## 1slbea2022004

## Source details

**Canonical URL:** [1slbea2022004](https://www.imf.org/-/media/files/publications/cr/2022/english/1slbea2022004.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2022/english/1slbea2022004.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2022/english/1slbea2022004.pdf.json)

---

### Mission overview and participants
- A Monetary and Capital Markets (MCM) Department mission provided technical assistance (TA) on central bank risk management during the period of August–September 2021.
- Mission team: Mr. Paul Woods (MCM expert, Central Bank of Ireland), Mr. Chris Aylmer (MCM expert, formerly Reserve Bank of Australia), backstopped at IMF headquarters by Ashraf Khan (MCM, Central Bank Operations Division).
- At the request of the Central Bank of Solomon Islands (CBSI).
- The virtual mission used desk review of CBSI documents and video-conferences with presentations and discussions.
- Officers participating in discussions included: Dr. Luke Forau (Governor), Mr. Raynold Moveni (Deputy Governor), Ms. Christina Lasaqa (Non-executive Director), Mr. David K.C. Quan (Non-executive Director), Bob Pollard (Non-executive Director), Mr Marlon Houkarawa (Management Advisor, Operations), and Mr. Michael Kikiolo (Management Advisor, Policy).
- RMCCD established in 2019 (referenced elsewhere); within RMCCD a Risk Management Unit (RMU) was created in 2020, initially staffed with two staff, reporting to the head of RMCCD who reports to the deputy governor.

### Executive Summary — Objective and context
- Objective: guide CBSI on developing its risk management framework.
- As part of its updated strategic plan (2020-2024), CBSI established a Risk Management and Corporate Communications Department (RMCCD) in 2021.
- RMU created in 2020 with two staff; RMU coordinates risk management including middle office function.

### Executive Summary — Desired outcomes emphasized by the mission
- Strengthen risk culture so that:
  - the governor and the Board subscribe to the need and benefit of a coherent and structured approach to risk management;
  - they communicate this to the wider organization; and
  - they are clear on respective roles and responsibilities (departmental management teams, RMCCD and RMU, Board Audit and Risk Committee, and the broader board).
- Strengthen CBSI risk governance, including:
  - central coordinating role of the RMU;
  - RMU to progressively advance responsibilities as second line of defense, including prioritizing risk framework components, integrating risk reporting, and cultivating embedding of risk-related responsibilities across departmental management (first line of defense);
  - improve risk oversight for senior leadership and the board;
  - clarify delineation of the role of risk management (second line) vis-à-vis internal audit (third line).

### Key recommendations (high-level synthesis of Table 1)
- Enhance CBSI Risk Governance
  - RMU to develop a standard risk report for CBSI leadership team and the board on a quarterly basis; all departmental management teams to ensure timely and accurate completion of risk reporting templates and endorse content to be incorporated into bank-wide integrated risk reports.
    - Priority: High
    - Timeframe: 3- 6 months
  - Establish an executive Risk Working Group (RWG), chaired by the deputy governor, with departmental management representation (first line of defense). RMU to draft ToR and act as secretariat.
    - Priority: High
    - Timeframe: 3- 6 months
- Progress phased implementation of the CBSI Risk Management Framework
  - RMU to draft the methodology for risk identification combining bottom-up ORM assessments with an annual top-down Strategic Risk Assessment (SRA). RWG to review and endorse.
    - Priority: High
    - Timeframe: 6- 12 months
  - RMU to prepare the first draft of a CBSI Risk Appetite Statement (RAS) defining risk thresholds across financial and operational categories; refine via annual governance review cycle. Each risk category in the RAS to be represented in integrated quarterly risk reporting. RMU to engage specialist risk experts in departments to define thresholds, including reserve management and information technology and information security.
    - Priority: High
    - Timeframe: 6- 12 months
  - RMU to document RWG outputs on risks and thresholds to ensure senior management alignment on risk materiality and reflect this in integrated reporting to inform quarterly recommendations to leadership and Board on risk treatment priorities.
    - Priority: High
    - Timeframe: 6- 12 months

### Implementation considerations and follow-up
- Recommendations account for limited RMU resourcing; RMU must be appropriately resourced to meet timeframes.
- Senior leadership representation on RWG, tone from the top, and board risk oversight are important enablers.
- Recommended follow-up TA:
  - A follow up to this TA in six to nine months from the start of the mission to examine implementation progress and provide guidance.
  - An interim check-in within three months of mission conclusion to provide timely feedback on follow-up queries.

