation, classification and provisioning (EC11)
- EC11 requires that valuation, classification and provisioning, at least for significant exposures, are conducted on an individual item basis with appropriate thresholds for significant exposures.
- Findings:
  - Section 1.3.2.3.2, Chapter II, CBCF requires CIs to carry out continuous monitoring and rating of all credit transactions based on borrower risk profile, payment ability, and loan contract characteristics.
  - CIs use collective and/or individual methodologies; individual methodologies are more commonly used to rate significant exposures according to CI-defined thresholds.
  - Common information for rating and provisioning: borrower financial evaluation, sectorial information, risk alerts from other intermediaries, and other relevant information.
  - CIs review at least annually the borrower’s approved credit limit, involving a complete financial review that may adjust the approved limit.

### Sector trends, concentrations and provisioning adequacy (EC12)
- EC12 requires the supervisor to assess trends and concentrations in risk and consider adequacy of provisions and reserves at bank and system level.
- Findings:
  - The SFC conducts onsite and offsite analysis including horizontal and comparative studies analyzing disbursements, total exposures, past due and risky portfolio trends, portfolio quality indexes, and provisioning coverage across the industry.
  - Analyses generate information by portfolio, product, activity, or economic sector, enabling consolidated views, macroeconomic consideration, and early warning indicators.
  - Results have led CIs to adjust borrower ratings and provisioning and to develop strategies and action plans to control and reduce portfolio impairment.
  - Supervision strategies cited include:
    - Strategy 1 (2017): identify deterioration processes in some CIs and define specific plans and goals; and
    - Strategy 2: a rating model to assess appropriate rating revelation for commercial loans.
  - Regulatory adjustments from supervision include:
    - CE026 of 2012: ordered an additional individual provision related to acceleration in past-due consumer loans; and
    - CE047 of 2016: adjustment in expected loss calculation associated with term of consumer loans, generating higher provisioning requirement for exposures with terms higher than 72 months.

### Assessment of Principle 18
- Assessment: Compliant
- Comment: The SFC works closely with external and internal audit in confirming correct classification and provisioning of the loan portfolio.

### Concentration risk and large exposure limits (Principle 19) — framework and findings
- Principle 19: supervisor determines banks have policies/processes for identification, measurement, evaluation, monitoring, reporting and control/mitigation of concentrations; supervisors set prudential limits for exposures to single counterparties or groups of connected counterparties.
- EC1 — policies and processes for comprehensive bank-wide view of concentration risk:
  - Findings:
    - Supervision activities (onsite, offsite, monitoring, half-yearly statutory auditor reports) confirm compliance with regulatory credit limits and consolidation of direct and indirect transactions and creditor positions, on- and off-balance sheet.
    - Supervisors review risk appetite limits and limits on large exposures, verifying concentration levels by product, sector, region, individual counterparties or groups.
    - Credit operations to be considered include loans of any kind; bills of exchange; granting of any kind of guarantee; credit lines and letters of credit; and other operations placing the bank as real or potential creditor.
  - Regulatory credit limits:
    - Limit of 10 percent of the total capital for credit transactions not covered by an admissible guarantee.
    - Limit of 25 percent of total capital for credit transactions covered with an admissible guarantee.
    - Limit of 40 percent of the total capital for credit transactions guaranteed with a stand-by credit letter granted by a foreign CI; reduced to 30 percent of the total capital if the stand-by letter issuer is the parent company or a subsidiary of the bank.
    - Limit of 30 percent of the total capital if the borrower is a CI.
    - Limit of 20 percent of the total capital if the borrower is a bank’s shareholder.
    - Specific credit limit for 4G road infrastructure projects: 25 percent of the total capital.
- EC2 — information systems identify and aggregate exposures:
  - Findings:
    - SFC validates that CI information systems identify and aggregate credit exposures at individual and group-of-connected-counterparties level and allow active management of concentration exposures.
    - Inspection checks include whether CI has automatic controls to consolidate group exposures, considers all creditor-role transactions, and includes off-balance exposures in credit limit controls.
    - The SFC verified CIs quantify credit exposures per criteria in Title 2, Part 2 of Decree 2555 of 2010.
- EC3 — thresholds for acceptable concentrations and Board oversight:
  - Findings:
    - The SFC produced the “Risk Appetite Guide” that sets criteria for evaluating CI risk appetite frameworks; RAS must be consistent with business plan and capital plan and ensure exposures align with CI risk appetite and limits.
    - The Guide assigns Board responsibility to participate in risk appetite definition and ensure alignment with business plan and capital levels.
    - When defining the risk appetite framework, CIs must set limits related to concentration risks.
    - The SFC verifies, via inspections, levels of portfolio concentration and capital-planning processes to identify resources to support business growth and verifies Board familiarity with CR exposure levels and proposed mitigation actions.

*Source: 1colea2022005 - Section III gives the instructions to determine the collateral’s value at granting and*

### 1. Portfolio’s concentration levels and exposure limits, verifying the level of CR

### 1. Portfolio’s concentration levels and exposure limits, verifying the level of CR

### Overview
- Board-approved policies and exposure limits must align with the CI’s risk appetite and business plan.
- Supervisory activities (onsite and offsite) verify that procedures and controls effectively monitor compliance with Board-approved policies and guidelines.
- Supervision validates underwriting-stage tools and procedures to ensure exposures and limits are consistent with CI definitions and Board approvals.
- Capital planning validation assesses the quantity, quality, and availability of allocated resources to support business growth.
- Half-yearly reports from statutory auditors on CR management systems provide supervisors additional inputs to verify CI compliance with internal policies, standards, and regulation.

### Reporting templates, indicators, and monitoring (EC4)
- The supervisor regularly obtains information enabling review of concentrations within a bank’s portfolio, including sectoral, geographical and currency exposures.
- The SFC receives periodic reports and uses them to develop follow-up indicators, early warning indicators, dashboards, and specialized analyses to guide onsite and offsite supervision.
- Relevant reports received by the SFC include:
  - Template 341 "Individual credit exposure by Borrower" CE 008 of 2005 — compiles individual credit exposure by borrower and portfolio; for commercial loans, contains credit exposure by economic sector. Frequency: quarterly.
  - Template 322 “Deposits and Placement by Municipality” created by CE 008 of 2005 — compiles information on deposits and placements by department and municipality. Frequency: quarterly.
  - Template 323 “Deposits and Placement by Municipality Zones” created by CE 008 of 2005 — compiles deposits and placements for Bogotá, Medellín, Cali, Barranquilla, Ibague, Pereira, Cartagena, Santa Marta, Manizáles, and Bucaramanga. Frequency: quarterly.
  - Template 453 “Balance exposure by products” created by CE 011 of 2008 — compiles information credit exposure by portfolio and product; product lines in commercial portfolio include foreign currency. Frequency: monthly.
  - “Balance Sheet” (chapters VII to X of the CBCF) — includes information by portfolio in local and foreign currency; intermediate financial statements: monthly; consolidated financial statements: quarterly.
  - Quarterly certification from CI legal representatives of individual credit exposures and/or groups of connected counterparties defined by the regulatory framework — used to identify warning signs.
  - Quarterly report related to "Portfolio by Currency" for CI that consolidate financial statements.
- Use cases:
  - Creation of a dashboard with monthly and quarterly indicators related to portfolio concentration and performance versus peers.
  - Identification of institutions with warning signals associated with high concentration indicators, particularly in the commercial portfolio.
  - During 2020 (COVID-19), identification of CI exposures in vulnerable economic sectors and customer profiles (e.g., independent debtors) and performance of hypothetical portfolio rolling exercises to quantify potential impact and request additional prudential provisions.

### Definition and treatment of groups of connected counterparties (EC5)
- Regulation explicitly defines “group of connected counterparties.”
- For legal entities, criteria include majority shareholding, preference share rights, and the right to appoint more than half of a company’s Board members; also mutual partners and/or directors, cross collateral, or direct commercial interdependence.
- For individuals, considered relationships include:
  - Kinship/blood: parents, children, siblings, grandparents, and grandchildren;
  - Affinity: the spouse's parents, children, siblings, grandparents, and grandchildren;
  - Civil: adopted children and adoptive parents;
  - Whether the credit transaction was granted to the spouses or permanent partners.
- Mixed groups (legal entities and individuals) consider the full set of interrelationship criteria.
- The SFC may determine common risk and, on a discretionary but reasoned basis, establish the composition of a group of connected counterparties for controlling individual credit quotas.
- The SFC validates group compositions during inspection processes and requires quarterly certifications from CI legal representatives for individual and group exposures.
- Supervisory review includes policies, procedures, information systems, criteria and controls for identification and accumulation of individual or group exposures; when regulatory limit excesses are identified, the SFC issues adjustment requests and administrative measures supported by compliance reports.

### Large exposure limits, scope and exceptions (EC6)
- Decree 2555 of 2010 regulates credit limits for individual counterparties or groups of connected counterparties and contemplates requirements to control credit exposures, including:
  - Different credit limits for large exposures according to different factors.
  - Necessary concepts for correct interpretation (e.g., concept of admissible collateral for limit application).
  - Inclusion of all types of credit exposures (real and potential), involving on- and off-balance sheet transactions.
  - An exception regime excluding certain transactions from limits, including:
    - (a) Credits granted to the Nation with terms shorter than 180 days;
    - (b) Those originated in instalment sales of property owned by the CI, which must have prior authorization of the SFC;
    - (c) Those carried out by the BR or Fogafin, as creditors or guarantors, with CI;
    - (d) Loans granted through credit cards to individuals, as long as the amount of the credit quota does not exceed Col$56,900,000 (current amount equivalent to Col$10,000,000 defined when this regulation was issued);
    - (e) Credit transactions carried out with territorial entities in development of restructuring agreements according to the Law 550 of 1999 and Law 617 of 2000, if a collateral from the Nation supports the agreement;
    - (f) CI’s operations originated in rediscount operations with Finagro, Findeter and Bancoldex (second floor or development banks).
  - Relevant criteria for defining groups of connected counterparties as specified in EC5.
  - Consolidated credit limits: CI with subordinates abroad must consolidate all credit transactions granted; total capital considered corresponds to each CI calculated on consolidated balance sheets.
  - Decree 1486 of 2018 mandates that the CF must define credit limits related to entities that are part of the conglomerate.
  - Extension of application: Article 2.1.2.1.17 Chapter 1, Title 2, Book 1, Part 2 Decree 2555 of 2020 extends credit limit rules to other entities subject to SFC control and surveillance.
- Article 1.3.1.2, Chapter II of the CBCF requires CI policies to include general guidelines for setting levels and exposure limits (real and potential) of the total and individual portfolio, as well as limits by borrower.

### Supervisory use of information and validation practices
- The SFC uses periodic information to:
  - Permanently follow and monitor portfolios and prepare aggregate or individual analyses.
  - Generate early warnings and guide onsite/offsite supervision to identify institutions with high concentration risk.
  - Validate CI underwriting tools, reporting frequency, report quality, and board escalation to ensure Board awareness and mitigation of CR exposure levels.
- Supervisors assess capital planning and request additional prudential provisions when hypothetical exercises indicate potential impact on financial statements.

*Source: 1colea2022005 - 1. Portfolio’s concentration levels and exposure limits, verifying the level of CR*

### Section 1.3.2, Chapter II of the CBCF indicates that the CI must have monitoring

### Section 1.3.2, Chapter II of the CBCF indicates that the CI must have monitoring

### Monitoring, supervisory framework, and compliance function
- Section 1.3.2, Chapter II of the CBCF requires that the CI must have monitoring systems regarding the CR administration, which involve credit limits compliance.
- Paragraph e), Article 1.3.2.1, Chapter II of the CBCF provides that the CI Board must require from the administration, for its evaluation, reports on a regular basis about the credit exposure levels.
- The SFC, through inspection processes, has determined that the Board knows and evaluates the levels of credit risk exposure.
- Within the risk-based supervision framework, the SFC reviews CI significant activities and, in offsite and onsite monitoring, follows up on policies, tools/methodologies, information systems and reports scaled to CI management and Board.
- The compliance function is assessed as part of the CI risk profile construction and is used by the supervisor to determine the CI effectiveness to control and limit credit exposures for on-balance and off-balance sheet exposures.

### Large exposures, stress testing (EPR), and regulatory gaps
- The supervisor requires banks to include the impact of significant risk concentrations into their stress testing programs for risk management purposes.
- The SFC implemented EPR through Chapter XXVIII of the CBCF. EPR objectives include:
  - (i) identify risks that may affect the business viability of a CI;
  - (ii) facilitate the adoption of timely decisions;
  - (iii) examine the consistency of the capital, liquidity, assets, and liabilities of the CI.
- Annex 1 of Chapter XXVIII specifies EPR are part of the CR management system and provides guidelines and scenarios.
- Article 4.1, Annex 1, Chapter XXVIII requires portfolio and provisions forecasts to consider risk derived from default of counterparties that may have a significant impact and include effects of adverse situations (such as macroeconomic ones).
- Article 5.4.5, Annex 1, Chapter XXVIII requires test results to incorporate effects of significant counterparties' possible default on balance sheets.

### Additional criteria for large exposures (AC1) and findings
- Regulatory thresholds:
  - (a) "10 percent or more of a bank’s capital is defined as a large exposure"; and
  - (b) "25 percent of a bank’s capital is the limit for an individual large exposure to a private sector nonbank counterparty or a group of connected counterparties."
- Decree 2555 of 2010, Article 2.1.2.1.2, states credit transactions may not exceed 10 percent of total capital; with admissible collateral, an operation’s amount may reach up to 25 percent of CI total capital.
- An admissible collateral is defined as: (i) its value is established based on technical and objective criteria; (ii) provides the CI a legally effective support by giving priority to obtain a payment from the obligation; and (iii) is sufficient.
- The regulation does not allow temporary limits or minor deviations for small or specialized CI.
- Assessment of Principle 19: Materially Non-compliant. Significant deficiencies include:
  - Current large exposure limits are based on total capital and not on Tier I capital as required by the 2014 BCBS standard.
  - Decree 2555 recognizes guarantees and letters of credit issued by an affiliated bank as acceptable credit risk mitigation and increases limits, creating exposures between related parties.
  - External Circular 013 (2019), implemented by Financial Holding Companies starting in June 2021, requires holding companies to address concentration risk by geographic location, business lines, economic sector and counterparties but lacks detailed risk-based guidance and threshold actions (e.g., Pillar 2 add-ons, increased reporting, more frequent onsite reviews).
  - Major Colombian banks have significant exposures as a percent of capital in Central America, reinforcing need to strengthen large exposures/concentration monitoring and requirements.
- URF 2020 study on large exposures aims to:
  - (i) align the definition of exposure according to the standard;
  - (ii) guarantee clear and homogeneous application of the concept of groups of connected counterparties;
  - (iii) simplify the framework with fewer limits.

