## Appendix II (pages 60–71)

## Source details

**Canonical URL:** [Appendix II (pages 60–71)](https://www.imf.org/-/media/files/publications/wp/2021/english/wpiea2021105-print-pdf.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/wp/2021/english/wpiea2021105-print-pdf.pdf.md)
- [Structured JSON version](/-/media/files/publications/wp/2021/english/wpiea2021105-print-pdf.pdf.json)

---

### Central theme: Fintech, cybersecurity, and nonfinancial risk in central banks
- Central banks face expanded risks including financial risks from policy decisions and nonfinancial risks: strategy and policy risk, operational risk, and reputational risk.
- Nonfinancial risk management received less attention historically; mandates expanded after the Global Financial Crisis (GFC).
- Recent topics—climate change, economic development/employment, financial inclusion, and fintech—have increased central banks’ roles and elevated nonfinancial risk exposure.
- The paper focuses on central bank nonfinancial risks specifically related to fintech and cybersecurity, emphasizing trade-offs between fintech upsides and guaranteed cyber downsides.

### Evidence base and sources analyzed
- Analysis draws on:
  - Findings from nine (9) IMF MCM Central Bank Operations and ITD/Digital Advisory TA cases.
  - Findings from four (4) country cases: Indonesia, Luxembourg, Sierra Leone, and Ukraine.
  - Informal interactions with heads of risk management of several IORWG central banks.
  - Participation in the EU’s Fintech Risk Management Project.
  - Findings from the IMF’s Article IV (AIV) database and selected FSAPs.

### Analytical focus and structure
- Section II: Definition and overview of “fintech” and enabling technologies.
- Section III: Extent of IMF TA and surveillance coverage of links between central bank risk management, fintech, and cybersecurity.
- Section IV: How fintech developments affect central bank risk management—strategy/policy risk and operational risk.
- Section V: Conclusions and recommendations.
- Appendix I: Bali Fintech Agenda (BFA) risk management details.

### Key implications for central bank risk management
- Fintech and cybersecurity materially strengthen the need for enhanced central bank risk management.
- Central banks must consider interplay between fintech upsides (new services, inclusion, efficiency) and cyber downsides (amplifying operational, reputational, policy risks).
- Widening central bank remit into areas overlapping fiscal authorities increases exposure to nonfinancial risks.

### Fintech: definition and enabling technologies
- Bali Fintech Agenda (BFA) definition: fintech relates to “the advances in technology that have the potential to transform the provision of financial services spurring the development of new business models, applications, processes, and products.”
- FSB definition: “technologically enabled innovation in financial services that could result in new business models, applications, processes or products with an associated material effect on financial markets and institutions and the provision of financial services.”
- Common enabling technologies: Big data on individuals and firms; AI/ML; computing power (distributed computing); cryptography; mobile access internet.
- Applications span payments, financing, asset management, insurance, and advice.

### BFA Principles relevant to central bank risk management
- Principle IX (Ensure the Stability of Domestic Monetary and Financial Systems): fintech “offers central banks the opportunity to explore new services, while having to consider new risks.” Focus areas include CBDC, payment systems, financial stability, and lender-of-last-resort aspects.
- Principle X (Develop Robust Financial and Data Infrastructure to Sustain Fintech Benefits): stresses effective governance, risk-management processes, operational risks, interdependencies among service providers, and outsourcing/vendor risk management.
- Principles IX and X, though framed for financial institutions, apply substantially to central banks.

### IMF involvement modalities and TA focus (2018–2020)
- Modalities: Technical Assistance (TA); Article IV (AIV) surveillance; Financial Sector Assessment Program (FSAP).
- TA focus (2018–2020): central bank risk management, governance, internal organization, cash currency management, cybersecurity/digital advice.
- Regional and topic distribution: most TA and interactions in Europe and Middle East and Central Asia; main topics: (1) central bank risk management (including BCM), (2) fintech organization (fintech units), (3) central bank cybersecurity, (4) digital payments and cash currency management (in two cases).

### TA-identified fintech issues and common requests
1. Risk Management
   - Many central bank risk management departments were not fully aware of emerging fintech risks (example: cloud computing).
   - Benefit from closer cooperation among (i) IT department, (ii) fintech department, and (iii) financial supervision department.
   - TA shared experience on setting up Security Operation Centers (SOC) and conducting cybersecurity assessments (red, blue, purple teaming).
2. Decision-making
   - Senior management and Board often not fully informed on fintech and cybersecurity and their link to strategic planning and risk appetite.
   - In three cases the decision-making body was not at full strength, with nonexecutive Board positions unfilled.
   - Internal silos: fintech reporting to one decision-maker, risk management to another, with poor information-sharing.
3. Internal Organization
   - Several requests for advice on setting up fintech departments for supervision, regulatory sandbox, financial inclusion.
   - Good practice: regular open meetings with fintech companies to showcase products and enhance staff understanding.
4. Cash Currency Management
   - Concerns about cashless trends, SIM-based stored value, CBDC operational gaps.
   - Need for stronger cyber resilience and SOC to monitor systems 24/7/365 if central bank maintains widely accessible backend systems like CBDC.

