## 1kazea2024004 — Detailed Assessment (Executive Summary and Selected Chapters)

## Source details

**Canonical URL:** [1kazea2024004 — Detailed Assessment (Executive Summary and Selected Chapters)](https://www.imf.org/-/media/files/publications/cr/2024/english/1kazea2024004.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2024/english/1kazea2024004.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2024/english/1kazea2024004.pdf.json)

---

### Institutional change, mandate, governance, and resourcing
- Transfer and mandate:
  - At the end of 2019 the financial sector supervisory responsibilities of the National Bank of Kazakhstan (NBK) were transferred to the newly established authorized body Agency of the Republic of Kazakhstan for the Regulation and Development of the Financial Market (ARDFM).
  - ARDFM has a dual mandate: financial stability and development (including supporting expansion of banks’ loan portfolios). The development objective is not subordinate to the financial stability mandate.
- Independence and governance constraints:
  - ARDFM independence is not prescribed in the legislation and is undermined by provisions in the Law 474-II that make ARDFM “directly subordinated” to the President who approves the organization structure and the staff.
  - Chair appointed by the President for a period of 6 years; three Deputy Chairs appointed for six years and dismissed by the President on proposal of the Chair.
  - Board composition includes Chair, three Deputies, one representative from the President, and one representative from NBK; recommendation to remove voting rights of the President’s representative.
- Funding and staff:
  - ARDFM is funded only from the republican budget.
  - Budget for 2023: 9.2 bln tenge (about $US 20 mln) and envisaged as constant until 2027.
  - Total staff size: 595 full-time employees.
  - Banking Supervisor Department total staff: 76 (breakdown provided).
  - BANKING ANALYTICS AND STRESS-TESTING DEPARTMENT: 30 staff.
- Key institutional risks and recommendations:
  - Multiple reorganizations (2004–2011 FSA → NBK integration → 2019 ARDFM) reduce continuity and capacity.
  - Recommendation: Amend Law 474-II to prescribe ARDFM independence and autonomy over organizational structure and staffing; clarify removal grounds for Chair and require public disclosure; consider alternative funding (e.g., levy fees on banks) and adopt procedure to protect staff against legal defense costs for actions/omissions made in good faith.

### Pandemic and geopolitical forbearance, timelines, and exit recommendations
- Forbearance measures adopted (selected):
  - Reduced risk-weighting ratios when calculating capital adequacy:
    - loans to small and medium enterprises (SMEs): from 75 percent to 50 percent;
    - loans in foreign currency: from 200 percent to 100 percent;
    - syndicated loans: from 100 percent to 50 percent.
  - Reduced limits to long foreign exchange position: from 12.5 percent to 7.5 percent of capital.
  - Reduced total foreign currency net position limit: from 25 percent to 12.5 percent of capital.
  - Temporarily reduced capital conservation buffer: from 2 percent to 1 percent.
  - Temporarily reduced liquidity coverage ratio (LCR): from 0.8 to 0.6 (March 30, 2020, to April 1, 2021).
  - Postponed tightening of the net stable funding ratio (NSFR).
  - Relaxed provisioning requirements for SMEs restructured loans by excluding the restructuring factor when forming allowances.
  - Banks provided deferment of payments on loans to SMEs with grace periods ranging from 30 to 90 days at the borrower’s choice.
- Exit and restoration:
  - By end of 2021 most regulatory easing was completed except reduced risk-weighting ratio of loans to SMEs and syndicated loans, which remained in place at the end of the assessment.
  - ARDFM should phase out remaining measures as soon as possible because they undermine credibility of banks’ capital adequacy ratios and reduce resilience.
  - To stem FX market tensions ARDFM postponed full implementation of LCR and NSFR; both were at 80 percent instead of 100 percent at date of assessment.
  - Violations of LCR, NSFR and other liquidity ratios tolerated from February 21, 2022, to December 31, 2022, subject to banks providing an action plan to address the violation within nine months.
  - ARDFM will restore LCR and NSFR at 100 percent from July 2024.
  - Recommendation: set LCR and NSFR at 100 percent as soon as feasible and work with impacted banks on plans to restore liquidity buffers.

### Supervisory approach, methodology, and tools
- Risk-based supervision:
  - ARDFM introduced a risk-based approach (RBA) and supervisory methodology based on the Risk Assessment System (RAS), feeding into the SREP.
  - RAS assesses four main areas and assigns final ratings 1 (low risk) to 4 (high risk); quantitative analysis uses 33 indicators; qualitative analysis uses 122 indicators.
- Asset Quality Review (AQR) and stress testing:
  - 2019 NBK full-scale AQR covered 14 banks (87 percent of banking assets and 90 percent of loan portfolio).
  - ARDFM piloted internal desk-based AQR in 2021 and by 2022 conducts regular AQR and supervisory stress-testing covering over 70 percent of banking sector’s assets (2022 coverage: 10 banks with 71 percent of banking sector’s assets).
  - 2022 internal desk-based AQR assessed about 1,400 borrowers individually and more than 19 million loans collectively; AQR reduced total capital adequacy of banks in sample by 1.7 percentage points (text truncated for full quantification).
  - Supervisory stress testing: pilot scenario example GDP – 0.3 percent; oil price US$40 per barrel; inflation 20 percent; USD/KZT rate 549,3 tenge; time horizon three years.
- Motivated judgment and legal limits:
  - Law enables ARDFM to exert “motivated judgment” only in five areas: licensing, related party transactions, risk management and internal controls, provisioning, and major participants (Law 474-II art. 13.5).
  - This restriction reduces supervisory discretion needed for an effective RBA; recommendation to expand motivated judgment to additional areas and allow provisional motivated judgments in urgent situations (with right to be heard afterwards).
- Pillar 2 and supervisory capital:
  - With IMF assistance ARDFM is developing a methodology for calculating Pillar 2 capital add-ons based on qualitative and quantitative parameters and stress test results; roll-out planned for 2024.
  - Recommendation: speed up Pillar 2 methodology implementation and broaden coverage to concentration, sovereign, and climate-related financial risks.

### Asset quality, provisioning, NPLs, and problem-asset treatment
- Transition and metrics:
  - Transition to IFRS 9 effective January 2018.
  - Official nonperforming loan (NPL) ratio: about 3 percent.
  - IFRS stage 3 loans as reported by ARDFM: 6.6 percent (reported in some summaries); 2022 AQR found Stage 3 loans about 15 percent (other sections report Stage 3 at 14.8 percent in 2022 and 13.5 percent in 2023 per ARDFM/AQR figures).
- Clean-up measures and distortions:
  - System clean-up largely achieved through government interventions: equity injections; issuance of subordinated debt at below market interest rates yielding capital gains used to write off past-due loans; purchase by state-owned Problem Loans Fund of past-due exposures significantly above market price or at 100 percent of nominal value.
  - Use of AMCs and transfers at preferential/non-market terms distorted asset quality, inflated profits, and delayed secondary market development.
- Recognition and reporting gaps:
  - NPL recognition is limited to 90 days past due exposures and does not include IFRS9 Stage 3 loans nor “unlikely to pay” (UTP) exposures; recommendation to align NPL definition with international standards and include IFRS9 Stage 3 and foreclosed assets.
  - Resolution n. 269 does not set timely write-off requirements for uncollectable loans; recommendation to introduce timely write-off requirements.
- Provisioning framework:
  - Resolution n. 269 implements IFRS 9 ECL framework; banks develop Methodology for calculating provisions agreed with supervisor; AQR and supervisory powers used to require additional provisions where warranted.
  - Liquidity haircuts for collateral (selected examples preserved exactly):
    - residential and/or commercial real estate, including land plots - 0.7;
    - vehicles - 0.5;
    - equipment, goods and materials, products ready for sale - 0.4;
    - highly liquid securities - 0.95;
    - guarantees issued by bank; a legal entity with a rating not lower than the sovereign rating ... - 1.
- Recommendation: reconcile prudential NPL and IFRS9 reporting; enforce timely write-offs; restrict non-market intra-group distressed-asset transfers.

### Related party transactions, insider abuse, and supervisory findings
- Reported exposure and evidence:
  - Reported exposure to related parties: 2.2 percent of banks’ capital (as at 1.1.23).
  - On-site inspection reports show hidden related party lending significantly above official reporting was the main source of NPLs and reason for liquidation in banks closed in recent years.
  - 18 asset management companies (AMCs) specialized in purchasing dubious and hopeless assets of parent banks; transfers to these entities were sometimes made at non-market terms (exception allowing up to 100 percent of bank equity).
- Legal and prudential limits:
  - Single related-party borrower exposure ≤ 10 percent of total capital; aggregate loans/guarantees to related entities ≤ 50 percent of equity; exception for subsidiaries buying doubtful assets can reach 100 percent of bank equity.
  - Prohibition on unsecured loans to related parties except ≤ 20 million tenge.
- Assessment and recommendations:
  - Assessment: Materially non-compliant for related party exposures.
  - ARDFM should perform more intrusive oversight (including on-site reviews), conduct thematic reviews (possibly with external experts), and revisit Banking Law Art. 40 par. 8 so distressed asset transfers to subsidiaries occur at market terms.

### Liquidity, IRRBB, concentration, and market/operational risk
- Liquidity and LCR/NSFR:
  - LCR and NSFR were at 80 percent at assessment; violations tolerated Feb 21, 2022 – Dec 31, 2022 subject to nine-month action plans.
  - ARDFM will restore LCR and NSFR at 100 percent from July 2024; starting January 2024 LCR and NSFR increased from 80 percent to 90 percent, with 100 percent effective from July 2024 (authorities’ implementation note).
  - Top 30 depositors account for 11.5% of total loans (top depositor concentration noted) and top 30 depositors account for about 11 percent of total deposits (other sections).
  - About 1/3 of deposits are in foreign currency.
  - Recommendation: exit liquidity forbearance, set LCR/NSFR at 100 percent, assess contingency funding plans, consider LCR per significant currency, and enforce sanctions for violations.
- Interest rate risk in the banking book (IRRBB):
  - Banks required to use EVE and NII; ARDFM requested EVE and NII only for two out of six Basel scenarios initially.
  - ARDFM lacked a challenger model and did not verify bank-provided IRRBB information at assessment; later developments note a challenger model developed in May 2023 (authorities’ response).
  - Recommendation: require EVE/NII for all six Basel scenarios, develop and use a challenger model, and roll out Pillar 2 IRRBB methodology.
- Market and operational risk:
  - Market risk included in SREP and stress testing but stress-test results not yet used to calibrate additional capital.
  - Operational risk: ARDFM adopted Basic Indicator Approach effective January 1, 2023; collection of operational loss data above 500.000 KZ tenge quarterly is being implemented.
  - Cybersecurity capacity and IT resources are constrained; recommendation to invest in staff, training, and certifications and clarify internal audit remit over outsourced functions.

### Consolidated supervision, home-host cooperation, and cross-border oversight
- Consolidated supervision:
  - Legal powers exist to regulate on consolidated basis, but risk management expectations and prudential requirements are not fully applied at group level.
  - As of end-2022, 12 banking groups supervised: 2 simple, 7 medium complexity, 3 complex; only two groups have overseas operations.
  - Assessment: Principle 12 — Materially non-compliant; recommendation to apply liquidity and capital requirements at consolidated level and strengthen consolidated reporting and supervision.
- Home-host cooperation:
  - ARDFM has MOUs with regional/international supervisors but has not been sufficiently proactive; supervisory colleges not revived/established for internationally active banks.
  - At least one missing MOU with the home country supervisor of a significant global bank active in Kazakhstan; recommendation to establish missing MOU and revive supervisory colleges.

### Licensing, fit & proper, beneficial ownership, and recovery/resolution
- Licensing and fit & proper:
  - No license applications since 2009 noted; ARDFM responsible for granting and withdrawing licenses.
  - Gap: ARDFM cannot assess suitability of Heads of internal control functions (CRO, Chief Compliance Officer, Chief Internal Audit Officer) because they are not defined as “executive employees” in Banking Law n. 2444 Art. 20; recommendation to amend law to enable such assessments.
  - Banking Law lacks explicit definition of “beneficial ownership” and “ultimate beneficial owner”; AML/CFT legislation contains a definition which could be referenced.
- Recovery and resolution:
  - ARDFM is the formal resolution authority but resolution function is integrated into Supervisory Department and not separated; no operative dedicated resolution authority.
  - No recovery and resolution planning framework at time of assessment: banks do not submit recovery plans and ARDFM Division “Resolution of Problem Bank” does not prepare resolution plans for systemic banks.
  - Legal process: only a court may declare a bank bankrupt (Art. 71); resolution options include compulsory reorganization, merger, or forced liquidation.
  - Recommendation: implement requirement for banks to prepare recovery and resolution plans and develop resolvability assessments; consider legislative amendments to operationalize resolution framework.

### AML/CFT supervision — staffing, methodology, and recommendations
- Framework and practice:
  - ARDFM adopted Requirements for Internal Controls for AML and includes AML/CFT in SREP; Agency inspects AML/CFT through onsite and offsite reviews.
  - Supervisory resourcing: 6 staff in Methodology Department; 14 staff in Banking Regulation Department for offsite AML/CFT; 20 staff for onsite AML/CFT inspections; a small number hold AML certifications (1 Certified Anti-Money Laundering Specialist; 3 Kazakhstani AML/CFT certificates).
  - Onsite methodology intensive: inspectors review large numbers of customer files and transactions (example: one bank high-risk required six staff and three months; typical one-year activity yields ~128 thousand transactions for average-risk bank).
- Findings and recommendations:
  - Onsite inspection approach appears to lack a risk-focused perspective; extensive review of every transaction shifts primary AML/CFT responsibility from firms to the supervisor and consumes time/resources.
  - Recommendation: rebalance to risk-focused supervision, invest in staffing and technology (SupTech, transaction analytics), encourage internationally recognized professional certificates for key staff, and consider establishing specialized teams for topics beyond AML/CFT (fraud, crypto).

### Key supervisory findings and prioritized recommendations (selected)
- Preserve numeric details exactly:
  - ARDFM budget for 2023: 9.2 bln tenge (about $US 20 mln).
  - Total ARDFM staff: 595 full-time employees.
  - Banking Supervisor Department total staff: 76.
  - BANKING ANALYTICS AND STRESS-TESTING DEPARTMENT: 30.
  - Minimum authorized and own capital for newly established bank: 10 000 000 000 (ten billion) tenge.
  - Minimum for housing construction savings bank: 4,000,000,000 (four billion) tenge.
  - Foreign parent bank minimum assets to open branch: US $20 billion.
  - Required irrevocable deposit for foreign branch with National Bank: 10 billion Tenge.
  - Individual deposit cap at foreign branch: US$ 120 thousand equivalent.
  - RAS quantitative indicators: 33 indicators; qualitative indicators: 122 indicators.
  - SREP 2021 results: 6 banks “low risk,” 11 banks “moderately low risk,” 4 banks “moderately high risk,” 1 bank “high risk.”
  - SREP 2022 results: 7 banks “low risk,” 8 banks “medium-low risk,” 5 banks “medium-high risk,” 1 bank “high risk.”
  - Motivated judgment restricted to five areas as per Law 474-II art. 13.5.
- Consolidated list of priority actions (extracted):
  - Amend Law 474-II to enshrine ARDFM independence, autonomy over structure/staffing, and clearer removal grounds for Chair; remove voting rights of President’s representative.
  - Consider alternative funding mechanisms, e.g., levy fees on banks calibrated to assets or risk-weighted assets.
  - Expand legal scope of motivated judgment beyond five enumerated areas and allow provisional motivated judgment in urgent cases; consider an Administrative Board of Review.
  - Roll out Pillar 2 capital add-on methodology in 2024 and expand to concentration, sovereign, and climate risks; introduce a leverage ratio (consider 2024 implementation plans).
  - Phase out remaining COVID/geopolitical forbearance measures (align SME and syndicated loan RWAs with Basel); restore LCR and NSFR to 100 percent.
  - Strengthen supervision of related party transactions, require market terms for distressed-asset transfers to subsidiaries, and conduct thematic reviews with external experts.
  - Require banks to prepare recovery plans and ARDFM to carry out resolvability assessments and resolution planning for D-SIBs.
  - Strengthen AML/CFT supervision by investing in SupTech, staffing, and training; pivot to risk-focused onsite inspections.
  - Enhance SupTech strategy, modernize data platforms, and reduce dependency risks from NBK IT systems through cooperation and targeted upgrades.

*Source: Excerpts from the IMF Detailed Assessment — 1kazea2024004 (Basel Core Principles assessment for the Republic of Kazakhstan, as provided).*

### Executive Summary_________________________________________________________________________________7

### EXECUTIVE SUMMARY

### Institutional change and mandate
- At the end of 2019 the financial sector supervisory responsibilities of the National Bank of Kazakhstan (NBK) were transferred to the newly established authorized body Agency of the Republic of Kazakhstan for the Regulation and Development of the Financial Market (ARDFM).
- ARDFM has a dual mandate: financial stability and development (including supporting expansion of banks’ loan portfolios). The development objective can conflict with safety and soundness and is not subordinate to the financial stability mandate.
- ARDFM independence is not prescribed in the legislation and is undermined by provisions in the Law 474-II that make ARDFM “directly subordinated” to the President of the Republic of Kazakhstan who approves the organization structure and the staff.
- ARDFM is funded only from the republican budget.
- ARDFM began operations during the coronavirus pandemic and has conducted stress tests and internal desk-based asset quality reviews (AQR) that complement the supervisory review examination process (SREP).

### Pandemic and crisis-era regulatory forbearance (measures and timelines)
- Regulatory easing implemented to mitigate Covid-19 effects and later geopolitical spillovers:
  - Reduced risk-weighting ratios when calculating capital adequacy:
    - loans to small and medium enterprises (SMEs): from 75 percent to 50 percent;
    - loans in foreign currency: from 200 percent to 100 percent;
    - syndicated loans: from 100 percent to 50 percent.
  - Reduced limits to long foreign exchange position: from 12.5 percent to 7.5 percent of capital.
  - Reduced total foreign currency net position limit: from 25 percent to 12.5 percent of capital.
  - Temporarily reduced capital conservation buffer: from 2 percent to 1 percent.
  - Temporarily reduced liquidity coverage ratio (LCR): from 0.8 to 0.6 (March 30, 2020, to April 1, 2021).
  - Postponed tightening of the net stable funding ratio (NSFR).
  - Relaxed provisioning requirements for SMEs restructured loans by excluding the restructuring factor from criteria for automatic loan impairment when forming allowances.
  - Banks provided deferment of payments on loans to SMEs with grace periods ranging from 30 to 90 days at the borrower’s choice.
- Exit from forbearance:
  - As economic activity recovered, forbearance measures were progressively exited; by end of 2021 most regulatory easing was completed except for the reduced risk-weighting ratio of loans to SMEs and syndicated loans, which remained in place at the end of the assessment.
  - ARDFM should phase out the remaining measures as soon as possible because they undermine credibility of banks’ capital adequacy ratios and reduce resilience.
- Geopolitical risks (including the Russian invasion of Ukraine) and related market pressures:
  - To stem FX market tensions and preserve liquidity, ARDFM postponed full implementation of LCR and NSFR, which were both at 80 percent instead of 100 percent at the date of the assessment.
  - Violation of LCR, NSFR and other liquidity ratios due to outflow of deposits, revaluation of assets and liabilities were temporarily tolerated from February 21, 2022, to December 31, 2022, subject to banks providing an action plan to address the violation within nine months.
  - ARDFM should set LCR and NSFR at 100 percent as soon as feasible and work with impacted banks on plans to restore liquidity buffers as needed.
  - ARDFM will restore LCR and NSFR at 100 percent from July 2024.

### Supervisory approach, capacity, and discretion
- ARDFM has introduced a risk-based approach (RBA) and a supervisory methodology based on the Risk Assessment System (RAS), which feeds into the SREP.
- In 2021 ARDFM conducted a full-scale SREP assessment for the first time and piloted an internal desk-based AQR and supervisory stress testing.
- Since 2022 ARDFM conducts regular AQR and supervisory stress-testing covering over 70 percent of the banking sector’s assets.
- With IMF technical assistance, ARDFM is developing a methodology for calculating Pillar 2 capital add-ons based on qualitative and quantitative parameters and stress test results.
- Legal constraints on supervisory discretion:
  - The law enables ARDFM to exert its “motivated judgment” (equivalent to supervisory judgment) only in five areas: licensing, related party transactions, risk management and internal controls, provisioning, and major participants.
  - This constraint reduces room for discretion needed for an effective RBA (for example in setting additional capital and liquidity beyond Basel Pillar 1) and should be expanded to other areas (e.g., concentration risk and ‘group of connected counterparties’) with strengthened legal protection of staff.

### Asset quality, provisioning, and past clean-up measures
- System clean-up of non-performing loans was largely achieved through government interventions that included:
  - equity injection;
  - issuance of subordinated debt at below market interest rates, with resulting capital gain used to write off past-due loans;
  - purchase by the state-owned ‘bad’ bank, the Problem Loans Fund, of past-due exposures significantly above market price or even at 100 percent of the nominal value.
- Transition to IFRS 9 (January 2018) moved banks from an incurred loss to an expected credit loss model.
- Reported asset quality metrics:
  - official nonperforming loan (NPL) ratio: about 3 percent;
  - IFRS stage 3 loans (credit impaired) as reported by ARDFM: 6.6 percent.

### Related party transactions and insider abuse
- Reported exposure to related parties: 2.2 percent of banks’ capital.
- Evidence of insider abuse and extrapolation of private benefits documented in on-site inspection reports; in all banks liquidated in recent years, de facto exposure to related parties was significantly above official reporting and was the main source of NPLs and reason for liquidation.
- Recommendations:
  - ARDFM should perform more intrusive oversight of related party transactions, including on-site reviews.
  - Authorities should take more stringent corrective measures to address gaps in banks’ related party frameworks and practices.

### Key supervisory findings and operational notes
- ARDFM has made progress in delivering on its supervisory mandate (stress testing, AQR, SREP), but the most recent transfer of supervisory functions represented a setback in mandate and budget.
- The ARDFM’s dual mandate and funding structure can undermine perceived independence and may create conflicts between development objectives and the safety and soundness of banks.
- The introduction and regular execution of AQRs and supervisory stress testing are positive developments; continued enhancement of RBA and Pillar 2 methodologies is underway with IMF support.

*Source: Executive Summary of the Basel Core Principles assessment for the Republic of Kazakhstan (as provided).*

### 7.      An assessment of compliance with the BCPs is not, and is not intended to be, an exact

### 1kazea2024004 - 7.      An assessment of compliance with the BCPs is not, and is not intended to be, an exact

### Assessment methodology and ratings
- Compliance assessment is judgment-based; the process is “not, and is not intended to be, an exact science.”  
- A common, agreed methodology is used to provide an internationally consistent measure versus the revised Core Principles (CPs).
- Four rating categories are used:
  - compliant — all ECs are met without any significant deficiencies, including where the principle has been achieved by other means.
  - largely compliant — only minor shortcomings; do not raise serious concerns about achieving the objective; clear intent to achieve full compliance within a prescribed period.
  - materially noncompliant — severe shortcomings; despite formal rules, supervision not effective and practical implementation is weak; shortcomings raise doubts about ability to achieve compliance.
  - non-compliant — principle not substantially implemented; several ECs and ACs not complied with; supervision manifestly ineffective.
  - non-applicable — criteria not relevant to the jurisdiction’s circumstances.

### Institutional and market structure — overview
- Institutional structure:
  - Decree No 203 of the President of the Republic of Kazakhstan as of November 11, 2019 transferred financial sector supervisory responsibilities of the NBK to the newly established authorized body (ARDFM), which formally launched in 2020.
  - Historical variability: 2004–2011 supervision by the FSA (reporting directly to the President); FSA abolished in 2011 and supervision integrated into NBK; 2019 reform created ARDFM.
  - Major new changes in institutional setting should be a last resort due to potential negative impact on supervisory capacity and continuity.
- ARDFM mandates (multiple and potentially conflicting):
  - (i) protects the rights of consumers of financial services,
  - (ii) contributes to maintaining financial stability,
  - (iii) regulates, supervises, and oversees financial organizations,
  - (iv) implements policies for the development of the financial market (including promotion of financial innovation such as regulatory sandbox, open banking technology).
- Performance indicators and potential conflict:
  - Increase in total banking loan portfolio “from 2019” (20–28 percent in 2022) and “from 2021” (38 percent in 2023).
  - Targets for increase of bank loans to legal entities “from 2021” (17 percent in 2023 and 28 percent in 2024).
  - Development mandate is not subordinate to prudential mandate and may be pursued at expense of safety and soundness.
- Inter-agency arrangements:
  - NBK “contributes to ensuring the stability of the financial system” but ARDFM has not signed a Memorandum of Understanding (MOU) with NBK; only an information sharing agreement exists.
  - Council on Financial Stability (strengthened by Decree No 220 of December 18, 2019) coordinates interdepartmental financial stability issues; functions include preliminary consideration of macroprudential policy, anti-crisis measures, resolution of systemically important banks, and financing restoration measures.