### Related-party transactions (Principle 20): rules, supervisory practice, and gaps
- Principle: supervisor requires banks to transact with related parties on an arm’s-length basis; monitor these transactions; mitigate risks; and write off exposures in accordance with standard policies.
- Definition and legal framework:
  - Related parties include subsidiaries, parties that control or are controlled by the company, as established in Articles 261, 262 and 263, CCo. Article 261 defines subordinated entity when controlled over 50 percent by parent.
  - Article 265 requires related-party transactions to be at market terms.
  - FCL and Decree 1486 of 2018 give the national government power to establish related-party criteria for financial conglomerates and holding companies.
- Key legal and procedural requirements:
  - Article 265, CCo: supervisors can verify related-party transactions and impose fines or suspend operations if transactions are not at market conditions harming government, shareholders or third parties.
  - Article 122, EOSF: all operations with shareholders with 5 percent or more of subscribed capital and their administrators, and with spouses and relatives of partners and administrators, must be approved through the unanimous vote of the Board members attending the meeting.
  - Paragraph b, Article 72, EOSF: supervised entities and officials must act within legal framework and principle of good faith, refraining from operations with related persons beyond legal limits.
  - Article 2.39.3.1.4., D2555: duty of transparency requiring operations with conflicts of interest to be at market prices and same conditions as general public.
- Specific findings and limits:
  - No general requirement that related-party transactions and write-offs exceeding specified amounts be subject to prior Board approval; requirement limited to managers and 5 percent shareholders transactions requiring prior unanimous Board approval.
  - Shareholders owning 20 percent or more of bank’s stock have a 20 percent of total capital borrowing limit.
  - SFC verifies existence and compliance of policies via bylaws, Board minutes, committee minutes, and information systems consolidating transactions and exposures of connected counterparties.
  - Supervisor obtains and reviews aggregate exposures via the “Concentration Report”; an analytical cell prepares alert signals for possible breaches; offsite examinations generate early warning indicators; inspection processes verify information systems control of limits including off-balance sheet exposures.
- Assessment of Principle 20: Materially Non-compliant. Key weaknesses and recommendations:
  - Regulatory framework remains weak and fragmented; related-party definitions, transaction rules, lending limits, approval and write-off requirements are dispersed across decrees and laws.
  - Recommendation to consolidate related-party definitions, transaction rules, aggregation rules, limits, approval and write-off requirements in a single comprehensive framework established by SFC (avoid allowing banks/holding companies to set their own limits and definitions).
  - URF project objectives to be discussed with industry: (i) consolidate all exposures with subordinates; (ii) ensure clear and homogeneous application of groups of related parties; (iii) simplify scheme with fewer limits; (iv) reduce incidence of exceptions that generate arbitrage and interpretation complexities.

### Country and transfer risk (Principle 21): supervisory approach and requirements
- Principle: supervisor determines banks have adequate policies/processes to identify, measure, evaluate, monitor, report and control or mitigate country risk and transfer risk in international lending and investment activities.
- Supervisory methodology and expectations:
  - When devising the Supervisory Plan and allocating supervisory resources, SFC considers local and abroad macroeconomic conditions focusing on jurisdictions where national entities have cross-border investments.
  - When SFC approves a capital investment, the ES must submit a description of the risk management system.
  - FCL requires HF to keep SFC updated of structural changes so Supervisor can update supervisory templates.
  - CF must have a risk management framework to identify each jurisdiction’s risk profile, including exposure to country and transfer risk, mitigation measures and follow-up of foreign units.
  - Supervisor fills/updates supervisory templates, including the Business Knowledge Template summarizing supervisory actions and risks.
  - Policies and procedures are assessed under proportionality (consistency with institution’s risk profile, systemic importance, macroeconomic environment).
- Board oversight expectations:
  - SFC verifies Boards approve Risk Governance Structure, control function design and implementation, define risk appetite with Senior Management, supervise Risk Appetite Framework implementation and compliance, and participate in review of management issues.
  - For Significant Activity (AS) foreign investments, supervisor assesses host jurisdiction macroeconomic conditions and Board’s policies/processes to manage country and transfer risks.
- Information systems and reporting:
  - Supervisor requires banks’ information systems, risk management systems and internal controls to aggregate, monitor and report country exposures timely and ensure adherence to country exposure limits.
  - Draft regulation requires ES to prepare:
    - (i) internal periodic reports on country risk profile and its relation to ES appetite framework (content/frequency reflecting decision needs);
    - (ii) a semi-annual report to SFC including: (a) indicators/variables used for country risk analysis, (b) list of countries with financial operations and their rating and provision, (c) policies used to set concentration limits per country/region/economic sector/currency-level, and (d) stress tests results.
  - ES must adopt adequate systems including IT support and data architecture for comprehensive knowledge of country and transfer risk.
- Provisioning and risk weights:
  - SFC follows option (c) for provisioning: banks set provisioning and adequacy is judged by external auditor and/or supervisor; supervisor conducts detailed evaluation and can require corrective action.
  - Article 2.1.1.3.7 of Decree 2555 of 2010 and sub-Section 2.4.4. of Chapter XIII-16 of CBCF require CI to consider international risk ratings when defining credit risk weights for borrowers' assets abroad and securities issued abroad.
  - Risk-weight table in Article 2.1.1.3.2 of Decree 2555 of 2010:
    - Credit rating: AAA to AA- weight 0%
    - A+ to A- weight 20%
    - BBB+ to BBB- weight 50%
    - BB+ to B- weight 100%
    - Less than B weight 150%
    - No rating weight 100%
  - Rules for subordinates in non-investment grade countries:
    - For sovereign rating between BB+ and B-: classify exposures using the next risk-weighted scale.
      - Example: counterparty rated AAA in a subordinate located in a country rated BB+ will have risk weighted asset of 50 percent.
    - For sovereign rating between B- and CCC: classify using the second next risk-weighted scale.
    - For sovereign rating less than C: classify using the third next risk-weighted scale.
  - Adoption of IFRS: per IAS 36, banks must determine impairment of assets through their own models fulfilling characteristics specified in the rule; supervisor may ask ES to revise provision level if not appropriate with risk level.
- Stress testing:
  - EC5 (Principle 21) indicates supervisor requires banks to include appropriate scenarios into their stress testing programs to reflect country and transfer risk analysis for risk management purposes.

*Source: 1colea2022005 - Section 1.3.2, Chapter II of the CBCF indicates that the CI must have monitoring*

### Chapter 28 of CBCF states the rules that every ES must follow in their bottom-up

### Chapter 28 of CBCF — rules for ES bottom-up stress-testing (EPR)

### Scope and mandatory requirements for EPR (Chapter 28, Article 4)
- Chapter 28 of CBCF states the rules that every ES must follow in their bottom-up stress-testing programs (EPR), following the assumptions and time horizon defined by the SFC.
- Pursuant to Article 4, Chapter 28 of CBCF every ES should adopt an EPR according to their size, risk-profile, business complexity, asset/liability structure, among others, and considering their business plan.
- Number 4.1: every ES must define methodologies that allow them to identify and mitigate their weaknesses while helping them to examine the consistency of their capital and liquidity management, according to their risk profile.
- Number 4.5: the methodology used needs to be robust in order to capture their business complexity.
- When the SFC releases the macroeconomic assumptions underlying the baseline and adverse scenarios, entities that have subordinates or branches abroad are required to consider the macroeconomic conditions of the host jurisdictions in which their investments are located.

### Circular Letter 23 of 2019 — macroeconomic scenarios and reverse stress testing
- Since 2019, Circular Letter 23 of 2019 dictates new instructions about the guideline the ES must follow about the Macroeconomic scenarios.
- Requirements under Circular Letter 23 of 2019:
  - The ES must select a set of variables and calibrate the adverse scenario with a reverse stress test, until the ES does not comply with the prudential indicators (or internal indicators), in a three-year forecast.
  - The ES must also project a base scenario considering their business plan.
  - These instructions apply only when determining the stress scenarios; ES must continue to consider their business complexity, including when they have foreign subordinates and branches.
  - The ES must consider Country and transfer risk when the business complexity determines so.
- The supervisor analyzes the consistency of the stressed scenarios’ results with the framework given by the SFC and may require additional assumptions (e.g., incorporation of the impact of other jurisdictions into the ES results) to ensure ES are considering country and transfer risk.
- Section 4.14: the tests must have the Board’s approval.
- Article 6.6: the Board must follow the SFC’s recommendations; the supervisor evaluates whether the EPR are being taken into account for risk management purposes.

### Frequency, scenarios, and business continuity
- Draft regulation requirement: ES must carry out stress tests at least once a year to assess resilience against the increase or materialization of country and transfer risk.
- Frequency may increase if the economic and socio-political environment further deteriorates.
- Stress tests must:
  - (i) consider scenarios where economic, market and socio-political indicators are expected to affect the exposure abroad; and
  - (ii) include a business continuity plan considering actions the Board and senior managers can undertake if risk exposure breaches ES internal limits.
- Board of Directors and senior managers must periodically review stress test results and have a full understanding of the scenarios and results.

### EC6 — supervisory information and cross-border cooperation (country and transfer risk)
- The supervisor regularly obtains and reviews sufficient information on a timely basis on the country risk and transfer risk of banks and has the power to obtain additional information as needed (e.g., in crisis situations).
- Sources of information for supervisory teams:
  - regulatory reporting by banks;
  - onsite visits and reviews;
  - stress tests.
- SFC cross-border cooperation scheme:
  - robust scheme to gather information regularly and adopt timely actions via internal reports and supervisory colleges;
  - information shows evolution of economic, social, and political conditions of jurisdictions where Colombian banks/groups carry out activities or hold assets, to evaluate country and transfer risk.
- Monthly Regional Report (For internal use only) summarizes main trends in Central America and South America (Brazil, Paraguay, and Peru); built on information from Central Banks, host Supervisors, the Central American Monetary Council, and the Center for Latin American Studies.
- Research and Analysis division (Subdirección de Investigación y Análisis) main tasks (Article 11.2.1.4.17 of Decree 2555):
  - Carry out studies, research and other documents on economic and financial aspects related to industries and financial conglomerates;
  - Design strategic guidelines with respect to standards and best practices in prudential matters, risk management, market development and other topics of interest to the SFC;
  - Perform stress tests on the aggregate exposure of supervised entities vis-á-vis the main risks they face;
  - Draft reports on macroeconomic risks and/or specific risks to which entities and financial conglomerates are exposed to support supervisory processes.
- Supervisory colleges:
  - formalize information sharing;
  - assist members to better understand banking group risk profiles;
  - perform effective consolidated and cross-border supervision.
- Powers to request additional information:
  - Financial Superintendent and Deputy Superintendents may request reports regarding the situation of financial institutions (Article 97 of the EOSF).
  - Article 11.2.1.4.33 of Decree 2555, numeral 15: bank supervisors may review documents provided by financial institutions and request any information allowing assessment of their status.

### Assessment of Principle 21
- Assessment: Compliant.
- SFC has addressed prior deficiencies and is following CP minimum requirements, including requirements on risk management and controls for country risk at banks and for banks to evaluate and monitor developments in country and transfer risk.
- A regulation has been drafted aiming at implementing best practices on country and transfer risk and is expected to be released in the third quarter of 2021.
- Colombian banks have significant exposures in Central America and concentration risk is addressed under CP 19.
- Draft regulation coverage and bank requirements:
  - covers sovereign and transfer risk management;
  - requires banks to define tolerance limits and perform analysis of the macroeconomic, political, and social environment of subsidiary institutions;
  - banks must have a model to manage country and transfer risk, considering:
    - Location of the subsidiaries;
    - Country risk rating;
    - Provisioning framework to absorb potential losses that may arise when the countries’ risk profile has deteriorated.

### Principle 22 — Market risk: supervisory expectations and prudential framework
- Principle 22 summary:
  - Supervisor determines banks have an adequate market risk management process that accounts for risk appetite, risk profile, market and macroeconomic conditions and risk of significant deterioration in market liquidity.
  - Includes prudent policies and processes to identify, measure, evaluate, monitor, report and control or mitigate market risks on a timely basis.

### EC1 — prudential standards for market risk (CBCF, Chapter 21)
- Requirements and definitions:
  - SFC requires supervised entities to implement a Market Risk Management System (SARM) to identify, measure, control and monitor market risk and to determine adequate capital.
  - Market risk defined as the possibility entities incur losses associated with a decrease in the value of portfolios and investment funds administered due to changes in prices of financial instruments recognized on- and off-balance sheet.
  - Trading book defined to include exposures created by trading operations aiming to benefit in the short term from price fluctuations, and investments sensitive to market factor variations; covers instruments classified as “negotiable” or “available for sale.”
  - Banks required to implement IFRS standards or equivalent for fair valuation.
- Prudential standards components:
  - organizational directive relating to market risk reflecting tolerance level; operational limits set at appropriate levels considering entity risk profile;
  - control and monitoring processes and supporting IT systems proportionate to volume and complexity of market operations;
  - internal and external periodic reports, including global exposure to market risk under current and adverse conditions and same details for each business line.
- Roles and responsibilities:
  - Board, executive management, independent risk management unit, and control bodies (including internal audit) clearly defined; strict separation between front, middle and back offices prescribed.
- SFC assessment frequency:
  - SFC reported to assess correct implementation of SARM standards at least every three to four years, or more frequently if emerging risk or warning signals triggered (e.g., stress tests).
- Daily reporting to SFC:
  - supervised entities must send daily reports relating to market activities (investment portfolio breakdown, new investments, derivative products valuation, underlying assets of derivative products, repos and interbank operations valuation, and underlying assets of repos).
- Central Bank requirement (PICE):
  - indicator for exchange risk for investment in subordinates abroad: difference between investments in subordinates abroad and their exchange hedges;
  - PICE cannot exceed 150 percent of the credit institution’s total capital (Central Bank external resolution 01 (2018)).

### Monitoring and supervisory use of market risk information
- Internal SFC committees monitor exposure weekly and monthly.
- Vulnerable institutions identified using prudential standards, financial and economic data, and tailored market risk stress tests.
- Joint Supervision Teams have access to supervisory exercises and indicators to track market risk at individual and consolidated levels.
- Under the MIS methodology, market risk evaluated when a supervised institution has significant treasury activity, proprietary trading, or an investment portfolio.

### Market risk exposures and investment portfolio (Breakdown as of December 2020)
- Breakdown of the Investment Portfolio as of December 2020 (balance in trillion Colombian pesos)
  - Investment portfolio:
    - Commercial banks: 158.74
    - Financial corporations: 18.97
    - Financing companies: 0.48
    - Financial cooperatives: 0.33
    - Total Credit institutions: 178.51
  - Sovereign bonds:
    - Commercial banks: 75.49
    - Financial corporations: 4.05
    - Financing companies: 0.24
    - Financial cooperatives: 0.07
    - Total: 79.85
  - Private debt:
    - Commercial banks: 15.24
    - Financial corporations: 0.50
    - Financing companies: 0.12
    - Financial cooperatives: 0.20
    - Total: 16.07
  - Stock:
    - Commercial banks: 57.24
    - Financial corporations: 14.26
    - Financing companies: 0.06
    - Financial cooperatives: 0.06
    - Total: 71.62
  - Derivative products:
    - Commercial banks: 10.76
    - Financial corporations: 0.15
    - Financing companies: 0.06
    - Financial cooperatives: (no value shown)
    - Total: 10.97
  - Total assets:
    - Commercial banks: 729.84
    - Financial corporations: 22.51
    - Financing companies: 12.20
    - Financial cooperatives: 4.17
    - Total: 768.72
  - Investment portfolio / Total assets:
    - Commercial banks: 22%
    - Financial corporations: 84%
    - Financing companies: 4%
    - Financial cooperatives: 8%
  - Regulatory capital:
    - Commercial banks: 90.59
    - Financial corporations: 8.11
    - Financing companies: 1.47
    - Financial cooperatives: 0.84
    - Total: 101.01

### EC2 — Board oversight of market risk
- CBCF, chap. 21, Art. 6.4.1: Boards responsible for approval of market risk policies and processes and periodic monitoring of compliance.
- Board obligations include discussing periodic market risk exposure reports and corrective actions for limit breaches.
- Board should ensure risk-appetite framework and associated limits are effectively implemented; validate stress test results and contingency plans; oversee senior management and control/internal audit functions.
- SFC supervisory techniques to verify Board oversight:
  - onsite inspection teams may require Board minutes to verify information flow and approvals;
  - meetings with Board members and senior management to verify implementation, methodology approvals, and reporting frequency.