### Example IMF TA recommendations on central bank risk management, fintech, and cybersecurity
- Selected recommendations (actors and time frames preserved):
  1. Appoint remaining central bank Nonexecutive Board members (and provide support for their nonexecutive responsibilities), in line with IMF Safeguards Recommendations. Actor: [Governor to highlight the necessity]. Time Frame: As soon as possible.
  2. Engage with central bank Nonexecutive Board members on strategic planning (initially, only focusing on strategic risk assessment). Actor: [Governor to highlight the necessity]. Time Frame: After appointment of remaining Nonexecutive Board members.
  3. Prepare for/conduct a Strategic Risk Assessment (SRA), built on Operational Risk Management (ORM) achievements, complete a multilayered perspective to avoid risk blindsides. Actor: Risk Management Department (RMD). Time Frame: 12-18 months.
  4. Develop Enterprise-wide Risk Management (ERM) to strengthen, streamline and integrate oversight and performance. Actor: RMD. Time Frame: 18-24 months.
  5. Integrate Fintech Unit’s (fintech risk) findings within the central bank’s risk management Framework. Actors: RMD, Fintech Unit. Time Frame: 1-6 months.
  6. Enhance fintech governance/compliance research with technologists within the RMD. Actor: RMD. Time Frame: 6-12 months.
  7. Conduct a cybersecurity gap assessment addressing (a) central bank cyber resilience; and (b) early security assurance research/activities for fintech adoption. Actor: RMD. Time Frame: 6-18 months.
- Additional strategic planning, governance, and cyber recommendations include time frames such as 3-6 months, 12-24 months, 12-15 months, 6-12 months, 12-18 months, 18-30 months, 24 months, and ongoing actions as specified in the source.

### COVID-19 impacts on fintech and central bank risk management (summary)
- IMF COVID-19 Special Series Notes: clear risk management framework (including BCM) is prerequisite; central banks must prepare prior to return to work and maintain flexible BCM and health/safety measures.
- Example categories and measures (constraints preserved):
  1. Staff-related: share best practices; cancel onsite supervision; reduce reporting; cross-training complicated in work-at-home.
  2. Board/Management: large-scale issuing of hardware; open IT for remote access; install Citrix/Microsoft Teams/OTP; identify crucial third parties; additional penetration tests; constraint: early-stage support sometimes difficult.
  3. Communication: internal measures to avoid fake news; external proactive communication; constraint: fast-changing news.
  4. Interaction with financial sector: share best practices; recommend moratoria and aligned policies.
  5. IT and cyber-security: monitor central bank VPN 24x7 by cyber security division; constraints: limited telework testing, weak endpoints, phishing increases.
  6. Overall risk management: review legislation and risk appetite; Strategic Risk Assessment to reprioritize objectives; BCM insufficient for extreme scenarios; example: expansion of critical functions from 50 to 300 processes due to an extended 90-day window.
  7. Cash currency management: quarantine banknotes between 7 to 15 days; increase strategic stock of banknotes in branches to 3 months; encourage electronic payments; constraint: cash currency management sensitive for new infections.

### IMF Article IV (AIV) surveillance findings related to technology and fintech
- AIV database: 1,095 unique hits relating to “technology” spanning 1978–2017.
- Average references per year by period shown in source figure: 9.3 (1978-1990), 2.63 (1991-2000), 3.97 (2001-2010), 44 (2011-2017).
- Post-2011 period shows the bulk of attention to technology-related issues in AIVs.
- For January 2018–February 2019, fintech discussions were mostly classified as “substantive discussions.”
- Geographical distribution: 1978–2017 attention centered on AFR and EUR; January 2018–February 2019 focus moved to APD and to a lesser extent WHD.
- Cybersecurity explicit references: out of 1,095 hits, only three AIVs had explicit references to cybersecurity (all after 2015), noting resilience to cyber-attacks and the Bangladesh Bank cyber heist.

### IMF FSAP findings on fintech, risks, and risk management (selected)
- Switzerland FSAP (2019): “risks in the rapidly growing fintech space may not be well understood due to data gaps, resource constraints, and the authorities’ liberal approach.” Recommends addressing data collection, analytical capacity, and resources.
- Singapore FSAP (2019): fintech brings opportunities and new risks; operational and technology-related risks; cautions on reputational risk from sandbox.
- Canada FSAP (2020): proactive monitoring, fintech research, retail payments oversight framework work, examination of open banking, establishment of “Heads of Agencies Crypto-Asset Working Group.”
- Korea FSAP (2020): benefits possible but warns of increasing interconnectedness and complexity, operational risk increases, negative impact on incumbents’ profitability.

### Central bank risk themes tied to fintech and cybersecurity
- Key themes: legacy IT systems; third-party involvement (cloud computing); identified nonfinancial risks: operational, reputational, legal; need for sufficient resources and strategic planning.
- Recommendation: ensure integrated fintech and cybersecurity analysis through the lens of central bank risk management.

### Examples of fintech impacts on central bank functions
- Fintech affects monetary policy, payments systems regulation, operations and oversight, financial supervision and financial stability, cash currency management, reserve management, financial integrity, and financial inclusion.
- Central bank risks categorized: strategy and policy risk; financial risk; operational risk; reputational risk.

A. Monetary Policy & Operations
- CBDC opportunities identified: increase effectiveness of monetary policy transmission; increase seigniorage income; facilitate cross-border payments.
- Wholesale CBDC: facilitate wholesale payments or improve RTGS effectiveness.
- Risks: foreign CBDCs and Global Stable Coins (GSC) could “raise pressures for currency substitution and worsen vulnerabilities from currency mismatches,” reduce ability of local authorities to run monetary policy, and “facilitate illicit flows and make it harder for regulatory authorities to enforce exchange restrictions and capital flow management measures.”
- Other issues: access to central bank money, provision of credit facilities, collateral and prefunding arrangements, operational risk considerations (examples: Bank of England’s access provision to TransferWise).

B. Financial Market Infrastructures (FMIs)
- FMIs are critical for clearing, settlement, and recording transactions but can pose significant systemic risks.
- PFMI (2012) identifies and mitigates risks related to systemic FMIs.