### Banking sector structure and key statistics
- System profile:
  - Kazakhstan has a bank-centered financial system.
  - Banking sector accounts for about 79 percent of financial system assets at end-2022.
  - Development Bank of Kazakhstan: 7 percent.
  - Remaining financial market sectors: 14 percent.
- Banking sector composition (end-2022):
  - 21 second-tier banks.
  - 12 banks with foreign participations, including 8 subsidiary banks.
  - 2 banks with 100 percent government participation.
  - 12 second-tier banks are part of banking groups.
- Assets and loan portfolio:
  - Total assets of the banking sector: 44.6 trillion tenge or 43 percent of GDP.
  - Asset growth: increasing by around 18 percent as compared to end of 2021.
  - Banks' loan portfolio: 54.4 percent or 24.3 trillion tenge.
- Financial system sector table (values preserved):
  - Banks — 44,6 bln. tenge — 79,2 %
  - Development Bank of Kazakhstan — 3,9 bln. tenge — 7,0 %
  - Securities market firms — 0,6 bln. tenge — 1,0 %
  - Insurance firms — 2,1 bln. tenge — 3,7 %
  - Pawnshops — 0,3 bln. tenge — 0,5 %
  - Credit partnerships — 0,8 bln. tenge — 1,3 %
  - MFO — 1,1 bln. tenge — 2,0 %
  - Mortgage lending non-banking organizations — 1,5 bln. tenge — 2,6 %
  - Agribusiness lending — 1,5 bln. tenge — 2,7 %
  - Total — 56,3 bln. tenge — 100 %

### Preconditions for effective banking supervision
- Macroeconomic shocks and responses:
  - Kazakhstan experienced: oil price shock (2014–2016), COVID-19 pandemic (2020), social unrest (January 2022) triggered by lifting a price cap on liquefied gas, and fallout from the war in Ukraine.
  - Consumer price index reached 20.3 percent y-o-y in 2022.
  - Authorities’ measures: fiscal support estimated at 3 percent of GDP; NBK policy rate hikes in 2022 from 9.75 to 16.75 percent (six times); NBK interventions in FX market.
  - Near-term recovery contingent on a more favorable external environment; long-term prospects depend on economic diversification, energy transition, and climate resilience.
- Financial stability policy formulation:
  - Financial Stability Council (FSC) strengthened after ARDFM spin-off; FSC composition includes Governor of NBK (Chairman), First Deputy Head of the Presidential Administration, Chairman of ARDFM, Minister of Finance, and Minister of National Economy.
  - Mandatory preliminary consideration by FSC: macroprudential policy, anti-crisis measures, resolution of insolvent banks, financing banks’ rehabilitation.
- Public infrastructure and legal reforms:
  - Insolvency Law strengthened: secured creditor right to accept pledged property after proposal from bankruptcy manager within five working days; 10-day term to file application to invalidate fraudulent transactions.
  - Personal bankruptcy law recently approved.
  - 2022 presidential announcements on political modernization, judicial reforms, and increased role for civil society and media.
- Crisis management, recovery, and resolution:
  - 2019 amendments introduced specific instruments to resolve failing banks, but framework has not been applied in practice.
  - MoU on Financial Stability Issues (2007) is outdated; NBK plans to develop a new triparty MoU among NBK, ARDFM, and the Government.
  - Resolution responsibility is not separated from banking supervision; no operative dedicated resolution authority; resolution function formally integrated into ARDFM Supervisory Department.
  - No recovery and resolution planning framework: banks do not submit recovery plans and ARDFM Division ‘Resolution of Problem Bank’ does not prepare resolution plans for systemic banks.
- Public safety net — KDIF:
  - Kazakhstan Deposit Insurance Fund (KDIF) established in 1999; NBK is founder and sole shareholder.
  - KDIF Board chaired by NBK Governor; board composition includes two NBK representatives and two independent members.
  - As of December 31, 2021, 19 out of 21 banks were KDIF members (two Islamic banks exempt).
  - KDIF functions: conduct payouts; maintain registry of member banks; participate in transfer of assets and liabilities; invest in assets; form a special reserve.
  - 2021 changes: contribution model modified; maximum insurance coverage increased:
    - Coverage for saving deposits in national currency: KZT 20 million.
    - Coverage for other types of deposits in national currency: KZT 10 million.
    - Coverage on deposits in foreign currency: KZT 5 million.
  - KDIF reserve in 2022: 5.7 percent of total insured deposits in member banks (minimum of 5 percent required by law).
  - Legislative period for start of payout is currently above those envisaged in the IADI principles.
- Lender of last resort (LoLR) framework:
  - Revised LoLR framework entered into force in 2019; provides liquidity support only to solvent banks with temporary liquidity problems.
  - 2020 amendments following spin-off: ARDFM assesses financial health of borrower bank; NBK decides on bank’s application to join agreement of general terms of LoLR.
  - Lack of MoU between ARDFM and NBK undermines operational certainty of LoLR; collaborative review of LoLR regulations is underway, aligning with annual Asset Quality Review by the Agency.
- Market discipline:
  - Regulations on risk management and internal control delineate responsibilities and reinforce risk governance concepts.
  - Authorities plan to introduce Basel framework Disclosure Standard (Pillar 3) to enhance market discipline and transparency.

### Main findings — selected issues and risks
- Institutional continuity and capacity:
  - High variability in financial sector oversight framework reduces institutional continuity and capacity building; recurrent reorganizations pose transition risks (mandate, independence, budget, IT, staff).
- Mandate prioritization and conflicts:
  - Safety and soundness is not legally prioritized over development mandates; ARDFM’s development KPIs (credit growth targets) risk trade-offs with prudential objectives.
  - Recommendation: law should create a hierarchy among objectives and ARDFM should embed prioritization in public documents and institutional arrangements (management committees, escalation processes).
- Independence and resourcing of ARDFM:
  - ARDFM independence not enshrined in legislation; Law N. 474-II 2003 (as amended 09/12/2022) contains provisions undermining independence: direct subordination to the President; Presidential approval of organizational structure and total staff; one presidential representative on ARDFM Board.
  - Lack of transparency in removal process for governing body; no duty to publicly disclose reasons for removal.
  - ARDFM funding from republican budget and assessors found actual constraints on budget that limit supervisory capacity (hiring external experts, cross-border on-site inspections, supervisory colleges, IT systems).
  - ARDFM staff lack adequate protection for legal costs defending actions/omissions undertaken in good faith.
- Licensing, fit & proper, and beneficial ownership:
  - No license applications since 2009; ARDFM should extend control mandate to assess suitability of Heads of control functions and periodically reassess qualifying shareholders.
  - Current law (Banking Law n. 2444, Art. 20) does not enable ARDFM to assess suitability of heads of internal control functions (chief risk officer, chief compliance officer, internal audit) as they are not considered ‘executive employees’.
  - No grounds in legislation to revoke a bank’s license granted on false information.
  - Banking Law lacks definition of “beneficial ownership” and “ultimate beneficial owner”; a definition exists in AML/CFT legislation and could be referenced or incorporated into the Banking Law.

*1kazea2024004 - 7.      An assessment of compliance with the BCPs is not, and is not intended to be, an exact*

### 33.      Laws and regulations provide for collaboration and cooperation between domestic

### 33.      Laws and regulations provide for collaboration and cooperation between domestic

### Collaboration with domestic and foreign supervisors
- Findings:
  - Laws and regulations provide for collaboration and cooperation between domestic authorities responsible for banking supervision, emphasizing confidentiality.
  - ARDFM has a number of memoranda of understanding with regional and international supervisors but has not been sufficiently proactive in collaboration.
  - ARDFM has not revived or established supervisory colleges for its internationally active banks.
  - At least one Kazakhstani bank plays a significant role in the region, suggesting benefits from more formal host-supervisor interactions.
  - ARDFM lacks one MOU with the home country supervisor of a significant global bank active in Kazakhstan.
- Recommendations:
  - Establish the missing MOU with the home country supervisor of the significant global bank active in Kazakhstan.
  - Revive or establish supervisory colleges for internationally active banks to improve understanding of cross-border activities and risks.
  - Align ARDFM’s approaches to collaboration with foreign supervisors and to supervision of banking groups.

### Strengthening home-host cooperation and supervision of cross-border exposures
- Findings:
  - More formal interactions with host supervisors could be beneficial given cross-border roles of some Kazakhstani banks.
- Recommendations:
  - Strengthen home-host supervisory cooperation.
  - Strengthen supervision of cross-border exposures and activities.

### Alignment with international standards and consolidated supervision
- Findings:
  - ARDFM should extend risk management expectations across banking groups and not solely at the solo bank level.
  - Present approach does not yet comply with international standards for consolidated supervision.
- Recommendations:
  - Continue plans to align key prudential standards with Basel.
  - Implement consolidated supervision principles across banking groups.

### Supervisory Approach (CP 8–10)
- Findings:
  - ARDFM transitioned to a risk-based approach (RBA); methodology for assessing nature, impact, and risk feeds into SREP.
  - Approach draws inspiration from the Eurozone Single Supervisory Mechanism (SSM) framework.
  - Use of “motivated judgement” anchors supervisory discretion to professional opinions and provides due process across five law-envisaged areas: licensing, related party transactions, risk management and internal controls, provisioning, and major participants.
  - There is a need for authority to adopt a “provisional motivated judgment” when urgent action is needed, with hearing as soon as possible after decision.
  - Although a framework exists for handling banks in stress, ARDFM has not carried out resolvability assessments.
- Recommendations:
  - Empower ARDFM to adopt provisional motivated judgments in urgent situations while ensuring due process.
  - Carry out resolvability assessments.

### Supervisory tools, inspections, and thematic reviews
- Findings:
  - ARDFM representative in a bank is the focal point for supervisory processes and leverages broad information sources.
  - SREP is complemented by an internal desk-based AQR, which feeds stress testing.
  - No formal process exists to regularly assess quality, effectiveness, and integration of on-site and off-site functions.
  - Making AQR an annual exercise has advantages and limitations; AQR should be instrumental to other activities, not an end in itself.
  - Inspection function is robust and findings are incisive but need prioritization (urgent vs medium-long term).
  - Interaction with independent board members should be strengthened.
  - Greater use of horizontal thematic reviews (corporate governance, cybersecurity, digital financial services, underwriting standards, related party transactions) is warranted.
  - ARDFM should speed up setting up the Pillar 2 methodology.
- Recommendations:
  - Establish a formal process to assess integration and effectiveness of on-site and off-site functions.
  - Prioritize inspection findings and strengthen engagement with independent board members.
  - Expand horizontal thematic reviews.
  - Accelerate Pillar 2 methodology implementation.

### Data, fair value, and IRRBB reporting
- Findings:
  - ARDFM can access information and reports from banks and groups collected by NBK.
  - Guidance to banks on validating and verifying fair value estimates should be strengthened and the supervisor’s evaluative role described.
  - Regulatory reporting on IRRBB should be enhanced: require banks to report economic value of equity (EVE) and net interest margin (NII) for each of the six scenarios prescribed by the Basel Committee.
- Recommendations:
  - Strengthen guidance on fair value estimation validation and supervisory evaluation.
  - Require reporting of EVE and NII for all six Basel IRRBB scenarios.

### IT dependency and SupTech
- Findings:
  - ARDFM is dependent on NBK IT systems to access data, creating potential risks if institutional priorities diverge.
- Recommendations:
  - Take stock of existing systems and data across ARDFM and NBK.
  - Consider strengthening, modernizing, or building platforms to support supervision, possibly as part of a “SupTech” strategy to increase data quality, automate manual processes, enhance cooperation, and support decision-making.

### Corrective and Sanctioning Powers (CP 11)
- Findings:
  - ARDFM has a range of supervisory response measures and sanctions and uses them.
  - ARDFM exercised forbearance by loosening capital and liquidity requirements in response to the COVID-19 pandemic and the outbreak of war in Ukraine.
  - Violations of liquidity coverage ratio (LCR), net stable funding ratio (NSFR), other liquidity ratios due to outflow of deposits, and revaluation of assets and liabilities were tolerated subject to banks providing an action plan to address violations within nine months.
- Recommendations:
  - Restore requirements to typical levels expediently to reduce risk expansion during prolonged uncertainty.
  - Exit liquidity forbearance measures and set LCR and NSFR at 100 percent.

### Corporate Governance and Risk Management (CP 14, 15)
- Findings:
  - Resolution n. 188/2019 strengthened the regulatory framework but gaps remain.
  - No requirement for boards to introduce succession plans.
  - No limit on multiple memberships for board members, potentially creating conflicts of interest and time commitment issues.
  - ARDFM did not structurally assess bank compensation systems.
  - Banks are not required to prepare recovery plans.
  - Supervisory assessment would benefit from targeted onsite inspections on corporate governance and a thematic review of Resolution n.188/2019 implementation.
  - Implementing ICAAP and ILAAP in the context of full Pillar 2 risk spectrum remains a key challenge.
- Recommendations:
  - Require succession plans and consider limits on multiple board memberships.
  - Structurally assess bank compensation systems and require recovery plans.
  - Conduct targeted corporate governance inspections and a thematic review of Resolution n.188/2019.
  - Implement ICAAP/ILAAP across Pillar 2 risk categories (sovereign, interest rate, climate-related financial risks).

### Capital (CP 16)
- Findings:
  - Kazakhstani banks transitioned to Basel II/III framework.
  - Risk weighted assets for credit risk are in some cases more conservative than the new standardized approach (consumer lending risk weights can reach as high as 350 percent—versus 75 percent in the Basel framework), but in other cases less conservative (exposure to SME and syndicated loans).
  - Consumer lending accounts for the largest share of total loans; conservative consumer lending weights compensate for less conservative SME weights at bank level.
  - Preferential treatment for exposures towards SME and syndicated loans in tenge was scheduled to expire at end of December 2023 and ARDFM did not prorogate it.
  - Definition of capital is broadly compliant with Basel standards, except revaluation reserves (which represent, on average, only 0.6 percent of Total capital).
  - Computability of non-bailinable subordinated debts into Tier 2 capital phased out between 2015 and 2020.
  - Capital conservation buffer (CCB) for non-systematically important banks is set at 2 percent (instead of 2.5 percent); CCB for domestically significant important banks (D-SIBs) is set at 3 percent.
  - No leverage ratio requirement is in place; ARDFM is considering its introduction in 2024.
  - Capital requirements do not fully reflect banks’ risk profile yet; roll-out of draft methodology for Pillar 2 capital add-on is planned for 2024.
- Recommendations:
  - Introduce a leverage ratio (consider in 2024 implementation plans).
  - Roll out Pillar 2 capital add-on methodology in 2024 to better reflect risk profiles.

### Credit Risk, Problem Assets, Provisions and Reserves (CP 17–18)
- Findings:
  - Consumer lending growth remains a concern: about 40 percent in 2021 and 25 percent in 2022.
  - Some banks are loosening underwriting standards (consumer loans used for mortgage down payments, repayment of overdue debt, or lending consumer loans to SME entrepreneurs).
  - Regulation does not cap absolute consumer loan amounts, potentially enabling unintended uses.
  - NPL recognition limited to 90 days past due exposures (around 3 percent of banks’ loans) but does not include IFRS9 stage three loans (6.6 percent, as at end 2022) nor “unlikely to pay” (UTP) exposures (foreclosed assets).
  - Resolution n. 269 does not set timely write-off requirements on uncollectable loans.
- Recommendations:
  - Require banks to strictly monitor intended use of consumer loans and apply supervisory measures for noncompliance.
  - Consider whether consumer lending acceleration is driven by moral hazard from prior debtor bailouts.
  - Align official NPL definition with international standards, including for IMF Financial Soundness Indicators reporting.
  - Set timely write-off requirements for uncollectable loans.

### Related Party Exposures, Liquidity and IRRBB (CP 19–25)
- Findings:
  - Law provides broad definition of related party; supervisor can exert motivated judgment.
  - Related party exposure risk for banks that defaulted between 2020 and 2021 was higher than officially reported.
  - Transfer of distressed assets at non-market terms to subsidiaries distorts credit risk, inflates profits, and delays distressed asset market development.
  - Supervision of liquidity risk needs strengthening.
  - ARDFM should exit liquidity forbearance and set LCR and NSFR at 100 percent; structurally assess banks’ liquidity contingency funding plans.
  - Perform more thorough monitoring of foreign currency liquidity, including foreign currency liquidity stress tests.
  - Supervision of IRRBB is at an infancy stage: ARDFM requested EVE and NII quantification but only for two out of six Basel scenarios; ARDFM lacks a challenger model and does not verify bank-provided IRRBB information nor identify outliers.
  - ARDFM presented on-going work to expand EVE scenarios and develop a challenger model, but implementation remains to be seen.
- Recommendations:
  - Strengthen supervision of related party exposures and prevent non-market transfers of distressed assets.
  - Exit liquidity forbearance; set LCR and NSFR at 100 percent; assess contingency funding plans and conduct foreign currency liquidity stress tests.
  - Expand IRRBB scenario coverage to all six Basel scenarios, develop and use a challenger model, and verify bank submissions.

### Market, Operational, Outsourcing and Cybersecurity Risk
- Findings:
  - Market and operational risk are incorporated into SREP but require further development.
  - Stress testing includes market risk, but results do not contribute to calibration of additional capital requirements.
  - ARDFM decided to adopt the basic indicator approach for operational risk (effective January 1, 2023), requiring supervisor validation of banks’ historical internal loss data; gathering of loss data exceeding 500 thousand tenge is being implemented only this year.
  - For outsourced functions, guidance should clarify internal audit authority and resources to evaluate risks from third-party tasks.
  - ARDFM needed to strengthen cybersecurity capacity at the time of onsite visit.
- Recommendations:
  - Ensure stress testing outcomes inform capital calibration where appropriate.
  - Complete collection and supervisory validation of operational loss data (losses > 500 thousand tenge).
  - Clarify guidance on internal audit authority over outsourced functions.
  - Invest in training and recruitment for cybersecurity expertise, and encourage internationally recognized professional certification for staff.

### Disclosures, External Auditors, and Transparency (CP 27–28)
- Findings:
  - Disclosure requirements are broadly aligned with international standards, and some prior deficiencies (e.g., auditor rotation) were corrected.
  - Supervisors should have power to limit conflicts of interest when an auditor provides consulting services to the same client.
  - ARDFM currently lacks power to reject or rescind selection of an external auditor even if inadequate or insufficiently independent.
  - Laws/regulations do not require disclosure of all material entities within a corporate group structure, undermining consolidated group presentation.
- Recommendations:
  - Empower ARDFM to reject or rescind external auditor selections considered inadequate or insufficiently independent.
  - Amend regulations to require disclosure of all material entities within a group and reporting of related risk management, governance, and remuneration information.

### Abuse of Financial Services / AML/CFT (CP 29)
- Findings:
  - ARDFM adopted an ambitious approach to implement and enforce AML/CFT legislation and regulations.
  - Onsite inspection approach appears to lack a risk-focused perspective, with extensive review of customer documentation and every transaction.
  - This approach risks shifting responsibility for identifying money laundering and terrorist financing risks from firms to ARDFM, incurs high time and resource costs, and may diminish ARDFM’s ability to spot problems.
- Recommendations:
  - Rebalance onsite inspection approach toward risk-focused supervision to preserve firms’ primary responsibility for AML/CFT risk identification and improve supervisory efficiency.

*Source: 1kazea2024004 - 33.      Laws and regulations provide for collaboration and cooperation between domestic*

### 53.      The ARDFM should continue to invest in its staffing and technology for AML/CFT,

### 1kazea2024004 - 53.      The ARDFM should continue to invest in its staffing and technology for AML/CFT,

### AML/CFT staffing, technology, and specialization
- The ARDFM should continue to invest in its staffing and technology for AML/CFT, including potentially procuring appropriate IT tools for conducting evaluations of customers and transactions when necessary.
- After the mission, assessors were informed that the ARDFM is building some new tools for AML/CFT supervision, which remain under development.
- The ARDFM should consider encouraging key managers and staff to seek internationally recognized professional certificates in AML/CFT to ensure staff are well prepared to evaluate banks’ practices and staff in the field.
- Given the wide range of responsibilities assigned to the team covering AML/CFT, the ARDFM may find it useful to establish specialized teams for the most significant topics beyond AML/CFT, such as fraud and crypto-related activities.

### Institutional evolution and legal foundation
- Banking supervision architecture in Kazakhstan has shown high variability:
  - From 2004 to 2011 the regulatory and supervisory functions were performed by the Agency of the Republic of Kazakhstan on Regulation and Supervision of the Financial Market and Financial Organizations (FSA).
  - The FSA was abolished in 2011 and banking supervision was integrated into the NBK.
  - Decree No 203 of the President of the Republic of Kazakhstan as of 11 November 2019 transferred financial sector supervisory responsibilities of the NBK to the newly established Agency of the Republic of Kazakhstan for the Regulation and Development of the Financial Market (ARDFM), which formally launched its operations in 2020.
- Law of the Republic of Kazakhstan "On State Regulation, Control and Supervision of Financial Market and Financial Organizations" dated 04.07.2003 No 474 (L. 474-II) and Decree n. 203 define ARDFM’s responsibilities, objectives, mission, tasks, functions, rights and obligations.
- Law 474-II art. 3 identifies:
  - two goals: (a) assistance in ensuring financial stability and maintain confidence in the financial system and (b) creation of equal conditions for the activities of financial organizations.
  - four tasks: (a) establish the standards for the activities of financial organizations; (b) monitoring of financial market and financial organizations; (c) concentrate supervisory resources in the areas most exposed to risk to ensure financial stability; (d) ensuring appropriate level of protection of the interest of consumers of financial services.
- Decree n. 203:
  - defines ARDFM mandate as ‘ensuring an appropriate level of protection of the rights and legitimate interests of consumers of financial services, contributing to the stability of the financial system and the development of the financial market, exercising state regulation, control over and supervision of the financial market and financial institutions, as well as other persons, within its competence’ (art. 1).
  - establishes the mission: (a) regulation and development of the financial market (b) promotion of financial stability of the financial market and financial organizations, (c) maintaining confidence in the financial system as a whole (d) creating equal conditions for the activities of financial organizations.
  - enucleates the same four tasks identified by Law 474-II.
- NBK’s role: Central Banking Law (Law n. 2155 ‘On the National bank of the Republic of Kazakhstan - NBK Law, Chapter 2) states NBK still ‘contributes to ensuring the stability of the financial system’ and ARDFM should interact with NBK (Decree n. 203, Chapter 2, par. 15, point 22).
- Memoranda and agreements:
  - ARDFM has not stipulated a Memorandum of understanding (MOU) with NBK yet, but only an information sharing agreement that excludes exchanges related to documents classified as "For Official Use" and those covered by state secrets; sharing can occur through reciprocal IT system access to a list of employees.
  - An old MOU (2007) existed involving the previous Agency for Supervision, the Government, Ministry of Economy and Budget Planning, and Ministry of Finance.
  - NBK is drafting a new MOU for further discussion with ARDFM and other relevant authorities.

### Findings under Essential Criteria (EC1 and EC2)
- EC1 (Responsibilities and objectives clearly defined and publicly disclosed):
  - The responsibilities and objectives of ARDFM are defined by Law 474-II and Decree n. 203.
  - A credible public framework to avoid regulatory and supervisory gaps is in place through these instruments, but inter-agency coordination mechanisms (an updated MOU) remain to be finalized.
- EC2 (Primary objective of banking supervision is safety and soundness):
  - ARDFM is assigned broader responsibilities which are not explicitly subordinated to the safety and soundness of banks and the banking system.
  - Financial stability goals coexist with (i) consumer protection, (ii) competition (‘creation of equal conditions . . ..) and (iii) development of financial markets.
  - The ARDFM acknowledged in its self-assessment questionnaire that the Law does not provide for the priority of these goals.
  - Example of potential conflict between development mandate and financial stability objective:
    - ARDFM KPIs set targets for increase in total banking loan portfolio “from 2019” (20–28 percent in 2022) and “from 2021” (38 percent in 2023), as well as in banking loans to legal entities “from 2021” (17 percent in 2023 and 28 percent in 2024).
    - Measures to stimulate lending noted in practice include reducing risk weighted assets from 75 percent to 50 percent for some exposures.
    - To support project financing exposures to legal entities in domestic currency with the form of syndicated loans, such exposures are risk weighted at 50 percent, regardless of the entities’ external rating (see CP16).
    - A capital conservation buffer for banks other than Domestically Significantly important (D-SIB) has been set at 2 percent instead of [text truncated at source].

*Source: Excerpt from the Republic of Kazakhstan Detailed Assessment (page content provided).*

### 2.5 percent; while a leverage ratio requirement is not in place at all. In addition, to

### 1kazea2024004 - 2.5 percent; while a leverage ratio requirement is not in place at all. In addition, to

### Innovation, fintech and crypto — opportunities and risks
- ARDFM to:
  - bring regulation in line with the needs of the development of digital technologies.
  - introduce regulatory sandboxes.
  - develop standards for open banking technologies.
  - consider authorizing banks to form and have equity interest in the capital of Fintech, with a limit of 15 percent of equity for all investments in non-financial assets.
- Broader goals: promote digitalization, favorable legal conditions for new technologies, support innovation in the financial market, develop digital financial infrastructure, and use block-chain technology.
- Astana International Financial Centre (AIFC):
  - Jurisdictionally separated from the domestic financial system (separate non-crime legislation, based on common law, and separate judicial).
  - Crypto pilot project in the AIFC; commercial banks are not able to have direct or indirect exposures to crypto assets, though monitoring indirect exposures can be difficult.
  - As part of the AIFC pilot, under supervision of ARDFM and NBK, commercial banks provide fiat settlement rails for Astana Financial Service Authority (AFSA) registered exchanges.
- Risks observed in crypto platforms: flaws in governance, inappropriate business model, operational fragilities, liquidity and maturity mismatches, leverage, interconnectedness.
- ARDFM has not strategized the implementation of FSB recommendations for Regulation, Supervision and Oversight of crypto-asset activities and markets (October 2022).
- ARDFM should remain vigilant on banks’ indirect exposures towards unbacked crypto assets or global stable coins without an effective stabilization mechanism, and towards mining activities (reference: BCBS, Prudential treatment of crypto assets exposures, 2022).

### Prudential powers, standards and supervisory tools (EC3–EC6)
- Legal bases and powers:
  - ARDFM can set ‘prudential standards and other mandatory standards and limits’ for banks and banking groups (art. 41 Law on Banks and Banking Activity in the Republic of Kazakhstan – BL 2444).
  - Prudential standards may cover capital, concentration, liquidity, and currency risk for banks; capital and concentration for banking groups; and additional standards ‘used in the international practices’ (art. 42, par. 1, BL 2444).
  - ARDFM power to set standards is also enshrined in Decree 203 (art. 14).
  - ARDFM can enforce capital prudential standards and request recapitalization plans (art 42 par. 4 BL 2444).
  - ARDFM can set/enforce prudential standards for branches of non-resident banks (art. 42, para. 6).
  - BL 2444 art. 46 empowers ARDFM to apply measures to improve financial condition and/or minimize bank risks, including maintenance of capital adequacy and/or liquidity ratios above minimum values established by ARDFM.
- Pillar 2 (supervisory allowance) methodology under development will consist of three components:
  - (i) a risk premium, based on quantitative parameters;
  - (ii) an allowance for deficiencies in risk management systems, business model and corporate governance, based on qualitative parameters;
  - (iii) surcharge for stress test.
- Major regulatory update: NBK Board Resolution dated November 12, 2019, No. 188 — ‘Rules for formation of risk management and internal control system for second-tier banks’ (Resolution 188) strengthened corporate governance, risk management, ICAAP, ILAAP, credit, market, and operational risk supervisory standards.
- Enforcement and corrective toolkit:
  - “Early response measures” (art. 45) — request action plans; factors for consideration specified by NBK Regulation n. 317/2018.
  - Supervisory response measures: recommendatory measures (Art. 45-2), measures to improve financial stability or minimize risk (Art. 46), compulsory supervisory response measures against major participants (Art. 47-1).
  - ARDFM can apply sanctions (Art. 47-2), suspend or revoke a banking license (Art. 48); ARDFM is the resolution authority.