### EC3 — controlled market risk environment (information systems, limits, exceptions, models, trading book)
- Prudential standards (CBCF, chap. 21) require:
  - effective information systems and IT parameters equivalent to market parameters, periodically reviewed; consolidation systems validated at least once a year and tested under scenarios;
  - definition of loss and market risk exposure limits consistent with entity risk profile; sub-limits at trader, desk and product levels as appropriate; mechanisms to communicate limits to traders;
  - actions for limit breaches and special authorizations in procedures; risk management unit to reject non-compliant operations and report daily rejected operations and weekly/monthly limit breaches and unconventional operations;
  - daily back-testing of internal model results; six-month back-testing period required before model can be used to calculate regulatory capital for market risk;
  - banks must develop policy for management of internal models (review assumptions, parameters, databases, software, validation).

### EC4 — valuation controls and market price providers
- CBCF Chapter I sets rules and minimum standards for valuation of investments in financial instruments; Chapter XVIII sets criteria for valuation of derivatives and structured products.
- SFC mandates market prices of securities must be estimated and delivered to financial institutions by one of two authorized Market Price Providers:
  - Proveedor Integral de Precios Colombia (PIP);
  - Precia Proveedor de Precios para Valoracion SA (Precia — subsidiary of the Colombian stock exchange (BVC for its Spanish name)).
- Market Price Providers are supervised by the SFC.

*Source: Chapter 28 of CBCF and related supervisory descriptions as presented in the supplied content.*

### introduction of new valuation methodologies, or the modification to current ones,

### introduction of new valuation methodologies, or the modification to current ones

### Valuation methodology approval and monitoring
- New valuation methodologies, or modifications to current ones, should be sent to the SFC at least 15 days before their entry into force (CBJ, Part 3, Title IV, Cap. IV, Art. 3.7).
- The SFC reviews relevancy and impact on the financial sector of each methodology received and can object if not satisfied.
- The SFC issued 14 non-objection letters during the 5 first months of 2021.
- Valuation is reported to be performed daily for most instruments; Precia provides reference prices for the great majority of positions held by banks (83 percent).
- For nontraded instruments, the CBCF provides detailed valuation criteria, mostly based on discounted cashflows.
- The SFC has established internal monitoring tools and dashboards that give warning signals when discrepancies arise between:
  - valuations informed by a bank through a daily report of its investment portfolio, and
  - prices provided by the Market Price Providers.
- The SFC conducts onsite evaluations to validate that institutions have systems to access information and to valuate, record and classify all financial instruments on a daily basis, as required by CBCF, Chapter I.

### EC5 — Capital and valuation adjustments for market risk
- Supervisor determination: banks hold appropriate capital against unexpected losses and make appropriate valuation adjustments for fair value uncertainties.
- Regulatory requirements:
  - Banks are required to hold regulatory capital against market risks (DL 2555, Art. 2.1.1.3.1.).
  - SFC published detailed regulatory requirements for calculating the market risk capital charge (CBCF, chap. 21), derived from Basel II standards.
  - Credit institutions should use a standard model unless they have an internal model not objected by the SFC (currently, no bank is using an internal model for market risk capital calculation).
- Standard model features:
  - Considers 5 market risk factors calculated separately and then added: interest rates, exchange rates, price of shares, collective investments, and credit default swaps (CDS).
  - Calculation incorporates sensibility factors set by the SFC.
  - No specific risk charge for interest rate risk is incorporated (noted as less prudent than relevant Basel II standards).
  - Aggregation does not use a correlation matrix; it adds all relevant risk factor exposures (considered prudent).
- Internal model requirements:
  - VaR methodology with a confidence level of 99 percent, a 10-day time horizon and an observation period of at least one year.
- Valuation adjustments for certain security classifications:
  - SFC requires adjustments when necessary for securities classified as: i) “Available for Sale” with no market price; or ii) “Investments at maturity,” to reflect issuer credit rating (CBCF, chap. 1.8).
  - Maximum values as a percentage of the nominal value of the security are set by the SFC, depending on issuer credit rating.
- Planned reforms:
  - Performance of a technical study on convergence to Basel III market risk standards is planned in 2021 for a possible introduction into the legal framework in 2022.

### EC6 — Market risk in stress testing
- Since December 2015, credit institutions are required to have a stress testing program measuring, at least once a year, the incidence of different scenarios on capital, liquidity, assets and liabilities.
- Scenarios:
  - Designed by banks and/or provided by the SFC.
  - Market risk is explicitly included in the stress testing framework, except for small banks (i.e., whose assets are less than 2 percent of the banking sector’s assets) whose main activity relates to granting of loans.
- Banks should estimate impact of scenarios on trading book instruments and derivative products (for the majority of banks).
- CBCF, chap. 21: minimum criteria for internal models include contemplation of adverse scenarios.
- Risk management and governance:
  - Risk management unit must provide risk committee reports on market risk exposures, including scenario analysis results.
  - The Board must validate contingency plans for each extreme scenario.
- Supervisory stress tests:
  - SFC has developed supervisory stress tests to evaluate resilience under price shock scenarios in investment portfolios, depending on identified vulnerabilities and economic/market conditions.
  - Example: in 2018, SFC carried out market risk stress tests that resulted in recommendations for some banks to define contingency plans and ensure mitigation actions were sufficiently prudent.
  - SFC can require stress-tests for specific institutions based on vulnerabilities and supervisory stress-test results.

### Assessment and overall comment on Principle 22
- Assessment of Principle 22: Compliant.
- Comment: Adequate regulatory standards are in place for management of market risks and SFC supervises their implementation. SFC has developed a robust framework for monitoring market risk exposures and identifying potentially vulnerable entities.
- Note: Colombian authorities planned a technical study on convergence to Basel III standards for market risk measurement in 2021, with possible introduction into the legal framework in 2022.

### Principle 23 / EC1 — Interest rate risk in the banking book (IRRBB)
- Objective: Supervisor determines banks have adequate systems to identify, measure, evaluate, monitor, report and control or mitigate interest rate risk in the banking book.
- Exposure profile (September 2020):
  - Assets predominantly at fixed interest rates: 53.3 percent.
  - Average duration of assets: slightly above 2.5 years.
  - Liabilities predominantly at variable interest rates: 44.8 percent are at variable interest rates and 42.2 percent at fixed interest rates.
  - Average duration of liabilities: about 1 year.
- Trend: After an increase in 2019, interest rate risk in the banking book on credit institutions’ net interest incomes decreased in 2020, with reduction in asset duration.
- Regulation and supervisory expectations (SFC public documents and frameworks):
  - SFC has not issued prudential requirements or detailed guidelines specifically for IRRBB, but provides general considerations:
    - IRRBB considered in Comprehensive Supervisory Framework (MIS) as a type of risk inherent to supervised entities and financial conglomerates.
    - Risk Management: SFC assesses appropriateness of tools (e.g., duration gap) used to quantify IRRBB and potential impact on earnings and economic capital; reviews contingency plans; expects IRRBB framework, including policies, processes and limits, to be approved by Board and senior management; expects regular reporting mechanisms.
    - Risk Appetite: entities can quantify risk appetite by calculating economic capital and comparing to own funds.
    - Profitability: entities should assess balance sheet structure consistency with strategic plan and risk appetite.
- Supervision and monitoring tools:
  - SFC built dashboards using weekly reports from institutions via a reporting template about "Interest rate structure of balance sheet" to monitor duration gap and asset-liability mismatches.
  - Emerging risk analysis in supervision planning considers possible changes in central bank policy rate to quantify effects on supervised credit institutions (e.g., 2018 and 2019 plans considered changes in the monetary policy rate as an emerging risk leading to offsite supervision exercises).
  - 2019 exercise:
    - Focused on a group of banks comprising approximately 70 percent of the industry assets.
    - Aimed to evaluate identification, measurement, monitoring and control of IRRBB; map banking book composition; identify gaps within assets and liabilities; measure sensitivity of Net Interest Margin and/or Economic Value of Equity to interest rate changes.
    - Allowed SFC staff to familiarize with institutions’ methodologies and processes for IRRBB.
    - Main conclusion: all systemically important banks implemented a robust and sound IRRBB framework, despite minor weaknesses in a number of supervised institutions.
  - 2021 supervision plan:
    - Intends to focus on medium and small banks to assess overall interest rate risk management and related policies in context of historically low interest rates and low economic growth.
    - Aim to map interest structure and degree of sophistication of IRRBB management and to understand preparedness to face the more than 200 basis points reduction in the central bank’s interest rate during the pandemic.

*Source: 1colea2022005 - introduction of new valuation methodologies, or the modification to current ones*

### 2020. Choosing medium and small banks, as well as financing companies and

### 1colea2022005 - 2020. Choosing medium and small banks, as well as financing companies and

### EC2 — Board and senior management governance for IRRBB
- The supervisor determines that a bank’s strategy, policies and processes for the management of interest rate risk have been approved, and are regularly reviewed, by the bank’s Board. The supervisor also determines that senior management ensures that the strategy, policies and processes are developed and implemented effectively.
- Description and findings re EC2:
  - IRRBB is taken into account when a supervisor assesses the bank’s risk management function.
  - Supervisor must determine whether a bank’s strategy, policies, and processes for the management of interest rate risk have been approved by the Board or the delegated instance and are regularly reviewed.
  - Through supervision exercises mentioned in EC1, the SFC required banks to disclose their governance framework used to manage the IRRBB and the degree of Board involvement.
  - The SFC reported the following findings:
    - Boards of Directors are responsible for approving policies and processes regarding management of interest rate risk;
    - internal committees such as Asset-Liabilities committees, made up of members of the areas associated with risk management, are responsible for monitoring compliance with these provisions;
    - policies and processes are periodically reviewed by senior management;
    - decisions about structural changes in strategy are communicated to operational areas for implementation.

### EC3 — Risk environment, measurement, models, limits, reporting
- The supervisor determines that banks’ policies and processes establish an appropriate and properly controlled interest rate risk environment including:
  - (a) comprehensive and appropriate interest rate risk measurement systems;
  - (b) regular review, and independent (internal or external) validation, of any models used by the functions tasked with managing interest rate risk (including review of key model assumptions);
  - (c) appropriate limits, approved by the banks’ Boards and senior management, that reflect the banks’ risk appetite, risk profile and capital strength, and are understood by, and regularly communicated to, relevant staff;
  - (d) effective exception tracking and reporting processes which ensure prompt action at the appropriate level of the banks’ senior management or Boards where necessary; and
  - (e) effective information systems for accurate and timely identification, aggregation, monitoring and reporting of interest rate risk exposure to the banks’ Boards and senior management.
- Description and findings re EC3:
  - Supervisors should determine if the entity has adequate calculation methodologies of its exposure to IRRBB, as well as appropriate reporting mechanisms to the Board and senior management.
  - Through 2018 and 2019 supervision exercises, the SFC required information related to IRRBB management processes and limits and evaluated:
    - the systems on which the IRRBB is built and their robustness;
    - whether or not there were reviews of internal models by approbatory instances, such as the risk committee of the Board;
    - how the limits regarding interest rate risk are established, and their relationship with the business model and market expectations;
    - which area carries out constant monitoring of the risk;
    - reporting obligations to senior management and the Board and how this framework is articulated with the bank’s risk appetite;
    - the strategies resulting from the analysis of sensitivity exercises on the interest rate risk.

### EC4 — Stress testing for adverse interest rate movements
- The supervisor requires banks to include appropriate scenarios into their stress testing programs to measure their vulnerability to loss under adverse interest rate movements.
- Description and findings re EC4:
  - The stress testing program (EPR) developed by the SFC does not explicitly refer to IRRBB and does not make mandatory the inclusion of scenarios to measure banks vulnerability to loss under adverse interest rate movements.
  - 2018 supervisory exercise: SFC required banks to estimate the impact of a flattening and steepening of the yield curve on the banking book.
  - 2019 offsite supervisory exercise: SFC mandated estimation of the impact of a parallel rise in 200 basis points in the yield curve.
  - Impacts were evaluated as changes in the Net Interest Margin and Economic Value of Equity of institutions (when banks were able to compute this measure), compared to profits and capital.
  - Within the scope of the 2021 supervision exercise, it is expected that medium and small banks would be required to conduct stress tests on the banking book to assess and measure their vulnerability to losses under adverse interest rate movements.
  - SFC had access to several internal stress-tests calculations, including main approaches, assumptions, and metrics; recommendations for improvement were given when necessary.
  - SFC found minor inconsistencies in scenarios used by entities, particularly related to identification of rate sensitive assets/liabilities or impact of changes in interest rates on both sides of the balance sheet.
  - SFC sent tailored recommendations to optimize scenarios and improve the quality of internal exercises to accurately measure potential vulnerabilities.

### Additional criteria — AC1 and AC2
- AC1: The supervisor obtains from banks the results of their internal interest rate risk measurement systems, expressed in terms of the threat to economic value, including using a standardized interest rate shock on the banking book.
  - Description and findings re AC1:
    - In 2018 and 2019, the SFC required institutions to estimate the effect of shifts from the yield curve considering idiosyncratic characteristics of each bank.
    - There are currently no prudential requirements relating to the IRRBB measurement by banks, including through standardized stress testing exercises, and its periodic reporting to the SFC.
- AC2: The supervisor assesses whether the internal capital measurement systems of banks adequately capture interest rate risk in the banking book.
  - Description and findings re AC2:
    - As part of supervision exercises, the SFC asked banks to calculate metrics regarding interest rate risk in the banking book expressed in terms of both profits and losses and total capital, and to indicate results of stress-tests and sensitivity analyses on the net interest margin and/or economic value of equity.
    - According to the SFC, its new regulation on ICAAP (see CP16) will encompass both Pillar 1 and Pillar 2 risks, including the IRRBB.

### Assessment of Principle 23 — overall judgment and planned actions
- Assessment: Materially non–compliant
- Comments:
  - Clear progress since the 2012 FSAP in supervision of IRRBB.
  - SFC carried out several offsite exercises and some onsite inspections since 2018, enabling better supervision of how Colombia largest banks and some medium-sized and small entities manage IRRBB.
  - Exercises are still to be completed for medium-sized and small credit institutions; a transversal exercise is planned in 2021, focusing on medium and small banks, financing companies and financial cooperatives not previously evaluated.
  - SFC identified as an emerging risk possible gaps in the management of interest rate risk in these institutions.
  - So far, SFC has not issued prudential requirements or detailed guidelines to specifically deal with IRRBB measurement, management and reporting.
  - Given average duration mismatch between assets and liabilities of credit institutions, issuance of prudential requirements and detailed guidelines is important.
  - The mandatory stress testing program (EPR) does not explicitly refer to IRRBB.
  - SFC considers establishing a formal standard on IRRBB through issuance of an External Circular in the second half of 2021 to complement and modify existing stress testing program (CBCF, Chap. XXVIII) and current requirements for management of market and liquidity risk (CBCF, chap. XXI and VI).
  - Contemplated methodology considers both earnings-based measures and changes in the Economic Value of Equity (EVE), pursuant to the BCBS principles.

### Principle 24 — Liquidity risk (EC1 and framework elements)
- Principle 24 summary:
  - The supervisor sets prudent and appropriate liquidity requirements for banks that reflect liquidity needs; supervisor determines banks have a strategy enabling prudent liquidity risk management and compliance with liquidity requirements; strategy considers risk profile and market and macroeconomic conditions; at least for internationally active banks, liquidity requirements are not lower than applicable Basel standards.
- EC1 — laws, regulations or supervisor require banks to observe prescribed liquidity requirements and monitoring tools:
  - Colombian regulatory framework for liquidity risk management has gradually converged toward Basel III liquidity standards; no difference between internationally active banks and other banks.
  - Framework elements described below.