### Box 1 — Distributed Ledger Technology (DLT): overview and risks
- DLT can enhance payment systems by integrating settlement accounts and ledgers; central banks have run DLT experiments (examples listed in source).
- Key risks: liquidity risk; credit risk; transaction delay risk; settlement finality risk; counterparty risk; operational risks including cyber incidents.
- Operational requirements: faster real-time environment requires “very fast and highly automated error-handling processes,” improved monitoring, and error-correction solutions.
- Cyberattacks could compromise confidentiality, availability, integrity, affect settlement finality rules and recovery time objectives.
- Central banks must factor faster operational environments, automated error-handling, monitoring systems, and preparedness for cyber incidents.

### Box 2 — Cloud Computing: definition, models, benefits, and risks
- Cloud computing definition (verbatim): “off-premise, on-demand computing where the end-user is provided applications, computing resources, and services (including operating systems and infrastructure) by clouds service provider via the internet.”
- Deployment types: Public cloud; Private cloud; Hybrid cloud; Community cloud.
- Service models: IaaS; PaaS; SaaS.
- Major providers: Big Four: AWS (Amazon), IBM, Microsoft, and Alphabet (Google) — raises systemic/provider-concentration questions.
- Benefits: scalability, elasticity, potential business continuity improvements, cost reduction, essential for fintech services.
- Key risks and legal considerations: ambiguity around liability, security, privacy, data-location legal variations; shift from “perimeter” to “data protection”; need for legal arrangements, assurance/audit access, business continuity, stakeholder involvement.
- Related fintech technology risks summarized: Open banking/APIs, Big data, Open-source software, DLT and smart contracts, reported digital currency laundering example: “Supposedly, US$1.2 billion was laundered through the use of tumblers in 2018.”
- AI/ML risks: bias, adversarial inputs, black-box problem; necessitate transparency and novel security modeling.

### Implications for central bank governance and organization
- Risk governance and an operationally effective risk management unit are prerequisites for managing fintech risks.
- Many central banks lack staff with right skill sets; supervisory frameworks need alignment.
- Training initiatives and selective external expertise recommended (e.g., TA from IMF/WB, peer review from IORWG, BIS Innovation Hubs).

### Five key recommendations for central banks (verbatim emphasis retained)
1) Ensure the central bank has a dedicated, independent risk management function:
   - Establish a risk management function independent of business departments and internal audit.
   - Integrate transversal second line of defense risks (operational, compliance, data protection, IT/cyber).
   - Develop a clearly articulated and communicated risk event escalation matrix.
   - Conduct a Strategic Risk Assessment (SRA) to inform strategic planning and resource prioritization.
   - Liaise with organizations such as the IMF and the IORWG to incorporate best practices, including Enterprise-wide Risk Management (ERM).

2) Ensure updated fit and proper requirements, and facilitate (ongoing) training of central bank staff and key decision-makers on relevant fintech issues:
   - Keep staff and decision-makers up to date with fast-paced fintech developments.
   - Provide fintech training for nonexecutive decision-makers to support strategy-setting and oversight.

3) Have clear reporting lines on fintech-issues to central bank decision-makers:
   - Avoid overly bureaucratic or complicated reporting that creates information asymmetries or bottlenecks.
   - Find balance to ensure identification, mitigation, reporting, and monitoring without duplication.

4) Ensure an integrated fintech approach involving business departments and lines of control:
   - Promote close cooperation between business departments (notably financial supervision), organizational departments (HR, BCM, IT/cybersecurity), and lines of control (risk management, internal audit).
   - Integrate fintech approach into mid- to long-term strategic planning.

5) Improve cyber resilience and security posture of central bank infrastructure, procedures, technologies, and skillset:
   - Conduct a security posture assessment (preferably by an independent third-party specialist) to identify gaps.
   - Measure cyber resilience by maturity of internal processes such as asset, change, configuration, risk, external dependency, and vulnerability management.

### Practical risk-management guidance
- Risk management function should map fintech and cybersecurity risks to central bank functions and organization, identify relevant technologies ex ante, and produce a basic risk matrix.
- Consider external expertise for pre-identified areas within specified timeframes (TA, peer review, bilateral feedback, international organizations).

### APPENDIX II — Case examples (selected highlights)

A. Indonesia
- Transaction value grew by 18.3 percent from US$22.4 billion in 2018, to a predicted value of US$26.5 billion in 2019—most of which (95.67 percent) comes from digital payments.
- Number of fintech players grew from 140 players by 2016, to 189 players by February 2019.
- 34 percent of players focused on payment systems.
- BI established a fintech function under the Payment System Department with nine full time employees.
- Sandbox: participation limited to six months, extendable for another six months; registration at BI required; crypto-currencies not legal tender; fintech payment systems must register and comply with AML/CFT Act.

B. Luxembourg
- No separate fintech unit; fintech dealt across departments.
- Risk Prevention Unit acts as second line of defense covering ORM, BCM, and information security.
- BCL does not yet use fintech in supervisory tasks or use cloud services.
- Planned fintech contributions include advanced GRC solutions, real-time risk information, continuous monitoring, and fraud detection/data-mining applications.
- Identified challenges: availability of suitable data; data silos; informal knowledge; transparency and ethics.

C. Sierra Leone
- BSL Regulatory Sandbox enables live testing of fintech products; licenses issued for twelve months.
- Sandbox Steering Committee includes Banking Supervision, Other Financial Institutions Supervision, Financial Stability, Legal Affairs, and Financial Inclusion Unit.
- Risk management unit not currently a member of Committee; participant obligations include Fit and Proper assessments, service-provider agreements, customer disclosure, and customer consent for personal data use.
- Monitoring tracker and testing plan assess test failures, fintech developments, control boundaries, data security, KYC, and AML/CFT safeguards.