### Independence, governance, accountability and resourcing (Principle 2; EC1–EC9)
- Independence and appointment:
  - ARDFM is “directly subordinated (and accountable) to the President of the Republic of Kazakhstan” and acts on the basis of the Regulation approved by him (Law 474-II art. 6-1).
  - Organizational structure and total staff of ARDFM is approved by the President (art. 6-2).
  - Chair appointed by the President for a period of 6 years and dismissed by the President (Decree 203, art. 13; L. n. 474-II art. 6-3). Grounds for removal are not specified in law; no duty to publicly disclose reasons for removal.
  - Three Deputy Chairs appointed for six years and dismissed by the President on proposal of the Chair (Law 474-II art. 6-4).
- Governance:
  - Board is main decision body; includes Chair, three Deputies, one representative from the President, and one representative from NBK (art. 6-6).
  - Chair has operational/executive powers, can object to Board decisions within a week; Board decisions confirmed by two-thirds require Chair to sign (Law n. 474-II art. 6-7).
  - Supervisory Committee (established 2020) considers risks of financial system and systemically important institutions; members include ARDFM Chairperson, First Deputy, directors of multiple departments, Deputy Governor of NBK, etc.
- Staff integrity and rules:
  - Employees prohibited from purchasing units of investment funds, bonds, and shares of commercial organizations; obliged to transfer to trust management such assets within one month of joining (Law n. 474-II, Art 15-13).
  - ARDFM policy on prevention and settlement of conflicts of interest n. 235/2022; whistleblower mechanism (except anonymous).
  - Prohibitions on disclosure of protected information (BL 2444 Art. 44, par 3).
- Resourcing and budget:
  - ARDFM activities financed from the republican budget (L. n. 475-II and Decree 203/2019, Art 11).
  - Budget for 2023: 9.2 bln tenge (about $US 20 mln) and envisaged as constant until 2027.
  - ARDFM does not levy fees on banks to build budget; fully dependent on Ministry of Finance for budget decisions.
- Staff numbers and structure:
  - Total staff size: 595 full-time employees (determined by Decree n. 203/2019).
  - Banking Supervisor Department total: n. 76 staff allocated as detailed:
    - Director, Deputy Directors: 4
    - 1.1. LICENSING: 9
    - 1.2. RESOLUTION OF PROBLEM BANKS: 10
    - 1.3. SUPERVISION OF GROUP II BANKS: 13
    - 1.4. COUNTERACTION TO UNFAIR PRACTICES: 11
    - 1.5. BANK INSPECTION: 13
    - 1.6. SUPERVISION OF SYSTEMICALLY IMPORTANT BANKS: 16
    - Total 76
  - BANKING ANALYTICS AND STRESS-TESTING DEPARTMENT: 30 (Director, Deputy Director 2; Banking sector development and analytics 10; Banking stress testing 10; Banking reporting and statistics 8).
- Capacity constraints and tools:
  - ARDFM staff view resources as limited but skilled; two Divisions for off-site supervision: Domestically Important Banks (D-SIBs) Division supervises n. 3 D-SIBs, n. 4 large banks and one bank with foreign ownership; Division of group II banks oversees remaining 13 banks, the Post Office and 4 organizations specialized in agriculture and mortgages.
  - Salary scales approved by the Board; wages are not indexed to inflation; country inflation runs at two digits (more than 20 percent).
  - Use of external experts is rare due to budget limitations; 2019 internal desk-based AQR was unique use of outside experts.
  - Technology/SupTech: supervisory IT solutions mainly belong to NBK; ARDFM implemented some tools for internal desk-based AQR and stress testing but overall SupTech tools require further upgrade; ARDFM needs to actively develop 4G SupTech tools (AI, ML, network analytics, NLP).
  - Travel budget limited, constraining participation in supervisory colleges and cross-border examinations.
- Legal protection:
  - Law provides legal protection to staff acting in good faith, but staff are not protected against the cost of defending claims in practice; ARDFM lacks a procedure to protect staff against legal defense costs.
- Assessment:
  - Principle 2: Materially non-compliant.
- Key recommendations (Principle 2):
  - Amend Law 474-II to prescribe ARDFM independence and autonomy to decide organizational structure and number of staff.
  - Law should state ARDFM Chair could be removed only if not physically or mentally capable or found guilty of misconduct; reasons for removal should be publicly disclosed.
  - Representative from the President on ARDFM Board should not have voting right.
  - Consider alternative budgeting (e.g., levy fees on banks calibrated to assets or risk weighted assets).
  - Adopt procedure to protect staff against legal defense costs for actions/omissions made in good faith.

### Licensing, permissible activities and fit & proper (Principles 4–5)
- Definition and permissible activities:
  - BL 2444 Art. 1: bank is ‘a legal entity which is a commercial organization, entitled to perform banking activities in accordance with this Law’.
  - BL 2444 Art. 30 lists permissible activities and allows additional services (leasing, factoring, fiduciary operations) subject to ARDFM license (Art. 30, par. 11) and securities activities if authorized (Art. 30, par. 12).
  - Use of word “bank” limited to licensed and supervised institutions (BL 2444 Art. 1 par. 3).
  - Taking deposits from physical persons reserved to licensed banks that are members of obligatory deposit insurance system and to the National Post (BL 2444 art. 30 par. 13). Legal entities may take deposits from legal entities within limits imposed by law (art. 30, par. 6-1).
  - List of licensed banks published on ARDFM website.
- Licensing process and criteria:
  - ARDFM is responsible for granting and withdrawing banking licenses (BL 2444 Art. 19–27).
  - Two-step process: permission to open a bank, then license to conduct banking operations; timelines: permission application considered within sixty-five working days (art. 23); license considered within thirty working days (art. 26).
  - Applicants must submit business plan, financial prospects (budget, balance sheet, profit and loss for first three financial operating years), marketing plan, risk management plan, documents on proposed executives, and other documentation.
  - Fit and proper requirements for executive employees prescribed by Art. 20; a person cannot be appointed as executive employee if lacking higher education, lacking work experience, lacking “impeccable business reputation,” or if certain adverse past roles/convictions exist.
  - ARDFM does not have the power to assess suitability of Heads of internal control functions (CRO, Chief Compliance Officer, Chief Internal Audit Officer) because they do not fall under the current definition of “executive employees.”
- Minimum capital:
  - Decree No 170 sets minimum authorized and own capital for newly established bank at 10 000 000 000 (ten billion) tenge.
  - Housing construction savings bank minimum: 4,000,000,000 (four billion) tenge.
- Foreign branches and cross-border requirements:
  - Since December 16, 2020, permitted to open branches of foreign banks.
  - Conditions to open foreign branch include parent providing irrevocable deposit with National Bank of 10 billion Tenge; foreign bank must have minimum assets at the level of US $20 billion.
  - A branch may accept deposits from individuals up to US$ 120 thousand equivalent; deposits from legal entities without restrictions.
- Assessment:
  - Principle 4: Compliant.
  - Principle 5: Largely Compliant.
- Key recommendations:
  - Amend Banking Law to enable ARDFM to carry out fit & proper tests on Heads of internal control functions.
  - Refer to AML/CFT Law for definition of “beneficial ownership.”

### Transfer of significant ownership and major acquisitions (Principles 6–7)
- Definitions and thresholds:
  - Control conditions under BL Art. 2 include ownership/voting exceeding fifty percent, election of at least half governing body, inclusion in consolidated financial statements, or ability to determine decisions by contract.
  - Significant participation defined as possession, directly or indirectly, of twenty or more percent of voting shares.
  - “Major participant” defined as owning directly or indirectly ten or more percent of the shares (BL 2444 Art. 2 par. 6); prior authorization required for 10 percent or more (Art. 17-1.1).
  - Bank holding company considered at ownership of more than twenty-five percent.
- Notification and approval powers:
  - No person may own, use or dispose of ten percent or more of outstanding shares without prior written consent of ARDFM (Art. 17-1.1).
  - ARDFM must respond within fifty working days; grounds for refusal must be explained in writing (Art. 17-1.14).
  - If consent was granted based on inaccurate information, ARDFM may reverse change in ownership within two months of detecting the inaccuracy (Art. 17-1.15).
  - Quarterly reporting requirement: banks and bank holding companies report list of all major participants and percentages (Art. 17-1.19); changes in shareholders owning more than ten percent must be reported within fifteen days.
- Gaps and observations:
  - Banking Law does not explicitly define “ultimate beneficial owners”; AML/CFT Law contains a beneficial owner definition (holders of more than twenty percent) which staff said can be used for licensing/ownership purposes, but this is not explicit in banking law.
  - Assessors did not see evidence ARDFM can suspend voting rights for opposed changes in significant ownership; legislation should explicitly assign this authority.
  - Laws/regulations should clearly require banks to notify ARDFM of material information affecting suitability of major shareholders.
- Major acquisitions/investments:
  - Acquisition by a bank of shares in authorized capital must not exceed ten percent of the bank’s own capital for one legal entity; total investments in authorized capital or shares of legal entities should not exceed 50 (fifty) percent of the bank's own capital.
  - Acquisitions equivalent to ten percent or more of the bank’s own capital require supervisory approval.
  - Certain acquisitions/investments allow notification only within fourteen working days (Art. 11-1.1).
  - Ground for denying permission to create/acquire a subsidiary includes failure to meet consolidated supervision requirements, noncompliance with prudential standards, indications acquisition could weaken bank’s financial condition, and other factors (B.L. Art. 11-6).
- Assessment:
  - Principle 6: Largely Compliant.
  - Principle 7: Compliant.

### Supervisory approach and risk-based supervision (Principle 8)
- Risk-based supervision (RBA) and tools:
  - ARDFM transitioned to Risk-Based-Approach in 2019; supervisory methodology based on Risk Assessment System (RAS) approved by Chairperson's Decree dated 06.08.2020 No 317K.
  - RAS feeds into Supervisory Review Examination Process (SREP); complemented by internal desk-based Asset Quality Review (AQR) and stress testing.
  - RAS assesses four main areas: (1) business model; (2) risks to capital (credit, market, operational, interest rate); (3) liquidity risk; (4) corporate governance. Final ratings assigned 1 (low risk) to 4 (high risk).
  - Quantitative analysis uses 33 indicators; qualitative analysis uses 122 indicators.
- Use of motivated judgment:
  - Law 474-II art. 13.5 allows motivated judgment in five areas: licensing (impeccable business reputation, unstable financial situation), related party determinations, risk management/internal control assessment, provisioning adequacy, and determining major participants.
  - Motivated judgment procedures anchored by NBK Resolution n. 189/2019; draft motivated judgment must be based on relevant and reliable facts and provide right to be heard; limitations: motivated judgment restricted to five areas by law, constraining supervisory discretion.
  - ARDFM cannot adopt a ‘provisional motivated judgment’ (i.e., act urgently and allow hearing after decision) under current law.
- SREP outcomes (examples):
  - 2021 SREP: 6 banks “low risk,” 11 banks “moderately low risk,” 4 banks “moderately high risk,” and 1 bank “high risk.”
  - 2022 SREP: 7 banks “low risk,” 8 banks “medium-low risk,” 5 banks “medium-high risk,” and 1 bank “high risk.”
  - Main quantitative issues identified: high proportion of accrued interest income on loans not generating cash flows, increased level of non-performing assets (NPA), high related parties’ loans, concentration risk, increased loans to deposits ratio, concentration of funding sources.
  - Main qualitative issues: lack of updated capital adequacy plans, shortcomings in strategic and budget planning, imperfect methods for determining risk appetite, failure to use stress test results.
- Resolvability and recovery planning:
  - No formal resolvability assessment; ARDFM has not prepared resolution plans at time of assessment (addressed under CP11).
- Assessment:
  - Supervisory methodology exists and is being applied; limitations noted in scope of motivated judgment and consolidated supervision (CP12).

### Key statistics and quantified facts (preserved exactly)
- ARDFM budget for 2023: 9.2 bln tenge (about $US 20 mln) and envisaged as constant until 2027.
- Total ARDFM staff: 595 full-time employees.
- Banking Supervisor Department total staff: 76 (breakdown listed under “Staff numbers and structure”).
- BANKING ANALYTICS AND STRESS-TESTING DEPARTMENT: 30 staff.
- Minimum authorized and own capital for newly established bank: 10 000 000 000 (ten billion) tenge.
- Minimum for housing construction savings bank: 4,000,000,000 (four billion) tenge.
- Foreign parent bank minimum assets to open branch: US $20 billion.
- Required irrevocable deposit for foreign branch with National Bank: 10 billion Tenge.
- Individual deposit cap at foreign branch: US$ 120 thousand equivalent.
- ARDFM identified D-SIBs per NBK Resolution n. 240/2019: n. 3 Domestically-Systemically Important Banks.
- RAS quantitative indicators: 33 indicators; qualitative indicators: 122 indicators.
- SREP 2021 results: 6 banks “low risk,” 11 banks “moderately low risk,” 4 banks “moderately high risk,” 1 bank “high risk.”
- SREP 2022 results: 7 banks “low risk,” 8 banks “medium-low risk,” 5 banks “medium-high risk,” 1 bank “high risk.”
- Motivated judgment restricted to five areas as per Law 474-II art. 13.5.

### Recommendations (extracted and consolidated)
- Clarify and strengthen ARDFM independence and governance:
  - Amend Law 474-II to prescribe ARDFM independence and autonomy over organizational structure and staffing.
  - Define clear, limited grounds for removal of Chair and require public disclosure of reasons for removal.
  - Remove voting rights of the President’s representative on ARDFM Board.
- Budget and resourcing:
  - Consider alternative funding (e.g., levy fees on banks calibrated to assets or risk weighted assets) to reduce dependence on republican budget.
  - Ensure budget mechanisms to permit hiring external experts, cross-border work, and SupTech investments.
  - Index staff wages or otherwise protect real remuneration from high inflation (country inflation more than 20 percent).
  - Put in place a procedure to protect staff against the cost of legal defense for actions/omissions made in good faith.
- Supervision and powers:
  - Expand legal scope for motivated judgment beyond the five enumerated areas to enhance RBA, while safeguarding due process (including possibility for provisional motivated judgments in urgent cases).
  - Enable ARDFM to conduct fit & proper assessments for Heads of internal control functions (CRO, Chief Compliance Officer, Chief Internal Audit Officer).
  - Clarify in banking law that definition of “beneficial owner” from AML/CFT Law applies to licensing, ownership and transfers; explicitly define ultimate beneficial owner where relevant.
  - Explicitly empower ARDFM to suspend voting rights when opposing changes in significant ownership.
  - Require banks to notify ARDFM promptly of material information that may negatively affect suitability of major shareholders.
- Fintech/crypto:
  - Strategize implementation of FSB recommendations for crypto-asset regulation and oversight (October 2022).
  - Monitor and limit banks’ indirect exposures to unbacked crypto assets and global stable coins without effective stabilization mechanisms; monitor mining activities.

*Source: 1kazea2024004 — https://www.imf.org/-/media/files/publications/cr/2024/english/1kazea2024004.pdf*

### Chapter 18 of the Supervisory Manual focuses on “verification of compliance with

### Chapter 18 of the Supervisory Manual focuses on “verification of compliance with prudential standards and other mandatory norms and limits and recalculation of individual prudential standards.”

### Verification of compliance and breaches
- At the assessors’ request, ARDFM made available a list of banks that were in breach of prudential requirements.
- As of February 2023, only one bank was breaching a prudential requirement (the large exposure limits); in January, the same bank had also breached the limits to open currency position.

### EC4 — Macroeconomic environment, cross‑sectoral developments, and non-bank financial institutions
- The supervisor takes the macroeconomic environment into account in its risk assessment of banks and banking groups and takes into account cross-sectoral developments through frequent contact with their regulators.
- Reference to related analysis: CP9, EC5 on stress testing.
- Key structural facts about the financial system:
  - Banks hold 78 per cent of total financial asset.
  - The Development Bank of Kazakhstan holds another 8 percent.
  - Other actors of the financial system include:
    - N. 2 mortgage companies, the National postal operator and 3 non-financial institution operating the field of agro-industrial complex) with total assets of amounted to 2,769.5 billion tenge (about 5 percent of banks’ asserts).
    - N. 27 insurance organizations (2 of which with 100 percent state participation) with total asset of 1.829 billion tenge (about 7 percent of banks assets).
    - 35 mutual investment funds, with total volume of assets under management amounted to just 483.3 billion tenge, just 1.2 percent of banking asset system.
  - Collective investment schemes have not grown to a point where they could represent a risk to financial stability and only 1 out of 35 is open-end.
- Institutional responsibility: ARDFM is responsible for supervision of NBFI; NBFI do not appear to generate systemic risk.

### EC5 — Identification, monitoring and assessment of systemwide risks (focus on consumer lending)
- The supervisor, with other authorities, identifies, monitors and assesses the build-up of risks, trends and concentrations within and across the banking system, including problem assets and sources of liquidity, and communicates significant trends to banks and relevant authorities.
- ARDFM identified consumer lending as an area where risk is building up:
  - At the beginning of 2020, the growth rate of consumer loans reached 26.9 percent.
  - Measures taken in response included:
    1) a ban on the accrual of penalties and fees on unsecured consumer loans after 90 calendar days past due (imposed at legislative level).
    2) prohibition of banks from issuing loans to citizens with incomes below the minimum cost of living, or where debtor's monthly total liabilities exceed 50 percent of his/her income (debt service to income ratio).
    3) ARDFM tightened prudential requirements to consumer loans.
  - Outcomes and subsequent developments:
    - While in 2020 these measures restricted the growth of loans to individual (+13 percent), in 2021 the growth rate of consumer lending peaked at about 40 percent, significantly exceeded the growth in personal income, and contributed to the accumulation of the debt burden of the population.
    - Loans to individuals include consumer and mortgage lending, which represent, respectively, 33.2 percent and 17.8 percent of total banking loans as at 1.1.2022.
    - Certain banks adopt aggressive underwriting standards, for example by granting consumer lending to enable borrowers to make the down payment (20 percent on new mortgage or to repay overdue debt including with other institutions).
  - Data reconciliation and scale of problem loans:
    - In 2021, the Agency, together with NBK, banks, MFOs and collection agencies, reconciled data on all problem loans of the population.
    - In total, 1.5 million unique borrowers with a total debt of 1.3 trillion tenge have problem loans in banks, MFOs and collection agencies.
  - Prudential calibration:
    - ARDFM recalibrated risk weight for consumer lending which now range from 100 percent to 350 percent, depending on:
      - (i) the borrower’s income, both official and unofficial but confirmed by certain statistical data (for example cash turnover on customer accounts), and
      - (i) the interest rate on the loan—the higher the interest rate, the higher the capital requirements.
  - Assessment: The efficacy of these prudential measures remains to be seen in the months ahead. Signs of loosening underwriting standards are noted (see CP 17).

### EC6 — Resolvability and systemic importance
- The supervisor, drawing on information from banks and other supervisors, assesses banks’ resolvability in conjunction with the resolution authority and requires measures to remove barriers to orderly resolution.
- Institutional roles and classification:
  - ARDFM is the Resolution Authority.
  - Pursuant to NBK Resolution n. 2019/240, the criteria to classify a bank as a domestically systemic importance (D-SIB) are: (1) size: (assets/liability); (2) interconnectedness (inter-banking assets/liabilities, individual deposits guaranteed by the Deposit Insurance Funds); (3) interchangeability (role in the payment system, loan portfolio, custodian services); (4) complexity (derivatives, foreign currency, securities).
  - The decision was taken by NBK and communicated to the bank and to the Agency.
  - Although n. 3 D-SIB has been identified, the Agency has not prepared resolution plans; therefore, it has not assessed barriers to orderly resolution.

### EC7 — Framework for handling banks in times of stress (early intervention and insolvency)
- The legal framework (BL 2444 and Banking Law provisions) sets out triggers, classifications and response measures for problem banks.
- Classification and triggers for "banks with unstable financial situation":
  - A bank is classified as a bank “with unstable financial situation” if any of the following signs are present:
    - a decrease in the values of the adequacy ratios of equity capital and its size to below the minimum values.
    - non-performance by the bank of monetary obligations and other claims of creditors of monetary character in connection with absence or insufficiency of money at the bank.
    - identification of facts (transactions), whose reliable reflection in financial or other reporting will lead to violation by the bank of its capital adequacy ratios and (or) non-performance of monetary obligations and other claims of creditors of monetary nature.
    - identification of deficiencies and (or) risks which may lead to creation of situation that threatens the stable functioning of the bank, and (or) interests of its depositors and (or) creditors, and (or) stability of the financial system.
  - Administrative and operational consequences:
    - This decision should be brought to the attention of NBK and of the Deposit insurance fund within five working days from its adoption.
    - The bank cannot distribute profits, pay dividends, fulfill any financial obligations to major participants and (or) bank holding companies, as well as pay remuneration to the executive employees, except for salaries and cases, established by the legislation of the Republic of Kazakhstan.
    - A bank classified “with an unstable financial situation,” its major participants, and the bank holding company are obliged to take measures to improve the financial status of the bank.
    - An action plan to improve the financial situation must be agreed with the bank’s major participant, the bank holding company, a non-resident bank of the Republic of Kazakhstan. Terms of implementation of these measures should not exceed twelve months and may be extended once by the supervisor for a period of not more than twelve months if there are improvements in the financial status of the bank.
    - In case of non-submission of the plan, disapproval, or non-execution, ARDFM shall apply supervisory response measures provided by Banking Law Art 45-1.
  - Practical use of early intervention:
    - Early intervention measures were recently used in the case of the crisis management of three banks (2020-2021). Banks and their major shareholders were required to take actions to improve the bank’s financial condition. Following the nonfulfillment of the action plans and the presence of grounds for revoking licenses, two banking licenses were revoked and a third banks was classified as an insolvent bank.
    - The early intervention framework should occur well before the breach of any regulatory requirement or threshold and work hand in hand with recovery planning requirements.
- Classification and grounds for "insolvent banks" (Banking Law Art. 61-7):
  - A bank is classified as insolvent in case of non-elimination of the signs of unstable financial situation after the expiration of the term to implement the measures to improve the financial status. ARDFM has the right to classify a bank as insolvent before that term, on the following grounds:
    1. performance by the bank, after being classified as banks with an unstable financial situation, of operations that lead to further deterioration of its financial status, including:
       - conclusion of transactions which lead to a significant deterioration in the quality of assets.
       - conclusion of transactions at non-market conditions in which the bank incurs losses, as well as transactions with related party in violation of the concerned requirements and restrictions.
       - acceptance of obligations which have entailed the impossibility to fulfil, in full or in part, monetary obligations to other depositors and/or creditors.
       - transfer of property (including for temporary use) free of charge or at a price significantly below the price of similar property under comparable economic conditions, or without any reasons to the detriment of the interests of creditors.
    2. reduction of the bank's equity capital adequacy ratios to a level by one-  third below the minimum.
    3. non-fulfillment within ten working days of monetary obligations and other claims of monetary nature to the depositors and or creditors in connection of absence or insufficiency of money.
    4. systematic (three or more times within twelve consecutive calendar months) improper performance of contractual obligations on payment and transfer operations.

*Source: 1kazea2024004 - Chapter 18 of the Supervisory Manual*

### 5. non-performance of measures to improve its financial status and/or minimizing

### 5. non-performance of measures to improve its financial status and/or minimizing risks, provided by Banking Law art. 46.

### EC8: Activity outside regulatory perimeter — description and findings
- If the Agency becomes aware of activity that is fully or partially carried out outside the regulatory perimeter, the Agency has the right to forward this information to another competent government body (in practice, there have been cases of information being sent on financial pyramids to law enforcement agencies).
- When carrying out operations, transactions that fall outside the regulation of banks, the Agency may initiate legislative amendments clarifying the scope of regulation (in practice, amendments were made to the Banking Law and the Law on Joint Stock Companies).

### Assessment of Principle 8 — overall judgment and comments
- Assessment of Principle 8: Largely Compliant
- ARDFM has recently transitioned to RBA and its supervisory methodology for assessing nature, impact, and risk of banks is based on the Risk Assessment System (RAS), which feeds into SREP.
- In 2021, for the first time, the Agency conducted a full-scale assessment of banks using the SREP methodology, and internal desk-based AQR and supervisory stress testing in a pilot mode (CP9).
- With IMF technical assistance, ARDFM is working to further enhance RBA, including developing a methodology for calculating the Pillar 2 add on, based on quantitative and qualitative parameters and stress test results.
- The motivated judgement anchors supervisory discretion to facts, gives persons subject to proceedings the opportunity of being heard, and forces the Agency to base decisions only on objections on which the parties concerned have been able to consent or disagree.
- The motivated judgment is fully respectful of rights of defense and ensures due process in adopting supervisory decisions.
- Limitations noted:
  - Limiting the motivated judgment to the five areas enucleated by the Law constrains supervisory discretion, which is essential to RBA.
  - Certain terms (for example, “ultimate beneficial owner,” “group of connected clients”) should be interpreted by supervisors on a case-by-case basis.
  - The Agency might need to expand the areas of motivated judgement, while strengthening legal protection of its staff.
  - Adoption of a motivated judgement might take time; where urgent action is needed, the Agency should be able to exert a “provisional motivated judgment” providing the concerned party the right to be heard after the decision is taken.
- The Agency has not prepared resolution plans; therefore, it has not assessed barriers to orderly resolution.

### Recommendations arising from Principle 8 / motivated judgment
- Expand to new areas the motivated judgement, which should become the ordinary modus operandi of the Agency.
- In case urgent action is needed (for example, classifying a borrower as a related party and preventing the bank from further lending), the Agency should be able to adopt a “provisional motivated judgment,” giving the persons concerned the opportunity to be heard as soon as possible after taking its decision.
- The Agency might consider establishing an Administrative Board of Review for the purposes of carrying out an internal administrative review of the decisions taken in the exercise of the motivated judgment, after a request for review submitted by any natural or legal person to which the decision is addressed or is of a direct and individual concern to that person.
- The Agency should conduct resolvability assessments.

### Principle 9: Supervisory techniques and tools — EC1 description and findings
- EC1: The supervisor employs an appropriate mix of on-site and off-site supervision to evaluate the condition of banks and banking groups, their risk profile, internal control environment and the corrective measures necessary to address supervisory concerns. The supervisor regularly assesses the quality, effectiveness and integration of its on-site and off-site functions, and amends its approach, as needed.
- The ARDFM deploys a combination of on-site and off-site surveillance processes for evaluating banks’ risk profile and internal control environment.