### Legal and organizational obligations
- Under the CBSI Act the board is responsible for, inter alia, “assessing risk and formulating contingency plans for the ongoing operations and security of the central bank.” (Section 39 of the CBSI Act).
- The Deputy Governor is also a member of the CBSI Board.

### Risk Management Diagnostic — Progress to date
- CBSI has improved financial risk management, particularly foreign exchange reserves, revising the Reserve Management Framework to focus on avoiding losses and liquidity relative to prior return focus.
- CBSI is developing operational risk management capabilities for high priority categories: information technology, currency management and procurement.
- RMU and ERM-related activity exists but approach remains fragmented, challenging coherent oversight by executive leadership and the board.

### ERM characterization and phased approach
- ERM is described as the aggregate of risk governance, risk policies and procedures, integrated risk reporting, and risk-related skills and competencies.
- A phased implementation is recommended, prioritizing strengthening risk governance and progressively aggregating risk intelligence from:
  - top-down strategic and emerging risks; and
  - bottom-up operational risks (ORM).
- Strengthening risk governance includes RMU engagement with senior leadership and the board to define risk appetite across material categories.
- Formalize Incident Management Team (IMT) capability, building on pandemic response.

### Risk Governance — Current situation (diagnostic findings)
- Effective risk governance should encourage understanding, dialogue and constructive challenge on organizational risks; it encompasses board/executive roles and adequacy of internal structures, controls and procedures to manage risk and support decision making and resource allocation.
- Current weaknesses:
  - No recurring review of the broad spectrum of risks confronting CBSI on an ongoing basis; executive and board have reviewed specific policies on a point or ad hoc basis.
  - Absence of structured risk and incident reports results in infrequent dialogue and inability for executive and board to have transparent, tailored oversight of material risks and prioritized mitigation.
  - Governance gap between first line departmental management and the board: no executive oversight working group to align management teams on material risks.
  - Opportunity exists to leverage RMU-developed risk intelligence for internal audit to support the third line of defense in providing independent assurance on effectiveness of control environment.

### Risk Governance — Recommendations (Selected; Recommendations 9–14)
- Adopt the Three Lines of Defense model of risk management.
  - First line: each department owns and manages risks within its remit.
  - Second line: RMU designs and coordinates the organization-wide risk management framework, aggregates risk information, and presents material risks to senior stakeholders and the board.
  - Third line: internal and external audit provide independent assurance on controls.
  - For central banks, policy risks generally managed outside the formal three lines by governance structures facilitating debate on policy options.
- Clearly define risk management roles and responsibilities (Recommendation 10)
  - Risk Management Framework should be drafted, reviewed, and approved by the board, allowing for a phased approach to implementation.
  - Assign a member of each department (risk champion) to coordinate the risk management process and support risk reporting to RMU.
- Ensure adequate resourcing of the second line (Recommendation 11)
  - Top-down leadership sponsorship of RMU is required.
  - RMU needs adequate resourcing and training to implement recommendations and to operationalize risk management analysis and reporting to provide governance oversight of risks on a quarterly basis.
- Establish a Risk Working Group (RWG) (Recommendation 12)
  - RWG chaired by the deputy governor to maintain ongoing executive-level oversight of CBSI’s risk profile.
  - Main objectives:
    - (i) review RMU’s aggregation of departmental risk inputs;
    - (ii) provide constructive challenge to ensure clear understanding of each risk;
    - (iii) support RMU in defining appropriate risk thresholds to recommend to the board in the CBSI risk appetite;
    - (iv) ensure management options have been considered for material risks;
    - (v) ensure chosen risk treatment is effectively resourced.
  - RMU staff should act as secretariat; outputs to include agreed minutes and actions to progress risk treatment on a risk-prioritized basis and report to executive and board.
- Executive and board oversight (Recommendation 13)
  - Include risk management as a recurring, structured, and quarterly agenda item for both executive and board.
  - Executive must understand risk profile and buy into mitigation priorities prior to integrated risk report being presented each quarter to the board.
  - Provide RWG minutes and action log to executive and board for information.
- Board Audit Committee (BAC) role (Recommendation 14)
  - Amend BAC terms of reference to split meetings into agenda items for both risk and control oversight as an initial step toward separating Board Risk Committee and BAC functions.
  - Conduct an effectiveness review survey of the BAC’s oversight of risk at the end of the first year.
  - RMU and Internal Audit should regularly share risk and control insights.