D. Ukraine (E-hryvnia pilot)
- NBU implemented a retail CBDC pilot “E-hryvnia” in 2018 with limited issuance and testing via web-wallets and mobile apps.
- Pilot analyzed models and chose a centralized model for simplicity and transparency.
- World Bank estimation: 37 percent of adults in Ukraine do not have a bank account.
- Pilot noted potential to compete with payment cards and electronic money; limited pilot size constrained demand assessment.
- Concerns: significant investments/time to modernize payment infrastructure; legal uncertainty requires legislative amendments.
- Use cases considered: retail cashless payments (P2P, P2B); social welfare payments (G2P); securities settlements (B2B); wholesale settlements (B2B); cross-border settlements (B2B, P2P, P2B); interest bearing instrument (not as means of payment).
- NBU initiated in December 2020 a Survey on Potential Demand and Consumer Motivations with 30 questions addressed to six target groups; Draft Law of Ukraine on Payment Services includes CBDC definition and changes to NBU functions; draft law under revision and voting expected in 2021.

*Source: wpiea2021105-print-pdf - Appendix II (pages 60–71)*

### Appendix II 60–71

### Appendix II (pages 60–71)

### Central theme: Fintech, cybersecurity, and nonfinancial risk in central banks
- Central banks have undergone an expansion of the risks they run, including financial risks from policy decisions (for example, asset purchase operations that have significantly expanded the balance sheets of central banks in the United States, the United Kingdom, the European Union, and Japan).
- Beyond financial risks, central banks also run nonfinancial risks: strategy and policy risks, operational risks, and reputational risk.
- Nonfinancial risk management of central banks has traditionally received less attention than financial risk management, in part because mandates, objectives, and functions were more limited before the Global Financial Crisis (GFC), after which mandates expanded beyond price stability.
- Recent topics—climate change, economic development/employment, financial inclusion, and fintech—have increased central banks’ roles and elevated their nonfinancial risk exposure.
- The paper focuses on central bank nonfinancial risks specifically related to technological innovations dubbed “fintech,” and the related area of cybersecurity, emphasizing that fintech's potential upsides must be weighed against guaranteed downsides of cyber risks when achieving multiple central bank objectives.

### Evidence base and sources analyzed
- The analysis draws on:
  - Findings from nine (9) central bank technical assistance (TA) cases from the IMF’s Monetary and Capital Markets Department (MCM, Central Bank Operations Division) and Information Technology Department (ITD, Digital Advisory Unit);
  - Findings from four (4) country cases: Indonesia, Luxembourg, Sierra Leone, and Ukraine;
  - Informal interactions on fintech with heads of risk management departments of several central bank members of the International Operational Risk Working Group (IORWG);
  - Participation in the EU’s Fintech Risk Management Project;
  - Findings from the IMF’s Article IV (AIV) database and from selected Financial Sector Assessment Programs (FSAP).

### Analytical focus and structure of the content unit
- Section II: Definition and overview of “fintech” and related developments relevant for central bank risk management.
- Section III: Examination of the extent to which IMF technical assistance by MCM Central Bank Operations and ITD/Digital Advisory, and IMF surveillance, have covered links between central bank risk management, fintech, and cybersecurity.
- Section IV: Detailed analysis of how specific fintech developments affect central bank risk management, focusing on strategy and policy risk and on operational risk.
- Section V: Conclusions and recommendations for central banks to consider.
- Appendix I: Lists relevant risk management details of the Bali Fintech Agenda (BFA).

### Key implications for central bank risk management (as presented)
- Fintech developments and cybersecurity materially strengthen the need for enhanced central bank risk management.
- Central banks need to carefully consider the interplay between:
  - the possible upsides of fintech (including new services, inclusion efforts, and efficiency gains), and
  - the guaranteed downsides of cyber risks (which can amplify operational, reputational, and policy-related risks).
- The widening remit of central banks into areas overlapping with fiscal authorities increases exposure to nonfinancial risks tied to newer policy domains.

*Source: wpiea2021105-print-pdf - Appendix II 60–71*

### Appendix II provides several country case examples.

### wpiea2021105-print-pdf - Appendix II provides several country case examples.

### Fintech: definition and major enabling technologies
- Bali Fintech Agenda (BFA) definition: fintech relates to “the advances in technology that have the potential to transform the provision of financial services spurring the development of new business models, applications, processes, and products.”4F5
- FSB definition: “technologically enabled innovation in financial services that could result in new business models, applications, processes or products with an associated material effect on financial markets and institutions and the provision of financial services.”
- Common enabling technologies emphasized:
  - Big data on individuals and firms
  - AI/ML
  - Computing power (distributed computing)
  - Cryptography
  - Mobile access internet
  - Resulting applications span payments, financing, asset management, insurance, and advice.

### BFA Principles relevant to central bank risk management
- Principle IX (Ensure the Stability of Domestic Monetary and Financial Systems): fintech “offers central banks the opportunity to explore new services, while having to consider new risks.” Focus areas include CBDC, payment systems, financial stability, and lender-of-last-resort aspects.
- Principle X (Develop Robust Financial and Data Infrastructure to Sustain Fintech Benefits):
  - Stresses effective governance structures and risk-management processes.
  - Highlights new operational risks and increased interdependencies among service providers.
  - Notes outsourcing and third-party service providers that “fall outside the regulatory perimeter,” requiring emphasis on outsourcing arrangements and potentially a vendor risk management framework.
- Principles IX and X are framed around financial institutions but “the risk management aspects of the principles hold for central banks to a large extent as well.”