### Liquidity Risk Indicator (IRL)
- Supervised entities must calculate and report weekly to the SFC a short-term liquidity risk indicator (IRL).
- IRL definition: ratio between liquid assets and net cash outflows, calculated over periods of 7 and 30 days and should be at least 100 percent.
- Enhancements implemented Q1 2019 via External circular 009-2018:
  - Differentiating assumed run-off rates by type of depositor in accordance with Basel III.
  - Haircuts of some liquid assets updated to reflect credit rating for BR repo transactions:
    - haircut of 15 percent for securities with a credit rating of AA or above;
    - haircut of 20 percent for securities with a rating between A+ and BBB-;
    - haircut of 50 percent for securities with a rating lower than BBB-.
- Differences vs Basel III LCR:
  - Liquid Assets:
    - Liquid assets divided into HQLA and other liquid assets (equivalent to level 2 assets under LCR); other liquid assets limited to 30 percent of total liquid assets (instead of 40 percent under LCR).
    - Investments in debt instruments issued by banks or their affiliates and investments in open collective investment funds without commitment for permanent stay are included in other liquid assets for IRL calculation, whereas not eligible under LCR; impact deemed not significant since 96 percent of total eligible assets are HQLA according to SFC.
    - RMBS excluded from liquid assets under IRL, although can be included under LCR subject to conditions and haircut; SFC considers RMBS not sufficiently liquid; impact not material given low level of securitization of banks’ credit portfolios.
  - Haircut Rates (relating to the Haircut Rates):
    - a haircut of between 2 percent and 7 percent is to be applied on domestic sovereign debt under the IRL standard, whereas such a haircut is not contemplated by the LCR standard;
    - a haircut of 20 percent is to be applied for those securities with a rating between A+ and BBB- under the IRL standard, although a 50 percent haircut is laid down by the LCR standard;
    - non-investment grade securities are eligible with a 50 percent haircut under the IRL standard although they are not eligible under the LCR standard.
  - Equivalent foreign currency assets:
    - Eligible with no limit under IRL provided haircuts for both liquidity and foreign exchange risk (12.5 percent for USD, 11 percent for EUR, and 13 percent for other currencies) have been implemented.
    - Under LCR, domestic sovereign or central bank debt securities issued in foreign currencies are eligible up to the amount of the bank’s stressed net cash outflows in that specific foreign currency.
    - IRL does not consider a limit for those securities; they represent less than 1 percent of liquid assets according to SFC.
  - Net Cash Outflows:
    - Regulatory run-off factors adjusted to reflect market conditions in Colombia between 2011 and 2017; not strictly aligned with LCR and are somewhat less conservative (e.g., deposits of supervised financial institutions receive a run-off factor of between 28 percent although a 100 percent is laid down by LCR).
    - Regulatory run-off factors complemented by run-off factors experienced by credit institutions since 2011.
    - In absence of precision in regulation, drawdowns of off-balance sheet commitments are to be calculated by each credit institution; SFC is considering introduction of a standard methodology.
    - Performing contractual inflows from retail, small business and corporate customers are to be fully included under IRL, with an adjustment by NPL ratio, while they have to be halved under LCR.
    - Term deposits maturing within the calculation period are assumed not to be renewed under IRL, while they are to be treated as demand deposits under LCR.
- Operational note: SFC assesses weekly the impact of new disbursements as part of its IRL stress testing exercise.

### Individual Exposure Index (IEI) and Consolidated Exposure Index (IEC)
- Developed by the central bank as indices of mandatory compliance relating to FX risk at short term; methodology equivalent to IRL.
- Methodology: estimate difference between Liquid Assets and Net Liquidity Requirements in each significant currency, including Colombian peso (the amount of inflows that can offset outflows being capped at 75 percent of total outflows).
- IEI:
  - Calculated as the sum of the net position in each significant currency, after net position in each significant currency has been expressed in U.S. dollars.
  - Time horizon: 7 and 30 days.
- IEC:
  - Institution must first estimate the IEI and then add all the net negative positions (in U.S. dollars) of their subordinates both inside and outside Colombia.
  - Time horizon: 30 days.
  - Purpose: consolidating institution should have sufficient liquid resources to cover liquidity need of its subordinates.

*Italic: Source — 1colea2022005 - 2020. Choosing medium and small banks, as well as financing companies and*

### 3. Net Stable Funding Ratio (CFEN)

### 3. Net Stable Funding Ratio (CFEN)

### Overview and implementation
- A longer-term liquidity indicator (CFEN, for its initials in Spanish) similar to the Basel III Net Stable Funding Ratio (NSFR) was introduced by the SFC in 2019 (External Circular 19-2019).
- The CFEN is being applied in stages:
  - beginning at 80 percent of target in March 2020 and reaching 100 percent by March 2022 for banks with assets greater than or equal to 2 percent of total banking sector’s assets;
  - for smaller banks, those thresholds are 60 percent and 80 percent, respectively.
- CFEN must be reported on a monthly basis to the SFC.
- The CFEN standard is broadly aligned with the NSFR standard, but there are differences:
  - The CFEN ratio is to be calculated on an individual basis only; the NSFR ratio should also be calculated on a consolidated basis. The SFC is analyzing to require a calculation of this ratio on a consolidated basis.

### Available Stable Funding (differences between CFEN and NSFR)
- Retail deposits:
  - considered as 95 percent stable under the CFEN standard;
  - deposits of foreign persons are only included for 25 percent of their accounting amount under the CFEN standard;
  - NSFR differentiates between stable and less stable deposits and lays down stricter rules for the latter; there is no specific treatment for deposits of foreign persons in the NSFR standard.
- Corporate deposits:
  - included for 90 percent of their accounting amount under the CFEN standard (based on the stability identified for this category in Colombia);
  - included for 50 percent under the NSFR standard.
- Transitory regime:
  - demand and term deposits of less than six months of financial institutions and collective investment funds are included for 25 percent of their accounting amount under the transitory regime;
  - these deposits will be completely excluded from March 2022 in compliance with the NSFR standard.

### Required Stable Funding (differences between CFEN and NSFR)
- Derivative products with a positive value:
  - under CFEN, they can be netted against collateral posted for variation margin purpose whatever form of collateral (i.e., securities or cash);
  - NSFR restricts the netting to cash collateral.
  - SFC highlighted that in the Colombian derivatives market, most of the collaterals constituted as variation margin are in cash and government bonds that have a high liquidity.
- Derivative products with a negative value:
  - 5 percent of the total amount of derivative products with a negative value has to be included in the calculation of the required funding calculation under the CFEN standard;
  - the NSFR standard has no such provision.

### Other requirements: SARL (Liquidity Risk Management System)
- Prudential standards with regard to liquidity risk management processes are laid down by chapter 6 of the CBCF.
- The SFC requires supervised entities to implement a Liquidity Risk Management System (SARL) to identify, measure, control, monitor and mitigate liquidity risk.
- The SFC reported to assess the correct implementation of the SARL standards at least every three to four years, or more frequently if considered an emerging risk or if warning signals are triggered (e.g., as a consequence of the stress tests performed).

### Supervisor’s monitoring tools
- Banks are required to send periodically to the SFC several reports for monitoring liquidity risk profile and dynamics:
  - Details of contractual cashflows and liquid assets for the calculation of the IRL under the standard approach (periodicity: weekly and monthly);
  - Details of available stable funding and required stable funding for the calculation of the CFEN (periodicity: monthly);
  - Information on deposits and money market operations (periodicity: daily);
  - Short-term exposure ratios for Intermediaries in the Currency Market (IMC).
- The assessors were shown both system-wide and individual dashboards developed by the SFC to monitor liquidity positions.
- The SFC has performed various top-down liquidity stress tests commensurate with its analysis of emerging risks.
- Based on these analyses, the SFC can require potentially vulnerable institutions to provide more frequent or detailed liquidity reports or perform off- and onsite supervision exercises.
- Consolidated supervision is done through planned onsite and offsite processes; cross-border inspections are coordinated with the host supervisor.
- Consolidated supervision includes:
  - periodic meetings with internationally active banks;
  - periodic meetings and information sharing with the Liaison Committee of the CCSBSO;
  - analysis of reports stating internal assessment of liquidity risk exposure within subordinates and the effect on overall liquidity risk and other risks.

### Other supervisory actions
- When a bank does not comply with minimum thresholds set for the IRL or the CFEN, it must inform the SFC without delay, explain why the liquidity indicator decreased and outline corrective measures so that:
  - the IRL exceeds the regulatory threshold within 30 days, or
  - the CFEN exceeds the regulatory threshold within 6 months (can be extended to 9 months if motivated).
- If no adjustment plan is communicated, the SFC objects to the plan, or the plan fails, the bank is not allowed to:
  - Be involved in money market operations;
  - Engage in new loans (including leasing operations);
  - Invest in financial instruments or make new acquisitions;
  - Increase credit cards’ limits (only for a breach of CFEN).
- If non-compliance persists, the SFC can take administrative measures against the bank.

### EC2 — Prescribed liquidity requirements reflect risk profile (description and findings)
- Chapter 6 of CBCF specifies that credit institutions’ SARL should be commensurate with structure, complexity, nature and size of activities.
- Both on- and off-balance sheet risks should be within the reach of the SARL.
- SFC and credit institutions should consider systemic importance and role in the financial system.
- Credit institutions are segmented into two groups depending on their share of total banking sector’s assets; smaller credit institutions are subject to lighter CFEN and stress testing requirements.

### EC3 — Supervisor determines banks have robust liquidity management framework (description and findings)
- Credit institutions are required to implement SARL (CBCF, chapter 6) to mitigate liquidity risk, including maintenance of a well-sized pool of liquid assets.
- Liquidity risk should be measured via internal models approved by the SFC and which include stress scenarios.
- Limits commensurate with stress test results and entity’s structure should be defined and monitored.
- Credit institutions should have sufficient liquidity, including a pool of liquid assets, to match needs in a time of crisis.
- Policies and processes for SARL functioning are required, including determination of limits and mitigation policies; contingency plans should be validated by banks’ boards.
- Components of SARL should be implemented at both individual and consolidated levels; stress tests analysis to be performed from each business line, portfolio and entity up to the financial conglomerate.
- Supervisor uses analysis of Board minutes and interviews to establish approval and oversight by Boards; supervisory criteria for liquidity management are published on the SFC website.

### EC4 — Liquidity strategy, policies and processes (description and findings)
- Banks are required to have an appropriate and controlled liquidity risk environment including:
  - (a) consistency of liquidity risk management policies and practices with banks’ risk appetite framework and statement; the SFC pays particular attention to this consistency;
  - (b) the liquidity risk management unit must inform daily the bank’s senior management and relevant committees of the evolution of the liquidity risk;
  - (c) banks should have information systems enabling effective SARL management; an adequate information system for quick consolidation of inflows and outflows should be in place and validated at least once a year;
  - (d) Boards are ultimately responsible for monitoring SARL implementation and liquidity risk profile; they receive monthly reports and review stress tests and approve contingency plans;
  - (e) banks’ liquidity risk management policies and processes should be regularly updated to reflect changing risk profile and external developments.
- The SFC carries out supervision through analysis of manuals and policies, evidence of compliance, onsite evidence such as live tests of systems and reports, and evidence of communication between key areas.
- Assessors were shown examples of recommendations made to strengthen liquidity management frameworks of several banks.

### EC5 — Funding strategies and policies (description and findings)
- The supervisor requires banks to establish, and regularly review, funding strategies and policies and processes for ongoing measurement and monitoring of funding requirements and effective management of funding risk. The policies and processes include consideration of how other risks (e.g., credit, market, operational and reputation risk) may impact the bank’s overall liquidity strategy, and include:
  - (a) an analysis of funding requirements under alternative scenarios;
  - (b) the maintenance of a cushion of high quality, unencumbered, liquid assets that can be used, without impediment, to obtain funding in times of stress;
  - (c) diversification in the sources (including counterparties, instruments, currencies and markets) and tenor of funding, and regular review of concentration limits;
  - (d) regular efforts to establish and maintain relationships with liability holders; and
  - (e) regular assessment of the capacity to sell assets.

*Source: 3. Net Stable Funding Ratio (CFEN), 1colea2022005 - 3. Net Stable Funding Ratio (CFEN)*

### Chapter 6 of CBCF includes a general requirement for credit institutions to design a

### 1colea2022005 - Chapter 6 of CBCF includes a general requirement for credit institutions to design a

### Liquidity risk management framework (CBCF, chapter 6)
- Credit institutions must design a SARL integrated with management of other risks that can have a direct or an indirect impact on the liquidity risk management strategy.
- Institutions are required to implement policies regarding:
  - access to funding and diversification of funding sources;
  - periodic review of the funding strategy by executive management.
- Requirements include:
  - measure liquidity needs from projected outflows and inflows at different time horizons under normal and stress conditions;
  - establish limits so available liquidity or the pool of liquid assets outmatch liquidity needs in a time of stress;
  - liquidity risk management unit must monitor appropriate balance between operations and level of available liquid assets;
  - set and monitor concentration limits by counterparty, economic sector, instrument, tenure and currency.
- Supervisory assessment of liquidity management includes review of manuals, risk committee and Board minutes, and interviews with senior management and staff.
- Supervisory guidance highlights that reputation and capital position may affect liquidity; stress scenarios for capital and liquidity should be complementary.

### Contingency funding plans (EC6)
- Supervisor determines banks must have robust liquidity contingency funding plans covering a range of stress environments without reliance on lender of last resort.
- Contingency plan requirements:
  - formally articulated and adequately documented;
  - set out strategy for addressing liquidity shortfalls in a range of stress environments;
  - establish clear lines of responsibility and communication plans (including communication with the supervisor);
  - regularly tested and updated to ensure operational robustness.
- Banks must maintain and review, at least once a year, liquidity risk mitigation mechanisms including contingency plans.
- Contingency plans should be based on stress test results and contemplate additional collateral needs from market price variations.
- Possible funding sources to include (with required estimations where indicated):
  - investors for the banks’ debt instruments and term deposits, with an estimation of the related amount and time needed to collect the funds;
  - money market financing, including through repos, with an estimation of the related amounts, collateral and counterparties;
  - new and/or rollover of deposits and other credits the banks have;
  - disposal of assets and loans, with an estimation of possible losses the bank might occur;
  - liquidity support from the parent entity, shareholders or other related parties, with an estimation of the opportunity and maturity of those funds and the related cost;
  - possible liquidity support from the BR, and related requirements, costs, opportunity and maturity of those funds and the related cost — specified as last resort since BR’s contingent facilities do not constitute a committed line of credit.
- Plans should include a communication plan to the supervisor and the public, processes for prioritisation of actions, and clear activation and crisis management group arrangements.
- SFC has issued requirements to several credit institutions to enhance and test contingency plans; corrective requirements included actionable plans to enhance liquidity position and modify procurement strategies.

### Liquidity stress testing (EC7)
- Banks are required to include a variety of short-term and protracted bank-specific and market-wide liquidity stress scenarios (individually and in combination) using conservative and regularly reviewed assumptions.
- Stress testing program (EPR) requirement since 2015:
  - objective: measure effects of SFC-determined stress scenarios on capital, liquidity, assets and liabilities;
  - liquidity stress tests aim to identify and measure exposures to future liquidity crises under different time horizons, including impacts on cashflows, liquidity position, earnings, profitability and solvency.
- Results of liquidity stress tests must be used to:
  - adjust liquidity risk management strategies, policies and positions;
  - develop effective contingency funding plans;
  - assess viability of business plans (CBCF, chapter 28).
- Boards and executive management are required to actively discuss stress test results and associated corrective actions.
- Internal liquidity stress tests frequency should be consistent with banks’ liquidity risk profile; banks must annually run stress scenarios provided by the SFC.