Off-site supervision — role of the curator and frequency of activities
- The ARDFM representative in a bank (‘curator’) is fundamental to the off-site supervisory process, providing a single point of contact and facilitating ongoing supervision.
- Curator activities and frequencies:
  - daily — monitoring of the quality of banks' loan portfolios (large loans, including to related parties, restructuring/refinancing).
  - weekly — assessment of changes in balance sheet items.
  - monthly — (i) changes in the main financial indicators (reviews of financial performance trends, and capital and liquidity position); (ii) checklists on fulfillment of certain requirements; (iii) analysis of activities which might lead to early intervention measures; (iv) monitoring of implementation of action plans (for example, measures to reduce NPLs, etc.), (v) monitoring of the flow of funds of large depositors.
  - quarterly — monitoring of activities of subsidiaries acquiring doubtful and hopeless assets of the parent bank.
  - annually — (i) analysis of the auditor’s report on the bank's financial statements and of the auditor’s recommendations; (ii) assessment based on SREP methodology; (iii) evaluation of banks’ exposure to AML/CFT risk.
- Outcomes of curator activities include: reports commenting on balance sheet changes; requests for explanations to banks; proposals of supervisory actions (for example, onsite inspections); engagement with auditors to provide explanations; requests to submit action plans; letters on acceptance/non-acceptance or adjustment of Action Plans; memos on significant movements of depositor accounts; SREP reports.
- Assessors reviewed curator notes (analysis of audited financial statements, operations of distressed assets management companies, AML/CFT analysis, and other material events) and found adequate reporting to ARDFM management and constructive interaction with banks.
- Offsite supervision covers risks beyond credit risk, including assessment of viability and sustainability of banks’ business models, quarterly liquidity adequacy assessments based on prudential indicators trends, loan portfolio growth rate, deposit outflows, assets and liabilities gap, and other information. Reports are submitted to ARDFM management and, if high risks are identified, the supervisory unit is requested to strengthen liquidity monitoring for these banks. Other risks (such as market and operational risk) are also covered.
- Since inception, ARDFM invested in stress testing and the regular internal desk-based AQR to strengthen off-site supervision. These tools complement SREP, whose outcome classifies banks into four categories depending on rating.
- The on-site function is incisive (for example, it discovered unreported related parties’ transactions in banks which defaulted between 2020 and 2021).
- The Banking Regulation Department assesses quality and efficiency of its functions on a continuous basis and, where improvements are identified, incorporates them into its annual Work Plan (for example, amendments to the Supervision Manual, Regulations, or modernization and automation of processes).
- However, there was no evidence of a formal process in place to assess the quality, effectiveness and integration of its on-site and off-site functions.

### Internal desk-based Asset Quality Review (AQR) — description, implementation, and findings
- ARDFM is progressively increasing the use of AQR, transforming it from an exceptional on-site exercise to a regular off-site tool.
- The internal desk-based AQR is carried out on an IT proprietary system.
- In conjunction with the spin-off of supervision, NBK completed in 2020 an independent full-scale AQR of 14 major banks, selected based on their economic significance (in total 87 percent of the banking assets and 90 percent of loan portfolio).
- The 2019 AQR was based on international financial reporting standards and prudential regulation, aiming to achieve an objective and fair view of bank assets and a reliable and fair assessment of capital adequacy.
- The AQR methodology envisages nine blocks:
  1. Analysis of accounting processes, policies and practices
  2. Creating a loan form and verifying data integrity
  3. Forming a selection of portfolios
  4. Analysis of credit files (ACF)
  5. Valuation of collateral
  6. Projection of ACF results
  7. Reservation analysis based on a collective assessment
  8. Analysis of assets measured at fair value
  9. Determination of capital adequacy ratios adjusted for the results of the internal desk-based AQR
- According to AQR results, as at of April 1, 2019, there was no shortage of capital both at the system level and at the level of individual participating banks. Areas of improvements identified in quality of processes, data, policies, and procedures included:
  - credit risk management — ensuring the "three lines of defense" model (including the independence of risk management), expanding the criteria and rules for determining “related parties” (CP20), and detailing the criteria for determining the “group of connection clients” (CP21), automating the storage of data from credit files and improving requirements for quality of information in credit files.
  - collateral — development of quality control processes for valuations of collateral and real estate.
  - business planning, budgeting and strategy development, calibration of risk appetite limits.
  - policies and accounting rules for hedging instruments — formalization of rules and criteria for classifying assets (amortized cost versus fair value), specification of criteria for the fair value hierarchy.
- In April 2020, the Agency agreed on individual corrective action plans for the 14 AQR participating banks, with a deadline of execution until the end of 2023 (CP 11). Action plans provide for individual measures aimed at eliminating specific violations/deficiencies, and general corrective measures to improve business processes (planning, budgeting, risk appetite, etc.).
- In 2021, AQR banks continued to work on implementation of these action plans and ARDFM followed up through remote supervision and inspections of 6 banks (see CP9, EC7).
- The Agency developed, implemented, and piloted a “regular AQR.” Based on the 2019 full-scale internal desk-based AQR experience, the regular AQR is carried out remotely and without involvement of auditors, independent appraisers, and consultants, while attempting to maintain statistical accuracy within specified ranges.
- One key goal of regular AQR is to automate the process of regularly assessing asset quality using regulatory reporting from other databases. To that goal, the Agency, together with NBK, expanded regulatory reporting to include 21 key indicators of loans, contingent liabilities, and collateral.
- Pilot and subsequent coverage:
  - In 2021, the regular AQR methodology was tested in a pilot mode with participation of a limited number of banks (n. 4).
  - In 2022, regular AQR and supervisory stress-testing was conducted on 10 banks with 71 percent of banking sector’s assets.
- Methodology used in 2022 regular AQR:
  - ARDFM prepared models for assessing the financial condition of banks’ borrowers, credit risk parameters templates, and a tool to calculate the effect of the regular AQR on capital adequacy.
  - For each bank, an assessment of individually significant loans was carried out (those exceeding 0.2 percent of banks equity), including analysis of collateral. Credit impairment stages and PDs of individually significant loans were determined using internal credit risk models.
  - For other loans, analysis is performed in the block of analyzing homogeneous loans, based on calculation of PD, EAD, LGD, and usage of credit limit by defaulted borrowers prior to default to calculate CCF and EAD.
  - To analyze homogeneous loans a statistical model was created using migration matrices to calculate PD and banks' repayment statistics for defaulted/withdrawn/modified loans to calculate LGD.
- Scope and outputs of the 2022 internal desk-based AQR:
  - ARDFM assessed about 1,400 borrowers on an individual level and more than 19 million loans on a collective basis, determining the level of credit risk and assessing its effect on capital adequacy.
  - As a result of the assessment in the 2022 internal desk-based AQR, the total capital adequacy of the banks included in the pilot AQR sample was reduced by [text truncated in source].

*IMF staff report excerpt.*

### 1.7 percentage points, confirming, according to the Agency, the efficiency of the AQR

### 1.7 percentage points, confirming, according to the Agency, the efficiency of the AQR

### AQR: role, form and limitations
- The AQR is intended as a tool to be used in exceptional circumstances and to be run, possibly, by third parties independent from both the banks and the supervisor, and to be conducted by specialized teams on-site at the banks.
- ECB use cases referenced: (i) SSM inception (2014); (ii) migration of less significant institutions (LSI) to significant institutions (SI); (iii) new member states joining the euro area (Croatia) or entering close cooperation (Bulgaria).
- Advantages of an annual desk-based AQR:
  - Helps focus offsite and onsite activity on banks and portfolios appearing more exposed to risks, based on internal desk-based AQR.
  - Can assess granular portfolios where on-site file review would be disproportionately labor-intensive.
- Limitations:
  - A desk-based AQR is instrumental to other activities (a means to an end, not an end in itself).
  - Reliability as a remote off-site tool can be limited for individually significant loans that require extensive documentation review and discussion with banks.
- Recommendation (implicit in text): For most important corporate exposures, complement desk-based AQR with ad hoc bank office visits and/or stronger coordination with on-site supervision.

### Supervisory Action Program: planning and principles
- Process basis: developed by off-site divisions using inputs including SREP rating, last risk-based inspection results, AML/CFT risk assessment, security risks, results of regular desk-based AQR, stress testing results, consumer complaints, supervisory actions in last twelve months, time since last inspection, bank petitions, business indicators, complexity/systemic importance, changes in bank management/structure, and other information.
- Offsite division principles when preparing the Supervisory Action Program:
  - Utilization of a supervisory cycle of no more than three (3) years.
  - Use of a combination of comprehensive, random, and thematic inspections as appropriate.
  - Allocation of resources in proportion to the risk profile, complexity, and systemic importance of banks.
  - Determination of inspection intensity depending on risk profile, complexity, and systemic importance.
- Decision and timing:
  - Proposals from ARDFM departments and NBK can influence inclusion in inspection list.
  - Timing decided by ARDFM based on internal priorities and staff availability.
  - Program updated at least once a year.
  - Approved by order of the supervising manager and sent to the Supervision Committee (CP2, EC4) for information by the end of February of the planning year.

### Frequency and intensity of supervision (defined by Supervisory Action Program)
- High supervisory intensity may include one or more of:
  - daily (weekly) monitoring of assets and liabilities.
  - regular participation of the representative at meetings of the bank's collegial bodies.
  - regular meetings with bank management.
  - thorough analysis of interbank activity, FX transactions, derivative transactions.
  - monitoring of payments through NBK correspondent account or SWIFT.
  - interaction with foreign regulatory authorities where subsidiaries are located.
  - appointment of additional ARDFM representatives to the bank.
- Medium supervisory intensity may include one or more of:
  - monthly monitoring of assets and liabilities.
  - participation, as necessary, of ARDFM representative at collegial body meetings.
  - meetings with bank management.
- Low supervisory intensity may include one or more of:
  - monthly monitoring of assets and liabilities.
  - carrying out supervisory actions as and when required.

### Coordination and information-sharing between on-site and off-site supervision
- Ongoing interaction across supervisory cycle:
  - Off-site unit communicates main risks and issues prior to on-site inspection.
  - On-site division submits signed report to curator to register violations, deficiencies and risks.
  - For comprehensive inspections, on-site division performs SREP assessment and submits separate report to off-site division.
  - On-site divisions agree remedial plans with bank and submit to off-site curator for monitoring.
  - Off-site receives on-site inspection outcomes (provisions, identified violations, intensity of risks) when drafting next year’s Supervisory Action Program.
- Identified need: on/off-site interaction needs further development, particularly for execution of regular AQR for corporate exposures.

### On-site inspections: types, duration, and coverage
- Two types under Law n. 474 II (Art 15-2):
  - (i) risk-based inspection: launched based on bank risk level, not more than once a year; inspection plan drawn semi-annually and approved by head of the Agency.
  - (ii) surprise inspections: carried out in cases provided by law (e.g., breach reports; risks that may undermine financial organization stability; threat to national/economic security; follow-up on remediation; bank classified as “bank with unstable financial position” or “insolvent”).
- Inspections can be general (comprehensive) or thematic (targeted), independently or jointly with other bodies.
- Duration: cannot last longer than thirty business days, extendable once for no more than thirty working days.
- Documentary checks (desk inspections) defined for review without on-site visit.
- Share of banks subject to inspections:
  - in 2022—29 percent (a total of 6 inspections: 5 scheduled, 1 unscheduled).
  - in 2021—50 percent (a total of 11 inspections: 10 scheduled, 1 unscheduled).
  - in 2020—38 percent (a total of 10 inspections: 1 scheduled, 9 unscheduled).
- ARDFM joint inspection with NBK in 2022 focused on accounting automation.
- Findings on inspection function:
  - Robust and incisive findings, but need prioritization (e.g., internal scoring) to distinguish urgent short-term corrections from medium-long term actions.
  - Need for more risk-focused approach in areas such as AML/CFT.

### Use of information, representative mechanism, and reporting (EC3, EC10, EC12)
- Supervisor reviews variety of information: prudential reports, statistical returns, related-entity information, public information; determines reliability of bank-provided information (see Principle 10).
- ARDFM representative (curator) roles and rights (pursuant to L. 474-II art. 15-9):
  - Tasks: analyze financial condition, control compliance, propose audits, observe meetings of boards/committees, attend general meetings as observer.
  - Rights: request information and documents in oral and written form, access automated systems/databases in view mode.
  - Obligations: report non-submission or obstruction; maintain professional secrecy; one-year post-termination employment restriction in the organization represented.
- Current practice:
  - One representative appointed for each of eight D-SIB banks; for medium-smaller banks, one staff may represent multiple banks.
  - Representatives receive board calendars and agendas and may attend with 24 hours’ notice; physical visit required to access documents (consideration underway to enable remote access).
- Systems and data:
  - ARDFM depends on NBK IT legacy platforms AIPS "Statistics" and AIPS "ECSP".
  - Need to take stock of systems/data and consider a “SupTech” strategy to strengthen/modernize platforms.

### Tools used to assess safety and soundness (EC4)
- Supervisor tools include:
  - (a) analysis of financial statements and accounts; internal desk-based AQR to confirm provisions.
  - (b) business model analysis (recently introduced; governed by NBK Resolution n. 188/2019).
    - Definitions: viability = profitability over next 12 (twelve) months; sustainability = profitability for at least 3 (three) years.
    - Strategy must be board-approved for at least 3 (three) years; budget approved annually with monthly forecasts.
    - ARDFM assesses viability and sustainability using quantitative indicators (e.g., ROA and cost-to-income) and qualitative information (budget, projections).
  - (c) horizontal peer review: peer review on consumer lending conducted; no other thematic reviews noted.
  - (d) review of bank stress test outcomes: to be carried out within ICAAP review; Agency conducts its own supervisory stress test (see EC5).
  - (e) analysis of corporate governance, including risk management and internal controls; assessment part of SREP qualitative analysis; need for targeted on-site inspections on corporate governance to assess implementation of Res.188/2019.

### Supervisory stress testing (EC5): framework and recent practice
- Stress testing conducted on Agency’s own IT system; process stages:
  1) Preparation:
     - Annual list of participating banks aims to include at least 80 percent of the banking system’s assets.
     - Performed on a non-consolidated basis currently.
     - Scenarios developed and approved jointly by ARDFM and NBK.
     - Pilot scenario considered: GDP – 0.3 percent; oil price dropped to US$40 per barrel; inflation rate 20 percent; USD/KZT rate 549,3 tenge.
     - Time horizon: three years.
  2) Conducting:
     - Internal desk-based AQR adjusts balance sheets; banks provided AQR results, methodology, templates, instructions, scenarios.
     - “Static” balance sheet assumption with selective allowable adjustments per guidance.
  3) Verification:
     - Agency checks initial data and calculations; assigns status: “green”, “yellow”, or “red”. Banks allowed limited iterations to resubmit.
  4) Decision:
     - Results intended as input to supervisory decisions within SREP to determine supervisory capital markup (Pillar 2).
  5) Publication:
     - Plan to publish methodology and templates; Agency has published list of participating banks and results at aggregate and individual bank levels (capital adequacy base and stress scenarios, key findings).
- History:
  - 2020: first stress testing with NBK in response to coronavirus crisis.
  - October 2021–March 2022: pilot stress testing with n. 4 banks to test process.
- Planned enhancements:
  - Expand scenario to operational risk.
  - Use stress test for Pillar 2 purpose (supervisory capital mark-up).
  - Expand scope to consolidated supervision after transition.
- Note: No stress testing on emerging risks (e.g., climate-related financial risk) has been conducted; a climate risk sensitivity analysis was run.

### Internal audit assessment (EC6)
- Resolution 188 establishes internal audit requirements (see CP 26).
- Internal audit assessed in SREP and during inspections, considering:
  - number and status of significant audit findings;
  - annual updating and comprehensiveness of Audit Plan (coverage at least once every three years);
  - skills and knowledge of internal audit unit;
  - internal audit’s identification and reporting of violations of risk limits and risk appetite implementation;
  - regular internal audit reviews of risk management system.
- Identified weaknesses in examples provided:
  - lack of board assessment of internal audit efficiency;
  - late consideration/approval of audit reports by board;
  - insufficient internal audit human resources and lack of IT-certified auditor;
  - internal audit not checking provisioning procedures for more than 5 years;
  - internal audit failed to identify non-compliance with current legislation on risk.

### Engagement with boards and communication of findings (EC7, EC8, EC9)
- Contacts with banks:
  - Representative mechanism and interviews with management/employees used to maintain frequent contact.
  - SREP results are presented to banks for comments and explanations.
  - Identified need: increase contact with non-executive members, particularly Audit and Risk Committees; calendarize meetings with independent board members in supervisory plan.
- Communication timeliness:
  - Preliminary inspection results shared via interim acts; banks must comment within two working days (considered too strict).
  - Final inspection results communicated within thirty working days; bank can submit objections within 10 working days.
  - Agency does not regularly meet separately with non-independent board members.
- Follow-up:
  - Examples include post-2019 AQR: n. 14 banks submitted action plans with deadlines until end of 2023; continued follow-up through remote supervision and inspections.
  - Supervisory concerns addressed areas such as accounting standards, loan classification and provisioning, collateral evaluation, collective provisioning reserve levels, PD/LGD/EAD methodologies, fair value assessment, prudential reporting, and internal audit.

### Notification and early response requirements (EC10)
- In case of breach of capital requirements, banks must submit recapitalization plan (banking law art. 42 par. 4).
- Temporary tolerance for liquidity requirement violations adopted in response to geopolitical tensions; banks must submit action plan to address violation within nine months.
- Early response measures (Rules 317 of NBK art. 5): banks and (or) large participants must submit action plan within 5 (five) working days upon identifying factors affecting financial deterioration. Factors listed include:
  - decrease in liquidity ratios.
  - increase in loans with overdue debts in excess of 90 (ninety) calendar days, excluding formed reserves.
  - increase in ratio of net classified loans to equity.
  - increase in loans overdue from 61 (sixty-one) to 90 (ninety) days.
  - exceeding ratio of loans overdue in excess of 90 (ninety) days to total loan portfolio.
  - increase in share of classified receivables without formed reserves.
  - decrease in return on assets ratio.
  - decrease in average ratio of free assets in national currency to demand liabilities in national currency.
- Banking group factors include decreases in equity capital adequacy ratios and increases in intra-group transaction claims.
- Other notification requirements:
  - Changes in composition of shareholders owning ten percent or more of voting rights: notify within fifteen calendar days.
  - Approval of financial products: notify authorized body within ten working days.
  - Open FX position excess due to reasons beyond bank control: inform supervisor immediately and eliminate excess within 3 (three) months; otherwise violation from detection date.
  - Operational risk events reporting under Res. 188; IT/security incidents under NBK Resolution No. 48 (March 27, 2018) and Agency Board Resolution No. 90 (September 21, 2020).
- Noted gap: list of ‘substantive change’ events does not include all possible material events, e.g., reputational issues and court actions.

### Use of external experts and validation (EC11, EC9, EC10, EC11)
- Law does not prohibit using external experts; use occurred during 2019 AQR and in stress test development.
- No evidence of outsourcing prudential responsibilities to third parties.
- Technical tasks define scope and conflicts of interest; budget limitations affect ability to hire external experts.
- When engaging external experts, regular discussions are held and experts are expected to bring material shortcomings promptly to supervisor’s attention.

### Information systems and SupTech considerations (EC12, EC2)
- ARDFM is a user of NBK IT systems (AIPS "Statistics" and AIPS "ECSP"); dependence limits access to more granular data.
- Need to inventory existing systems/data and consider strengthening, modernizing, or building new platforms as part of a SupTech strategy.
- Reporting forms and definitions require IFRS compliance; reporting submitted via NBK legacy platforms and used to generate indicators.

### Assessment highlights and recommendations (Assessment of Principle 9; Principle 10; Principle 11)
- Assessment of Principle 9: Largely Compliant.
  - Strengths noted:
    - Representative (curator) is focal point enabling ongoing supervision.
    - Business model analysis and stress testing contribute to forward-looking RBA.
    - Regular AQR transforming to desk-based tool supports targeted supervision, particularly for granular portfolios.
    - Inspection function effective and incisive.
  - Areas for improvement:
    - Expand stress testing scenarios to include operational risk and climate-related financial risks; use results for Pillar 2 capital.
    - Clarify internal desk-based AQR role as support for targeted supervision; complement with on-site work for major corporate exposures.
    - Prioritize on-site inspection findings and recommendations.
    - Greater use of horizontal thematic reviews (corporate governance, cybersecurity, digital financial services, related party transactions, underwriting standards).
    - More frequent contacts with non-executive board members.
    - Include court actions and reputational issues in events to be notified to ARDFM.
  - Recommendations (explicit):
    - Clarify the role of the internal desk-based AQR as a support tool for targeted supervision.
    - Regularly assess quality, effectiveness and integration of on-site and off-site functions; reap synergies between AQR and on-site inspections on corporate exposures.
    - Prioritize importance of on-site inspection findings and recommendations.
    - Use more horizontal thematic reviews.
    - Increase contacts with non-executive bank board members.
    - Include court actions and reputational issues in the notification list.
- Assessment of Principle 10: Largely Compliant.
  - Supervisory authorities have sufficient power to collect, review and analyze information.
  - Curator mechanism central to information collection and analysis.
  - Need to strengthen guidance on validating and verifying fair value estimates and to describe supervisor role in evaluating reliability and prudence of fair market values.
  - Consider SupTech strategy to modernize data platforms and improve supervision effectiveness.
- Principle 11: corrective and sanctioning powers summarized:
  - Early-stage supervisory intervention authority exists (B.L. Arts. 45-47; Art. 46.1 lists specific remedial measures).
  - Range of measures includes supervisory response measures, sanctions, administrative fines, classification as bank with unstable financial position or insolvent, conservatorship, dismissal of executives, requirement to raise capital, restrictions on activities, change of related-party transaction terms, cessation of dividends, and more.
  - Agency lacks a dedicated “enforcement unit” and relies heavily on curators for validation; may escalate to confidential sanctions.
  - Agency can remove executives, oversee fit and proper evaluations, and bar executives involved in insolvencies for five years (practice noted), though public list of barred individuals is not published.
  - Gaps and considerations:
    - B.L. Art. 45 par. 7 exempts non-resident bank holding companies rated no lower than “A” from early intervention if information exchange agreement exists; may limit early measures.
    - No legal requirements for recovery plans for systemic banks at assessment time; ARDFM plans by end-2023 to adopt amendments requiring banks’ recovery plans and to develop supervisory methodology to assess them.

*Source: 1kazea2024004 - 1.7 percentage points, confirming, according to the Agency, the efficiency of the AQR*

### conclusion that the bank is insolvent. Only a court may declare that the bank is

### 1kazea2024004 - conclusion that the bank is insolvent. Only a court may declare that the bank is

### Legal framework for insolvency and resolution
- Only a court may declare that the bank is bankrupt and must be resolved (Art. 71).
- A court may also consider the resolution of a bank if its license has been revoked on grounds provided in banking legislation or if “authorized state bodies, legal entities and individuals” apply to the court to terminate the bank’s activities on the basis of other laws (Art. 72 and Art. 70).
- The resolution process could include:
  - compulsory reorganization of the bank (Art. 74–3);
  - a merger with another institution (Art. 74-3.4);
  - forced liquidation (Art. 74–4).
- Current laws do not allow for the use of deposit insurance for resolution.

### Role of NBK and Financial Stability Council (FSC) in resolution decisions
- The NBK is involved in the decision-making process to resolve systemically important banks through its membership in the Financial Stability Council (FSC).
- The FSC preliminarily considers and provides recommendations on:
  1) macroprudential policy implementation to mitigate systemic risk in the financial system.
  2) anti-crisis measures.
  3) the resolution of an insolvent bank, a forced liquidation that leads to systemic risks to the financial system, including government participation in its resolution.
  4) financing second-tier banks’ rehabilitation, including financing from NBK and (or) its subsidiaries.
- Comment: The involvement of the executive branch in decisions regarding the resolution of a bank could lead to questions about supervisory authorities’ independence; this matter was assessed under CP 2.

### Supervisory corrective actions, forbearance, and resolution preparedness
- The ARDFM has a range of supervisory response measures and sanctions at its disposal and has exercised them in practice.
- Forbearance example: certain violations (of the liquidity coverage ratio (LCR), net stable funding ratio (NSFR), other liquidity ratios due to outflow of deposits, revaluation of assets and liabilities) were temporarily tolerated from February 21, 2022, to December 31, 2022, subject to banks providing an action plan to address such violations within 9 months.
- Assessors’ view: Requirements should be restored to their typical levels expediently given persistent stressed global conditions.
- At time of assessment:
  - requirements had not yet been created for supervised banks to develop resolution and recovery plans;
  - the presence of the resolution authority within the ARDFM simplifies coordination, but the authorities should implement the requirement for banks to prepare recovery and resolution plans.
- The resolution process is assessed in greater detail within a separate workstream of this Financial Sector Assessment.

### Consolidated supervision (Principle 12) — description and key findings
- As of year-end 2022, the Agency counted 12 banking groups under its supervision, a reduction by one compared to year-end 2021 following a merger of two banks.
  - Of these twelve: two are considered to have a simple structure (meaning less than seven subsidiaries); seven are of medium complexity (seven to nine subsidiaries); and three are considered complex (nine or more subsidiaries).
  - Only two banking groups have any overseas operations: one has just one office abroad and 6 subsidiaries at home; the other has offices in 4 other countries, but 14 based in Kazakhstan.
- Legal and regulatory powers:
  - B.L. Art. 1, subpar 3 defines a banking group.
  - B.L. Art. 41 gives the Agency authority to regulate activities of banks both individually and on a consolidated basis.
  - B.L. Art. 40-5 establishes the requirement for a banking group to have a risk management and internal control system on a consolidated basis.
  - B.L. Art. 44 grants the Agency inspection powers over banking group members and affiliated persons for purposes of determining their influence on banks.
  - Resolution No. 309 of the Board of the NBK dated December 26, 2016, lists minimum prudential requirements for banking groups (minimum authorized capital, equity capital adequacy ratio, maximum size of exposure per borrower).
- Prudential gaps identified:
  - The Agency has not yet developed capital adequacy standards for banking groups that align with international standards, nor does it apply liquidity standards at the group level.
  - Liquidity prudential standards apply only at the individual bank level; no laws or regulations currently apply liquidity requirements at the group level.
  - Agency’s capital requirements for groups sum up capital across financial institutions in a group regardless of the kind of financial service provider (e.g., insurance companies not excluded as under Basel).
  - Agency staff have identified consolidated supervision as an area for further development and are working to strengthen these aspects.
- Reporting the Agency regularly receives from banking groups includes:
  - information on investments;
  - data on intragroup transactions;
  - information on major liabilities of banking group members to third parties;
  - report on the structure of the securities portfolio of banking group members.
- Assessment of Principle 12: Materially non-compliant.
  - Comment: Risk management and key prudential requirements apply only on a solo level and not yet on a consolidated level; deficiency severely weakens consolidated supervision.
  - Recommendation (from assessors): consider application of prudential standards such as liquidity and capital at both individual bank and consolidated levels; build supervisory expectations for risk management on a consolidated basis; require international groups to assess impediments to receiving information from foreign operations and evaluate effectiveness of supervision in jurisdictions where banks operate, including on-site visits when warranted.