### IMF involvement modalities and scope
- Three IMF modalities addressing fintech, cybersecurity, and central bank risk management:
  - Technical Assistance (TA)
  - Article IV (AIV) surveillance discussions
  - Financial Sector Assessment Program (FSAP)
- TA focus (2018–2020): central bank risk management, governance, internal organization, cash currency management, and cybersecurity/digital advice.

### Technical Assistance (TA) findings and common country requests (2018–2020)
- Regional and topic distribution (2018–2020):
  - Most TA and informal interactions: European and Middle East and Central Asia regions.
  - Main topics: (1) central bank risk management (including Business Continuity Management, BCM), (2) fintech organization (setting up fintech units), (3) central bank cybersecurity, (4) digital payments in context of risk/cash currency management (in two cases).
- Main fintech issues raised in TA:
  1. Risk Management
     - Many central bank risk management departments were not fully aware of emerging fintech risks (example: cloud computing).
     - Benefit from closer cooperation among (i) IT department, (ii) fintech department, and (iii) financial supervision department.
     - TA shared experience on setting up Security Operation Centers (SOC) and conducting cybersecurity assessments (red, blue, purple teaming).
  2. Decision-making
     - Senior management and Board often not fully informed on fintech and cybersecurity and their link to strategic planning and risk appetite.
     - In three cases decision-making body was not at full strength, with nonexecutive Board positions unfilled.
     - Internal silos observed: fintech reporting to one decision-maker, risk management to another, with poor information-sharing.
  3. Internal Organization
     - Several requests for advice on setting up fintech departments; purposes varied (supervision, regulatory sandbox, financial inclusion).
     - Good practice: regular open meetings with fintech companies to showcase products and enhance staff understanding.
     - Cooperation with other agencies and donors (UN, World Bank) provided useful training.
  4. Cash Currency Management
     - Concerns about moving toward cashless society and digital payments (examples: SIM-based stored value, CBDC operational gaps).
     - Identified need for stronger cyber resilience and SOC to monitor systems 24/7/365, especially if central bank maintains backend core-system for widely accessible services like CBDC.

### Example IMF TA recommendations on central bank risk management, fintech, and cybersecurity (anonymized)
- Selected recommendations (Table 1 summary with actors and time frames preserved):
  1. Appoint remaining central bank Nonexecutive Board members (and provide support for their nonexecutive responsibilities), in line with IMF Safeguards Recommendations. Actor: [Governor to highlight the necessity]. Time Frame: As soon as possible.
  2. Engage with central bank Nonexecutive Board members on strategic planning (initially, only focusing on strategic risk assessment). Actor: [Governor to highlight the necessity]. Time Frame: After appointment of remaining Nonexecutive Board members.
  3. Prepare for/conduct a Strategic Risk Assessment (SRA), built on Operational Risk Management (ORM) achievements, complete a multilayered perspective to avoid risk blindsides. Actor: Risk Management Department (RMD). Time Frame: 12-18 months.
  4. Develop Enterprise-wide Risk Management (ERM) to strengthen, streamline and integrate oversight and performance. Actor: RMD. Time Frame: 18-24 months.
  5. Integrate Fintech Unit’s (fintech risk) findings within the central bank’s risk management Framework. Actors: RMD, Fintech Unit. Time Frame: 1-6 months.
  6. Enhance fintech governance/compliance research with technologists within the RMD. Actor: RMD. Time Frame: 6-12 months.
  7. Conduct a cybersecurity gap assessment addressing (a) central bank cyber resilience; and (b) early security assurance research/activities for fintech adoption. Actor: RMD. Time Frame: 6-18 months.

- Selected recommendations (Table 2 summary on strategic planning, risk management, and cybersecurity):
  1. Appoint central bank nonexecutive members (and provide support for their nonexecutive responsibilities), in line with IMF Safeguards Recommendations. Actor: [Governor to highlight the necessity]. Time Frame: [asap].
  2. Adjust the Strategic Objectives to express how the central bank intends to deliver the priorities in the Strategic Plan; undertake a thorough review of the strategy planning and monitoring procedures. Actor: Governor (sponsor), RMD. Time Frame: 3-6 months and 12-24 months (two-stage timing preserved).
  3. Have the central bank’s nonexecutive Board members monitor implementation of the Strategic Plan at a sufficient frequency and depth. Actor: Board. Time Frame: Ongoing (after appointment).
  4. Develop a Risk Management Framework and Risk Appetite. Actor: RMD. Time Frame: 12-15 months.
  5. Ensure empowerment and presence of the risk management function, including monitoring strategic plan progress and risks, and mandatory participation in the central bank’s key forums. Actors: Governor (sponsor), RMD. Time Frame: Ongoing.
  6. Create further awareness of risk management and of the departmental risk champions. Actor: RMD. Time Frame: Ongoing.
  7. Conduct a Risk Control Self-Assessment (RCSA) of processes. Actor: RMD. Time Frame: 6-12 months.
  8. Set up the incident registration process. Actor: RMD. Time Frame: 12-18 months.
  9. Incentivize risk management research and benchmarking. Actor: RMD. Time Frame: Ongoing.
  10. Strengthen the cyber resilience and security posture. Actors: RMD, IT Department (ITD). Time Frame: 24 months.
  11. Build and launch the Security Operations Center (SOC) capabilities and perform periodic evaluation exercises. Actors: RMD, ITD. Time Frame: 18-30 months.
  12. Enhance cybersecurity risk management and security assurance activities during the evaluation, development or acquisition of new and existing information technology projects and systems. Actors: RMD, ITD. Time Frame: Ongoing.
  13. Adopt a cloud computing strategy. Actors: RMD, ITD. Time Frame: 24 months.