### Foreign currency liquidity (EC8)
- Central bank rules and prudential indicators limit foreign exchange liquidity risk (Administrative Act DODM-361 (2018) and external resolution n01 (2018)).
- Examples of supervisory monitoring tools and indices:
  - IEI estimates total exposure to short-term foreign exchange risk in a set of currencies, then computes indicators in U.S. dollars to monitor liquidity needs in each significant currency;
  - IEC monitors that a bank has sufficient excess liquidity to cover liquidity shortfalls in Colombian and foreign subsidiaries by adding its own IEI with any net negative position of its subsidiaries;
  - IRC+ and IRC- indices control currency mismatches at individual or consolidated levels by separating positive and negative net positions in different currencies;
  - IMC institutions must disclose net foreign exchange position (PP), spot foreign exchange position (PPC) with maturities shorter than 3 days, and gross leverage position in foreign exchange (PBA);
  - PICE ratio (see CP 22) tracks overall investments in subordinates as a proportion of total capital by each IMC.
- SFC requires monitoring of cashflow mismatches for foreign currencies in aggregate and setting associated limits, considering the ability to transfer liquidity across jurisdictions and legal entities (CBCF, chapter 6).
- In practice, SFC did not observe a high level of foreign currency liquidity risk.

### Encumbered assets (Additional criterion AC1)
- No explicit SARL regulatory requirement specifically for management of the level of encumbrance of assets or for setting limits.
- Two regulatory constraints affecting encumbered assets:
  - CFEN ratio: SFC requires banks to fund 100 percent of all assets encumbered for a period of more than one year and 50 percent of high quality assets encumbered for a period of between six months and one year.
  - IRL ratio: encumbered assets are not considered part of High-Quality Liquid Assets.
- These constraints place limits on the ability to hold encumbered assets by increasing funding requirements and excluding them from HQLA.

### Assessment of Principle 24 (liquidity)
- Assessment: Largely compliant.
- Observations and recommendations:
  - SFC has system-wide and individual dashboards and supervisory tools for ongoing monitoring of banks’ liquidity.
  - Comprehensive framework requires calculation and monitoring of several liquidity ratios, including IRL (short-term liquidity ratio) aligned further with LCR in 2018 and CFEN (structural liquidity ratio) derived from NFSR introduced in 2019.
  - Several regulatory parameters in ratio computations are not fully aligned with Basel III; many run-off factors are more favorable than LCR standard.
  - Recommendation: further align local LCR and NSFR ratios with international standards and require NSFR to be calculated at consolidated level.

### Operational risk and business continuity (Principle 25; EC1–EC5)
- SARO (operational risk management framework) mandatory since 2007 (CBCF, chapter 23).
  - SARO must be commensurate with bank’s strategy, structure, size, social object, and support activities, including outsourcing.
  - Includes mandatory processes for identification, assessment and control of operational risks and aims to ensure residual risks are within tolerance levels.
- Supervisory assessment methods:
  - onsite inspections (six onsite inspections in credit institutions included this topic in 2019), interviews and tests;
  - offsite supervision using tools to measure inherent cyber risk and maturity of Information Security, Cybersecurity and Business Continuity management.
  - SFC proactive in 2020 issuing specific instructions to strengthen operational risk management during the pandemic.
  - SFC informs monitored entities about cyber threats and requires incident reporting; incidents affecting service or information security may trigger inspections.
- Governance and Board responsibilities (EC2):
  - Board must establish SARO policies, approve operational risk manual and updates, rule and monitor operational risk profile, establish procedures aligned with risk tolerance, act on periodic SARO reviews, and provide resources.
  - SFC reviews that Boards receive adequate reports and training, especially on information security, cybersecurity and business continuity.
- Management responsibilities and integration (EC3):
  - Senior management must implement SARO, monitor implementation, present updates to Board, ensure operational risk division exists, ensure controls operate effectively, adopt measures to maintain risk profile within tolerance, approve business continuity plans, and evaluate and report operational risk matters to the Board at least twice a year.
  - SFC assesses effectiveness via onsite exercises and relies on internal audit evaluations.
- Disaster recovery and business continuity (EC4):
  - Banks required to define, implement, test and maintain business continuity processes including prevention, emergency response, crisis management, contingency plans and resumption capabilities (CBCF, chapter 23, §3.1.3.1).
  - BR periodically summons banking establishments to participate in application tests and cash provision simulations of high-impact events.
  - SFC carried out transversal maturity assessment in 2018 and 2019 using questionnaires; recommendations included:
    - evaluate migrating main and alternate processing centers to facilities meeting ANSI/TIA 942, TIER 3 or higher or equivalent standards;
    - locate main and alternate data processing centers so the same event does not affect both;
    - execute functional, comprehensive and simultaneous tests of critical services including technological platforms, human resources, physical infrastructure and third parties;
    - operate in the alternate processing center during periods to verify adequate execution of critical processes;
    - define and execute a continuity test schedule that includes operation from the Alternate Operation Center (CAO) of all critical processes identified in the BIA, considering cyber-attacks, natural disasters, lack of human resources and process failures.
  - SFC plans to perform the transversal supervisory exercise every two to three years.
  - SFC complemented transversal exercise with onsite missions to review disaster recovery and business continuity plans in detail.
  - For Covid-19, SFC published transitory external circular n°008-2020 in March 2020 requiring contingency plans with short and medium term actions and enhancements to IT infrastructure; SFC concluded entities implemented action plans enabling continued operations during COVID-19 crisis.
- IT risk and infrastructure (EC5):
  - Comprehensive and progressively extended requirements relative to IT policies, systems and security management were in place; banks must ensure IT infrastructure meets current and projected business requirements under normal and stress conditions to ensure data and system integrity, security and availability and support integrated risk management.

*Source: Chapter 6 and related sections of the provided IMF / SFC supervisory assessment text.*

### part 1, title 2, chapter 1 and CBJ, part 1, title 1, chapter 4). Banks are required to

### 1colea2022005 - part 1, title 2, chapter 1 and CBJ, part 1, title 1, chapter 4). Banks are required to

### IT governance, policies and controls
- Banks are required to establish, implement, document and communicate IT policies and define the underlying necessary resources, processes, methodologies and controls.
- Information security policies, whose one of the main objectives is to protect data confidentiality, are mandatory.
- Prudential requirements should be included in banks’ policies and processes on information management.
- Banks should:
  - have hardware, software and telecommunication systems, as well as adequate processes and controls, which enable them to provide customer services and manage information with appropriate security and quality;
  - take appropriate steps to ensure minimum services to customers and have appropriate IT support;
  - have separate development, testing and production developments for their software programs; and
  - implement a system for the analysis of IT vulnerabilities including penetration tests; a consolidated report of vulnerabilities should be produced automatically at least twice a year and remedial actions should be taken.
- Technology management is a significant activity to be assessed in determining a credit institution’s risk profile; analysis includes inherent risk, effectiveness of controls, and conclusions and recommendations. Adequacy of IT systems used in relation to each significant activity should be assessed.

### Cybersecurity
- The SFC published in 2018 specific requirements relating to the management of cybersecurity (CBJ, part 1, title 4, chapter 5).
- Supervised entities must have Board‑approved policies, procedures, technical and human resources to manage cybersecurity risks, including prevention, detection, management, communication, and recovery from a cyber-attack.
- Requirements include:
  - testing business continuity plans under a cyber-attack scenario;
  - having a dedicated unit for cyber-security management.
- Based on information provided by supervised entities at end 2019, the SFC concluded:
  - 60 percent of the questioned entities comply with all the supervisory requirements published in 2018;
  - 37 percent comply with between 70 percent and 99 percent of those requirements; and
  - 2 percent comply with less than 70 percent of those requirements.
- SFC actions and tools:
  - 2020 reviews of banks’ cybersecurity maturity and 2018 and 2021 assessments of inherent cyber risk profile using specially designed tools;
  - issuance of recommendations by operational risk experts and monitoring of implementation of action plans;
  - 2020 pilot exercise using a market tool to identify website vulnerabilities of banks and other supervised entities, with recommendations to correct them; planned renewal and expansion in 2021 with another market tool;
  - 2019 publication of requirements for entities using cloud computing services (external circular 005 (2019)) and control of core and accounting processes taken to the cloud via information requests to credit institutions;
  - expanded SFC team of experts in cybersecurity, business continuity and project management to develop new regulations/guidelines and support onsite inspection teams.

### EC6 — Information systems for operational risk monitoring and reporting
- EC6 requirement: supervisor determines that banks have appropriate and effective information systems to:
  - (a) monitor operational risk;
  - (b) compile and analyze operational risk data; and
  - (c) facilitate appropriate reporting mechanisms at the banks’ Boards, senior management and business line levels that support proactive management of operational risk.
- Description and findings:
  - General requirement for supervised entities to have information systems commensurate with size and activities (CBCF, chapter 23, §3.2.7).
  - Information systems and processes must enable entities to:
    - monitor periodically their operational risk profile and exposure to losses;
    - compile necessary information to feed the register of operational loss events, under the coordination of the Operational risk unit; minimum data to be recorded enhanced with external circular 025 (2020);
    - report, at least twice a year, to the Board of Directors about the evolution of operational risk, residual exposure, and preventive and corrective actions implemented.
  - The SFC assesses technological resources and reports on operational risk and cybersecurity to senior management and the Board as part of risk management and supervisory exercises, ensuring entities have:
    - necessary IT tools to support identification, measurement and documentation of risks, recording of events, accounting disclosure and report generation;
    - adequate processes for reporting events, monitoring action plans, and sufficient competent human resources for SARO administration;
    - a culture for adequate risk management.
  - SFC has issued recommendations for adequate IT systems supporting operational risk management (identification, measurement, control, monitoring, register of operational loss events, indicators and action plans).
  - External circular 025 (2020) required enhancement of event recording with new data fields.

### EC7 — Reporting mechanisms to the supervisor
- EC7 requirement: supervisor requires banks to have appropriate reporting mechanisms to keep the supervisor apprised of developments affecting operational risk.
- Description and findings — communication channels and reporting requirements:
  - (a) When events cause unavailability of channels, banks report the incident by telephone to the Office for Operational Risk and Cybersecurity and then report it to riesgooperativo@superfinanciera.gov.co (CBJ, Part I, Title II, Chapter I, §2.3.3.1.23);
  - (b) Entities must subsequently report causes, impact, materialized risks, violated controls, information provided to financial consumers, the Internal Audit report on the event and activities carried out to fix the incident;
  - (c) Entities must send a quarterly report about the monthly availability of distribution channels (local branches, website, etc.) and the methodology used to calculate it (CBJ, Part I, Title II, Chapter I, §2.3.3.1.22);
  - (d) Entities shall send a risk analysis prior to providing services through a new distribution channel (CBJ, Part I, Title II, Chapter I, §2.3.4.10); similarly, specific information must be sent prior to using cloud computing services (CBJ, Part I, Title I, Chapter VI, Section 6);
  - (e) Value of operational risk events and related expenses must be reported monthly to the SFC in the expense accounts of the income statement (CBCF, Chapter 23, §3.2.8.3);
  - (f) Statutory Auditors are required to report to the SFC relevant risks not being adequately administered by management that significantly impact the corporate purpose (see BCP 27).
- SFC monitoring capabilities:
  - automated daily test on website availability, review of complaints, quarterly review of operational losses reported, and review of operational event registers enable checking of reported information or lack thereof.
- Supervisory practice: supervised entities sometimes voluntarily inform the SFC of new products/services launches that do not require authorization.

### EC8 — Outsourcing risk management
- EC8 requirement: supervisor determines that banks have appropriate policies and processes to assess, manage and monitor outsourced activities covering due diligence, structuring, managing and monitoring risks, ensuring an effective control environment, and contingency planning; contracts/SLAs must clearly allocate responsibilities.
- Description and findings — minimum requirements (for distribution channels or access to confidential information, CBJ, part 1, chapter 2, title 1, §2.3.6):
  - define criteria and procedures for selecting potential service providers and outsourced activities;
  - include in legal agreements provisions related to levels of service and operation, confidentiality, property rights, restrictions in software used by the service provider, norms for physical and IT security, processes when there is evidence of alteration or manipulation, processes and controls over communication and destruction of information; supervised entities should establish and communicate to internal audit processes to check compliance with these clauses;
  - require service providers to have documented contingency and business continuity plans; supervised entities should check compatibility of those plans with legal agreements;
  - have processes for physical identification of service providers;
  - implement robust encryption mechanisms for exchange of confidential information with service providers.
- July 2020 SARO additions:
  - supervised entities must: (i) carry out a risk assessment to determine activities/processes to outsource; (ii) understand operational risk from outsourced activities; (iii) include outsourcing risks in their risk strategy; (iv) determine what outsourced activities/processes are critical.
  - For critical outsourced activities/processes, supervised entities should:
    - define selection criteria and procedures for potential providers;
    - include provisions in legal agreements on obligations, service levels (including emergencies), risk management affecting provider compliance, and confidentiality;
    - manage risks when third parties provide services to several entities;
    - have processes to monitor provider compliance with contractual obligations;
    - include outsourced activities review in risk management and internal audit scopes.
- Common outsourced services: IT support, communication and network services, datacenter management, IT security services, cash transportation, credit scoring services, and collection services.
- Observations:
  - Covid-19 tested many outsourced activities due to increased digital transactions.
  - SFC assesses management of outsourcing risks through onsite visits and meetings with banking service providers; visits to IT service provider installations conducted to understand service conditions.
  - Launched in 2021 a transversal supervisory exercise assessing how banks check operational and financial performance of critical service providers in the pandemic context; relevant recommendations sent to assessed entities.

### AC1 — Identification of common points of exposure
- AC1 requirement: supervisor regularly identifies common points of exposure to operational risk or potential vulnerability (e.g., multiple banks outsourcing to a common provider).
- Description and findings:
  - SFC developed a tool for supervised entities to identify and evaluate their service providers; tool enables identification of common exposure points such as trading systems, trading clearing and settlement systems, interbank transfers through Swift and CUD, infrastructure providers, custodians, centralized securities deposits, securities transporters, payment gateways, cloud service providers, data processing centers, cybersecurity and data processing providers, call centers, ATM providers, servers, equipment or communications links, workstations, software, and core systems.
  - Although third‑party providers are not supervised entities, SFC has met with relevant providers to assess their ability to provide services simultaneously to multiple supervised entities.
  - SFC recommended credit institutions carry out joint continuity plan tests with critical suppliers to improve business continuity maturity.

### Assessment and overall findings (Principle 25 and Principle 26 introduction)
- Assessment of Principle 25: Compliant.
- Comments:
  - Since 2018, SFC enhanced the operational risk framework for supervised entities, including instructions to strengthen information security, cybersecurity, operations performance, recording of operational events and outsourcing management.
  - SFC developed tools and launched the first evaluation of banks’ cybersecurity and business continuity management in 2018 and 2019; a new measurement is planned in the second half of 2021.
  - SFC was proactive in 2020 issuing specific instructions to strengthen operational risk management during the pandemic and followed up on implementation status.
- Principle 26 (Internal control and audit) introduced as the next assessed principle, emphasizing adequate internal control frameworks covering delegation, separation of functions, reconciliation, safeguarding assets, and independent audit and compliance functions.

### EC1 — Internal control frameworks (introductory findings)
- EC1 requirement: laws, regulations or the supervisor require banks to have internal control frameworks adequate to establish a properly controlled operating environment, covering organizational structure, accounting policies and processes, checks and balances, and safeguarding assets.
- Description and findings:
  - Supervised entities are required to have an internal control system (SCI) commensurate with their size and activities (CBJ, part 1, title 1, ...).