### Risk Appetite and Tolerances — Current situation
- There is currently no defined, board-approved risk appetite.
- Absence of board-approved risk appetite leads departmental management teams to implicitly set their own risk appetite, weakening consistent internal risk governance.
- A formal Risk Appetite Statement (RAS) would articulate tolerance levels CBSI is willing to accept in pursuit of its mandate and business objectives; RAS defines approach to managing strategic, financial and operational risks, including sub categories.
- A risk tolerance is set for each sub category representing risk limits intended not to be breached and to support escalation and enhanced oversight if exposures approach or breach the limits.
- Current inconsistencies noted:
  - Financial risks associated with investment of foreign exchange reserves have stronger implicit understanding and progress on policies.
  - Progress in IT security management, including appointment of a Chief Information Security Manager.
  - Without a formal RAS, CBSI has not proportionately set thresholds for specific categories of risk, important given constrained resources.

### Risk Appetite — Recommendations (Paragraphs 17–18)
- Formally articulate the Risk Appetite Statement (RAS):
  - Separate each major risk category and define risk appetite for each, including specific risk tolerances for significant sub categories.
  - Consider short term (up to one year) and longer term horizons such as within the timeline of the strategic plan.
  - Clarify ‘state dependent’ constraints (e.g., lender of last resort impact on overall balance sheet risk).
  - RMU should coordinate drafting with input from RWG, governor and board.
  - RAS should have an annual governance review.
- Gradually calibrate integrated risk reporting to mirror the RAS structure:
  - Risk reporting should mirror risk categories and provide status updates relative to thresholds in the RAS so board members can determine adherence, near-breaches, or breaches.
  - Example: define the threshold/standard for managing fraud related risk and provide simple status updates on whether standard is achieved.
  - RAS can set backstops on overall distribution of risks, e.g., setting a limit for the proportion of operational risks categorized as “red,” having high impact and high likelihood; example provided during mission: set the backstop threshold for operational risks graded as “red” to 5 percent or less.
  - This approach helps ensure CBSI is not running too many material risks in parallel.

### Risk Identification and Assessment — Current situation
- Current approach leverages bottom-up analysis where each department records risks, existing controls and action plans in departmental risk registers.
- CBSI’s bottom-up approach is inconsistent; risks articulated differently across departments, complicating delineation between risk types, controls, and materiality.
- Bottom-up alone can produce a risk blindside:
  - Insufficient consideration of inter-relationships between risks and incidents.
  - Single operational risk reviews may miss broader thematic patterns that traverse multiple departments (e.g., conduct, business continuity, strategic risks).
  - Weak for identifying forward-looking or emerging risks that do not map to a specific department, producing a risk ownership blindside.

### Risk Identification and Assessment — Recommendations (Paragraphs 22–23)
- Reinforce bottom-up with a top-down Strategic Risk Assessment (SRA):
  - Top-down SRA captures senior management and Board views on top strategic risks to integrate risk management with strategic planning.
  - Combining top-down assessment with bottom-up insights yields an end-to-end risk perspective to guide prioritized actions across the risk universe.
- Formalise the approach to risk identification and assessment:
  - Develop and communicate a standard approach delineating bottom-up operational assessments and top-down strategic assessments.
  - Define methodology for integrating both perspectives, governance and alignment on priority risks, and common language for grading risks by impact and likelihood.
  - Define a common template for departmental risk and incident reporting to RMU and guidance for root cause analysis.
- Align leadership and board on frequency of the SRA:
  - Use a Delphi-style interview methodology (open-ended surveying of senior leadership and board representatives with iterative probing).
  - RMU should filter views alongside external risk intelligence and broader industry trends.