### COVID-19 impacts on fintech and central bank risk management (summary of Table 3)
- IMF COVID-19 Special Series Notes emphasize a clear risk management framework (including BCM) as a prerequisite; central banks must prepare prior to return to work and maintain flexible BCM and health/safety measures.
- Example categories and measures (constraints preserved):
  1. Staff-related measures
     - Identify and share best practices with financial institutions; cancel onsite supervision; reduce reporting requirements; recommend compliance with government measures; cross-training of staff complicated in working-at-home environment (suggestion: have junior staff listen in on selected technical discussions).
  2. Board/Management involvement
     - Large-scale issuing of hardware (laptops); opening IT systems for remote access; installing additional software (Citrix, Microsoft Teams, OTP); identify crucial third parties (especially for cloud computing and IT infrastructure); draft basic telephone lists; additional penetration tests.
     - Constraint: Support from Board or Management at early stage sometimes difficult as COVID-19 effects not fully clear.
  3. Communication
     - Internal: avoid fake news, boost morale (videos/messages by Governor/Board), provide health care info, clear feedback. External: public communication and sharing with stakeholders. Constraint: Difficult to keep up with continuously changing news; need to be proactive, fast, and accurate.
  4. Interaction with financial sector
     - Share best practices; cancel onsite supervision; reduce reporting requirements; recommendations aligned with government measures (moratory of payments, dividend policy).
  5. IT and cyber-security
     - Large-scale issuing of hardware; open systems for remote access; install Citrix/Microsoft Teams/OTP; identify crucial third parties; basic telephone lists; additional penetration tests; increased staff awareness (phishing); Central bank VPN monitored 24x7 by cyber security division.
     - Constraints noted: Almost no central bank had deployed or tested telework at large-scale; cyber risk biggest concern, weak endpoints (private laptops), limited data-protection; phishing attacks increasing; unclear mid- to long-run IT infrastructure support.
  6. Overall risk management
     - Examine legislation sufficiency; increase monetary policy risk tolerance; review risk appetite; strategic risk assessment to reprioritize objectives; expand RMD role in collecting bank-wide information; BCM planning found insufficient for extreme scenarios; enhanced assessment of critical functions (example: expanded from 50 to 300 processes due to an extended 90-day window); extension of BCM scope; develop new internal risk templates to minimize administrative burden.
     - Constraints: Legal and reputational risks from additional policy measures and changed public opinion.
  7. Cash currency management
     - Minimize interpersonal contacts via shifts and distancing; quarantine banknotes between 7 to 15 days; limited interaction with financial institutions for cash deliveries; increase strategic stock of banknotes in branches to 3 months; encourage electronic payments (reduce/eliminate fees during crisis).
     - Constraint: Cash currency management is most sensitive area for new COVID-19 central bank infections.

### IMF Article IV (AIV) surveillance findings related to technology and fintech
- AIV database: 1,095 unique hits relating to “technology” spanning 1978–2017.
- Average references per year by period (1978–2017): shown in Figure 4 with period averages listed as 9.3 (1978-1990), 2.63 (1991-2000), 3.97 (2001-2010), 44 (2011-2017) — these values are presented in the source figure.
- Post-2011 period shows bulk of attention to technology-related issues in AIVs.
- For January 2018–February 2019, fintech discussions were mostly classified as “substantive discussions” (Figure 5).
- Geographical distribution:
  - 1978–2017: attention predominantly centered on AFR and EUR (Figure 7).
  - January 2018–February 2019: focus moved to APD and to a lesser extent WHD.
- AIV technology references are broader than current fintech scope and include:
  - General investment/FDI policies
  - Agricultural technology and other application areas
  - Fiscal technology to improve fiscal operations
  - Subsets relevant to central bank risk management: information and communication technology, financial inclusion technology, digital development strategies, telecommunications development, occasional explicit “fintech” and “regtech” references, and cybersecurity.
- Cybersecurity in AIVs: out of 1,095 hits, only three AIVs had explicit references to cybersecurity (all after 2015), highlighting resilience to cyber-attacks and referencing the Bangladesh Bank cyber heist.
- Recent AIV fintech discussions noted links between digital payments and financial inclusion (examples cited in source: Cambodia, Peru, Tuvalu) and frameworks for crypto-assets and digital currencies in small states (examples cited in source: RMI, Curacao and Sint Maarten). Fintech has also arisen in contexts such as China’s fintech industry and development of fintech hubs (Hong Kong SAR, Singapore).
- Note: the source also highlights links between finance/technology and climate change risks in several AIV cases.

*Source: wpiea2021105-print-pdf - Appendix II provides several country case examples.*

### references

### wpiea2021105-print-pdf - references

### IMF attention in AIVs: outsourcing, operational risk, and cybersecurity
- IMF AIV database entries (14F 15) frequently relate to risk management in the context of operational risk for financial sector oversight (financial supervision).
- Outsourcing by financial institutions raises concerns about third-party risk; outsourcing aspects of governmental services (including outsourcing of supervisory functions and “e-government”) are often discussed with emphasis on cost-efficiency and higher operational efficiency rather than explicit risk identification.
- Specific attention exists for central bank risks related to IT, operational risks for Financial Market Infrastructures (FMIs), and setting up and maintaining infrastructure for RTGS systems.
- Central bank-related cybersecurity risks emerged more recently: several AIV cases, predominantly after 2015, refer to “cyber” issues, including initiatives to reinforce central bank cyber-security following the Bangladesh Bank “cyber-heist” in February 2016.
- IMF staff recognize opportunities and risks from technological developments (IT, financial inclusion technology, digital development strategies, telecommunications development, initial “fintech” activities), noting that “advances in AI, digital identification and cybersecurity are enabling new models for managing risk for individuals, financial institutions, and regulators.”15F16
- Substantive discussions on fintech in AIVs are increasingly common; authorities are advised to prepare for these discussions.