*Source: 1colea2022005 - part 1, title 2, chapter 1 and CBJ, part 1, title 1, chapter 4). Banks are required to (PDF).*

### chapter 4, §1. & 2.). The SCI should achieve the following objectives with a

### 1colea2022005 - chapter 4, §1. & 2.). The SCI should achieve the following objectives with a

### Objectives of the SCI
- The SCI should achieve the following objectives with a reasonable level of assurance:
  - (i) improve the efficiency and effectiveness of the entity’s operations;
  - (ii) prevent and mitigate frauds (both internal and external);
  - (iii) ensure an adequate management of risks;
  - (iv) strengthen the reliability and opportunity of the information produced by the entity; and
  - (v) ensure that norms and regulations are duly complied with.

### Governance responsibilities
- Banks’ Boards:
  - Explicitly responsible for the definition and approbation of general policies related to the SCI (CBJ, part 1, title 1, chapter 4, §6.1.1.).
  - Responsible for monitoring implementation of SCI policies.
- Senior management:
  - Responsible for implementing Boards’ strategies and policies related to the SCI (CBJ, Part 1, Title 1, Chapter 4, §6.1.3.).

### Main SCI requirements
- (a) Organizational structure:
  - Determination of an organizational structure with clear levels of authority and responsibility.
  - Further detailed in SFC risk management frameworks (SARC, SARM, SARL, SARO and SARLAF).
  - Example: SARM requires supervised entities to have separate and independent front, middle and back offices.
- (b) Accounting policies and processes:
  - Requirement for accounting policies and processes and proper monitoring and control, including validation of data quality, inventories and analyzes of the entity’s assets.
- (c) Control activities:
  - Implementation of control activities across all business areas, operations and processes, including IT controls, access restrictions, physical controls, and segregation of duties.

### SFC supervisory assessments and methodology
- The SFC assesses the internal control system and internal audit in each onsite and offsite supervision exercise.
- Risk-based supervision methodology includes assessment of supervisory functions:
  - Board of Directors, Senior Management, operational management and risk management, financial analysis, and compliance.
- Assessment performed at both bank level and for each significant activity (performance).
- Supervisor assesses:
  - Adequacy of organizational structure to allow governance;
  - Existence of policies, procedures, and guidelines necessary to carry out assigned roles; and
  - Adequate internal control and monitoring by Internal Audit.

### EC2 — Balance and capability of control functions (Description and findings)
- Supervisor determines appropriate balance in skills and resources of back office, control functions and operational management relative to business origination units.
- Supervisor determines staff of back office and control functions have sufficient expertise and authority (and, where appropriate, access to the bank’s Board) to act as effective checks and balances.
- Requirements for staff in trading, risk management and control, back office, accounting and audit of financial market operations:
  - Deep knowledge of negotiated products and administrative/operational processes linked to the SARM (CBCF, chapter 21, §6.1.2.).
  - Risk monitoring/control staff should have deep knowledge of financial markets, good command of risk valuation methods and information tools.
  - Remuneration and training policies should ensure sufficient capacity for risk monitoring/control and back office staff.
- Middle office (market risk management) reporting:
  - The unit shall report twice a year to the risk committee (or the bank’s Board) the entity’s market risk exposure, limit breaches, and operations objected for non-alignment with SARM requirements.
- SFC assesses operational management, control and supervisory functions through onsite and offsite exercises.
- Supervisory expectations publicly stated: financial analysis, compliance, risk management, internal audit, senior management, and Board of Directors.
- Evaluation includes compliance with supervisory criteria and effectiveness of supervisory functions.

### EC3 — Compliance function (Description and findings)
- EC3 requires an adequately staffed, permanent and independent compliance function that assists senior management to manage compliance risks; staff should be suitably trained, experienced and have sufficient authority; Board oversight required.
- Findings:
  - No specific regulatory requirement to have a segregated compliance unit in SCI standard; in practice:
    - Small entities: compliance ordinarily assumed by legal department.
    - Bigger entities: dedicated compliance units exist (e.g., “Regulatory Control” or “vice presidency for Legal and Regulatory Compliance”).
  - Legal, regulatory and supervisory expectations include:
    - Directors shall promote strict observance of regulatory and statutory provisions (Art. 23, Ley 222/95).
    - Compliance with regulatory provisions part of mandatory opinion delivered by the statutory auditor of credit institutions.
    - Directors to put in place structure, procedures and processes enabling compliance.
  - CBJ provisions relating to compliance (part 1, title 4, chap. 5):
    - SCI should aim to ensure compliance with norms and regulations (§2.5);
    - Risk management fundamental to achieve compliance (§4.2.11);
    - Board should analyze reports by the “compliance official” whose functions relate exclusively to AML/CFT risk (§6.1.1.1.14);
    - Internal audit responsible for assessing quality and adequateness of systems to ensure compliance (§6.1.4.2.2.5.3.3).
  - SFC published assessment criteria on its website to evaluate effectiveness of compliance function:
    - Adequacy of organizational structure (head of compliance should have sufficient authority and direct access to the Board; independence from business areas).
    - Adequacy of resources and staff.
    - Adequacy of oversight by Boards and executive management.
    - Detailed internal guidelines complement published criteria.
  - SFC actions to assess effectiveness of compliance function:
    - Discuss with management and Board members, including head of compliance;
    - Review entity’s practices to detect/resolve compliance deficiencies;
    - Review independent reports on compliance function;
    - Review exchanges between the entity and control organisms.

### EC4 — Internal audit independence and scope (Description and findings)
- EC4 requires an independent, permanent and effective internal audit function charged with:
  - (a) assessing whether existing policies, processes and internal controls are effective, appropriate and sufficient; and
  - (b) ensuring that policies and processes are complied with.
- SFC regulatory requirements (CBJ, title 1, chapter 4, §6.1.4):
  - Internal audit to be effective and add value by assessing and enhancing efficacy of risk management, controls and corporate governance.
  - Internal audit required to present, at least annually, a report summarizing effectiveness of internal control and risk management systems, comments on quality of compliance systems, recommendations to address significant deficiencies, and implementation status of recommendations.
- SFC assesses internal audit at least every four years as part of risk-based approach and published criteria for assessment.
- SFC assessment actions:
  - Discuss with management and Board members, including head of internal audit and external auditors;
  - Review how Audit Committee manages significant findings and measures implemented by management;
  - Review internal audit’s practices and reports;
  - Review audit plans and working files.
- 2020 SFC exercise:
  - Assessed internal audit components and implementation based on meetings with 35 entities.
  - Result: SFC improved its rating of supervised entities’ internal audit function in 31 percent of the cases and promoted transition from compliance audits toward risk-based audits.
- SFC engagement with internal auditors:
  - Requires internal auditors to provide information and conduct verifications on supervisory interest matters.
  - Holds meetings with internal auditors at least once a year to review past year results and next year audit plan.

### EC5 — Internal audit resources, independence and remit (Description and findings)
- EC5 expectations:
  - (a) sufficient resources, suitably trained staff with relevant experience;
  - (b) appropriate independence with reporting lines to the Board or audit committee and status to ensure senior management acts on recommendations;
  - (c) kept informed timely of material changes to risk management strategy, policies or processes;
  - (d) full access to staff, records, files or data of the bank and affiliates;
  - (e) methodology identifying material risks;
  - (f) prepares an audit plan based on its own risk assessment and allocates resources accordingly;
  - (g) authority to assess outsourced functions.
- Findings:
  - Responsibilities and activities of internal audit should be formally defined and approved by the Board (CBJ, title 1, chapter 4, §6.1.4.2.).
  - Audit Committee required to supervise internal audit activities, ensure independence and adequacy of resources.
  - Internal audit should discuss unresolved disproportionate residual risks with executive management or the Board.
  - Executive management should grant internal audit access to data, personnel and other relevant information.
  - Internal audit required to annually prepare an audit plan based on risk assessment, considering operations and relationships with affiliates.
  - No explicit SCI standard mention on training of internal audit staff, timely notification of material changes to risk management strategy, or authority to assess outsourced functions; however, SFC assessment criteria include these aspects and are published on SFC website.
  - SFC priority for 2020: strengthen internal control functions, assess corporate governance structures and appropriately supervise internal audit.

### Assessment of Principle 26
- Compliance status: Compliant
- Comments:
  - Regulatory standards in place regarding internal control and audit functions; to be updated in the first half of 2022.
  - Supervisory criteria against which SFC assesses banks’ supervision functions, including compliance and internal audit, are published on its website.
  - SFC meets periodically with internal auditors and follows up on internal audit results.
  - SFC carried out in 2020 a dedicated exercise with 35 credit institutions to assess components of internal audit function and performance.

### Principle 27 — Financial reporting and external audit (EC1–EC3 findings)
- Principle 27: Supervisor determines banks maintain adequate and reliable records, prepare financial statements in accordance with internationally accepted accounting policies/practices, publish information that fairly reflects financial condition and performance with independent external auditor’s opinion; supervisor determines adequate governance and oversight of external audit.

- EC1 — Board and management responsibility for financial statements:
  - Since December 2015, credit institutions required to prepare and report financial statements pursuant to applicable IAS and IFRS standards (law 1314 (2009) and DUR 2420 (2015)).
  - International standards incorporated into Colombian legislation through a dedicated annex to DUR 2420, updated annually to reflect IAS/IFRS modifications.
  - Last update made in December 2020 (decree 1432 (2020)); a new update expected at year-end 2021 to incorporate latest Code of Ethics.
  - Management responsible, prior to issuing financial statements, to ensure five conditions are met (DUR 2420 (2015), annex 6, Art. 3):
    - (i) existence;
    - (ii) integrity;
    - (iii) rights and obligations;
    - (iv) valuation; and
    - (v) presentation and disclosure.
  - Credit institutions required to maintain proper recordkeeping including date, origin, description and involved accounts (DUR 2420 (2015), annex 6, Art. 7).
  - SFC published detailed IT systems and controls requirements for accounting data (CBJ, part 1, title 2, chapter 1 and CBJ, part 1, title 2, chapter 4).

- EC2 — External auditor opinion and standards:
  - All entities supervised by the SFC must have a statutory auditor (revisor fiscal) appointed by the Meeting of Shareholders (EOSF, Art. 79).
  - Entities required to establish financial statements at least once a year, presented with statutory auditor opinion (Code of Commerce, Art. 445 and 446).
  - Since January 2016, credit institutions’ statutory auditors shall perform duties pursuant to applicable international auditing and assurance standards (law 1314 (2009) and DUR 2420 (2015)).
  - International auditing standards incorporated into Colombian legislation via annex to DUR 2420, regularly updated.

- EC3 — Valuation practices and fair value estimation:
  - IAS/IFRS framework is reference for credit institution financial reporting.
  - Significant difference: for individual accounts, credit institutions should not follow IAS 39/IFRS 9 principles relating to loan portfolio impairment and classification/measurement of financial instruments; they must follow SFC instructions (DUR 2420 (2015), Art. 1.1.4.1.2).
  - Specifics:
    - CBCF chapter 1: financial instruments classified into three categories based on IAS 39: held for trading, available for sale, held to maturity; credit derivatives valued daily at fair value.
    - SARC prescribes individual provisions against incurred credit loss and possible credit risk deterioration (counter-cyclical provisions); Colombian loan loss provisioning regime not totally aligned with IFRS 9 impairment provisions.
    - COVID-19 measures: SFC allowed credit institutions to make “aggregate additional provisions” in 2020 and 2021, as well as “accrued interest provisions,” temporarily narrowing the gap with IFRS 9.
    - Colombian banks must add counter-cyclical provisions to individual provisions for credit loss.
  - SFC conducted a COLGAAP–IFRS comparison in 2020 and did not consider differences material.
  - URF and SFC work plan for next two years includes removal of remaining deviations from IFRS for individual credit institutions.
  - Compliance with SFC requirements on classification, measurement and accounting of financial instruments for individual financial statements is checked by bank’s external auditors (CBCF).

*Source: chapter 4, §1. & 2., 1colea2022005.*

### chapter 1, Art. 9.1). More generally, as mentioned in EC2 above, the bank’s external

### chapter 1, Art. 9.1). More generally, as mentioned in EC2 above, the bank’s external

### External audit standards and supervisory training
- External auditors are required to consider the International Standards on Auditing (ISA) when performing their duties, including:
  - ISA 540 on “Auditing Accounting Estimates, Including Fair Value Accounting Estimates, and Related Disclosures.”
  - ISA 200 on “Overall Objectives of the Independent Auditor.”
  - ISA 315 on “Identifying and Assessing the Risks of Material Misstatement.”
- The SFC reported it rigorously reviews reports elaborated by financial institutions and, through its assessment of their financial analysis and compliance functions, makes sure that the information provided is in accordance with that audited by the statutory auditor.
- Training and capacity building:
  - The SFC hired in 2014-2015 KPMG and Los Andes University for training supervisors in charge of the supervision of financial institutions in IFRS related matters.
  - Since then, supervisors have benefited from continuous training in IFRS.
- Reporting scheme changes:
  - Since 2015, the SFC modified the scheme for collecting information from financial institutions, adapting it to IFRS. This scheme allows controlling all incoming information and rejecting reports that deviate from the requested standards.
  - The SFC informed assessors that, in some instances, it sanctioned entities which failed to correct deficiencies in their regulatory reporting process.

### Legal/regulatory scope of audits (EC4)
- Laws or regulations set, or the supervisor has the power to establish, the scope of external audits of banks and the standards to be followed; these require the use of a risk and materiality based approach in planning and performing the external audit.
- On top of international standards, SFC has established additional obligations for statutory auditors with regard to its supervised entities (CBJ, part 1, title 1, chapter 3, section 3), elaborating and making precisions on articles 207 to 209 of the Code of Commerce.
  - This standard is partly outdated and the SFC has a plan to update it, together with the SCI standard, in the first half of 2022.
- Statutory auditors are required to:
  - express their opinion regarding the quality and reasonableness of the financial statements and other accounting information; to this end, external auditors must gather sufficient evidence of the operations performed;
  - verify throughout the year the criteria and procedures used to carry out the accounting, the management of accounting records, books, archives and other documents, not only with regard to the entity, but also with regard to the resources of third parties that it administers;
  - verify periodically the existence of assets, the adoption of adequate measures for the protection of the capital and whether or not these are commensurate to the risks assumed;
  - evaluate the internal control system of supervised entities, including the systems for the management of risks;
  - report irregular acts or material deficiencies in supervised entities’ SAR to their representatives or decision making bodies and, in case those deficiencies are not adequately addressed, they shall be reported to the SFC.

### Audit coverage expectations (EC5)
- Supervisory guidelines or local auditing standards determine that audits cover areas such as:
  - the loan portfolio;
  - loan loss provisions;
  - nonperforming assets;
  - asset valuations;
  - trading and other securities activities;
  - derivatives;
  - asset securitizations;
  - consolidation of and other involvement with off-balance sheet vehicles; and
  - the adequacy of internal controls over financial reporting.
- Description and findings re EC5:
  - The CBJ establishes the general functions of the statutory auditor covering, among others, the review of the adequacy of internal control systems and their compliance with SAR regulations.
  - Statutory auditors are required to report to the SFC:
    - at least twice a year, their work relating to the compliance of the supervised entity with SARC instructions (CBCF, chapter 1, section 9); SARC includes instructions on loan classification and provisioning; and
    - any material deviation with regard to the way the supervised entity classifies, valuates, and accounts its investments in financial instruments (CBCF, chapter 1, ...).

*Source: chapter excerpt from original IMF PDF content unit.*

### section 9).

### 1colea2022005 - section 9)

### EC6 — Supervisor power over external auditors
- The supervisor (SFC) authorizes appointment of statutory auditors (EOSF, Art. 326.2) and performs a fit & proper test covering suitability, experience, conflicts of interest, and human and technical resources.
- Objective requirements and subjective qualities must be maintained during the auditors' tenure.
- Over the last five years the SFC has rejected the appointment of nine statutory auditors mainly for lack of availability or lack of experience.
- The SFC has the power to remove and impose sanctions on statutory auditors who fail to comply with duties and the law (EOSF, Art. 208 & 209).
- Note: some aspects of external control are not specifically covered, in particular derivatives, asset securitizations, consolidation of and other involvement with off-balance sheet vehicles.