### Other Recommendations — Risk Culture
- Cultivate risk culture at all levels:
  - Embed the risk management framework across staff, reinforced through governance and tone from leadership.
  - Encourage an environment where staff feel safe to identify risks and report incidents.
  - Staff should understand departmental risk registers, be incentivized to register new risks, and suggest control environment improvements.
- Guide board, leadership and staff through ongoing risk seminars and training:
  - Ongoing cycle of training for departments on risk identification, assessment, and incident reporting.
  - RMU should advise departments how risk intelligence is used by senior leadership and board.
  - Tone from the top is critical; decisions by senior leaders influence employee behaviours.
  - RMU can reinforce coherence via processes, timeliness, templates, and usefulness of risk reports to RWG, executive leadership and the board.
- Engage with external peers:
  - Share progress and experiences bilaterally with other central banks and with the International Operational Risk Working Group (IORWG).
  - Possibility of IMF’s PFTAC facilitating further regional information-sharing on central bank risk management.

### Crisis, Continuity, and Incident Management
- Formalize governance and procedures for crisis, continuity and incident management:
  - Establish a core Incident Management Team (IMT) that meets once per quarter to exercise and maintain readiness for critical incidents.
  - Response procedures should take an organizational perspective to supplement RMU’s standardized incident reporting and logging of learnings from lower-level incidents.
  - Tighten response capability including strengthening communications with internal and external stakeholders during a crisis.
  - Build on Pandemic Task Force lessons from the past eighteen months to formalize long-term governance of crisis and incident management.

### Concluding remarks — Findings and actions
- Findings and analysis:
  - Strengthened oversight and ensuring risk is a recurring agenda item for the Board (including its BAC) and executive are needed to advance the CBSI’s ERM journey.
  - Establishment of the RWG is recommended to support governance and bring senior leadership representation into risk deliberations.
  - A combined risk identification methodology—bringing bottom-up and top-down risk perspectives together—is required to improve risk identification and assessment.
  - A defined Risk Appetite Statement should be established and integrated into the RMU’s regular risk reporting to provide clarity on acceptable risk levels.
  - There is an obligation on CBSI leadership to ensure that RMU is appropriately resourced to progress implementation of the recommendations within the timeframes outlined.
  - Strengthening the tone from the top and enhancing risk oversight from the board are important complements to governance changes.
- Recommendations and actions:
  - Establish the RWG with senior leadership representation.
  - Implement a phased rollout of the combined risk identification methodology.
  - Develop and approve a Risk Appetite Statement and reflect its status in RMU’s regular risk reporting.
  - Ensure RMU is appropriately resourced (staffing and tools) to implement recommendations within the specified timeframes.
  - Reinforce the tone from the top and clarify the Board’s (including BAC’s) role in ongoing risk oversight, making risk a recurring agenda item.
- Follow-up technical assistance and timelines:
  - A follow-up technical assistance mission is tentatively foreseen for six to nine months from the start of this mission, focused on examining implementation of the mission’s recommendations and providing follow-up guidance and support as appropriate.
  - An interim check-in should be completed within three months of the mission concluding to provide timely feedback to CBSI on any follow-up queries.

*IMF | SOLOMON ISLANDS Central Bank Risk Management | Content unit: 1slbea2022004*

### Preface.................................................................................................................

### Preface

### Mission overview and participants
- A Monetary and Capital Markets (MCM) Department mission provided technical assistance (TA) on central bank risk management during the period of August–September 2021.
- Mission team: Mr. Paul Woods (MCM expert, Central Bank of Ireland), Mr. Chris Aylmer (MCM expert, formerly Reserve Bank of Australia), backstopped at IMF headquarters by Ashraf Khan (MCM, Central Bank Operations Division).
- At the request of the Central Bank of Solomon Islands (CBSI).
- The virtual mission used desk review of CBSI documents and video-conferences with presentations and discussions.
- Documents reviewed are listed in Appendix I.
- Officers participating in discussions included: Dr. Luke Forau (Governor), Mr. Raynold Moveni (Deputy Governor), Ms. Christina Lasaqa (Non-executive Director), Mr. David K.C. Quan (Non-executive Director), Bob Pollard (Non-executive Director), Mr Marlon Houkarawa (Management Advisor, Operations), and Mr. Michael Kikiolo (Management Advisor, Policy). Appendix II lists additional CBSI officers and broader management representation.
- Appendix III provides the schedule of meetings, including presentations on best practice for executive leadership and Board representatives.
- The mission team thanks CBSI for cooperation, engagement and constructive feedback.

### Purpose and focus of the TA
- Purpose: guide CBSI on how to establish an Enterprise Risk Management (ERM) framework, emphasizing foundational components and initiatives required to:
  - strengthen risk governance; and
  - foster the internal risk culture.