### Home-host relationships (Principle 13) — description and key findings
- Given insignificant foreign operations (staff estimate fewer than 5 percent of assets booked in overseas branches or subsidiaries), the Agency has not established cross-border supervisory colleges to date but is considering establishing a small number for banks active in multiple jurisdictions.
- The Agency is a member of IOSCO and IAIS and has MOUs in place with foreign regulators; however, staff acknowledge limited contact with those regulators and limited collaborative work since the Agency’s founding.
- Examples of limitations:
  - Some MOUs predate the Agency’s current form and have not been updated.
  - The ARDFM was unable to conclude one MOU for a G-SIB with a limited presence in Kazakhstan because the home supervisor did not respond to the ARDFM’s request.
  - The Agency has made no trips abroad to conduct assessments of foreign offices, citing their insignificance.
- Crisis and resolution coordination gaps:
  - The MoU on Financial Stability Issues, signed in 2007, is outdated; NBK plans a new triparty MoU involving NBK, the ARDFM, and the Government.
  - Resolution responsibility is not separated from banking supervision: resolution authority is not operative and is formally integrated into ARDFM Supervisory Department.
  - No recovery and resolution planning framework: banks do not submit recovery plans and ARDFM Division “Resolution of Problem Bank” does not prepare resolution plans for systemic banks.
  - Assessment of Principle 13: Materially non-compliant.
  - Comment: The Agency has not been sufficiently proactive in home-host relations; a number of MOUs exist but one is missing for a significant global bank active in Kazakhstan.

### Corporate governance (Principle 14) — regulatory framework and supervisory practice
- Key regulatory instruments:
  - NBK Resolution No. 188/2019: “Rules for formation of risk management and internal control system for second-tier banks.”
  - Joint Stock Company Act (JSC Act) and Banking Law provisions govern boards, executive bodies, and related governance rules.
- Board and executive responsibilities (per Resolution No. 188/2019 par. 21 and related provisions) include (selection):
  - duty of care and duty of loyalty;
  - approval of organizational structure, strategy, profitability policies, stress testing procedures and scenarios, contingency financing plan, business continuity management policies, remuneration procedures, ICAAP and ILAAP, and risk appetite strategy;
  - ensuring availability of a financial service responsible for accounting and quality of financial reporting;
  - election of members of the executive board, appoint the head of risk management, the head of internal audit and the chief compliance controller;
  - setting up the three lines of defense system (CP25);
  - periodically (at least once a year) assess the performance of each board member; maintain records of decisions and make them available to ARDFM upon request.
- Supervisory assessment of governance:
  - ARDFM assesses corporate governance as one of the four pillars of SREP (along with business model, risk to capital and liquidity), leveraging a questionnaire (about 30 questions) and observations (including ARDFM representative attending board and committee meetings as an observer).
  - The ARDFM has not conducted targeted onsite inspections focused solely on governance nor a thematic review on state of implementation of Resolution No. 188/2019.
  - ARDFM enforces corrective measures; examples provided include written notices and required action plans (typically one year for implementation, extensions considered with robust motivation).
- Specific governance elements and findings:
  - Board composition: members elected by general shareholder meeting; at least one third of the board must be independent (JSC Art. n. 20 and Art. 54 par. 5).
  - Committees: Audit, Risk management, Strategic planning, Staff and remuneration are mandatory; ARDFM has not conducted a system-wide assessment of implementation.
  - Audit Committee: chairman must be an independent director; no similar requirement for other members.
  - Risk management committee: chairman shall be an independent director or chairman of the board; includes at least one member with experience in risk management or internal control.
  - Multiple board memberships: no limit to multiple memberships for board members, which could give rise to conflicts of interest and time commitment concerns.
  - Succession planning: no requirement for succession plans.
  - Remuneration: NBK Resolution 2012 No. 74 requires banks to develop internal remuneration policy with fixed and variable components, deferral, conversion, and cancellation provisions; ARDFM has not structurally assessed board oversight of compensation systems.
- Assessment of Principle 14: Largely Compliant.
- Recommendations (from assessors):
  - Resolution No. 188 should consider (i) requirements for the board to introduce plans for succession, and (ii) limits to multiple memberships.
  - Given limited on-site inspection coverage (share of banks with on-site inspections: 38 percent in 2020; 50 percent in 2021; 29 percent in 2022), the Agency could:
    - conduct thematic reviews on state of implementation of Resolution No. 188/2019, including targeted on-site inspections;
    - schedule targeted on-site inspections on corporate governance as part of the supervisory examination plan;
    - conduct a structured assessment of remuneration policies and practices and consider preventing banks which benefitted from state support from paying variable remuneration until the banks reimburse the public support.

### Risk management process (Principle 15) — framework, implementation, and supervisory gaps
- Legal and regulatory basis:
  - BL 2444 Art. 40-5 requires banks and banking groups to form a system of risk management and internal control, including internal policies, limits, internal reporting, and criteria for effectiveness.
  - Resolution No. 188/2019 sets detailed requirements for formation of risk management and internal control systems, ICAAP and ILAAP, and responsibilities of board and risk management functions.
  - Resolution No. 189/2019 sets out the use of motivated judgment by ARDFM when assessing the system of risk management and internal control, listing specific assessment elements (including stress testing, ICAAP/ILAAP procedures, effectiveness of early warning systems, etc.).
- Key supervisory practices and developments:
  - ARDFM verifies boards’ approval of risk management strategies and risk appetite mainly during SREP; SREP includes qualitative analysis and uses motivated judgment where appropriate.
  - Resolution No. 188/2019 introduced ICAAP and ILAAP requirements; banks were to submit ICAAP and ILAAP for the first time at the end of April 2023.
  - At the time of assessment, no supervisory methodology or standard forms for ICAAP and ILAAP had been finalized; ARDFM developed a draft internal methodology and draft standard forms, with IMF technical assistance in 2022.
  - Draft supervisory methodology (Order of the Chair of the Agency n. 465. November 2022) was expanded to cover IRRBB quantitative assessments (economic value of equity (EVE) and net interest income (NII)) but does not cover other Pillar 2 risks (for example, sovereign).
  - Assessors note the Agency might consider implementing BCBS Principles for effective management and supervision of climate related financial risk (2022) and require banks to incorporate climate risk into ICAAP and ILAAP.
- Specific elements of risk management assessed:
  - Model use and validation:
    - Banks are not authorized to use internal models for calculating capital requirements, but use internal models for other purposes (credit due diligence, IFRS 9, stress testing).
    - Regulation n. 188/2019 par. 41 requires banks to have procedures for validation, back testing, and permissible deviations; validation at least once in 4 years (frequency may increase with market changes).
    - ARDFM conducts inspections of internal rating systems and independent validation practices; examples show Agency requesting enhancements and independent validation.
  - Management information systems and reporting:
    - Risk Management Committee responsible for ensuring management information systems provide the board with complete, reliable, and timely information.
    - ARDFM reviews systems for reporting on capital and liquidity, IRRBB monitoring, operational risk incident notification, and data architecture to support integrated risk reporting under stress.
  - ICAAP and ILAAP organizational requirements (Resolution No. 188/2019 par. 38, 40, 53, 54) require board approval, defined participants and responsibilities (board, Risk Management Committee, internal control unit, risk management unit, internal audit, budget and money management units).
- Overall supervisory findings:
  - ARDFM evaluates existence of processes for identifying all material risks and required levels of capital for material risks under SREP.
  - Implementation of ICAAP/ILAAP supervisory assessment was incomplete at time of review; ARDFM had draft methodology and forms under development.
  - Supervisory attention given to risk management and internal controls across credit, market, operational, liquidity risks, and IRRBB, with examples where ARDFM challenged adequacy of credit risk management and provisioning.
- Principle 15: detailed EC-level descriptions and agency practices are reported throughout the chapter; progress noted on regulatory framework but supervisory implementation (especially consolidated and Pillar 2 coverage) remains a work in progress.

*Source: 1kazea2024004 - conclusion that the bank is insolvent. Only a court may declare that the bank is — https://www.imf.org/-/media/files/publications/cr/2024/english/1kazea2024004.pdf*

### introduction of appropriate changes.

### introduction of appropriate changes.

### Risk management requirements and controls
- Banks must have procedures and methods for identifying, measuring, monitoring and controlling risks inherent in new products, activities, processes and systems or in the case of significant changes to existing products, activities, processes and systems.
- Supervisory verification includes:
  - the availability of the necessary control mechanisms.
  - the availability of information on the level of residual risks.
  - an assessment of the bank's ability to invest in human resources and the technological infrastructure before introducing new products, activities, processes and systems or in the event of significant changes.
- New products include those developed by the bank or by a third party and purchased or distributed by the bank.
- For supervised organizations, information security requirements apply to new implemented solutions. The Cyber Security Department monitors compliance with information security requirements for all implemented assets; assessors noted this department needed strengthening (weighted under CP 25).

### EC9 — Risk management function (description and findings)
- Legal basis and duties:
  - Pursuant to Resolution n. 188/2019, par. 34, the board of directors must ensure there is a risk management unit(s) supervised and (or) headed by a head of risk management with sufficient authority, independence, and resources, interacting with the board of directors.
  - The risk management unit is responsible for:
    1) development of a risk management system, including policies, procedures, risk appetite strategy levels;
    2) identification of significant current and potential risks;
    3) risk assessment and determination of the aggregated level(s) of risk appetite;
    4) monitoring compliance with risk appetite levels;
    5) development of early warning systems and triggers aimed at identifying violations of risk appetite levels; and
    6) reporting to the management board, the risk management committee, and the board of directors.
  - The risk management system shall provide for separation of the risk management and internal control functions from the bank’s operations by means of three lines of defense system (Resolution n. 188/2019, par. 5, n. 9).
  - The Head of Risk Management shall not combine the position of the chief operating director, financial director, other similar functions of the bank’s operational activities (except for underwriting, collateral service), and the head of the internal audit unit.
  - The Head of Risk Management must have access to any information necessary to fulfill his/her duties and must have unhindered access to the board of directors without the participation of the management board (Resolution n. 188/2019, par. 35).
- Evidence provided to assessors:
  - ARDFM provided an assessment of the internal audit function (vulnerabilities, insufficient staff, limited competency, inadequate control of the models used for internal management purpose).
  - n. 3 examples of banks’ internal audit of the risk management function (efficacy of risk management and adequacy of internal control system, operational risk management, AML/CFT).

### EC10 — CRO and senior risk management (description and findings)
- Requirements and practice:
  - As stated under EC9, the board must ensure there is a risk management unit(s) supervised and (or) headed by a head of risk management.
  - Qualifications and professional experience of the head of risk management shall correspond to the chosen business model, the scale of activity, types and complexity of operations, and risk profile (Resolution n. 188/2019, par. 35).
  - The head of risk management shall be appointed and released by the board of directors. Information on the decision to dismiss the head of risk management shall be passed to the Agency, which could request the board of directors to provide a justification.
- Gap:
  - Resolution n. 188/2019 addressed most findings from the 2014 BCP related to this EC; however, there is still no requirement that the Board removal of the head of risk management should be publicly disclosed.

### EC11–EC14 — Standards, contingency arrangements, stress testing, and pricing
- EC11:
  - Resolution n. 188/2019 provides for standards on credit risk, market risk, liquidity risk, interest rate risk in the banking book and operational risk.
- EC12 (contingency arrangements):
  - NBK Resolution 188 contains requirements on development and approval of financing plans and on conducting contingency risk analysis and defining contingency risk management measures (Resolution 188, par. 66).
  - Contingency risk analysis should cover inaccessibility of employees, technologies (including viruses, computer hardware failure, loss of communication), supply (water, electricity) and key suppliers (contractors), key information, and lack of access to buildings (premises).
  - Contingency risk management measures should cover at least personnel, premises, technology, information, suppliers, contractors, and supply channels.
  - Gap: there are no legal requirements for banks to prepare recovery plans. ARDFM received IMF technical assistance in 2022 recommending clear and comprehensive recovery plans requirements and an internal methodology; ARDFM plans to implement these recommendations by the end of 2023.
- EC13 (stress testing):
  - Pursuant to Res. 188/2019 par. 50, banks shall periodically (but at least 1 (once) every six months) conduct stress testing to identify sources of potential threats to capital adequacy.
  - Banks should conduct scenario analysis and sensitivity analysis; degree and frequency of stress testing is consistent with business model, scale, complexity, and systemic role. Frequency may increase in worsening market conditions or at the request of senior management.
  - The board of directors is actively involved in the stress testing process by approving procedures, scenarios, evaluating results and taking measures to minimize impact on capital; the board regularly reviews stress testing scenarios for significant changes.
  - Stress testing scenarios include:
    - general economic scenario (impact of a decrease in the economic situation in the country).
    - a scenario specific to the bank’s business (local stress factors related to bank activity and loan portfolio structure).
  - Scenario design guidance:
    - Scenarios include all significant risks to which the bank is potentially exposed.
    - The bank shall (i) consider the relationship of various types of risks; (ii) take a conservative approach in determining assumptions; (iii) consider short-term and protracted, idiosyncratic and market scenarios, including: lack of access to capital markets; reduction in the cost of energy; depreciation of the national currency; real estate market crisis; change in rates; agricultural crisis; rising inflation expectations; increasing unemployment and lower incomes; decrease in market value of assets.
  - Results and actions:
    - Results and subsequent actions are communicated and discussed with the board of directors and liquidity risk management departments.
    - The board shall integrate stress testing results into strategic and budget planning and use results to establish internal limits.
  - Implementation note:
    - ARDFM plans to assess banks’ bottom-up stress test capability in the context of the ICAAP review; April 2023 represented the first ICAAP submission.
- EC14 (internal pricing and new products):
  - The Agency verifies implementation of the Internal Transfer Pricing Mechanism and evaluates the risk appetite structure or equivalent document in the process of approval of new products or business lines.

### Assessment, additional criteria and recommendations
- AC1:
  - The supervisor requires banks to have appropriate policies and processes for assessing other material risks not directly addressed in the subsequent Principles, such as reputational and strategic risks.
- Assessment of Principle 15: Largely Compliant.
- Strengthening since 2019:
  - NBK Resolution n. 188 introduced requirements addressing multiple 2014 BCP deficiencies, including recognition of uncertainties attached to risk measurement (par. 37), prompt attention and authorization for exceptions (par. 36), independent validation of models, board approval of new products and services through strategy approval (par. 8), establishment of the head of risk management and safeguards for removal (board approval and discussion with supervisor).
- Remaining gaps:
  - No legal requirements for banks to prepare recovery plans.
  - Supervisory expectations need expansion to the entire spectrum of Pillar 2 risk (for example, sovereign) and new and emerging risks (climate risk) which should be embedded in the ICAAP and ILAAP.
  - ARDFM can exert motivated judgment and provided evidence of implementation; a key test will be supervisory assessment of ICAAP and ILAAP (first submissions at end of April 2023).
- Recommendations:
  - Introduce requirements for banks to prepare recovery plans.
  - Prioritize the assessment of ICAAP and ILAAP.

### Principle 16 — Capital adequacy (EC1 description and findings)
- Legal and regulatory framework:
  - Banking Law art. 41 enables the supervisor to regulate banks’ activities, including through establishment of prudential standards and other mandatory standards and limits, to ensure financial stability, protect interests of depositors, and maintain stability of the monetary system of the Republic of Kazakhstan.
  - Banking Law art 42 envisages among the structure of prudential standards established by the supervisor: (i) the minimum amount of the authorized capital of the bank; (ii) the minimum amount of the equity capital of the bank; (iii) the equity capital adequacy ratio.
  - NBK Resolution n. 170/2017, “About establishment of normative values and techniques of calculations of prudential standard rates and other regulations and limits, obligatory to observance, size of the capital of bank and Rules of calculation and limits of open foreign exchange position.”
- Capital regime and implementation:
  - Kazakhstan transitioned to Basel III and banks operate under credit risk standardized approach, market risk standardized approach, operational risk basic indicator approach (BIA).
  - The Agency has not conducted an assessment on whether any modifications to the capital requirements are needed in relation to the new Basel framework which entered into force in January 2023.
  - The assessor found local RWA for credit risk are in some cases more conservative than those provided by the new standardized approach (for example, consumer lending, mortgage), but in other cases less conservative:
    - exposure to SME are risk weight 50 percent instead of 75 percent.
    - exposures to legal entities in tenge with the form of syndicated loans are risk weighted by 50 percent, regardless of the rating.
  - The Agency indicated these measures were temporary: the capital support measures were introduced back in March 2020 and rolled over twice until December.

*Source: 1kazea2024004 - introduction of appropriate changes.*

### 2023. However, from January 1, 2024, the risk weights   for exposures to SME and to

### 1kazea2024004 - 2023. However, from January 1, 2024, the risk weights   for exposures to SME and to

### Risk-weight changes and treatment of selected exposures
- From January 1, 2024, the risk weights for exposures to SME and to legal entities in tenge in the form of syndicated loans will be re-aligned with Basel; ARDFM board did not further extend these temporary risk weights.
- Exposures to multilateral development banks (MDBs) with a rating not lower than "AA-" and from "A+" to "A-" are risk weighted, respectively, 0 percent instead of 20 percent and 20 percent, instead of 30 percent.
- ARDFM noted most MDBs have a rating of "AAA"; only two minor regional MDBs fall into the "A+" to "A-" range and Kazakhstani banks’ exposure to those MDBs are negligible.
- The Agency will consider changing these risk weights to be fully compliant with the Basel requirements.
- The materiality of exposures carrying a more conservative prudential treatment is higher than that of exposures benefitting from a preferential treatment; consumer lending constitutes the largest share of the banks’ total loans.

### Operational risk framework
- Operational risk capital requirements are calculated under the Basic Indicator Approach (BIA), which is less risk sensitive than the new standardized approach as it does not incorporate banks’ operational losses experience.
- ARDFM collects on a quarterly basis banks operational losses above the threshold of 500.000 KZ tenge and might consider moving to the new framework.

### Minimum capital requirements and buffers (NBK Resolution n. 170/2017)
- Coefficient of fixed capital - k1: 5.5 percent.
- Capital adequacy ratio of first level - k1-2: 6.5 percent.
- Coefficient of equity of k2: 8 percent (total capital).
- The denominator for these three ratios: RWA for credit and market, plus operational risk capital requirement under the BIA. The numerators differ: fixed capital for k1; capital of the first level (fixed capital + added capital) for k1-2; equity for k2. These indicators correspond in substance to CET1, AT1 and T2 ratios.
- Revaluation reserves included in fixed capital are limited to 0.6 percent of total capital.
- New subordinated debt instruments are bail-inable and their early repayment is subject to supervisory authorization; they represent about 17.5 percent of the total capital.

Buffers in place:
- Capital conservation buffer (CCB): 2 percent for all banks and 3 percent for domestically systemically significant banks (D-SIB).
- Systemic buffer: 1 percent of the sum of assets, conditional and potential liabilities, weighted taking into account risks.
- Countercyclical buffer (CCyB): size and timing established by Resolution No 170 no later than 12 months before the start date of calculation; ranges from 0 percent to 3 percent of the sum of assets, conditional and potential liabilities, weighted taking into account risks.
- CCB for banks other than D-SIB was reduced to 1 percent during the Covid-19 pandemic; subsequently restored to 2 percent.
- There is no approved methodology for setting the CCyB; NBK carries out regular monitoring of need to set a CCyB. The buffer was not activated.
- Debt Service to Income Ratio (DSTI): ratio of the amount to monthly payment on all outstanding loans of the borrower, including the amount of overdue payment and the average monthly payment on new debt of the borrower to the average monthly income of the borrower for the last six months should not exceed 0,5.

### Capital adequacy, risk sensitivity, and systemic considerations
- For at least internationally active banks, the definition of capital, the risk coverage, the method of calculation and thresholds for the prescribed requirements are not lower than those established in the applicable Basel standards.
- Capital requirements do not properly reflect banks’ risk profiles because they are set at the same level for all banks.
- ARDFM drafted a methodology for Pillar 2 capital add-on, with roll-out planned for 2024. The draft covers IRRBB and capital shortfall resulting from under provisioning but does not cover other Pillar 2 risks (for example, sovereign and climate).
- Capital requirements reflect systemic importance through a systemic risk buffer (1 percent of RWA) for the three identified Domestically Systemic Important Banks (D-SIB); the size was determined from differences in stress-test outcomes between large banks and other banks.
- A leverage ratio requirement is not in place; its introduction will be considered in 2024. The Agency is analyzing Basel rules on leverage ratio calculation and plans to assess current leverage levels for banks accordingly.

### Supervisor powers, internal models, and forward-looking capital management
- The supervisor (Agency/ARDFM) has the power to impose a specific capital charge and/or limits on all material risk exposures, including those not adequately transferred or mitigated through transactions (e.g., securitization). Both on-balance sheet and off-balance sheet risks are included in prescribed capital requirements.
- The Agency has the power to impose specific capital charges; however, there is no active securitization market (only one operation in 2017).
- Capital requirements include contingent liabilities based on the credit conversion factors provided by Appendix n. 6 NBK Regulation n. 170/2019.
- Banks are not authorized to use internal models for calculating capital requirements; subsidiaries of foreign banks calculate capital requirements under the standardized approach.
- ARDFM has the power to require banks to adopt a forward-looking approach to capital management (Resolution n. 188/2019 introduces ICAAP requirement (CP 15), which will include internal stress testing). Resolution entered into force in October 2019, but due to lack of an ICAAP template and supervisory methodology, banks will submit their first ICAAP in 2023.
- The supervisor lacks power under point b) of EC6 (requirement for feasible contingency arrangements) because the recovery plan requirement is not in place.

### Assessment summary and compliance
- Assessment of Principle 16: Largely compliant.
- Kazakhstani banks transitioned to Basel III and calculate capital adequacy requirements under the credit and market risk standardized approach, and the operational risk basic indicator approach (BIA).
- The Agency has not conducted an assessment as to whether any modifications to the prudential framework are needed in relation to the new Basel framework which entered into force in January 2023.
- Local risk weights for credit risk are in some cases more conservative than those provided by the new standardized approach (for example, consumer lending), but in other cases less conservative (exposures to SME, syndicated loans in tenge, and exposure to MDB).

*Source: 1kazea2024004 - 2023. However, from January 1, 2024, the risk weights   for exposures to SME and to*

### 0.6 percent of total capital. The computability of non bail-inable subordinated debts

### 0.6 percent of total capital. The computability of non bail-inable subordinated debts

### Capital framework: findings
- The computability of non bail-inable subordinated debts into the Tier 2 has been phased out between 2015 and 2020.
- CCB for non D-SIBs is set at 2 percent instead of 2.5 percent; no leverage ratio requirement is in place, but the ARDFM will consider its introduction in 2024.
- Capital requirements do not reflect the banks’ risk profile yet:
  - ARDFM has drafted a methodology for Pillar 2 capital add-on, but the roll-out is planned for 2024.
  - The draft methodology covers IRRBB and capital shortfall resulting from under provisioning, but it does not cover other Pillar 2 risks (for example, concentration, sovereign, climate-related financial risks).
- Risk-weighting asymmetries and compensating measures:
  - Consumer lending constitutes the largest share of banks’ total loans and has more conservative risk weights that could reach 350 percent (as opposed to 75 percent prescribed by the Basel framework).
  - SME exposure risk weights were reduced to 50 percent instead of 75 percent under current practice.
  - The assessors considered that the more conservative risk weighted assets for consumer lending adequately compensate for the less conservative risk weighted assets for SME and syndicated loans in tenge.
- From January 1, 2024 ARDFM will realign risk weights for exposures to SME and to legal entities in tenge in the form of syndicated loans with the Basel framework.
- ARDFM clarified that exposure to MDB with a rating below AAA are negligible and ARDFM is considering changing these risk weights to be fully compliant with the Basel requirements.
- All these considerations, along with the phasing out of non bail-inable subordinated debts, contributed to the decision to assign a LC score.

### Capital framework: recommendations
- Pashing out the residual Covid-19 capital forbearance measures (align RWA calculation for exposures towards SME and syndicated loans with Basel framework).
- Eliminate revaluation reserves from the eligible items in the definition of capital.
- Introduce a leverage ratio requirement.
- Increase CCB to 2.5 percent also for non-D-SIBs.
- Calibrate prudential requirements to risk profile by implementing the draft Pillar 2 methodology.
- Expand methodology and Pillar 2 add on to concentration, sovereign, and climate related financial risk.

### Principle 17 — Credit risk: summary assessment
- Assessment: Largely Compliant.
- Comment: Despite tightened capital requirements, the growth rate of consumer lending (about 40 percent in 2021 and 25.3 percent in 2022) remains a source of concern due to lack of clarity on underlying drivers. Some banks may be loosening underwriting standards (for example, granting consumer loans to enable borrowers to make the minimum down payment on mortgage loans, or repay overdue debt, including with other financial institutions).
- Regulation n. 188/2019 has strengthened the credit risk management framework, but several deficiencies remain.

### Principle 17 — Key findings by Essential Criterion (EC)
EC1 — Credit risk management system requirements and components
- Regulation n. 188/2019 par. 41 requires banks to ensure an effective credit risk management system that meets current market situation, strategy, size and complexity of operations and ensures effective identification, measurement, monitoring and control of credit risk.
- An effective credit risk management system should have: procedure for adoption of relevant decisions; credit administration procedures; credit risk assessment procedures; credit monitoring; collateral management; troubled loan management; assessment of effectiveness of the credit risk management system.
- ARDFM assesses credit management system consistency with risk appetite, risk profile, systemic importance, and capital strength during SREP and on-site inspections. Inspection function is robust but findings need prioritization.

EC2 — Board and senior management responsibilities
- Management board develops credit policy for submission to risk management committee and board of directors’ approval.
- Regulation n. 188/2019 par. 42 requires board of directors (and risk management committee) to ensure completeness and reliability of information; compliance with laws and internal policies; reliable management, regulatory and financial reporting; existence of loan assessment procedures; procedures for interaction; effective internal control system.
- ARDFM assesses board and senior management roles in SREP and inspects board approval and regular updates to strategy, risk appetite, capital plan and related policies.