### EC7 — Auditor rotation
- Supervised entities must include contract provisions requiring individual persons performing the audit to rotate at least every five years; auditors cannot return to audit the same entity for a minimum period of 2 years (CBJ, title 1, chapter 3, section 3, Art. 3.3.1.4.2).
- SFC reports that statutory auditors rotate on average every four years and has recommended action in a few exceptions where auditors served more than five years.
- Colombian Code of Best Practice of Corporate Governance recommends a maximum contract term with the auditing firm ranging between 5 to 10 years to safeguard independence (recommendation 29.9).
- The SFC assesses yearly compliance with the Code.

### EC8 — Meetings between supervisor and audit firms
- Meetings with statutory auditors are common and may be convened anytime, especially during restructurings or significant operations.
- Supervisors may meet auditors to discuss material information regarding banking operations.
- SFC increasingly requests direct involvement of statutory auditors in supervisory matters, such as:
  - verification of correct implementation of new regulations on capital adequacy;
  - adjustments in disclosure of risks or accounting records.

### EC9 — Auditor reporting to supervisor
- External auditors have a duty to report matters of material significance to the supervisor (Code of Commerce, Art. 207.3).
- Reporting requirements detailed in CBJ include:
  - reporting of crisis situations that materially affect the supervised entity’s ability to perform (CBJ, title 1, chapter 3, section 3, Art. 3.1.3); auditors making such reports cannot be held liable for breach of professional secret;
  - immediate reporting of material deficiencies in supervised entities’ SAR if not adequately addressed (CBJ, title 1, chapter 3, section 3, Art. 3.1.8);
  - reporting (directly or via the bank’s administration) of additional information necessary to understand the bank’s situation (CBJ, title 1, chapter 3, section 3, Art. 3.1.10.5);
  - annual communication of a report including main observations on audited accounts, observed weaknesses and their significance, comments and conclusions from bank administration and the auditor (CBJ, title 1, chapter 3, section 3, Art. 3.3.3.4).
- Laws/regulations provide that auditors reporting in good faith cannot be held liable for breach of confidentiality.

### AC1 — Access to auditors’ working papers
- SFC has the power to access external auditors’ working papers, electronic documentation, files and user manuals when required in exercise of legal powers (CBJ, Part I, Title I, Chapter III, Art. 3.3.2.3).
- Although audit evidence and work papers are the property of the statutory auditor, they must be made available to the SFC upon request.

### Assessment of Principle 27
- Compliant.
- Comments:
  - International accounting and auditing standards are in force; since December 2015 credit institutions must prepare and report financial statements pursuant to applicable IAS and IFRS standards.
  - One significant exception: in individual accounts, credit institutions do not follow IAS 39 and IFRS 9 provisions relating to the loan portfolio and its impairment, and classification and measurement of financial instruments; they follow SFC instructions.
  - The Colombian regime for loan loss provisioning is not totally aligned with IFRS 9 impairment provisions; main difference relates to the introduction of macroeconomic variables under IFRS 9 which increases provision requirements.
  - The Colombian Public Accounting Technical Advisor (CTCP) plans to review in 2021 this exception to the IAS/IFRS framework.
  - Recommendations:
    - remove the last exception to the international accounting framework or at least complement the forward-looking approach in loan loss provisioning at individual level under COLGAAP by introducing macroeconomic variables;
    - as part of planned update of SFC standard on statutory audits, consider completing requirements relating to the perimeter of statutory audits of credit institutions;
    - strengthen requirements on independence of statutory auditors, for instance by imposing a mandatory firm rotation.

### Principle 28 — Disclosure and transparency: EC1–EC5 and AC1 summary
- EC1: Since December 2015 credit institutions required to prepare and disclose financial statements pursuant to IAS/IFRS, including Conceptual Framework and IAS 1. Laws/regulations require publication at least once a year; financial statements must be signed by the accountant and legal representative and reviewed by external auditor who must opine on fairness, compliance with legal norms and effectiveness of risk management frameworks.
- EC2: IAS/IFRS framework and CBCF require quantitative and qualitative disclosures including:
  - balance sheet, profit and loss, changes in own funds, cashflows;
  - notes disclosing accounting policies, maturities, composition of loan portfolio, transactions with related parties (including shareholders >10 percent, Board members, managers);
  - disclosures on risk management for each significant risk;
  - governance disclosures on Board responsibilities, reporting, internal control and risk management infrastructure, organizational structure, human resources, audit, compliance;
  - disclosures on law requirements, including compliance with solvency ratios.
- EC3: IAS 24 and IFRS 12 require disclosure of all material entities in group structure; SFC requires disclosure of name and localization of subsidiaries and, for consolidated financial statements, name of subsidiaries included in consolidation perimeter, social object, and total assets, liabilities and capital (CBCF, chapter 10, Art. 7.1).
- EC4: SFC effectively reviews and enforces compliance:
  - SFC can publish or order publication of financial statements and required adjustments (EOSF, Art. 326, §2k; Art. 97, #3).
  - SFC checks compliance with disclosure standards (IFRS and XBRL) via predefined templates, analyzes consistency and adequacy of disclosure, and has required some entities to modify notes.
  - SFC can impose sanctions for violations including inaccurate and untimely information (EOSF, Art. 326, §6d; EOSF, Art. 209d).
  - Supervisory approval before publication is required in specific cases (Decree 089 (2008)), e.g., entity in operation < three years; merger/acquisition/segregation/sale of assets or liabilities; subject to SFC preventive measures; SFC required corrections; detection of deterioration.
- EC5: SFC publishes on its website comparable bank-by-bank monthly financial information using the Chart of Accounts (Plan Unico de Cuentas), balance sheet and profit and loss indicators, balance sheet structure, solvency ratio, composition and quality of credit portfolio, investment portfolio composition, and a monthly report on the Colombian financial system with aggregate information on profits, assets (including quality and provision coverage), liabilities, capital ratios and liquidity risk indicator.
- AC1: Disclosure requirements promote understanding of risk exposures; since 2015 banks must follow IFRS 7 disclosures on financial instruments (credit, liquidity, market risk). SFC publishes breakdowns of revenues, costs, investment and credit portfolios, and other assets.

### Assessment of Principle 28
- Compliant.
- Comments:
  - Since December 2015 credit institutions must prepare and disclose financial statements under IAS/IFRS, except IFRS 9/IAS 39 provisions on loan portfolio impairment and classification/measurement of financial instruments for individual financial statements.
  - Laws/regulations require annual publication; audited statements include quantitative and qualitative information and are checked by SFC.
  - SFC publishes a broad range of reports facilitating public understanding of the banking system and market discipline.

### Principle 29 — Abuse of financial services: EC1–EC6 summary (selected findings)
- EC1: Legal framework:
  - Anti-money laundering and countering financing of terrorism (ML/FT) responsibilities addressed in CBJ 029 of 2014 and EOSF.
  - Decree D2555 assigns duties/powers to Office of Senior Deputy Superintendent for supervision of ML/FT risk and Technical Departments.
  - Law 1121, 2006 includes financing of terrorism as a criminal activity and makes banks mandatory to prevent such activities and report them to UIAF and/or competent authorities.
  - SFC monitors compliance via onsite and offsite supervision; non-compliance leads to administrative sanctions.
  - IMF/FATF fourth round mutual evaluation (2017/2018) produced “IEM Colombia 2018” showing satisfactory technical compliance and effectiveness in implementation of the 40 FATF recommendations.
- EC2: Banks’ policies and processes:
  - ML/TF is incorporated into risk matrix for supervision planning.
  - Corporate governance and Board responsibilities required by SFC aid ethical standards.
  - KYC and suspicious transaction reporting requirements:
    - Articles 102 to 107, Chapter 16, Part 3, EOSF — “Prevention of Criminal Activities” obligate institutions to establish control mechanisms including KYC and reporting to UIAF.
    - Chapter 4, Title 4, Part 1, CBJ — instructions relating to ML/TF risk management.
  - September 2020 update: CE 027 of 2020 updates SARLAFT to promote innovation and financial inclusion and strengthen ML/TF risk management; credit institutions have one year from issue date to implement adjustments.
  - SARLAFT structure:
    - Phases: risk prevention (prevent introduction of illicit resources) and risk control (detect/report suspicious operations).
    - Elements: policies, procedures, documentation, organizational structure, internal/external audit, technological infrastructure, information disclosure, training.
  - Obligations to establish internal policies/procedures to detect and report unusual and suspicious transactions to UIAF and competent authorities.
- EC3: Reporting to supervisor:
  - CCICLA (Decree 3420, 2004) formulates government policy against ML/TF.
  - Informal procedure exists for banks’ Legal Representatives, Control Bodies, Compliance Officers to directly communicate with Financial Superintendent or Designated Superintendents on events identified by SARLAFT that may affect the institution or financial system; evidence of cooperation is maintained via attendance formats in SFC’s Integrated Management System.
  - SFC communicates relevant situations to competent authorities and takes administrative measures as needed; coordinates with Police and Attorney General's Office to identify and collect evidence for criminal activities.
- EC4: Supervisor informs FIU and relevant authorities:
  - Based on Article 209 of the Colombian Constitution and Article 3, Law 1437, 2011, SFC reports suspicious transactions identified in its functions to public entities including UIAF.
  - Inter-administrative Agreements and MoUs:
    - July 2015: Agreement between SFC and Office of the Attorney General for cooperation in investigations and actions.
    - November 2015: Agreement among Ministry of Foreign Affairs, General Prosecutor's Office, SFC, and UIAF for compliance with UNSC resolutions on financing of terrorism and proliferation.
    - October 2016: Inter-institutional Agreement on Technical Cooperation between SFC and UIAF to exchange information for supervision and identification of ML/TF typologies.
    - October 29, 2019: “Pact of Financial Supervisors for Cooperation, Exchange of Information and Compliance with FATF Standards in the Fight against ML/FT/FPADM” among SFC, Superintendency of Solidarity Economy, DIAN, MINTIC and UIAF.
  - SFC has MoUs with national and international authorities for information exchange supporting investigations.
  - Two-way information exchanges reported between Deputy Superintendent for ML/FT Risk, General Prosecutor's Office and National Police, including results of SARLAFT supervision exercises and joint planning of supervision with cooperation objectives for investigations.
- EC5: CDD policies and processes:
  - Article 102, EOSF obliges credit institutions to design and implement control mechanisms including CDD.
  - CDD process/documentation must cover procedures and methodologies to know the customer, procedures for financial conglomerates, simplified KYC, PEP procedures, minimum periodicity for updating customer information, special rules for political campaign accounts, and obligation to consult binding/restrictive lists.
  - CBJ requirements addressing EC5 elements:
    - (a) policies within risk management system requiring more stringent linking guidelines for higher ML/TF exposure;
    - (b) information to know the client permanently and updated, including identification and verification and duty to know final beneficiaries of corporations;
    - (c) mechanisms to identify and analyze unusual transactions and report suspicious transactions, with obligation of permanent monitoring;
    - (d) actions to mitigate major ML/TF risks individually or consolidated.
  - Minimum parameters:
    - Procedures for KYC for current and potential customers and updating at least every three years; periodicity depends on client ML/TF risk profile.
    - For higher risk customers, updating must be at least annually.
    - If a client is reclassified as high risk and information not updated in more than one year, bank must update data within the month following change of categorization.
    - More stringent requirements for PEPs.
    - Minimum retention period of five years from date of last registry for CDD information (following Article 96, EOSF).
  - Supervisory practice:
    - Office of Deputy Superintendent for ML/TF Risk performs supervisory plan via onsite/offsite activities; reviews Compliance Officer role and Board-defined policies/procedures.
    - Supervisory teams execute walk-through tests of technological tools supporting SARLAFT, focus on parameterization and evaluation of information analysis techniques.
    - Chapter 4 of “ML/FT/PWMD risk management in the Colombian Financial Sector” on SFC website describes supervision procedures.
    - 2013–2016: onsite supervision for all credit institutions (25 in 2016/26 in 2019); since then risk-based approach selects institutions with greater ML/TF exposure for onsite work.
    - If regulatory breaches identified, sanction measures are taken per EC8 of BCP.

*Source: 1colea2022005 - section 9).*

### Chapter 4, Title 4, Part

### Chapter 4, Title 4, Part

### EC7 — Supervisor determines banks have sufficient controls and systems to prevent, identify and report potential abuses (ML/FT)
- SFC established the Comprehensive Supervision Framework (MIS) as a risk-based supervision methodology.  
- MIS contains detailed standards and criteria to carry out consolidated supervision of credit institutions regardless of jurisdiction.
- Each financial entity or conglomerate has a risk matrix with the entity's ML/FT Risk Profile (unique), composed of:
  - Inherent Risk ML/FT: an estimated unique and consolidated rating indicating level of exposure to inherent risk of ML/FT of each credit institution, based on assessment of vulnerability of the activities it develops and composition of activity with respect to the three remaining SARLAFT risk factors (customers, distribution channels and jurisdictions). Results of the National Risk Assessment in force are used as information inputs.
  - Supervisory Functions (SARLAFT): five supervisory functions (ML/FT internal risk audit, ML/FT risk management, Compliance, Senior management, and Board of Directors or equivalent organ).
- Vulnerability to ML/FT is calculated for each SARLAFT risk factor by incorporating these parameters:
  1. Vulnerability of the Product Risk Factor (Activity, Business Line, Business Unit or Process): possibility the product is prone to achievement/materialization of ML/FT risk due to its own/natural characteristics, regardless of supervised entity.
  2. The Office of the Deputy Superintendent of ML/FT risk assesses Vulnerability of each product (activities, business lines, business units or processes) of credit institutions according to natural characteristics of operation.
  3. Assessment obtained from qualitative analysis and tabulation of variables (FATF recommendations, typologies of ML/FT, supervisor experience, complaints, consultations, reports from other Offices of SFC, among others) using the Delphi method based on a panel of experts.
  4. Vulnerability of the Client Risk Factor (Economic Activity/Occupation): possibility that client activity/occupation is prone to ML/FT risk due to its own/natural characteristics or conditions in country.
  5. Vulnerability of the Jurisdiction Risk Factor (National (Departments)/International): possibility a jurisdiction is prone to ML/FT risk due to location characteristics and ML/FT source crime materialization statistics; used to construct geographic risk maps.
  6. Vulnerability of Distribution Channels Risk Factor: possibility that customer linking channel and/or transactional vehicle is prone to ML/FT risk due to own/natural characteristics of constitution, operation and functioning regardless of supervised entity.
- Supervision functions and procedures:
  - MIS evaluates governance structure of ML/FT Risk; for SARLAFT there are five supervisory functions as noted above.
  - Application of “Onsite” and “Offsite” supervision allows assessment of control functions in accordance with Chapter 4, Title 4, Part 1, CBJ emphasizing five aspects:
    1. Customer knowledge: procedures for timely knowledge of current and potential customers and verification of information.
    2. Segmentation of risk factors: process to determine usual transaction parameters and compare with client transactions to detect unusual activity.
    3. Red flag signs: facts, situations, events, amounts, quantitative/qualitative indicators and other relevant information to infer possible abnormal situations.
    4. Identification, analysis of unusual transactions, and report of suspicious transactions: methodologies to analyze and identify unusual transactions and report to UIAF.
    5. Risk matrix—SARLAFT Stages: design/implementation of stages (identification, measurement, control, monitoring) and matrix consolidating results, enabling permanent control and monitoring.
- Supervision processes are planned annually according to SFC risk-based methodology; verification of SARLAFT regulatory compliance and effectiveness is carried out. Implementation adjustments are periodically monitored until a 100 percent implementation certification is required, signed by a Legal Representative, the Compliance Officer, and the Statutory Auditor.