---

### Executive Summary

### Objective and context
- Objective: guide CBSI on developing its risk management framework.
- In 2021, as part of its updated strategic plan (2020-2024), the CBSI established a Risk Management and Corporate Communications Department (RMCCD).
- Note: RMCCD was established in 2019 (as referenced elsewhere in the document).
- Within RMCCD a Risk Management Unit (RMU) was created in 2020, initially staffed with two staff, to coordinate risk management, including middle office function. The RMU reports to the head of RMCCD who reports to the deputy governor.

### Desired outcomes emphasized by the mission
- Strengthen risk culture so that:
  - the governor and the Board subscribe to the need and benefit of a coherent and structured approach to risk management;
  - they communicate this to the wider organization; and
  - they are clear on respective roles and responsibilities (departmental management teams, RMCCD and RMU, Board Audit and Risk Committee, and the broader board).
- Strengthen CBSI risk governance, including:
  - central coordinating role of the RMU;
  - RMU to progressively advance responsibilities as second line of defense, including prioritizing risk framework components, integrating risk reporting, and cultivating embedding of risk-related responsibilities across departmental management (first line of defense);
  - improve risk oversight for senior leadership and the board;
  - clarify delineation of the role of risk management (second line) vis-à-vis internal audit (third line).

### Key recommendations (high-level synthesis of Table 1)
- Enhance CBSI Risk Governance
  - RMU to develop a standard risk report for CBSI leadership team and the board on a quarterly basis; all departmental management teams to ensure timely and accurate completion of risk reporting templates and endorse content to be incorporated into bank-wide integrated risk reports.
    - Priority: High
    - Timeframe: 3- 6 months
  - Establish an executive Risk Working Group (RWG), chaired by the deputy governor, with departmental management representation (first line of defense). RMU to draft ToR and act as secretariat.
    - Priority: High
    - Timeframe: 3- 6 months
- Progress phased implementation of the CBSI Risk Management Framework
  - RMU to draft the methodology for risk identification combining bottom-up ORM assessments with an annual top-down Strategic Risk Assessment (SRA). RWG to review and endorse. 
    - Priority: High
    - Timeframe: 6- 12 months
  - RMU to prepare the first draft of a CBSI Risk Appetite Statement (RAS) defining risk thresholds across financial and operational categories; refine via annual governance review cycle. Each risk category in the RAS to be represented in integrated quarterly risk reporting. RMU to engage specialist risk experts in departments to define thresholds, including reserve management and information technology and information security.
    - Priority: High
    - Timeframe: 6- 12 months
  - RMU to document RWG outputs on risks and thresholds to ensure senior management alignment on risk materiality and reflect this in integrated reporting to inform quarterly recommendations to leadership and Board on risk treatment priorities.
    - Priority: High
    - Timeframe: 6- 12 months

### Implementation considerations and follow-up
- Recommendations account for limited RMU resourcing; RMU must be appropriately resourced to meet timeframes.
- Senior leadership representation on RWG, tone from the top, and board risk oversight are important enablers.
- Recommended follow-up TA:
  - A follow up to this TA in six to nine months from the start of the mission to examine implementation progress and provide guidance.
  - An interim check-in within three months of mission conclusion to provide timely feedback on follow-up queries.

---

### I. Introduction

### Legal and organizational obligations
- Under the CBSI Act the board is responsible for, inter alia, “assessing risk and formulating contingency plans for the ongoing operations and security of the central bank.” (Section 39 of the CBSI Act).
- As part of its strategic plan (2020-2024), CBSI established RMCCD; within RMCCD the RMU was created in 2020 with two staff and reports to the head of RMCCD who reports to the deputy governor. The Deputy Governor is also a member of the CBSI Board.

### TA objectives and approach (detailed)
- Objectives:
  - establish strong risk culture (governor and board commitment; clear roles, including Board Audit Committee);
  - strengthen risk governance (risk champions in first line, RMCCD/RMU second line responsibilities; integrate reporting to governor, BAC, and board).
- Mission activities:
  - review documentation;
  - engage pre-discussion with management, governor and Board;
  - present international and regional best practices for central bank risk management;
  - provide practical guidance to mature CBSI risk management capabilities with reasonable milestones.