EC3 — Credit policies, underwriting, administration, information systems, limits, model controls
- Regulation n. 188/2019 par. 42 sets requirements on credit risk policies and control environments.
- (a) Strategy and undue reliance on external assessments:
  - Banks operate under the credit risk standardized approach; corporates are mostly unrated.
  - Use of external expert assessments must follow a regulated process with limits and documented assumptions.
- (b) Criteria for approving exposures and differentiated due diligence:
  - For loans to individuals: thresholds trigger more detailed creditworthiness analysis when exceeding 0.01 percent of the bank’s capital and 100 billion KZT, or below 100 billion KZT but above 0.02 percent of the bank's capital.
  - For loans to legal entities: similar thresholds trigger financial statement analysis and other detailed assessments.
  - Deficiency noted: regulation allows exemptions from credit due diligence in certain cases (issuance of bank guarantees, letters of credit, loans secured by highly liquid assets) — the assessors consider such exemptions inappropriate.
  - Subsidiaries of non-resident banks with S&P long-term rating not lower than "A-" may use parent credit analysis if done within 12 months.
- (c) Credit administration:
  - Credit dossier requirements include identification documents, intended use documentation (with some exemptions), feasibility study thresholds tied to equity and bank size, documentation for credit monitoring.
  - Collateral procedures must define types, acceptability criteria, limits, share of highly liquid collateral, loan-to-value coefficients, enforceability procedures, adequacy assessments and appraisal frequency for certain high-value real estate (when market value > 100,000 monthly calculation indices equivalent to US $ 750k).
- (d) Effective information systems:
  - Management reporting must include loan portfolio quality, exposures reaching internal limits, group exposures, concentrations, internal ratings, provisioning adequacy, restructured/problem loans, compliance with limits, and deviations.
- (e) Limits:
  - Lending limits should be established by currency, industry, borrower category, products, related parties, and per borrower.
- (f) Exception tracking:
  - Deviations from procedures are reported to the board; the board should set restrictions to avoid significant deviations.
- (g) Controls over models:
  - Board to determine responsible divisions for rating/scoring model development and validation; credit ratings subject to periodic monitoring and increased frequency on negative information.

EC4 — Monitoring indebtedness and credit registry access
- Due diligence requires assessment of 'other debt'.
- Kazakhstan has one credit registry managed by NBK; banks report all loans (no threshold) but cannot access it; the Agency (ARDFM) can access the credit registry.
- Banks must purchase information from two existing credit bureaus (one public, managed by NBK; one private). The Credit Register covers banks but not microfinance activities.
- Opportunity exists to better exploit credit registry data for analytical public-good benefits.

EC5 — Arm’s length decisions and conflicts of interest
- Resolution n. 188/2019 defines conflict of interests and prescribes organizational structure to minimize conflicts (par. 2 n. 17; par. 20).
- Draft code of corporate governance should include conflict of interest management procedures and abstention mechanisms for board members.
- ARDFM verifies availability of conflict of interest policies in banks.

EC6 — Board decision thresholds for major exposures
- Regulation n. 188/2019 requires board approval for:
  - loans exceeding 5 (five) percent of the bank’s own capital.
  - unsecured consumer loan exceeding 20,000,000 (twenty million) KZT (not applicable to refinancing mortgage loans).
- Restructuring decisions for borrowers whose total debt exceeds thresholds (1 percent of own capital when > 100 billion KZT; 2 percent when ≤ 100 billion KZT) must be adopted by board or authorized collegial body and reported quarterly.

EC7 — Supervisor access to credit and investment portfolios and officers
- ARDFM has full access to information and the right to request oral and written documents, including financial statements and meeting materials.

EC8 — Credit risk stress testing
- Resolution n. 188/2019 par. 50 requires banks to conduct stress testing at least once every six months to identify threats to capital adequacy. Scenarios must consider general economic and idiosyncratic factors; board approves scenarios and results and integrates them into planning.
- ARDFM verifies existence and use of stress-testing programs during SREP and inspections.

### Principle 17 — Regulatory deficiencies and recommended actions
Key regulatory gaps and weaknesses:
- Regulation n. 188/2019 does not cap the maximum amount of a consumer loan in absolute terms (not only relative to borrower income), enabling potential misuse of consumer loans.
- Regulation enables banks to determine cases (including loans secured by highly liquid assets) where analysis of borrower’s creditworthiness is not applied; exemptions from due diligence should not be allowed.
- Threshold for annual assessment of real estate collateral is high (equivalent to US $ 750k).
- Lack of specific requirement for assessment of significant unhedged foreign exchange risk and its impact on credit risk.
- Regulation is silent on the evaluation method of collateral.

Recommendations (Agency should):
- Perform closer oversight of consumer lending and apply measures to banks that do not strictly monitor adequate use of those loans.
- Consider capping the maximum amount of a consumer loan in absolute terms.
- Eliminate exceptions to banks’ due diligence.
- Reduce the threshold for annual assessment of real estate collateral and prescribe the use of more than one valuation methodology.
- Require assessment of unhedged foreign exchange risk and its impact on credit risk.

### Principle 18 — Problem assets, provisions and reserves: framework and findings
- Regulatory basis:
  - BL 2444 art. 43: banks to establish provisions (reserves) according to international financial reporting standards; empowers ARDFM to assess adequacy including motivated judgment.
  - Law 474-II art. 13-5: authorizes ARDFM to use motivated judgment for adequacy of provisions.
  - Resolution n. 188/2019: board to approve policy on problem assets; banks to have reliable methodology for formation of provisions and annual (or more frequent) review.
  - Resolution n. 269 Dec. 2017: implemented IFRS 9 ECL framework; requires banks to develop Methodology for calculating provisions agreed with supervisor. IFRS 9 effective January 2018; no parallel run with incurred loss method; no prudential backstops retained.
- ARDFM conducts annual SREP, inspections of provisioning methodologies, and AQRs (involvement of external experts in AQR 2019).

EC2 — Classification and provisioning adequacy
- Banks required to classify assets into at least 5 categories for prudential purposes, but ARDFM does not spell out these five categories and classification follows IFRS 9 three-stage process—lack of reconciliation between prudential five-category requirement and accounting IFRS 9 three-stage process.
- AQR-based provisioning of retail lending was lower than banks’ adopted provisioning, indicating need to review AQR assumptions to ensure they are not systematically less conservative.

EC3 — Off-balance sheet exposures
- Resolution 269 paragraphs 21 and 22 require provisions at each reporting date for financial assets and contingent liabilities.
- ARDFM includes contingent liabilities in classification and provisioning using historical drawdown data and in regular AQR.

EC4 — Provisions timeliness and write-offs
- Resolution n. 269 requires methodology for provisioning consistent with IFRS 9; methodology elements listed include PD, LGD, EAD, SICR criteria, definition of default, ECL scenario analysis, sources of statistical/macro data, frequency of calculation, etc.
- Changes to the methodology admissible only for predefined reasons; methodology submitted to Agency within five working days of approval; Agency comments within sixty working days; banks must address findings within 30 working days.
- Resolution n. 269 does not set timely write-off requirements for uncollectable loans; IFRS 9 requires write-off when no reasonable expectation of recovery (par. B4.5.9) but sets no timeline; assessors note benefit of timely write-offs for transparency and NPL comparability.

EC5 — Early identification, oversight, and treatment of problem assets
- Resolution n. 269 and n. 188/2019 set minimum overdue days:
  - more than 30 calendar days trigger SICR on both homogeneous and individual assets.
  - overdue indebtedness over 60 calendar days triggers impairment for individually significant assets.
  - overdue indebtedness over 90 calendar days triggers default.
- Provisioning follows IFRS 9 staging: 12 months ECL (Stage 1), lifetime ECL when SICR (Stage 2), Stage 3 credit impaired loans.
- SICR criteria left to bank methodologies; Resolution n. 269 par. 10 does not spell out some IFRS9 B5.5.17 criteria (e.g., adverse change in business, significant changes in operating results, covenant waivers), leaving choice to bank methodology.
- Credit-impaired (Stage 3) definitions compared to IFRS9 show overlaps and some methodological discretion.
- Assessors note ARDFM refers to non-performing loans as 90 days overdue in official documents, but BCBS guidance implies NPL should include all credit-impaired exposures and exposures unlikely to be repaid without collateral realization. In practice:
  - NPL recognition is limited to 90 days past due exposures (around 3 percent of loans).
  - IFRS9 Stage 3 loans are about 15 percent according to 2022 AQR.
  - Foreclosed assets and Stage 3 assets on AMCs are not always captured in NPL metrics.
- AQR results include assets on balance sheets of bank-created subsidiaries (AMCs); 14.8 percent of stage 3 loans includes credit impaired assets on AMCs’ balance sheets.
- Banks reduced NPL by selling them to subsidiaries created for purchasing distressed assets from parent companies; such transactions exempted from related party requirements allowed NPL to be sold at nominal rather than market value.

EC6 — Supervisor access and reporting
- ARDFM monitors loan portfolio quality during off-site supervision and banks provide monthly reporting on loans and contingent liabilities per Regulation No 313.
- Assessors confirmed ARDFM access to classification and provisioning information.

EC7 — Supervisor powers to require adjustments
- ARDFM can exert motivated judgment on adequacy of reserves and require banks to increase provisioning, including via motivated judgment per Res. 2019/189 par 24.
- On-site inspection reports show ARDFM required banks to increase provisioning in sampled cases.

EC8 — Valuation of risk mitigants and collateral haircuts
- Res. n. 269 par. 17 requires banks to consider information on sale of collateral for at least two years when calculating ECL; absent this information, liquidity haircuts are applied:
  - residential and/or commercial real estate, including land plots - 0.7;
  - vehicles - 0.5;
  - equipment, goods and materials, products ready for sale - 0.4;
  - guarantees of individuals and/or legal entities, except guarantees issued by banks with S&P or similar rating not lower than sovereign rating or by quasi-public sector - 0;
  - property, including in the form of money coming in the future - 0;
  - highly liquid securities - 0.95;
  - guarantees issued by bank; a legal entity with a rating not lower than the sovereign rating of the Republic of Kazakhstan by S&P or similar; by a subject of the quasi-public sector - 1;
  - security in the form of money – 1.
- For other securities without confirmed sale information over two years, a liquidity ratio up to 0.7 may be applied; for types not provided by Methodology, liquidity ratio equals zero.

EC9 — Criteria for problem asset identification and reclassification
- Banks’ problem asset policy must include identification methods, management methods (restructuring, sale, write-off, withdrawal of collateral, bankruptcy, others), early response limits and procedures, internal roles, and board reporting (Res. n. 188/2019 par. 21 n. 6).
- Reclassification to performing is tied to restructuring rules; regulation lacks a required minimum ‘cure period’ for exiting non-performing status and legitimates practices that may enable evergreening (e.g., providing a new loan to pay overdue debt).
- Restructured loans categories and examples are extensive and include payment schedule changes, term extension, deferrals > 30 days, forgiveness, capitalization of overdue interest > 30 days, currency changes with capitalization, new loans to pay overdue debts, credit limit increases when aggregate overdue > 30 days, and interest rate reductions.
- Res. 269/2019 distinguishes (a) restructuring motivated by financial difficulties (which may trigger Stage 3 if restructured one or more times in the last 12 months) and (b) forced restructuring due to deterioration of borrower’s financial condition.
- Res. 269 par. 14 provides cure rules:
  - Stage 3 transferred to Stage 2 when counterparty repays debt for not less than 12 months (and gross carrying amount decreases to level at initial transfer or no objective evidence of impairment).
  - Financial asset with SICR (Stage 2) moves to Stage 1 when debt is repaid reducing gross carrying amount to previous level and absence of SICR; a minimum cure period of 1 months is present in Russian version (not English), noted as compliant with BCBS minimum.

EC10 — Board reporting on asset portfolio condition
- Resolution 188/2019 par. 41 requires classification system to provide information enabling board, board committees, management, and other divisions to assess credit risk at portfolio and asset levels.
- ARDFM assesses that Board obtains timely and appropriate information via risk management unit reporting and Head of Risk Management communications.

EC11 — Individual assessment threshold
- For ‘individual’ financial assets, threshold ties to 0.2 percent of equity (but not less than KZT fifty million) for individual assessment; provisioning thresholds and treatment described under EC5.

### Principle 18 — Conclusions and concerns
- There is regulatory alignment with IFRS 9 and detailed methodological requirements for provisioning; ARDFM has supervisory tools (inspections, AQR, SREP) and motivated judgment powers.
- Key concerns:
  - Discrepancy between NPL definition (90 days overdue) and broader BCBS concept that would include IFRS9 Stage 3 and exposures unlikely to be repaid without collateral realization; this leads to lower NPL ratios (around 3 percent) versus Stage 3 estimates (about 15 percent per 2022 AQR).
  - Use of AMCs and related-party exemptions allowed reductions in reported NPLs via transfers at nominal value rather than market value.
  - Absence of explicit timely write-off requirement in Resolution n. 269.
  - Potential systemic risks from consumer lending growth and underwriting loosening as noted under Principle 17.

*Source: 1kazea2024004 - 0.6 percent of total capital. The computability of non bail-inable subordinated debts (PDF chapter/section).*

### 0.2 percent of equity and KZT fifty million - are calculated separately. The same rule

### 1kazea2024004 - 0.2 percent of equity and KZT fifty million - are calculated separately. The same rule

### Problem assets and provisioning (Principle 18)
- Findings:
  - NPL recognition is limited to 90 days past due exposures (around 3 per cent of loans).
  - IFRS9 stage 3 loans (about 15 percent, according to 2022 AQR) and ‘unlikely to pay’ (UTP) exposures (foreclosed assets) are not included in NPL recognition.
  - Resolution n. 188/2019 par. 42 n. 7) requires banks to form provision on individual basis for loans that, based on the indicators provided by the methodology on problem assets, exhibit a SICR.
  - The Agency was not able to provide granular data on the concentration of Stage 3 loans per economic sector.
  - Resolution n. 269 does not set timely write-off requirements for uncollectable loans.
- Assessment: Materially Non-Compliant
- Recommendations:
  - NPL recognition criteria should include IFRS9 stage 3 loans, as well as foreclosed assets.
  - Timely write off requirements could be considered.

*Italic: Source — IMF assessment text provided.*

### Concentration risk and large exposures (Principle 19)
- Findings:
  - Regulations (Res. 188/2019; Resolution No 170) require banks to have policies and processes providing a comprehensive bank-wide view of concentration risk, covering on- and off-balance sheet exposures.
  - Managerial reporting includes concentration of credit risk of the largest borrowers (Res. n. 188/2019, par. 42, n. 11).
  - Top 30 borrowers account for 11.5% of total loans.
  - Geographic concentration: 46 percent of loans in Almaty.
  - Major sector exposures: industry 11.5 percent, trade 10 percent; loans to individuals 52 percent (not attributed to sector).
  - Banking Law does not define “group of connected counterparties”; Resolution n. 170 prescribes a detailed, prescriptive list of 13 conditions that aggregate borrowers into a group.
  - Prudential limits per Resolution No170 par. 52-57:
    - exposures to non-related borrowers < 25 percent of total capital (k3-  0.25)
    - aggregate amount of large exposures (those exceeding 10% of the bank's equity capital) must be kept below 5-time bank's equity.
    - exposure to Development Bank of Kazakhstan ≤ 5 percent of banks total capital.
    - aggregate amount of securitized loans transferred to a special financial company of the Stress Assets Fund ≤ amount of the bank's capital.
  - Prudential limits are calibrated to total capital instead of Tier 1.
- Assessment: Largely Compliant
- Recommendations:
  - Calibrate large exposure limits to Tier 1, instead of total capital.
  - Expand ‘motivated judgement’ for defining “group of connected counterparties” to include a general clause regarding economic interdependence.

*Italic: Source — IMF assessment text provided.*

### Transactions with related parties (Principle 20)
- Findings:
  - Broad legal definition of related parties (Banking Law art. 40 par. 3) with enumerated categories and thresholds (including 0.7 percent and 0.5 percent of bank capital thresholds for certain decisions).
  - Supervisor (ARDFM) may apply motivated judgment to recognize related parties (Res. 189 par. 16); thresholds for considering motivated judgment: >2 percent or >1 percent of equity capital depending on bank capital size (100,000,000,000 tenge).
  - Banks are prohibited from granting preferential terms to related parties (B.L. 2444 art 41 par. 1) with specific preferential-term examples listed (8 itemized types).
  - Board approval required for transactions with related parties (Banking Law art. 40 par. 5); related parties excluded from decision-making; notification to general meeting of shareholders required for waiver of claim rights to related parties, with exceptions for subsidiaries acquiring dubious and hopeless assets of parent bank.
  - There are 18 asset management companies (AMP) specialized in purchasing dubious and hopeless assets of the parent bank; they currently hold only 3 percent of NPL but have been used to clean up balance sheets at preferential terms.
  - Prudential limits to related party transactions:
    - single related-party borrower exposure ≤ 10 percent of total capital (Resolution No170 par. 52-57)
    - aggregate loans and guarantees to related entities ≤ 50 percent of equity (NBK Resolution n. 80/2012)
    - exception: loans/guarantees to subsidiaries buying doubtful assets can reach 100 percent of bank equity.
  - Collateralization: unsecured loans to related parties prohibited except for amounts ≤ 20 million tenge (B.L. art. 41 par 1).
  - No power to deduct related-party exposures from capital.
  - Reported ratio of related party exposures to capital: 2.2 percent (as at 1.1.23).
  - Evidence from insolvency cases (2020 and 2021) showed hidden related party lending was a main source of NPLs and bank failures.
- Assessment: Materially non-compliant
- Recommendations:
  - Revisit Banking Law Art. 40 par. 8 so distressed asset transfers by banks to subsidiaries or organizations specialized in acquiring dubious and hopeless assets take place at market terms.
  - ARDFM should consider an off-site and on-site thematic review on related party transactions, including external experts, to assess the size of the phenomenon and prevent insiders extracting private benefits.

*Italic: Source — IMF assessment text provided.*

### Country and transfer risk (Principle 21)
- Findings:
  - Country risk is mentioned in requirements (Resolution 188) but not explicitly defined; transfer risk is not specifically identified.
  - Supervisor does not require firms to establish or report exposures on an individual country basis.
  - Information systems requirements exist but do not mandate separate country-risk tracking processes.
  - Country risks are taken into account for capital risk weighting; high-rated countries (at least "AA-") have zero-weighting factor for credit risk assessment purposes.
  - No regulatory provisioning requirements specifically for country risk; no requirement for provisioning ranges or fixed percentages by country.
  - Supervisor can request additional information as needed but does not require regular country-risk reporting.
- Assessment: Materially non-compliant
- Recommendations:
  - Incorporate explicit requirements for defining country and transfer risk, regular reporting on country risk, provisioning against high-risk country exposures, and inclusion of country risk in stress testing.

*Italic: Source — IMF assessment text provided.*

### Market risk (Principle 22)
- Findings:
  - NBK Resolution No. 188 (par. 43–46) requires banks to adopt market risk management systems appropriate to their operations and to establish roles, reporting lines, and market-risk measurement (including value-at-risk and back-testing).
  - Resolution No. 188 requires effective management information systems (Par. 45.9), model back-testing (par. 45.2), segregation of trading and banking books (par. 44), and stress testing requirements (Par. 45).
  - Resolution does not explicitly require model validation by an independent function; it embraces the three lines of defense but lacks specific independent validation guidance.
  - Resolution does not set expectations regarding valuation adjustments for concentrated, less liquid, or stale positions.
  - Market risk is included in the ICAAP (Resolution No. 188, Chapter 5) though ICAAP implementation is ongoing and not yet evidenced as effective.
- Assessment: Largely compliant
- Recommendations:
  - Clarify in Resolution 188 or related guidance that models used for valuation should be subject to independent validation.
  - Require banks to establish policies for valuation adjustments of positions that are difficult to value prudently.

*Italic: Source — IMF assessment text provided.*

### Interest rate risk in the banking book (IRRBB) (Principle 23)
- Findings:
  - No prior requirement for IRRBB strategy; Res. n. 188/2019 (amended December 2022) introduced quantification requirements.
  - Banks must use at least two complementary methods: economic value of equity (EVE) and net interest income (NII).
  - For foreign-currency interest-rate sensitive instruments exceeding 5 (five) per cent of assets (liabilities), measurement must be separate by currency.
  - Banks currently quantify EVE only for two out of six Basel-prescribed scenarios.
  - ARDFM does not verify bank IRRBB submissions due to lack of a challenger model.
  - Draft Pillar 2 methodology on IRRBB prepared but not tested; ARDFM has not identified outliers.
- Assessment: Materially Non-Compliant
- Recommendations:
  - Require banks to calculate EVE under the six scenarios prescribed by the Basel Committee for Banking Supervision.
  - Develop a challenger model to engage supervisory dialogue on IRRBB.
  - Identify outliers and roll out the Pillar 2 methodology on IRRBB.

*Italic: Source — IMF assessment text provided.*

### Liquidity risk (Principle 24)
- Findings:
  - Legal and regulatory framework: Banking Law art 42; NBK Resolution n. 170/2017 (prudential liquidity ratios); NBK Resolution n. 188/2019 (ILAAP and liquidity management).
  - Prudential liquidity ratios (Resolution No. 170/2017):
    - Current liquidity ratio: K -4 set at 0.3.
    - Quick ratio K4-1 (7days) = 1.
    - Quick ratio K4-1 (1 months) = 0.9.
    - Quick ratio K4-1 (three months) 0.8.
    - Currency liquidity ratio K4-4 (7 days) = 1.
    - Currency liquidity ratio K4-5 (one month) = 0.9.
    - Currency liquidity ratio K4-6 (three months) = 0.8.
  - LCR and NSFR requirements follow Basel definitions; LCR phased in from 50 percent to 100 percent, effective full 100 percent as of January 1, 2022; NSFR effective January 1, 2019 with minimum 100 percent after monitoring period.
  - At assessment date, LCR and NSFR were at 80 percent (phased-in / temporary support). Violations of LCR/NSFR and other liquidity ratios were temporarily tolerated (from February 21, 2022, to December 31, 2022) subject to a nine-month action plan.
  - The definition of highly liquid assets for quick/current ratios differs from LCR HQLA (overnight loans and deposits with banks qualify for quick/current but not for LCR HQLA).
  - Liquidity requirements are set uniformly for all banks (not risk-based); Agency has power to set higher requirements but does not calibrate to bank risk profile.
  - Top 30 depositors account for about 11 percent of total deposits.
  - Approximately 1/3 of deposits are in foreign currency.
  - Resolution n. 188/2019 Chapter 6 establishes ILAAP, contingency funding plan, stress testing, and liquidity governance requirements.
- Assessment: Largely Compliant
- Recommendations:
  - Exit liquidity forbearance measures and set LCR and NSFR at 100 percent as soon as feasible.
  - Enforce sanctions for violations of prudential liquidity requirements.
  - Structurally assess and test liquidity contingency funding plans.
  - Perform more thorough monitoring and stress testing of foreign currency liquidity; consider introducing LCR per significant currency.
  - Reconsider the weight of liquidity risk in the overall SREP score (currently low at 10 percent).
  - Test ILAAP methodology and calibrate liquidity prudential requirements to banks’ risk profiles.

*Italic: Source — IMF assessment text provided.*

### Operational risk (Principle 25)
- Findings:
  - New operational risk reporting requirement (Resolution No. 54 of NBK dated April 21, 2020) requires reporting of operational losses exceeding 500,000 tenge; operational risk requirement instituted at beginning of 2023 (basic approach).
  - Resolution No. 188 (Paras. 46–52) establishes operational risk management system requirements, including internal reporting, classification of events, operational risk appetite, and inclusion in ICAAP (Chapter 5, par. 38).
  - Agency evaluates operational risk through onsite supervision, curators’ monitoring, and SREP; curators monitor daily.
  - Banks are required to conduct annual self-evaluations of operational risk and provide results to the Agency.
  - No evidence yet that the new reporting regime and operational risk framework are effective; time required to assess impact.
- Assessment: Largely Compliant
- Notes:
  - Operational risk metrics will feed into SREP quantitative indicators (capital requirements and operational loss ratios).
  - Inspectors’ reports include detailed operational risk findings requiring corrective measures.

*Italic: Source — IMF assessment text provided.*

### Chapter 5).

### Chapter 5

### EC5 — Information technology policies, processes, and infrastructure
- Supervisor determines banks have established appropriate information technology policies and processes to identify, assess, monitor, and manage technology risks.
- Supervisor determines banks have appropriate and sound information technology infrastructure to meet current and projected business requirements (under normal circumstances and in periods of stress), ensuring data and system integrity, security and availability and supporting integrated and comprehensive risk management.
- Legal and regulatory requirements:
  - Res. No.188 (Chapter 8, Para. 72): Board of Directors must ensure availability of an information technology risk management system corresponding to the external operating environment, strategy, organizational structure, volume of assets, nature and level of complexity of bank operations, and ensuring minimization of information technology risks.
  - Para. 73: Information technology risk management system must include IT risk management policies and procedures; a relevant management information system; and evaluations by internal audit of the IT risk management system, among other requirements.
  - Para. 74: Risk management system must include the risk management function as well as the information technology unit.
  - Article 75: Structural unit for IT risk management functions include development of a risk management system for IT; participation in implementation of the bank’s strategy to ensure availability of information and communication technologies; participation in assessment of and monitoring of risk in information technology; planning and analyzing IT risk assessments; reporting on implementation of measures to mitigate IT risk to the risk management committee and the board of directors.
  - Article 76: Structural unit functions include conducting IT risk assessments; developing measures for IT risks and reporting on their implementation to the risk management unit; preparing reports on significant risks and efforts to mitigate them.
  - NBK Resolution No. 48: Requirements for banks to ensure the security of their information and manage their cybersecurity risks.
- Agency capacity and staffing constraints:
  - The Agency’s cybersecurity resources are constrained and it has lost talent to the private sector.
  - At the time of this assessment, only one staff member holds an internationally recognized professional certificate related to information technology security.
  - Recommendation: train existing IT and cybersecurity supervisors and recruit staff with appropriate professional expertise; encourage staff to attain internationally recognized professional certification in operational risk-related IT/security areas.
- Assessment balance: existence of a relevant operational risk scenario is weighed against ongoing challenges to maintain sufficient resources to be effective.