### EC8 — Supervisor has enforcement powers against noncompliant banks
- SFC has enforcement powers, both regulatory and criminal prosecution, to act against supervised entities not complying with obligations regarding prevention of criminal activities as stated in Article 107, EOSF, and in Paragraph s), Article 50, Law 964, 2005.
- Sanctioning is further detailed under CP 11.

### EC9 — Supervisor determines banks have internal audit/external experts, compliance officers, screening policies, and training
- (a) Internal audit and external experts:
  - Pursuant to Article 102, EOSF, credit institutions required to establish independent ongoing control and audit mechanisms to aid in prevention and monitoring of criminal activities.
  - SARLAFT requires banks maintain adequately staffed, independent, external and internal auditors (Control Bodies) to assess risk.
  - CBJ requires quarterly and semi-annual evaluation reports to the Board of Directors and the Compliance Officer addressing deficiencies, gaps and weaknesses in SARLAFT content, control and operations, and responsibility to report suspicious activities to UIAF. SFC can request results at any time.
- (b) Compliance officers:
  - Pursuant to Article 4.2.4.3, Chapter 4, Title 4, Part 1, CBJ, credit institutions must nominate an AML/CFT compliance officer to verify implementation of anti-money laundering procedures.
  - Compliance officer must communicate detected suspicious activities to UIAF via SARLAFT whistleblower channels.
  - Individuals selected must obtain prior approval of the SFC’s Appointments Committee.
- (c) Screening policies:
  - Banks must conduct enhanced due diligence on employees, clients, partners, vendors and third-party service providers including personal and business details, financial status, certifications and consulting information about sanction lists, law enforcement lists and PEPs relationships.
- (d) Ongoing training programs:
  - Banks required to conduct AML/CFT training for employees, Board members and third parties to raise awareness of AML/CFT legislation, policies and procedures and ML/FT risks relevant to the entity.
  - Training content should address: (i) entity’s prevention model and risk management of ML/FT (SARLAFT); (ii) risks to which entity is exposed; (iii) typologies and potential instances of ML/FT in the business; (iv) warning signs to detect unusual and suspicious transactions; (v) procedures for reporting unusual transactions; (vi) roles and responsibilities of Compliance Officer, employees, senior managers and Board of directors; and (vii) penalties for AML violations.
  - Banks should ensure training for new employees in a timely manner and for all employees and third-parties at least on an annual basis. Ongoing training should be updated regularly. Entities with higher ML/FT risk exposure should provide training more frequently if necessary.
- Supervision review:
  - During onsite or offsite reviews, SFC reviews files and training records and executes walk-through tests of technological tools supporting SARLAFT procedures, focusing on parameterization and evaluation of results from information analysis techniques/methodologies.
  - Supervision procedures of the delegation are described in Chapter 4 of "ML/FT/PWMD risk management in the Colombian Financial Sector" published on the SFC website.

### EC10 — Policies and MIS for reporting and management information systems
- SARLAFT element Disclosure of Information (Article 4.2.7., Chapter 4, Title 4, Part 1, CBJ) requires design and implementation of effective, efficient and timely report systems for internal and external reporting of unusual transactions and disclosure to competent authorities, including communication channels between compliance officer, employees, Board of Directors and third-parties.
- Technological Infrastructure (Article 4.2.6., Chapter 4, Title 4, Part 1, CBJ) requires credit institutions, according to activities, operations, risk and size, to implement technological systems to optimize and guarantee adequate management of ML/FT risk.
  - Systems should allow capture and periodic updating of information of different risk factors, consolidation of operations of different risk factors per entity criteria, centralization of records corresponding to each risk factor and each client, and automatic generation of internal and external reports (distinct from suspicious transaction reports). All reports to UIAF can be sent electronically.

### EC11 — Legal protection for good-faith reporters
- Article 42, Law 190, 1995; Article 102 and 105, EOSF; and Article 4.2.7.2.1, Chapter 4, Title 4, Part 1, CBJ state members of credit institutions who report suspicious activities in good faith cannot be held liable.
- CE 007, 2019 issued instruction on communication channels and special tools credit institutions must have for reception and processing of complaints, establishing internal policies and procedural manuals that include protection of complainants in good faith against retaliation and confidentiality of complaints and identity of complainants.

### EC12 — Cooperation and information sharing with domestic and foreign supervisors
- Article 45 of Law 510 of 1999 and Article 22 of Law 964 of 2005 allow SFC to enter into cooperation agreements and mechanisms for information exchange for investigating criminal activities or transactions, including AML/CFT matters, with local and international supervisory agencies and international organizations.
- SFC has cooperated with foreign supervisors under MOUs, International Internships and Supervisory Colleges (see EC2 for detail).
- Pacts and Cooperation Agreements:
  - SFC signed an Inter-Administrative Cooperation Agreement with the Ministry of Foreign Affairs, Attorney General Office and the UIAF to ensure compliance with FATF recommendations 6 and 7 and obligations described in Article 20, Law 1121, 2006, and international obligations related with AML/CFT and prohibition of financing proliferation of weapons of mass destruction.
  - On November 7, 2019, SFC subscribed the Pact of Supervisors of DNFBPs and the Pact of Supervisors for the Real Sector to allow cooperation, exchange of information and compliance with FATF standards against ML/FT and proliferation.
- Memorandums of Understanding:
  - SFC has signed bilateral or multilateral cooperation agreements/arrangements with foreign authorities that include ML/FT aspects. MoÚs have facilitated information sharing on sanctions and examination results.
- Supervisory Colleges:
  - In 2016, central theme of Colleges of Supervisors led by SFC was ML/FT Risk Management with supervisors presenting jurisdictional risk profiles and improvement opportunities.
  - From 2015, SFC, through the Deputy Superintendent for ML/FT Risk, coordinated the ML/FT Prevention Committee with planning 2015-2019 to identify and measure ML/FT risk regionally and promote best practices; planning 2020-2024 continues coordination to promote best practices of regulation and supervision of AML/CFT and Anti-proliferation risks in the regional banking sector.

### EC13 — In-house specialist resources and regular risk information to banks
- By end-2020, the Office of the deputy Superintendent of AML/CFT had 41 officials and 1 trainee dedicated to supervision of SARLAFT in banks.
- Of these professionals, 24 have specializations and 4 have master's degrees.
- From 2016 to 2020 there was an increase in supervisors assigned to the Office equivalent to 39 percent (from 25 in 2016 to 41 in 2020), reflecting increased coverage and scope of supervision processes.
- Professional profiles in the Office include:
  - Delegated Superintendent
  - Director
  - Advisor
  - Specialized professionals
  - University professionals
  - Technicians
  - Executive secretaries
  - Administrative assistants
- Allocation of staff:
  - 63 percent of the professionals attached to the Office (26 officials) are assigned to technical areas (including the FATF Group).
  - 24 percent (10 officials) are part of the Legal Directorate.
- Decree 2399, 2019 (effective January 1, 2020) modified SFC structure and strengthened the Office by creating an additional Technical Directorate to support supervision of banks in compliance with SARLAFT. As a result, seven positions to be filled in the Office (three positions have been provided already), evidencing growth trend of the area.
- The Office regularly provides information to banks related to risks of money laundering and financing of terrorism (details follow in source).

*Source: 1colea2022005 - Chapter 4, Title 4, Part — 1colea2022005 - Chapter 4, Title 4, Part (PDF).*

### 1.     Meetings (officials' functions manuals): When it is necessary, the officials of

### 1colea2022005 - 1.     Meetings (officials' functions manuals): When it is necessary, the officials of

### Meetings, coordination, and supervisory guidance
- Meetings
  - Officials of the office of the deputy Superintendent of AML/CFT carry out meetings with the credit institutions' guilds or Board of Directors to provide feedback on the main weaknesses found in respective supervision.
- Committee of Compliance Officers and Responsible Officials
  - Created on September 22, 2020, as an instance of coordination, cooperation and exchange of experiences and best practices in ML/FT risk management.
  - Has featured the presence of officials of Superintendencies from international jurisdictions.
- Circular Letters and External Circulars
  - SFC has issued several Circular Letters (CC) and External Circulars (CE) providing or clarifying instructions to credit institutions on administration of ML/FT risk.

### Regulatory modifications to SARLAFT
- Public consultation
  - From February 13 until March 6, 2020, the SFC published for comments a project to update and improve the regulations of the SARLAFT (Chapter 4, Title 4, Part 1, CBJ) to promote innovation and financial inclusion and to make ML/FT risk management more robust.
- Communication and implementation
  - The most relevant changes were communicated through External Circular 027, September 2, 2020.
  - Implementation of adjustments by credit institutions will have a one-year term.

### Assessment of Core Principle 29 and BCP summary grades
- Assessment: Principle 29 — Compliant
- Selected Core Principle grades and comments (preserve exact wording and grades)
  - Principle 1: C — Comprehensive framework for banking regulation and supervision. Supervisor invested with a broad range of preventive and corrective powers and exercises them.
  - Principle 2: LC — Supervisor endowed with separate legal status and administrative and financial autonomy, as well as adequate financial and human resources. Formal safeguards could be strengthened to ensure that its independence is not threatened.
  - Principle 3: C — SFC supervises the bulk of the financial system, and a network of committees has been established to ensure collaboration with other parties.
  - Principle 15: LC — Risk management requirements, and internal control processes are defined in the guidance. Some risk areas are rated less than compliant.
  - Principle 16: LC — Adequate capital adequacy framework, progressively aligned with the Basel III capital standards. The remaining differences could be further reduced. Effective supervision in place. Improvements of the regulation of the internal capital adequacy assessment process (ICAAP) planned.
  - Principle 19: MNC — Focuses mainly on direct connected lending and lacks comprehensive guidance on concentrations (geographic, industry).
  - Principle 20: MNC — Framework should be consolidated to include limits, definitions and process requirements.
  - Principle 23: C/MNC notes — No prudential requirements issued so far, but the supervisor is planning to issue a formal standard on IRRBB in the second half of 2021. Several offsite exercises have been carried out since 2018.
  - Principle 24: LC — Comprehensive framework in place for credit institutions to manage their liquidity risk, including in foreign exchange currency. Several regulatory parameters used in the computation of the liquidity ratios are not completely aligned with those prescribed by the Basel III standards or are not determined yet. Active monitoring of the banks’ liquidity by the supervisor.
  - Principle 25: C — Enhanced framework for the management of operational risk by credit institutions. Active supervision focused on cybersecurity, business continuity management, and strengthening operational risk management during the pandemic.
  - Principle 27: C — As of December 2015, credit institutions prepare and report financial statements pursuant to applicable IAS and IFRS standards, except for specified derogations. Internal Standards on Auditing introduced in Colombian law.
  - Principle 28: C — International disclosure requirements in force. Credit institutions required to publish financial statements with accompanying notes at least once a year. Broad range of reports published on the supervisor’s website.
  - Principle 29: C — Strong procedures are in place.

### Recommended actions (selected, verbatim)
- Principle 2
  - Specify in the law that the Superintendent is appointed for a minimum term and is removed from office during his/her term only for reasons specified in it.
  - Strengthen formal safeguards to prevent SFC staff from being involved in lawsuits for actions taken and/or omissions made while discharging their duties in good faith and any potential interference in the SFC’s decision-making process.
- Principle 6
  - Describe in an internal guideline the minimum criteria to be analyzed in each case.
- Principle 7
  - Consider lowering the 100 percent cumulative limit on banking investments in authorized financial subsidiaries and some real sector companies and/or conditioning the above-mentioned investments to a prior supervisory approval.
- Principle 15
  - Develop additional guidance to support the “principles-based” approach to communicating supervisory expectations.
- Principle 16
  - Consider removing the remaining deviations from international standards on capital adequacy (i.e., credit risk weighting of some assets, treatment of minority interests as eligible capital).
  - Complement the internal guideline on the assessment of capital to give supervisors a clear guidance on what supervisory actions should be considered, including an increase of the capital requirements, in case some predetermined triggers or thresholds are reached.
  - Proceed with the planned new regulation aiming at formalizing the need for supervised entities to have a comprehensive management approach that links together the risk appetite framework with the ICAAP, ILAAP, stress tests, and recovery and resolution plans.
- Principle 17
  - Amend regulation to clarify the loans must be made at market terms.
  - Establish requirement that loans above a certain threshold must be Board approved.
- Principle 19
  - Increase guidance on concentrations (geographic, industry, sourcing, supply lines).
  - Eliminate intra-group guarantees or letters of credit as risk mitigant to increase limits.
- Principle 20
  - Develop comprehensive related-party transaction framework.
- Principle 23
  - Proceed with the planned regulation on IRRBB pursuant to the applicable Basel III standards.
- Principle 24
  - Consider readjusting or determining some parameters used in the computation of the local LCR and NSFR ratios and requiring the local NSFR ratio to be also calculated at consolidated level.
- Principle 28
  - Consider strengthening the requirements relating to the forward-looking approach on loan loss provisioning and, more generally, reviewing the exception to the application of IAS 39 and IFRS 9 standards.
  - Consider completing the regulatory requirements relating to the perimeter of the statutory audits of credit institutions and the need to have a mandatory firm rotation.

### Authorities’ response — key points (verbatim highlights)
- Participating authorities
  - The Colombian authorities (the Ministry of Finance (MHCP), Banco de la República (BR), the Guarantee Fund for Financial Institutions (FOGAFIN), the Financial Regulatory Unit (URF), and the Financial Superintendency of Colombia (SFC)) thanked the FSAP Mission and noted broad participation despite virtual modalities.
- Progress and commitment
  - Authorities highlight progress since the last assessment (2012 - 2014) and commitment to consolidate recommendations and align policies, regulation, methodologies, and supervisory practice to the highest international standards.
- SFC Integrated Supervisory Framework (MIS) and SIAR
  - MIS employs a risk-based supervision approach providing a comprehensive view of risks and enabling prioritization of supervisory resources.
  - Procedures for MIS have been formalized through supervisory guidelines that provide additional guidance without restricting expert judgment; guidelines are mostly public.
  - SIAR (issued in 2021) complements instructions regarding risk governance structures, management practices, and preparation/presentation of risk reports.
- Liquidity risk (Principle 24)
  - SFC implemented an IRL and a CFEN reflecting Basel principles while recognizing the nature and dynamics of the Colombian financial system (Paragraph 70, Basel III).
  - Run-off factors calibrated using historical demand deposit behavior do not affect comparability of the indicator.
  - Risk indicators IEC and IEI introduced to reflect liquidity behavior abroad; consolidated supervision monitors parent and subordinate liquidity risk management.
  - Prudential short-term liquidity indicator (IEC) accounts for independent liquidity risk management of foreign subordinates; implementation of consolidated CFEN is being analyzed.
  - Differences in certain local parameters versus Basel III are framed within the jurisdictional nature of the Colombian system; prudential standards and supervision of liquidity risk are effective.
- Operational risk and cybersecurity (Principle 25)
  - SFC assesses availability of ES websites/Apps, platforms' exposure, and verification of critical third parties' capacities.
  - SFC coordinated regional cybersecurity initiatives (CCSBSO and Pacific Alliance) including a guide for cybersecurity incidents in cloud architecture, simulation exercises, platform terms of reference, methodology for critical cyber-infrastructure, and training/awareness sessions.
- Banking Book Interest Rate Risk (Principle 23)
  - SFC has issued guidelines for management; materials are available on the SFC website and are complemented by work on convergence to International Basel Standards.
- Commitment
  - Authorities reaffirm commitment to continue advancing implementation of recommendations, best practices, and robust standards to consolidate robustness, resilience, and credibility of the Colombian financial system.

*Source: Excerpt from the IMF assessment document (COLOMBIA) provided in the source content.*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2022/english/1colea2022005.pdf_