---

### II. Risk Management Diagnostic

### Progress to date
- CBSI has improved financial risk management, particularly foreign exchange reserves, revising the Reserve Management Framework to focus on avoiding losses and liquidity relative to prior return focus.
- CBSI is developing operational risk management capabilities for high priority categories: information technology, currency management and procurement.
- RMU and ERM-related activity exists but approach remains fragmented, challenging coherent oversight by executive leadership and the board.

### ERM characterization and phased approach
- ERM is described as the aggregate of risk governance, risk policies and procedures, integrated risk reporting, and risk-related skills and competencies.
- A phased implementation is recommended, prioritizing strengthening risk governance and progressively aggregating risk intelligence from:
  - top-down strategic and emerging risks; and
  - bottom-up operational risks (ORM).
- Strengthening risk governance includes RMU engagement with senior leadership and the board to define risk appetite across material categories.
- Formalize Incident Management Team (IMT) capability, building on pandemic response.
- Phased approach aims to progress foundational blocks while accounting for CBSI resource constraints and reinforcing organization-wide contribution to safeguard CBSI and its legal objectives.

---

### III. Risk Governance

### A. Current situation — diagnostic findings
- Effective risk governance should encourage understanding, dialogue and constructive challenge on organizational risks; it encompasses board/executive roles and adequacy of internal structures, controls and procedures to manage risk and support decision making and resource allocation.
- Current weaknesses:
  - No recurring review of the broad spectrum of risks confronting CBSI on an ongoing basis; executive and board have reviewed specific policies on a point or ad hoc basis.
  - Absence of structured risk and incident reports results in infrequent dialogue and inability for executive and board to have transparent, tailored oversight of material risks and prioritized mitigation.
  - Governance gap between first line departmental management and the board: no executive oversight working group to align management teams on material risks.
  - Opportunity exists to leverage RMU-developed risk intelligence for internal audit to support the third line of defense in providing independent assurance on effectiveness of control environment.

### B. Recommendations
- (Recommendations section begins in the source but detailed recommendations beyond the governance diagnostic are provided earlier in Table 1 and the Executive Summary; RMU, RWG, RAS, integrated reporting and resourcing priorities are the primary recommended actions.)

*Source: Preface and sections I–III of the IMF TA report “Central Bank Risk Management,” CBSI mission (August–September 2021).*

### 9. Adopt the Three Lines of Defense model of risk management. With rare exception,

### 9. Adopt the Three Lines of Defense model of risk management. With rare exception,

### Three Lines of Defense model — structure and purpose
- Each department constitutes part of the first line of defense, with responsibility for identifying and managing risks; the first line of defense own the respective risks under each of the management team’s local remit.
- The second line of defense is represented by risk management staff (in the CBSI’s case, the RMU) that design and coordinate the implementation of the organization-wide risk management framework, aggregate risk information, and ensure presentation that covers all material risks to facilitate senior stakeholders and the board pinpointing and challenging the most material risk exposures.
- The third line is represented by internal and external audit to ensure controls are operating effectively and provide independent assurance on the efficacy of the control environment.
- For central banks, policy risks are generally managed outside of the formal three lines of defense model by ensuring effective governance structures that facilitate open dialogue and debate on policy options.

### Clearly define risk management roles and responsibilities (Recommendation 10)
- Risk Management Framework should be drafted, reviewed, and approved by the board, allowing for a phased approach to implementation.
- Roles and responsibilities aligned with the Three Lines of Defense should be clearly outlined.
- Assign a member of each department (risk champion) responsibility for coordinating the risk management process to ensure departments discharge first line responsibilities and support risk reporting back to the RMU for organization-wide aggregation.

### Ensure adequate resourcing of the second line (Recommendation 11)
- Top-down leadership sponsorship of RMU is required.
- RMU needs adequate resourcing and training to implement recommendations and to operationalize risk management analysis and reporting to provide governance oversight of risks on a quarterly basis.

### Establish a Risk Working Group (RWG) (Recommendation 12)
- Establish RWG chaired by the deputy governor to maintain ongoing executive-level oversight of CBSI’s risk profile.
- Main objectives:
  - (i) review RMU’s aggregation of departmental risk inputs;
  - (ii) provide constructive challenge to ensure clear understanding of each risk;
  - (iii) support RMU in defining appropriate risk thresholds to recommend to the board in the CBSI risk appetite;
  - (iv) ensure management options have been considered for material risks;
  - (v) ensure chosen risk treatment is effectively resourced.
- RMU staff should act as secretariat for the RWG, with management representatives from key first line departments.
- Outputs should include agreed minutes and actions to progress risk treatment on a risk-prioritized basis and report to executive and board.