### EC6 — Information systems for monitoring and reporting operational risk
- Supervisor determines banks have appropriate and effective information systems to:
  - (a) monitor operational risk;
  - (b) compile and analyze operational risk data; and
  - (c) facilitate appropriate reporting mechanisms at the banks’ Boards, senior management and business line levels to support proactive management of operational risk.
- Findings and implementation notes:
  - ARDFM supervisory staff conduct onsite work to ensure supervised banks monitor operational risk and evaluate information systems that banks maintain to monitor this and other risks.
  - The ARDFM recently adopted the basic indicator approach and intends to require banks to collect data on operational losses above 500 thousand tenge.
    - That data collection requirement was not yet in force at the time of this assessment; assessors cannot express an opinion on its implementation.
  - Under NBK Resolution No. 188:
    - The Bank must ensure availability of the management information system, including establishing internal procedures that set the composition and frequency of internal reporting on operational risk management.
    - Procedures must define responsible persons (or departments) of the bank that prepare and communicate operational risk-related information to relevant recipients (Para. 49).
    - Para. 78: Information technology unit is responsible for ensuring availability of information and communication technologies to support critical business processes, including identifying budgetary and technology needs.
    - Banks are required to ensure existence of a management information system and policies that define criteria for reporting.
  - Audience for operational risk reports includes relevant senior management, the risk management committee of the board of directors, and the board of directors itself.

### EC7 — Reporting mechanisms to supervisor on operational risk
- Supervisor requires banks have appropriate reporting mechanisms to keep the supervisor apprised of developments affecting operational risk.
- Findings:
  - Res. No. 188 sets requirements for banks to maintain an appropriate management information system related to operational risk and reports for relevant senior management, the risk management committee of the Board of Directors, and the Board of Directors itself.
  - The Resolution only occasionally refers to reports required to be provided to the supervisor.
  - Para. 113.4: Bank’s internal audit is responsible to evaluate effectiveness of risk management and reporting processes for the bank’s own management and the Agency.
  - The Agency and especially its curators have the ability to request any documentation from the bank and to participate in meetings as observers.
- Suggested improvement:
  - The Resolution or related regulations could be improved by setting an explicit requirement for banks to report operational risk developments to the Agency.

### EC8 — Outsourcing risk management
- Supervisor determines banks have established appropriate policies and processes to assess, manage and monitor outsourced activities. Outsourcing risk management program covers:
  - (a) conducting appropriate due diligence for selecting potential service providers;
  - (b) structuring the outsourcing arrangement;
  - (c) managing and monitoring the risks associated with the outsourcing arrangement;
  - (d) ensuring an effective control environment; and
  - (e) establishing viable contingency planning.
- Requirements for contracts:
  - Outsourcing policies and processes require the bank to have comprehensive contracts and/or service level agreements with a clear allocation of responsibilities between the outsourcing provider and the bank.
- Board responsibility:
  - When outsourcing individual operations and (or) implementation of business processes, the Board of Directors of the bank shall ensure that effective principles and practices of risk management resulting from outsourcing are in place.

*Chapter 5, 1kazea2024004 - Chapter 5).*

### Chapter 13 of Res. No. 188 establishes a minimum list of actions required when

### Chapter 13 of Res. No. 188 establishes a minimum list of actions required when outsourcing, which include establishing procedures for determining which functions may be outsourced; process for conducting due diligence on the financial condition of external contractors; setting principles for entering into contracts with external parties, including considering their ownership structure; and establishing effective controls at the bank and at the party that has contracted with the bank, among other requirements.

### Operational risk and outsourcing (Principle 25)
- Assessment: Largely Compliant.
- Findings:
  - Res. No. 188 requires procedures to determine which functions may be outsourced, due diligence on external contractors’ financial condition, contract principles (including ownership structure), and effective controls at both the bank and contracted party.
  - During the assessment, assessors did not see evidence that reviews of outsourcing risk had been undertaken.
  - Supervisory rules on operational risk management exist but have not been fully implemented, notably the adoption of the basic indicator approach and the ICAAP.
  - Information technology and cybersecurity are key operational risks; the Agency’s resources in cybersecurity are constrained.
- Policy recommendations / actions suggested:
  - Invest in training existing staff and recruit professionals with cybersecurity skills and expertise.
  - Encourage Agency staff to attain internationally recognized professional certification in cybersecurity and operational risk.
  - Complete implementation of the basic indicator approach and ICAAP to generate better evidence of effectiveness in managing operational risk and outsourcing exposures.

### Internal control and internal audit (Principle 26)
- Assessment: Compliant.
- Key provisions of Res. No. 188:
  - Banks must maintain internal controls “consistent with the current market situation, strategy, volume of assets, and level of complexity of bank operations” (Par. 98).
  - Board responsibility for forming the control environment (Par. 99) and implementing the “three lines of defense” (para. 100.5).
  - Requirements for accounting and financial reporting controls (para. 37) and credit controls (para. 42).
  - Checks and balances, including the “four eyes principle” (Para. 104) and segregation of duties (“separation of powers,” par. 102.2).
  - Controls over assets and fraud prevention measures (para. 104 and para. 11.4).
  - Requirement to establish a “compliance control unit” as an independent second-line unit; Board appoints chief compliance controller (paras. 20, 21.11, 21.14).
  - Internal audit described as the third line of defense; head of internal audit appointed by the Board and accountable directly to the Board (paras. 108–110, Para. 108 references international standards).
- Findings on ECs:
  - EC1: Res. No. 188 contains organizational, accounting, checks-and-balances, and safeguarding requirements; effectiveness assessed during SREP onsite reviews.
  - EC2: Resolution requires articulation of professional requirements for control staff (para. 100.2); Agency lacks authority to conduct fit and proper testing of senior managers in control functions (gap previously noted in Core Principle 5).
  - EC3: Compliance unit independence and head of compliance’s access to the Board are specified; Agency cannot conduct fit and proper testing of chief compliance officer.
  - EC4–EC5: Internal audit independence, powers, resource requirements and risk-based audit planning are set out (paras. 108–115, par. 111.8, par. 115). Internal audit powers include “unlimited access to bank documents, data, material objects, management reporting, records and minutes” (par. 111.8). Internal audit expected to prepare an annual risk-based audit plan (para. 115).
- Observations and recommendations:
  - Agency’s onsite SREP reviews provide credible oversight; inspection reports reviewed were generally detailed with clear remediation requirements.
  - Agency should conduct fit and proper reviews for senior leaders in internal control functions analogous to those for senior business leaders.
  - Clarify supervisory guidance to explicitly state that Internal Audit must have authority and resources to evaluate outsourced activities (current Res. No. 188 indicates board must establish outsourcing risk mitigation principles (par. 116), but does not explicitly state Internal Audit’s remit over outsourced functions).

### Financial reporting and external audit (Principle 27)
- Assessment: Largely Compliant.
- Legal and institutional framework:
  - Ministry of Finance upholds accounting standards except for financial institutions; NBK oversees accounting standards for financial institutions and establishes the chart of accounts. Law on Accounting and Financial Reporting requires financial organizations to carry out reporting in accordance with IFRS and regulatory legal acts of the NBK (para. 4 of Article 2).
  - B.L. Art 54 and Article 55 require banks to keep records in accordance with legislation and IFRS and to publish audited consolidated financial reports annually and quarterly balance sheet and profit-and-loss statements (quarterly statements not required to be audited).
  - NBK Res. No. 188 (par. 5, par. 21.14) assigns Board responsibility for timely and reliable disclosure and compliance with accounting and financial reporting requirements.
- Findings on ECs:
  - EC2: Audit committee oversees engagement with external auditor and review of auditor’s certification (Par. 26.2).
  - EC3: Res. No. 188 requires procedures for calculating fair value and back-testing (para. 45.11; paragraph 45) but did not require independent verification and validation of fair value estimates at the time of assessment.
  - EC4: External auditors must be licensed and independent per B.L. Art. 57; expectations for audit planning are not specified.
  - EC5: Audit scope and content requirements exist; Agency coordinates with authorized state body to establish lists of issues subject to audit.
  - EC6: Supervisors do not have the power to reject or rescind appointment of an external auditor; Ministry of Finance sets minimum requirements; supervisors cannot place restrictions on auditor provision of consulting services to reduce conflicts of interest; auditors not obliged by law to report circumstances that could impact reliability of audited statements.
  - EC7: Rotation required if an audit organization audits the same organization continuously for 7 years.
  - EC8: Agency meets with external audit firms occasionally but not regularly; meetings typically occur prior to inspections rather than periodically on emerging issues.
  - EC9: Law "On Auditing Activities" requires audit organizations to notify the competent authority of violations identified in audits of financial organizations.
- Observations and recommendations:
  - Agency lacks power to reject an auditor deemed inadequate or insufficiently independent and lacks authority to establish the scope of external audits.
  - Agency did not require independent verification and validation of fair value estimates at the time of the assessment.
  - Recommendation: empower the ARDFM to require a bank to hire a more competent auditor when material concerns exist; enable supervisors to limit conflicts of interest arising from auditors providing both audit and consulting services; meet regularly with external audit firms to discuss emerging issues.
- Notable numeric/time details:
  - Rotation rule: continuous audit by same audit organization triggers rotation after 7 years.

### Disclosure and transparency (Principle 28)
- Assessment: Largely Compliant.
- Legal and regulatory requirements:
  - B.L. Art. 55 requires publication of annual consolidated financial statements and quarterly balance sheet and profit-and-loss statements in accordance with IFRS; NBK Resolutions No. 282 and No. 138 set procedures and timing for publication.
  - At Agency request, banks must post other reports on the Internet per Agency regulatory legal acts (Art. 55.1).
  - The Agency has not yet adopted the “Pillar 3” elements of the Basel capital framework; it plans to do so in 2030.
- Findings on ECs:
  - EC2: Current disclosure requirements include annual and quarterly financial reporting but do not require disclosures on risk management strategy, governance, or remuneration — deficiencies noted at the prior assessment remain unaddressed.
  - EC3: No legal requirement to disclose all material entities in the group structure.
  - EC4: Agency verifies statutory publication requirements for annual and quarterly reports; banks must inform the Agency about publication and face supervisory response measures for missed deadlines.
  - EC5: Aggregate banking system information is regularly published on the Agency and NBK websites; the Agency’s website includes:
    - current state of the banking sector.
    - Key risks identified based on the results of the annual SREP assessment.
    - results of the AQR and SST conducted by the Agency.
    - the main priorities of the supervisory policy.
  - NBK publishes monthly/quarterly aggregate indicators including total balance sheet of tier two banks, total statement on income and expenses, owned capital, liabilities and assets, average interest margin and spread, balance and off-balance sheet balances, compliance reports, liquidity, loan portfolio structure and quality, deposit structure, funding structure, indicators of banking groups, concentration of assets of banking groups, compliance with prudential standards by bank groups, and measures and sanctions applied for reporting breaches.
  - Decree No. 774 requires consolidated balance sheet and consolidated income and expense report for second-tier banks to be posted on the Open Data Portal monthly.
- Observations and recommendations:
  - Supervisors should amend regulations to require disclosure of all material entities in a group structure to ensure truly consolidated reporting.
  - Authorities are encouraged to amend regulations to require disclosures of risk management strategy, governance, and remuneration in line with Basel Core Principle expectations.
- Notable numeric/time details:
  - Planned adoption of Pillar 3 elements in 2030.

### Anti‑money laundering / Countering financing of terrorism (Principle 29)
- Findings and legal basis:
  - Legal basis includes Law 474-II Art. 15-2, Art. 9 clause 2-1, the Law on Counteraction of Legitimization (Laundering) of Incomes Received by Illegal Means, and Financing of Terrorism (Law on AML/CFT).
  - Resolution No. 18 (Board of the Agency, March 22, 2020) established Requirements for Internal Controls for AML for second-tier banks and certain other entities.
  - Order No. 13 (Chairman of the Financial Monitoring Agency, February 22, 2022) approved Rules for Provision of Information by Financial Monitoring Units on operations subject to financial monitoring and characteristics of suspicious operations.
  - NBK Res. No. 188 (November 12, 2019) approved requirements for risk management and internal controls for second-tier banks, including mitigation of money laundering and terrorist financing risks.
  - Res. No. 140 (June 29, 2018) approved requirements for customer due diligence in remote business relationships.
- Supervisory practice and resources:
  - The Agency’s Supervisory Department analyzes banks’ AML/CFT compliance through: internal documents, internal audit and compliance reports on AML/CFT, and review of measures for current and future products.
  - The Agency employs an annual risk-based SREP process that includes evaluation of AML/CFT exposure and compliance.
  - Staff involvement and qualifications:
    - 6 staff from the Methodology Department develop and maintain the Agency’s AML/CFT approaches.
    - 14 staff from the Banking Regulation Department conduct offsite supervision of AML/CFT matters.
    - 20 staff from the same department conduct onsite inspections of banks’ AML/CFT frameworks.
    - 1 Agency staff member holds the Certified Anti-Money Laundering Specialist designation.
    - 3 staff hold a Kazakhstani AML/CFT certificate (as described by Agency staff).
  - The Agency provides regular AML/CFT training.
- Supervisory actions:
  - AML/CFT reviews are included in regular SREP inspections; special onsite reviews and unannounced inspections can be undertaken when concerns arise or intelligence is received.
  - Onsite inspections can include evaluation of customer due diligence (CDD) and transaction monitoring processes.
- Observations:
  - The Supervisory Department requests explanations and supporting documents when non-compliance is identified and may take supervisory measures when violations are confirmed.
  - Agency staff stated that the Agency never exerted “motivated judgement” on banks’ AML risk management.
- Note: assessors reviewed two examples of inspection reports related to Core Principle ... (text ends in source).

*Source: Chapter content from "1kazea2024004 - Chapter 13 of Res. No. 188 establishes a minimum list of actions required when" (PDF).*

### 29. The intensity of the work for the Agency’s staff was evident in one case in which a

### 1kazea2024004 - 29. The intensity of the work for the Agency’s staff was evident in one case in which a

### EC3 — Reporting, responsible employee, and supervisory inspection workload
- A bank with a high degree of money laundering risk required six staff members and three months to review.
- Article 10-2 of the Law on AML/CFT requires banks to submit information to the Agency about transactions subject to financial monitoring, including information about participants and grounds for suspicion.
- Banks must appoint a “responsible employee” (from management) to implement and ensure compliance with internal control rules.
- Requirements for the responsible employee:
  - 1) higher education.
  - 2) work experience as manager of bank division related to performance of banking and (or) other operations for at least 1 (one) year or work experience in AML/CFT sphere for at least 2 (two) years or work experience in the sphere of rendering and (or) regulation of financial services for at least 3 (three) years.
  - 3) Impeccable business reputation in accordance with the Banking Law.
- Functions of the responsible employee/AML/CFT unit include:
  - 1) ensuring availability and monitoring compliance of internal control rules and amendments.
  - 2) organization and control of submission of reports to the authorized body on financial monitoring in accordance with the Law on AML/CFT.
  - 3) making decisions on recognition of customer operations as suspicious and need to notify the financial monitoring authority.
  - 4) informing bank management of revealed violations of internal control rules.
  - 5) preparing information on results of implementation and recommended measures for AML/CFT risk management and internal control systems.
  - 6) coordinating collection of quantitative and qualitative indicators to assess the risk of bank's involvement in ML/TF processes and transferring requested information to the Agency annually no later than February 5 of the year following the reporting year.
- Agency supervisory grouping and inspection frequency:
  - Institutions allocated into three groups: high, medium, low degree of ML/TF risk.
  - High risk: annual inspection.
  - Medium risk: supervisory review every other year.
  - Low risk: supervisory review every third year.
- Transaction data access and review:
  - Institutions required to upload files containing list of all payments and similar transactions since prior onsite inspection; Agency thus can access up to three years’ worth of transaction data for low-risk institutions or one year’s for high-risk institutions.
  - One year of activity for a bank of average risk yields approximately 128 thousand transactions.
  - Agency evaluators rely on spreadsheets or free tools to review transactions and compare with institution-flagged suspicious items.
  - The Agency applies this intensive methodology at all onsite inspections regardless of a bank’s risk profile.

### EC4 — Information sharing with FIU and other authorities
- AML/CFT legislation obliges state bodies, including the Agency, to send information on suspicious transactions to the Agency for Financial Monitoring.
- Paragraph 2 of Article 18 of the AML/CFT Law requires state bodies to inform the authorized body about:
  - • suspicious transactions; or
  - • violations of the AML/CFT Law by the subjects of financial monitoring.
- The supervisor informs the financial intelligence unit and, if applicable, other designated authorities of additional suspicious transactions and shares information related to suspected or actual criminal activities with relevant authorities.

### EC5 — CDD policies, legal/regulatory framework, and supervisory activities
- Expected CDD management program elements (group-wide):
  - (a) customer acceptance policy identifying relationships the bank will not accept.
  - (b) customer identification, verification and due diligence programme on an ongoing basis, including verification of beneficial ownership, purpose and nature of relationship, and risk-based reviews.
  - (c) policies/processes to monitor and recognize unusual or potentially suspicious transactions.
  - (d) enhanced due diligence on high-risk accounts with escalation to senior management where appropriate.
  - (e) enhanced due diligence on politically exposed persons with senior management escalation.
  - (f) clear rules on record keeping and retention period; records have at least a five-year retention period.
- Legal and regulatory requirements:
  - Clause 4 of Article 5 of the AML/CFT Law: due diligence by subjects of financial monitoring shall be carried out in accordance with the Agency Requirements for Internal Controls for AML.
  - Item 3-2 of Article 11: Agency establishes requirements for second-tier banks.
  - Law requires internal controls adopted by board and senior management proportionate to size, character, complexity and degree of exposure.
  - Banks must adopt a monitoring program including: internal control organization program; a risk management program (low, high risk); customer identification and due diligence program; transaction monitoring/examination program; training and education program; and other internal control programs.
- Agency Requirements for Internal Controls for AML — identification and due diligence program elements:
  - 1) procedure for accepting clients, grounds/terms to refuse or terminate relationships.
  - 2) procedures for identifying and conducting due diligence including simplified and enhanced CDD measures.
  - 3) requirements for due diligence in correspondent relationships.
  - 4) measures to identify and conduct due diligence on customers, beneficial owners, public officials, spouses and close relatives.
  - 5) procedures for addressing targeted financial sanctions and verification against Lists under Articles 12 and 12-1.
  - 6) procedure for termination of targeted financial sanctions when excluded from List and FROMU List.
  - 7) requirements for identification and CDD when establishing remote business relationships.
  - 8) requirements regarding exchange, storage and confidentiality of information obtained during identification and CDD.
  - 9) requirements for identification and due diligence when obtaining information from other financial institutions.
  - 10) procedures for verification of authenticity of client and beneficial owner information.
  - 11) requirements for form, content and procedure for maintaining client file, updating info and periodicity.
  - 12) procedures to assess customer risk level and grounds for such assessment.
  - 13) procedures for obtaining and submitting information on beneficial owners at request of the bank per paragraphs three and four of item 5 of Article 5 of the AML/CFT Law.
- Definition of “beneficial owner” (AML/CFT Law Article 1.3): “an individual to whom more than twenty-five percent of partnership shares in a charter capital belong (sic) directly or indirectly or allotted (the deduction of privileged and repurchased by society) of shared of a client legal entity; carrying out a control over the client by other methods; in whose interests the client commits transactions with money and (or) other property.”
- Public officials and related parties requirements:
  - 1) assess public official’s reputation regarding AML/CFT involvement.
  - 2) obtain written permission of bank’s managerial staff to establish/continue relationship.
  - 3) establish source of funds and (or) other property.
  - 4) take enhanced due diligence measures on an ongoing basis.
  - Such clients must be assigned a high-risk level and additional measures applied.
- Recordkeeping:
  - Information under Items 23 and 24 documented and kept in client file for whole period of relations and not less than 5 (five) years after termination or one-time operation.
  - Monitoring program information entered in customer file and kept for entire business relationship and not less than five (5) years after transaction or one-time transaction.
  - Notices of transactions and results of examination kept by the Bank for at least five years after the transaction.
- Supervisory activities and workload:
  - Agency onsite inspections review newly onboarded customers since prior supervisory review.
  - Inspectors may evaluate 3,000 to 5,000 new customer files; this can take two inspectors one to up to three months to complete.
  - In most cases Agency staff review electronic records and files containing new customer information.

### EC6 — Correspondent banking controls
- Article 9 of the Law on AML/CFT requires banks, when establishing correspondent relations with foreign financial organizations, to:
  - 1) collect and document publicly available information on reputation and nature of activities, including investigations and sanctions for AML/TF violations in country of registration.
  - 2) document internal control measures of respondent and assess their efficiency.
  - 2-1) obtain confirmation that respondent has conducted due diligence of customers with direct access to correspondent accounts and can provide required customer due diligence information upon request.
  - 3) take steps to prevent establishment and maintenance of correspondent relationships with shell banks.
  - 4) ensure respondent denies use of its accounts by shell banks.
  - 5) obtain permission from entity's executive officer to establish new correspondent relationships.
- Evaluations of compliance with AML-related laws and regulations are part of onsite supervisory process, including regular SREP examinations.
- Establishing correspondent relations with shell banks shall be determined based on information from respondent or other sources.

### EC7 — Controls and systems to prevent abuse of financial services
- The supervisory authority assesses banks’ exposure to ML/TF risks and compliance with AML/CFT Law requirements.
- Supervisory activities relevant to this assessment are described under EC3 and EC5.

### EC8 — Supervisory powers and sanctions
- The Supervisory Department, upon discovering violations or non-compliance, requires explanations with supporting documents and, if necessary, opens a documentary inspection.
- Article 17 of the AML/CFT Law grants the Agency rights including:
  - (17.1.1) requesting information from supervised entities;
  - (17.1.2) suspending suspicious transactions for up to three working days;
  - (17.2.1) taking measures in response to money laundering or terrorist financing.
- If violations are confirmed, the Supervisory Department initiates application of supervisory measures or sanctions.

### EC9 — Internal audit, compliance officers, staffing and training
- Since prior FSAP, banks are required to identify a specific AML-related compliance officer (“the responsible employee” or “responsible officer”).
- Paragraph 11 of the Agency Requirements: functions of responsible officer and AML/CFT unit shall not be combined with internal audit or operational functions.
- Internal control rules must require internal audit service to assess effectiveness of internal control for AML/CFT; management reports based on internal audit assessments to management body and executive body are required.
- Paragraph 5 of Agency Requirements: appoint responsible employee from bank executives or managers not below head of structural unit and identify AML/CFT unit.
- AML/CFT internal control program must describe AML/CFT division functions, interaction with other divisions, and powers/procedure for interaction with management.
- Functions of responsible employee/AML/CFT subdivision include (non-exhaustive):
  - 1) ensuring availability and monitoring of internal control rules.
  - 2) organization and control of notifications to authorized body.
  - 3) decisions on recognizing operations as suspicious and need to notify financial monitoring authority.
  - 4) informing management of revealed violations.
  - 5) preparing information on implementation and recommended improvements.
  - 6) coordinating collection of quantitative and qualitative indicators and submitting requested information to the authorized body annually no later than February 5 of the year following the reporting year.
- Powers vested in AML/CFT unit officers include:
  - 1) access to all bank premises, information systems, telecommunication means, documents and files as necessary.
  - 2) sending instructions to bank divisions regarding performance of operations with money and/or other property.
  - 3) ensuring confidentiality of information received.
  - 4) ensuring safety of documents and files received.
- Training:
  - Chapter 6: purpose of AML/CFT Training and Education Program is to provide bank employees with knowledge/skills for compliance.
  - Training Program developed per paragraph 8 of Article 11 of the AML/CFT Law.
  - Agency management and staff noted frequent AML/CFT training offerings, though no specific number of training days mandated each year.
  - At present, no Agency staff hold international AML/CFT professional certificates or related certifications.

### EC10 — Internal reporting and management information systems
- Clause 13-2 of the AML/CFT law requires second-tier banks, branches of non-resident banks of the Republic of Kazakhstan, and the National Post Operator to adopt an internal control program for AML/CFT purposes that includes elements to ensure staff report problems related to abuse of financial services and to provide management with timely information (program elements described in earlier sections).

*REPUBLIC OF KAZAKHSTAN INTERNATIONAL MONETARY FUND*

### 1. the procedure for recording information, as well as storage of documents and

### 1. the procedure for recording information, as well as storage of documents and

### Required internal-control documentation and procedures
- Procedures for recording information, as well as storage of documents and information obtained in the course of the implementation of internal controls for AML/CFT purposes.
- Procedures for informing the management and executive body of the institution, including the responsible employee (AML officer), about any violations of the Law on AML/CFT and internal control rules by the bank’s employees.
- A description of AML/CFT requirements of the banking group, which includes the bank (if any).
- Procedures for the preparation and submission to the management body and executive body of the bank of management reports, including on a consolidated basis within the banking group, based on the results of AML/CFT internal controls assessment by the bank’s internal audit function.
- Procedures of decision-making by the responsible officer, management body and (or) executive body of the bank or managerial staff of the bank on:
  - the establishment, continuation or termination of business relations with customers;
  - the suspension or refusal to perform transactions for customers in cases related to the Law on AML/CFT and (or) agreements with customers and in accordance with the procedure stipulated by internal documents of the bank.
- Procedures for assessing, determining, documenting, and updating the results of ML/TF risk assessment.
- Descriptions of AML/CFT subdivision functions, including procedures for interacting with other subdivisions of the bank, branches, and subsidiaries when implementing internal controls for AML/CFT purposes; as well as the functions and powers of the responsible employee, and the procedures for the responsible employee to interact with the management body and executive body of the bank.
- The procedures for the observance and implementation of internal control rules, including the procedures for applying additional control measures, and procedures for ML/TF risk management and mitigation by its branches, representative offices, subsidiaries located both in the Republic of Kazakhstan and abroad, assuming that such rules to not contradict the legislation of the host state of those operations.