### IMF FSAP findings on fintech, risks, and risk management
- IMF FSAPs show increasing attention to links among risk management, fintech, and cybersecurity.
- Switzerland FSAP (IMF, 2019, Switzerland Financial Sector Assessment Program. IMF Country Report No. 19/183, June 2019) finds that “risks in the rapidly growing fintech space may not be well understood due to data gaps, resource constraints, and the authorities’ liberal approach.” It recommends addressing data collection, analytical capacity, and resources for fintech-related challenges to inform development of fintech-related policies and legislation.
- Singapore FSAP (IMF, 2019, Singapore Financial Sector Assessment Program Technical Note – Fintech: Implications for the Regulation and Supervision of the Financial Sector) notes fintech brings opportunities and new risks for clients, financial institutions, and the financial system; highlights operational and technology-related risks, legacy systems, and increasing reliance on third-party service providers. It cautions that operating a fintech sandbox entails reputational risk that “needs to be monitored” and stresses balancing innovation benefits against downside risks.
- Canada FSAP (IMF, 2020, Canada Financial Sector Assessment Program Technical Note – Oversight of Financial Market Infrastructures and Fintech Development) reports proactive monitoring of fintech developments, fintech research to assess impacts on the financial system and the Bank of Canada’s core functions, work on a new retail payments oversight framework, examination of open banking possibilities, and establishment of a “Heads of Agencies Crypto-Asset Working Group” to coordinate monitoring of crypto-assets and develop a consistent domestic regulatory framework.
- Korea FSAP (IMF, 2020, Republic of Korea Financial Sector Assessment Program Technical Note – Technological Change, Legal Frameworks, and Implications for Financial Stability) notes that significant benefits can still be reaped from innovation even in advanced financial sectors, but warns that “new risks could arise in time, such as increasing interconnectedness and complexity in the financial sector, the introduction of greater operational risk, and negative impact on the profitability of incumbent banks.”
- Figure 8 (schematic overview) summarizes attention for fintech in selected FSAPs and their focus on risks and risk management-related areas.

### Central bank risk themes tied to fintech and cybersecurity
- Key themes central banks should address:
  - Legacy (IT) systems.
  - Involvement of third parties (for instance, cloud computing—see Section IV.H and Box 2).
  - Identified nonfinancial risks: operational, reputational, and legal risk.
  - Need for sufficient resources requiring proper strategic planning by the central bank.
- Recommendation: ensure an integrated fintech and cybersecurity analysis through the lens of central bank risk management because many risks overlap.

### Examples of fintech impacts on central bank functions
- Fintech affects multiple central bank functions: monetary policy, payments systems regulation, operations and oversight, financial supervision and financial stability functions (macroprudential oversight, resolution, ELA/LOLR), cash currency management, reserve management, financial integrity, and financial inclusion.
- Central bank risks categorized (Figure 9):
  - Strategy and policy risk (from central bank strategy and policies).
  - Financial risk (from financial operations).
  - Operational risk (IT infrastructure, cybersecurity, outsourcing, governance, processes).
  - Reputational risk (resulting from other risks materializing).

A. Monetary Policy & Operations
- IMF staff identify fintech-related opportunities, particularly CBDC, including:
  - Increase effectiveness of monetary policy transmission.
  - Increase seigniorage income for central banks.
  - Facilitate cross-border payments.21F22
  - Wholesale CBDC: facilitate wholesale payments or improve RTGS effectiveness.
- CBDCs may be designed with attributes like cash or deposits, and could be interest-bearing.22F23
- Risks from digital money across borders: foreign CBDCs and Global Stable Coins (GSC) could “raise pressures for currency substitution and worsen vulnerabilities from currency mismatches,” reduce ability of local authorities to run monetary policy, and “facilitate illicit flows and make it harder for regulatory authorities to enforce exchange restrictions and capital flow management measures.”23F24
- Other monetary policy issues: access to central bank money, provision of credit facilities, collateral and prefunding arrangements, operational risk considerations (examples: Bank of England’s access provision to TransferWise; access to non-bank switching company in Australian National Payment Platform).

B. Financial Market Infrastructures (FMIs)
- FMIs facilitate clearing, settlement, and recording of monetary and other financial transactions and play a critical role in financial stability.
- FMIs can also “pose significant risks to the [financial system]” given their systemic role.
- The 2012 Committee on Payments Market Infrastructures Principles for Financial Markets Infrastructures (PFMI) were drafted to identify and mitigate risks related to systemic FMIs.25F26

*Source: wpiea2021105-print-pdf - references*

### Box 1. Distributed Ledger Technology

### Box 1. Distributed Ledger Technology

### Overview
- Distributed Ledger Technology (DLT) is a possible platform for enhancing payment systems by integrating and reconciliating settlement accounts and ledgers.
- Various central banks have conducted DLT research (and experiments with large-value interbank payments) to examine benefits, risks, limitations, and implementation challenges of DLT in the context of payments and settlements. This includes Brazil, Canada, the Euro area/Japan, Singapore, South Africa, and Thailand.
- Some central banks and private sector participants have also examined DLT for cross-border payments.