### Executive and board oversight (Recommendation 13)
- Include risk management as a recurring, structured, and quarterly agenda item for both executive and board.
- Executive must understand risk profile and buy into mitigation priorities prior to integrated risk report being presented each quarter to the board.
- Provide RWG minutes and action log to executive and board for information.

### Board Audit Committee (BAC) role (Recommendation 14)
- Due to scale, amend BAC terms of reference to split meetings into agenda items for both risk and control oversight as an initial step toward separating Board Risk Committee and BAC functions.
- Conduct an effectiveness review survey of the BAC’s oversight of risk at the end of the first year.
- RMU and Internal Audit should regularly share risk and control insights to ensure integrated and coherent approach.

---

### IV. RISK APPETITE AND TOLERANCES — Current situation (Paragraphs 15–16)
- There is currently no defined, board-approved risk appetite.
- Absence of board-approved risk appetite leads departmental management teams to implicitly set their own risk appetite, weakening consistent internal risk governance.
- A formal Risk Appetite Statement (RAS) would articulate tolerance levels CBSI is willing to accept in pursuit of its mandate and business objectives; RAS defines approach to managing strategic, financial and operational risks, including sub categories.
- A risk tolerance is set for each sub category representing risk limits intended not to be breached and to support escalation and enhanced oversight if exposures approach or breach the limits.
- Current inconsistencies noted:
  - Financial risks associated with investment of foreign exchange reserves have stronger implicit understanding and progress on policies.
  - Progress in IT security management, including appointment of a Chief Information Security Manager.
  - Without a formal RAS, CBSI has not proportionately set thresholds for specific categories of risk, important given constrained resources.

### IV.B. Recommendations on Risk Appetite (Paragraphs 17–18)
- Formally articulate the Risk Appetite Statement (RAS):
  - Separate each major risk category and define risk appetite for each, including specific risk tolerances for significant sub categories.
  - Consider short term (up to one year) and longer term horizons such as within the timeline of the strategic plan.
  - Clarify ‘state dependent’ constraints (e.g., lender of last resort impact on overall balance sheet risk).
  - RMU should coordinate drafting with input from RWG, governor and board.
  - RAS should have an annual governance review.
- Gradually calibrate integrated risk reporting to mirror the RAS structure:
  - Risk reporting should mirror risk categories and provide status updates relative to thresholds in the RAS so board members can determine adherence, near-breaches, or breaches.
  - Example: define the threshold/standard for managing fraud related risk and provide simple status updates on whether standard is achieved.
  - RAS can set backstops on overall distribution of risks, e.g., setting a limit for the proportion of operational risks categorized as “red,” having high impact and high likelihood; example provided during mission: set the backstop threshold for operational risks graded as “red” to 5 percent or less.
  - This approach helps ensure CBSI is not running too many material risks in parallel.

---

### V. RISK IDENTIFICATION AND ASSESSMENT — Current situation (Paragraphs 19–21)
- Current approach leverages bottom-up analysis where each department records risks, existing controls and action plans in departmental risk registers.
- CBSI’s bottom-up approach is inconsistent; risks articulated differently across departments, complicating delineation between risk types, controls, and materiality.
- Bottom-up alone can produce a risk blindside:
  - Insufficient consideration of inter-relationships between risks and incidents.
  - Single operational risk reviews may miss broader thematic patterns that traverse multiple departments (e.g., conduct, business continuity, strategic risks).
  - Weak for identifying forward-looking or emerging risks that do not map to a specific department, producing a risk ownership blindside.
- Recommendation to reinforce bottom-up with a top-down Strategic Risk Assessment (SRA):
  - Top-down SRA captures senior management and Board views on top strategic risks to integrate risk management with strategic planning.
  - Combining top-down assessment with bottom-up insights yields an end-to-end risk perspective to guide prioritized actions across the risk universe.