### Findings on whistleblower protection and information sharing (EC11–EC13)
- EC11: Laws provide that a member of a bank’s staff who reports suspicious activity in good faith either internally or directly to the relevant authority cannot be held liable.
  - As part of the requirements of the AML/CFT Law, the Methodology for assessing ML/TF risks and the Rules, the responsibility for providing information on suspicious transactions lies with the bank.
  - Article 11 of the AML/CFT law: “In the event that information, data, and documents are provided to the authorized body in accordance with this Law, the subjects of financial monitoring, their employees, and officials, regardless of the results of notification, shall not be liable under the laws of the Republic of Kazakhstan, as well as a civil law contract.”
- EC12: The supervisor, directly or indirectly, cooperates with the relevant domestic and foreign financial sector supervisory authorities or shares with them information related to suspected or actual criminal activities where this information is for supervisory purposes.
  - There is a possibility to exchange information under the AML/CFT Law and on the basis of agreements and memorandums.
  - Assessors found approaches to sharing information with relevant domestic authorities, such as the financial intelligence unit (the Financial Monitoring Agency), to be adequate.
  - Joint inspections are sometimes conducted with the Financial Monitoring Agency.
  - Assessors saw little evidence of substantial coordination with foreign supervisory authorities on a variety of topics, though the ARDFM has responded to requests for information on AML/CFT related investigations abroad.
- EC13: The supervisor has in-house resources with specialist expertise for addressing criminal activities and regularly provides information on risks of money laundering and the financing of terrorism to the banks.
  - The Financial Monitoring Agency conducts efforts to counter laundering of illegally-gained income and terrorism financing, and on prevention, revealing, suppression, disclosing and investigation of economic and financial offenses.
  - The Agency offers guidance to banks on emerging risks and typologies regarding AML/CFT.
  - The inspection team that evaluates banks’ AML/CFT risk management is also responsible for supervising crypto asset supervision, fraud, and sanctions.

### Assessment of Principle 29 (AML/CFT supervision)
- Grade: Largely Compliant
- Comments and findings:
  - The Agency has adopted an ambitious approach to implement and enforce existing legislation and regulations, many amended significantly since the prior Basel Core Principles Assessment.
  - Noted improvements:
    - Introduction of a definition for beneficial owner.
    - Strengthening of customer due diligence requirements, including coverage of both foreign and domestic politically exposed persons.
    - Requirement for banks to identify a specific AML-related compliance officer (the responsible employee).
    - Prohibitions on forming correspondent relationships with shell banks.
  - Concerns about the Agency’s onsite inspection approach:
    - Appears to lack a risk-focused approach; extensive reviews of all customer documentation and evaluation of every transaction shifts responsibility for identifying ML/TF risks from firms to the Agency.
    - This approach consumes significant time and resources and may diminish the Agency’s ability to spot problems and expose it to legal and reputational risks.
    - A risk-focused approach should evaluate a bank’s policies and procedures and test a limited number of customer due diligence files and transactions, rather than replicate the bank’s entire AML risk management practices.
  - Recommendations to strengthen capacity and focus:
    - Continue to invest in staffing and technology for AML/CFT, including potentially procuring appropriate tools for conducting evaluations of customers and transactions when necessary.
    - Encourage Agency staff and management training on AML/CFT issues; consider encouraging key managers and staff to seek internationally recognized professional certificates in AML/CFT.
    - Consider establishing specialized teams for significant topics beyond AML/CFT, such as fraud, sanctions, crypto-related activities.

### Summary compliance with the Basel Core Principles (selected core principles and comments)
- Core Principle 1 — Responsibilities, objectives and powers: LC
  - Safety and soundness of banks is not prioritized over other mandates in the law; promotional mandates and innovation objectives may create conflicts with financial stability.
  - Institutional arrangements exist to manage trade-offs (division of reporting among Deputy Chairmen; Supervisory Committee participation).
- Core Principle 2 — Independence, accountability, resourcing and legal protection for supervisors: MNC
  - ARDFM independence is not enshrined in legislation; Law 474-II makes ARDFM ‘directly subordinated’ to the President and gives the President the power to approve organizational structure and total staff.
  - Lack of transparency and specified grounds for removal of the governing body; no duty to publicly disclose reasons for removal.
  - One representative from the President is a voting member of ARDFM’s Board.
  - Funding from the republican budget threatens autonomy and limits actions such as hiring external experts and cross-border supervision work.
  - ARDFM staff not adequately protected from the cost of defending actions/omissions made in good faith.
- Core Principle 3 — Cooperation and collaboration: C
  - Laws/regulations provide for domestic cooperation and recognize confidentiality.
  - Executive branch involvement in Financial Stability Council considered in Core Principle 1.
  - Engagement with foreign supervisory authorities assessed under Core Principle 13.
- Core Principle 4 — Permissible activities: C
  - Law defines ‘bank’ and permissible activities; use of the word “bank” limited to licensed banks whose list is published on the ARDFM website.
  - Taking deposits from individuals is reserved to licensed banks; taking deposits from legal entities is not similarly reserved.
- Core Principle 5 — Licensing criteria: LC
  - ARDFM does not have power to conduct fit and proper tests on Heads of internal control functions (CRO, Chief Compliance Officer, Chief Internal Audit) because they are not defined as ‘executive employees’ per Article 20 of Banking Law n. 2444.
- Core Principle 6 — Transfer of significant ownership: LC
  - Laws/regulations define control and significant participation clearly.
  - AML/CFT law addresses beneficial owner concept; clarification would be useful to confirm coverage of investments.
  - Notification requirements regarding transfers of significant ownership likely apply to a larger set of owners than the AML definition of beneficial owner.
  - Laws/regulations should more clearly require banks to notify ARDFM of material information affecting suitability of a major shareholder.
- Core Principle 7 — Major acquisitions: C
  - Banking Law gives ARDFM authority to approve/reject major acquisitions and impose prudential conditions.
- Core Principle 8 — Supervisory approach: LC
  - Agency does not conduct resolvability assessments.
  - Supervisory discretion constrained by law limiting ‘motivated judgment’ to five areas.
- Core Principle 9 — Supervisory techniques and tools: LC
  - ARDFM has not formally assessed quality, effectiveness, and integration of on-site and off-site functions.
  - Internal desk-based AQR could be made a regular (annual) exercise to focus supervision on higher-risk banks and portfolios.
  - Stress testing results do not contribute to determination of Pillar 2 capital yet.
  - Inspection function is robust but findings are not prioritized; scope exists for greater use of horizontal thematic reviews.
- Core Principle 10 — Supervisory reporting: LC
  - Supervisory authorities can collect, review, and analyze information from banks and groups.
  - ARDFM should strengthen guidance to banks on validation and verification of fair value estimates and consider a “SupTech” strategy with NBK to modernize systems and platforms.
- Core Principle 11 — Corrective and sanctioning powers: LC
  - ARDFM has a range of supervisory response measures and sanctions and has used them.
  - ARDFM exercised forbearance loosening capital and liquidity requirements in response to COVID-19 and the outbreak of war in Ukraine; violations were tolerated subject to action plans to be addressed within 9 months.
  - Recommendation: restore typical requirements expediently to reduce potential for risk expansion.
- Core Principle 12 — Consolidated supervision: MNC
  - Risk management and prudential requirements apply only on a solo level, not consolidated, weakening consolidated supervision.
  - ARDFM intends to align prudential regulation of financial groups with Basel Committee requirements and to set expectations at consolidated level.
  - Prudential standards such as liquidity and capital should be applied across the group.
- Core Principle 13 — Home-host relationships: MNC
  - ARDFM has been passive in home-host relations and has not revived/established supervisory colleges as home supervisor.
  - ARDFM has MOUs with foreign supervisors but appears to lack one MOU for the home country supervisor of a significant global bank active in Kazakhstan.
- Core Principle 14 — Corporate governance: LC
  - Resolution n. 188/2019 enhanced corporate governance framework, but improvements still needed:
    - Requirement for board succession plans is missing.
    - No limit to multiple memberships for board members, raising potential conflicts of interest and time commitment concerns.
  - ARDFM’s representative plays a pivotal role in assessing corporate governance, but practice is not complemented by thematic reviews or targeted on-site inspections on corporate governance.
  - ARDFM does not structurally assess banks’ and banking groups’ compensation systems.

*REPUBLIC OF KAZAKHSTAN  INTERNATIONAL MONETARY FUND*

### 15. Risk management

### 15. Risk management

### Risk management process
- No legal requirements for banks to prepare recovery plans.
- ICAAP and ILAAP not submitted yet by banks at the end of the FSAP mission (conducted during the first in‑country mission).
- Supervisory expectations on ICAAP and ILAAP need to be expanded to the entire spectrum of Pillar 2 risk (for example, sovereign, interest rate, and climate related financial risks).

### 16. Capital adequacy (LC)
Findings:
- Local RWA for credit risk are in some cases less conservative (exposure to SME, and syndicated loans), but in other more prudent (consumer loans).
- The definition of capital is broadly compliant with the applicable Basel standards, with the exception of revaluation reserves (which represent 0.6 percent of total capital).
- CCB for no D‑SIBs is set at 2 percent instead of 2.5 percent.
- No leverage ratio requirement is in place.
- Capital requirements do not reflect the banks’ risk profile yet: ARDFM has drafted a methodology for Pillar 2 capital add-on, but roll‑out is planned for 2024. The draft methodology covers IRRBB and capital shortfall resulting from under provisioning, but does not cover other Pillar 2 risks (for example, sovereign, and climate related financial risk).

Recommended actions (Principle 16):
- Phase out the residual Covid-19 capital forbearance measures (align RWA calculation for exposures towards SME and syndicated loans with Basel framework).
- Eliminate revaluation reserves from the eligible items in the definition of capital.
- Introduce a leverage ratio requirement.
- Increase CCB to 2.5 percent also for non‑D‑SIBs.
- Calibrate prudential requirements to risk profile by implementing the draft Pillar 2 methodology.
- Expand methodology and Pillar 2 add on to concentration, sovereign risk, and climate related financial risk.

### 17. Credit risk (LC)
Findings:
- Consumer lending growth: about 40 percent in 2021 and 27 percent in 2022; remains a source of concern due to lack of clarity on underlying drivers.
- Some banks are loosening underwriting standards (e.g., granting consumer loans to enable borrowers to make the minimum down payment on mortgage loans, repay overdue debt including with other financial institutions, or loans to SME owners for financing their business).
- Regulation n. 188/2019 strengthened credit risk management but has shortcomings:
  - a) does not cap the maximum amount of a consumer loan in absolute term (and not only in relation to the borrower income);
  - b) enables banks to ‘determine the cases (loans secured by highly liquid assets) in which the analysis of the borrower's creditworthiness is not applied’;
  - c) envisages a threshold for annual assessment of the real estate collateral which is too high (equivalent to US 750k $);
  - d) is silent on the evaluation method of the collateral.

Recommended actions (Principle 17):
- Perform closer oversight of consumer loan use and apply measures to banks that do not strictly monitor adequate use.
- Cap the maximum amount of a consumer loan in absolute term.
- Eliminate exceptions to banks’ due diligence.
- Reduce the threshold for annual assessment of real estate collateral and prescribe the use of more than one methodology.

### 18. Problem assets, provisions, and reserves (MNC)
Findings:
- Prudential framework not fully aligned with international standards:
  - NPL recognition limited to 90 days‑past‑due exposures (currently around 3 per cent of loans as at end 2022), but excludes IFRS9 stage 3 loans (6.6 percent, at the same date), as well as ‘unlikely to pay’ (UTP) exposures (namely, foreclosed assets).
- Resolution n. 269 does not set timely write‑off requirements of uncollectable loans.

Recommended actions (Principle 18):
- Expand NPL recognition criteria to IFRS9 stage 3 exposures, as well as foreclosure assets.
- Consider timely write off requirements for uncollectable loans.

### 19. Concentration risk and large exposure limits (LC)
Findings:
- Regulations require bank policies and processes to provide a comprehensive bank‑wide view of concentration risk.
- Prudential limits are calibrated to total capital instead of Tier 1.
- Definition of ‘group of connected counterparties’ is broad but prescriptive (Resolution n. 170 par. 54); ARDFM has limited discretion and lacks power to exert ‘motivated judgment’.

Recommended actions (Principle 19):
- Calibrate large exposure limits to Tier 1, instead of total capital.
- Expand the “motivated judgement” to the “group of connected counterparties” to provide supervisor discretion on a case‑by‑case basis.

### 20. Transactions with related parties (MNC)
Findings:
- Law provides broad definition of related party; supervisor can exert motivated judgment, but on‑site inspection reports showed related party exposure risk was higher than officially reported.
- Related party lending was a major driver of recent bank defaults; abusive related party loans led to extrapolation of private benefits by insiders.
- Transfer of distressed assets at non‑market terms to subsidiaries distorts credit risk reflection, inflates profits, disincentivizes conservative origination, and delays NPL secondary market development.

Recommended actions (Principle 20):
- Conduct off‑site and on‑site thematic review on related party transactions (possibly with external experts).
- Revisit Banking Law Art. 40 par. 8 so distressed asset transfers to subsidiaries or specialized organizations occur at market terms.

### 21. Country and transfer risks (MNC)
Findings:
- Laws/regulations identify country risk and set requirements for monitoring country risk for AML purposes.
- Supervisors do not explicitly require regular reporting of country risk, nor set provisioning requirements for country risk.

Recommended actions (Principle 21):
- Incorporate requirements for gathering and regularly reporting on country risk; set and apply provisions against credit exposures to certain countries or geographies; include country risk as a variable in stress testing.

### 22. Market risk (LC)
Findings:
- Requirements exist for identifying, measuring, monitoring, reporting, and controlling market risk.
- Key elements of international standards still in development or being implemented, notably ICAAP implementation and imposing capital increases reflecting stress testing.
- Models used for valuation of assets are not subject to independent validation.
- No policies for valuation of positions that are difficult to estimate prudently.

Recommended actions (Principle 22):
- Continue developing and fully implementing market risk mitigation requirements, including full ICAAP implementation and capital increases reflecting stress testing.
- Clarify that models used for valuation of assets should be subject to independent validation.
- Require banks to establish policies for valuation of difficult‑to‑estimate positions.

### 23. Interest rate risk in the banking book (MNC)
Findings:
- Supervision of IRRBB at an infancy stage; ARDFM training reached only one bank.
- Banks recently requested to quantify IRRBB via two supervisory indicators (EVE and NII); EVE quantified only for two out of four Basel Committee scenarios.
- ARDFM does not verify this information due to lack of a challenger model.
- Draft Pillar 2 IRRBB methodology prepared but never tested.
- ARDFM does not identify outliers.

Recommended actions (Principle 23):
- Require banks to calculate EVE under the six scenarios prescribed by the Basel Committee for Banking Supervision.
- Develop a challenger model to initiate supervisory dialogue on IRRBB exposures.
- Identify outliers.
- Roll out the Pillar 2 methodology on IRRBB.

### 24. Liquidity risk (LC)
Findings:
- Prudential requirements below Basel standards: LCR and NSFR requirements set at 80 percent.
- Violation of LCR, NSFR, and other liquidity ratios (due to deposit outflows, revaluation) was temporarily tolerated from February 21, 2022, to December 31, 2022, subject to banks providing an action plan within 9 months.
- Liquidity requirements set at the same level for all banks; do not reflect individual risk profiles.
- ARDFM does not structurally assess contingency funding plans.
- ARDFM assesses liquidity risk during the SREP, partially untested as banks will submit first ILAAP at end of mission.
- About 1/3 of deposits is in foreign currency; LCR in tenge does not fully capture currency liquidity mismatches.

Recommended actions (Principle 24):
- Exit liquidity forbearance measures and set LCR and NSFR at 100 percent.
- Enforce sanctions for violations of prudential liquidity requirements.
- Structurally assess liquidity contingency funding plans.
- Perform more thorough monitoring of foreign currency liquidity (including liquidity stress tests in foreign currency).
- Reconsider liquidity risk weight in SREP (currently seems low at 10 percent).
- Test ILAAP assessment methodology and calibrate liquidity prudential requirements to banks’ risk profiles.
- Consider introducing LCR per significant currency to capture currency mismatches, since about 1/3 of deposits is in foreign currency.

### 25. Operational risk (LC)
Findings:
- Rules/regulations on adequacy of operational risk management frameworks exist.
- Supervisors have not fully implemented rules, notably basic indicator approach and ICAAP.
- IT and cybersecurity are key operational risk sources; ARDFM resources—especially in cybersecurity—are constrained.

Recommended actions (Principle 25):
- Fully implement capital rules for operational risk, including adopting the basic indicator approach and the ICAAP.
- Invest in training existing staff and recruiting professionals with skills/expertise in cybersecurity, including internationally recognized certifications.

### 26. Internal control and audit (C)
- NBK Resolution 188 outlines sufficient guidance to meet essential criteria for internal controls and internal audit.

Recommended actions (Principle 26):
- Consider requiring fit and proper testing for senior leaders involved in internal control functions (e.g., chief risk officer, chief compliance officer, internal auditor).

### 27. Financial reporting and external audit (LC)
Findings:
- Rules/regulations broadly aligned with international standards, correcting prior deficiencies such as rotation of external auditors.
- ARDFM is not empowered to reject or rescind selection of an external auditor it considers inadequate, insufficiently independent, or not aligned with professional standards.
- Supervisors lack power to require a more competent auditor or limit conflicts of interest from auditors providing consulting services to the same client.

Recommended actions (Principle 27):
- Grant ARDFM authority to reject or rescind selection of inadequate external auditors.
- Allow ARDFM to set scope for external audits of supervised banks.
- Require fair value estimates to be subject to independent verification and validation.

### 28. Disclosure and transparency (LC)
Findings:
- Regulations require regular disclosure on consolidated or solo basis reflecting financial condition, performance, and risk exposures.
- Laws/regulations do not require disclosure of all material entities within a corporate group structure.
- Laws/regulations do not require reporting of information related to risk management, strategy, governance, or remuneration.

Recommended actions (Principle 28):
- Amend laws/regulations to require disclosure of all material entities within a corporate group.
- Require disclosures related to risk management strategy, governance, and remuneration.

### 29. Abuse of Financial Services (LC)
Findings:
- ARDFM’s onsite inspections lack a risk‑focused approach; extensive review of all customer documentation shifts identification of money laundering and terrorist financing risks from firms to ARDFM.
- ARDFM relies on free online tools and some self‑built tools for AML/CFT evaluations.
- At mission time, ARDFM employed few managers/staff with internationally recognized AML/CFT professional certificates.
- A wide range of responsibilities assigned to AML/CFT team, including fraud and crypto‑related activities.

Recommended actions (Principle 29):
- Onsite AML/CFT inspections should hold firms accountable for managing these risks.
- Continue investing in staffing and technology for AML/CFT supervision and encourage attainment of internationally recognized professional certificates.
- Establish dedicated teams to cover significant/specialized risks (e.g., crypto asset activities, fraud), rather than having the AML/CFT team handle multiple disparate risks.

### Governance, supervisory capacity, and institutional recommendations (selected)
- Law should state ARDFM’s primary objective is promotion of safety and soundness of banks; any additional mandate subordinated to this objective (Principle 1).
- Eliminate growth lending rates from ARDFM KPIs (Principle 1).
- Amend Law 474‑II to prescribe ARDFM independence and autonomy over organizational structure and staffing; specify removal conditions for ARDFM Chair; representative from the President should not have voting rights (Principle 2).
- ARDFM may consider building its own budget (e.g., levying fees calibrated to assets or RWAs) and adopt legal protection procedures for staff (Principle 2).
- Embed motivated judgment as ordinary modus operandi and enable provisional motivated judgment in urgent cases; consider Administrative Board of Review for decisions (Principle 8).
- Conduct resolvability assessments (Principle 8).
- Strengthen on‑site/off‑site integration, expand stress testing to climate risks, prioritize on‑site findings, use horizontal thematic reviews (Principle 9).
- Strengthen guidance on fair value validation/verification; consider a “SupTech” strategy with NBK to modernize supervision platforms (Principle 10).
- Restore forbearance measures to typical levels expediently (Principle 11).
- Revive supervisory colleges and ensure MOUs with home supervisors of significant global banks active in Kazakhstan (Principle 13).
- Resolution n. 188 should consider board succession plans and limits to multiple memberships; conduct thematic reviews on corporate governance and remuneration, prevent banks that benefitted from state support from paying variable remuneration until reimbursement (Principle 14).
- Introduce requirements for banks to prepare recovery plans; prioritize ICAAP and ILAAP assessment (Principle 15).

*Source: 1kazea2024004 - 15. Risk management*

### 1. The authorities of Kazakhstan appreciated the FSAP’s assessment of the

### 1kazea2024004 - 1. The authorities of Kazakhstan appreciated the FSAP’s assessment of the

### Overview and general assessment
- The authorities of Kazakhstan appreciated the FSAP’s assessment of the implementation of the Basel Core Principles for Effective Banking Supervision (BCP) in Kazakhstan.
- Authorities valued the professionalism and constructive approach of the FSAP team and described collaboration as efficient, leading to successful completion of the complex project.
- Authorities highlighted that the BCP assessment was beneficial in the areas of systemic risk analysis, exploring emerging issues, and bringing banking regulation and supervision frameworks in line with international standards.
- The Agency and the NBK broadly agreed with the conclusions of the BCP assessment.

### Supervisory mandate and risk-based supervision
- The Report highlighted significant improvements in enhancing supervisory mandate by introducing risk-based supervision based on:
  - supervisory review and evaluation process (SREP),
  - stress test, and
  - internal desk-based assets quality review (AQR).
- Since 2022 the Agency has been working on aligning consolidated supervision with Basel standards. By December 2023, the Agency developed regulatory legal acts on key prudential standards, risk management and corporate governance systems on a consolidated level. These requirements will be put in place in 2024.
- The Agency introduced regulatory requirements for capital add-ons in December 2023 based on results of SREP, AQR and supervisory stress testing.

### Prudential requirements, buffers, and liquidity standards
- In December 2023 the Agency increased the requirement for the capital conservation buffer to 2.5 percent for non-systemic banks.
- Temporary easing of prudential measures for SMEs and syndicated loan exposures expired at the end of 2023.
- As of January 2024, the risk weights for SME and syndicated loans have been aligned with Basel requirements.
- Starting in January 2024, both the LCR and NSFR requirements increased from 80 percent to 90 percent, with a subsequent rise to 100 percent effective from July 2024.

### Resolution framework and crisis management
- Work on changes to legislation related to resolution of insolvent banks and state intervention framework started in 2023.
- The Agency requested IMF technical assistance to develop legislative amendments to:
  - improve efficiency of the insolvent bank resolution mechanism,
  - define roles and responsibilities of different stakeholders,
  - specify the forms and mechanism for using public funds and tightening underlying conditions.
- Authorities also requested technical assistance on development of playbooks to further operationalize crisis management framework.

### Consumer lending, DSTI, and consumer protection
- The Agency takes systemic measures to reduce risks in consumer lending on a constant basis, including tightening prudential regulation of consumer loans and Debt Service-to-Income (DSTI) requirement.
- In November 2023, the Agency proposed to Parliament a draft Law providing further measures on reducing debt burden and strengthening consumer protection. The draft Law includes BCP recommendations that empower the Agency to cap the maximum amount of a consumer loan.
- In December 2023, all exemptions to DSTI calculation were removed and DSTI requirement was extended to all loans, including secured loans and loans to individuals with high income.

### Asset quality, NPLs, and provisioning
- The Agency noted the BCP assessment did not sufficiently reflect progress in enhancing stability of banks and resolving NPL on a systemic level, leading to an underestimation of the grade on Core Principle 18 «Problem assets and provisioning».
- The Agency acknowledged that the NPL definition needs revision to align with international standards, but emphasized:
  - a large share of problem loans accumulated in previous crises has been resolved,
  - NPL and Stage 3 loans are declining rapidly,
  - while the NPL definition is confined to 90 days past due exposures, it does not affect recognition and adequacy of provisioning for stage 3 loans,
  - all banks classify stage 3 loans and provisioning of distressed assets in line with IFRS 9 and Provisioning rules.
- Key statistics published in AQR Reports:
  - NPL90+ level has reached a historical minimum of 3.2 percent.
  - Stage 3 loans were at 21.1 percent in 2019, decreased to 14.8 percent in 2022, and further to 13.5 percent in 2023.
- International experts conducted an independent asset quality review in 2019-2020. Since 2021, the Agency has been consistently evaluating asset quality as part of regular AQR, and banks are required to form additional provisions based on results. Since 2020, the Agency regularly publishes the level of distressed assets in the AQR Report including stage 3 loans.

### Related-party lending and distressed asset transfers
- The Agency took note of the recommendation on related party lending transactions and stated such exposures are no longer a systemic issue due to the shift to risk-based supervision and implementation of motivated supervisory judgment.
- In December 2023, the Agency submitted legislative amendments to Parliament obliging banks to sell distressed assets to any investor, including to their subsidiaries that acquire distressed assets, exclusively through digital platforms accredited by the Agency at market terms.
- The Agency noted participation of other potential investors in these digital auctions will ensure market conditions for transfer of distressed assets and plans to conduct a thematic review on related party lending transactions on a regular basis.

### Interest rate risk in the banking book (IRRBB) and operational risk
- In May 2023 the Agency developed a challenger model for IRRBB to assess the economic value of equity and net interest income based on six scenarios, and integrated it into the SREP-2023.
- The Agency developed an operational risk assessment model in accordance with the latest Basel recommendations, which was also incorporated into SREP-2023 assessment.

### SupTech, IT infrastructure, and data governance
- In 2023 the Agency developed an automated system with modules for analyzing key indicators and risks of banks within the SREP supervisory model, and automated systems using machine learning algorithms to assess suspicious transactions and credit risks. A comprehensive automated system for conducting on-site inspections is under development.
- Regarding dependence on the IT infrastructure of NBK:
  - NBK and ARDFM have created a mechanism for financing the Agency’s IT projects in the field of supervision at the expense of NBK’s own budget.
  - NBK collects, processes, manages all regular reporting data, including granular (e.g., Credit registry) and granted ARDFM access to this data and basic analytics. ARDFM is responsible for deeper analysis of data for supervision purposes.
  - All authorities’ mandates and responsibilities in that area are set by Law. All additional regular data collection (not one-time queries) needs legal requirements to be set by ARDFM for market participants. In case of introduction of such requirements, NBK develops its IT-system to collect and manage such data (e.g., recently introduced AML reporting for banks, risk metrics to Credit registry, etc.).

### Implementation roadmap and next steps
- By the time the BCP assessment Report was completed the Agency implemented some of the key BCP recommendations.
- Some recommendations (introduction of consolidated supervision, capital add-ons, Basel Pillar 3 disclosure requirements, and expansion of motivated judgment) were already in implementation stage as part of the Concept for the Development of the Financial Sector of Kazakhstan, approved by the President in September 2022.
- There is tangible progress towards implementation and BCP assessment recommendations helped improve the quality of new regulatory and legislative changes.
- In December 2023 the Financial Stability Council of Kazakhstan approved a Roadmap on implementation of FSAP recommendations. The Roadmap includes a wide range of measures, including adoption of legislative and regulatory changes in 2024–2025.

*Source: 1kazea2024004 - 1. The authorities of Kazakhstan appreciated the FSAP’s assessment of the*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2024/english/1kazea2024004.pdf_