### V.B. Recommendations on Risk Identification and Assessment (Paragraphs 22–23)
- Formalise the approach to risk identification and assessment:
  - Develop and communicate a standard approach delineating bottom-up operational assessments and top-down strategic assessments.
  - Define methodology for integrating both perspectives, governance and alignment on priority risks, and common language for grading risks by impact and likelihood.
  - Define a common template for departmental risk and incident reporting to RMU and guidance for root cause analysis.
- Align leadership and board on frequency of the SRA:
  - Use a Delphi-style interview methodology (open-ended surveying of senior leadership and board representatives with iterative probing).
  - RMU should filter views alongside external risk intelligence and broader industry trends.

---

### VI. OTHER RECOMMENDATIONS — Risk Culture (Paragraphs 24–26)
- Cultivate risk culture at all levels:
  - Embed the risk management framework across staff, reinforced through governance and tone from leadership.
  - Encourage an environment where staff feel safe to identify risks and report incidents.
  - Staff should understand departmental risk registers, be incentivized to register new risks, and suggest control environment improvements.
- Guide board, leadership and staff through ongoing risk seminars and training:
  - Ongoing cycle of training for departments on risk identification, assessment, and incident reporting.
  - RMU should advise departments how risk intelligence is used by senior leadership and board.
  - Tone from the top is critical; decisions by senior leaders influence employee behaviours.
  - RMU can reinforce coherence via processes, timeliness, templates, and usefulness of risk reports to RWG, executive leadership and the board.
- Engage with external peers:
  - Share progress and experiences bilaterally with other central banks and with the International Operational Risk Working Group (IORWG).
  - Possibility of IMF’s PFTAC facilitating further regional information-sharing on central bank risk management.
  - Such engagement supports monitoring maturity of CBSI’s risk framework relative to peers.

### VI.B. Crisis, Continuity, and Incident Management (Paragraph 27)
- Formalize governance and procedures for crisis, continuity and incident management:
  - Establish a core Incident Management Team (IMT) that meets once per quarter to exercise and maintain readiness for critical incidents.
  - Response procedures should take an organizational perspective to supplement RMU’s standardized incident reporting and logging of learnings from lower-level incidents.
  - Tighten response capability including strengthening communications with internal and external stakeholders during a crisis.
  - Build on Pandemic Task Force lessons from the past eighteen months to formalize long-term governance of crisis and incident management.

---

### VII. CONCLUDING REMARKS
- (Concluding remarks follow in source material.)

*IMF | SOLOMON ISLANDS Central Bank Risk Management | Content unit: 1slbea2022004*

### 28. A phased strengthening of risk governance, supported by implementing some

### 28. A phased strengthening of risk governance, supported by implementing some

### Findings and analysis
- Strengthened oversight and ensuring risk is a recurring agenda item for the Board (including its BAC) and executive are needed to advance the CBSI’s ERM journey.
- Establishment of the RWG is recommended to support governance and bring senior leadership representation into risk deliberations.
- A combined risk identification methodology—bringing bottom-up and top-down risk perspectives together—is required to improve risk identification and assessment.
- A defined Risk Appetite Statement should be established and integrated into the RMU’s regular risk reporting to provide clarity on acceptable risk levels.
- There is an obligation on CBSI leadership to ensure that RMU is appropriately resourced to progress implementation of the recommendations within the timeframes outlined.
- Strengthening the tone from the top and enhancing risk oversight from the board are important complements to governance changes.

### Recommendations and actions
- Establish the RWG with senior leadership representation to ensure operational and strategic risks are reviewed at an appropriate level.
- Implement a phased rollout of the combined risk identification methodology to integrate bottom-up and top-down perspectives.
- Develop and approve a Risk Appetite Statement and ensure its status and changes are reflected in the RMU’s regular risk reporting.
- Ensure RMU is appropriately resourced (staffing and tools) to implement recommendations within the specified timeframes.
- Reinforce the tone from the top and clarify the Board’s (including BAC’s) role in ongoing risk oversight, making risk a recurring agenda item.

### Follow-up technical assistance and timelines
- A follow-up technical assistance mission is tentatively foreseen for six to nine months from the start of this mission, focused on examining implementation of the mission’s recommendations and providing follow-up guidance and support as appropriate.
- An interim check-in should be completed within three months of the mission concluding to provide timely feedback to CBSI on any follow-up queries arising as the recommendations are being implemented.

*IMF | SOLOMON ISLANDS Central Bank Risk Management*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2022/english/1slbea2022004.pdf_