### Key risks for payments and settlements
- Identified risk categories include:
  - liquidity risk
  - credit risk
  - transaction delay risk
  - settlement finality risk
  - counterparty risk
  - operational risks (including cyber risk incidents)
- Operational risk context and requirements:
  - Even though these operational risks are not different from the standard computerized processing, it is the faster (real-time) environment that requires “very fast and highly automated error-handling processes to limit the volume of transactions affected by operational errors.”
  - This requirement “calls for improved monitoring systems and error-correction solutions.”
  - Cyberattacks could “compromise data confidentiality, service availability, and systems integrity (...) [and] also affect established settlement finality rules and recovery time objectives.”

### Implications for central bank risk management
- The potential benefits of DLT therefore require careful consideration from a (central bank) risk management perspective.
- Central banks evaluating DLT must factor in the faster, real-time operational environment and the consequent need for:
  - very fast and highly automated error-handling processes
  - improved monitoring systems
  - robust error-correction solutions
  - preparedness for cyber incidents that could affect confidentiality, availability, integrity, settlement finality, and recovery objectives

*Source: Shabsigh, G., T. Khiaonarong, e.a., 2020, Distributed Ledger Technology Experiments in Payments and Settlements, IMF Fintech Note. Washington, D.C.: International Monetary Fund.*

### Box 2. Cloud Computing

### Box 2. Cloud Computing

### Definition and deployment models
- Cloud computing definition (verbatim): “off-premise, on-demand computing where the end-user is provided applications, computing resources, and services (including operating systems and infrastructure) by clouds service provider via the internet.”
- Four cloud deployment types:
  - Public cloud: the physical infrastructure is located at the third party’s premises. This implies that the user has no clarity regarding the location.
  - Private cloud: specifically designed for the user. A private cloud does not need to be located at the user’s location; it could also be hosted externally. The infrastructure is dedicated for the specific user only, and is not shared with other organizations.
  - Hybrid cloud: a mix with private components (critical, secure applications hosted in a private cloud) and public components (hosted in a public cloud). Linked to “cloud bursting,” where an organization uses its own infrastructure for normal use but allows excessive data use and/or storage to overflow to a public cloud.
  - Community cloud: the cloud infrastructure is shared between two or more organizations in the same community. Some central banks are exploring a private cloud shared between themselves.

### Service models (three)
- Infrastructure as a service (IaaS): the cloud provider offers computer resources such as virtual servers, network devices and storage. This service model requires more involvement of the client to manage their network and servers.
- Platform as a service (PaaS): the cloud provider offers a platform for clients to develop and host applications. This service model requires less client involvement since the cloud provider manages the backend virtual servers and network.
- Software as a service (SaaS): the cloud provider offers the application and manages the virtual servers and networks. This requires much less involvement and management from clients since the cloud provider manages the environment and develops and maintains the offered applications.

### Major providers and systemic questions
- The major cloud providers world-wide are the so-called Big Four: AWS (Amazon), IBM, Microsoft, and Alphabet (Google), raising additional questions on the systemic nature of these providers, and whether more direct oversight would be warranted.

### Benefits for fintech and central banks
- Cloud computing provides scalability, elasticity and has the potential to improve business continuity and reduce overall costs.
- Cloud computing may reduce operational risks for central banks struggling with on-premise development and maintenance of hardware, software, and infrastructure which comes with substantial operational burden and risk.
- Cloud computing is an essential component for fintech services to flourish.

### Key risks, operational and legal considerations
- Leveraging and managing the cloud without careful planning and design security may complicate central bank infrastructure and raise ambiguity around liability, security, privacy, and legal regulations on sensitive data that may vary by geographical location.
- Security industry shift: from “perimeter” to “data protection.”
- External dependencies: central banks should strengthen management of external dependencies as the pool of cloud providers and vendors expands; central banks might have even more at stake—including critical infrastructure.
- Legal arrangements: establish clear legal arrangements with third party (including cloud) providers that define responsibilities distinctly to facilitate transparency and accountability.
- Assurance and audit: include appropriate means for the central bank to get frequent reassurance and audit attestation of third party and cloud providers’ systems, procedures, and infrastructure.
- Business continuity: equip central banks with appropriate business continuity plans to address data portability and continuity of the central bank’s services.
- Stakeholder involvement: demand more involvement among central bank stakeholders in early stages of solution design and requirement gathering, with emphasis on threat modeling and early risk management.

### Related fintech technology risks (summarized)
- Open banking / APIs: can increase market competition and resilience but may exacerbate digital risks (e.g., brute-force attacks, credential stuffing, parameter manipulation, data harvesting) and require rigorous assurance, stronger authentication, and robust risk management.
- Big data: offers real-time analysis potential but introduces risks in data management, transmission, access control, coverage biases, data inaccuracy, attractiveness to hackers, and security/usability trade-offs.
- Open-source software: enables innovation but requires continuous security patching; vulnerabilities and their remediation timelines vary across projects and can pose risks to central banks.
- Distributed Ledger Technologies (DLT) and smart contracts:
  - DLT provide features like consensus and immutability, and can address double-spending, but are not secure-by-default and remain vulnerable to software bugs and architecture flaws (e.g., 51 percent attack).
  - Encryption key management is critical for DLT-based systems.
  - Immutability may be problematic if transactions need reversing.
  - Smart contracts and DeFi can amplify consequences of security flaws; immutability of deployed source-code can negatively impact central banks if exploited.
- Digital currency laundering risk example: “Supposedly, US$1.2 billion was laundered through the use of tumblers in 2018.”
- AI/ML: efficiency and automation potential, but bias risks based on algorithms and training data, adversarial input vulnerabilities, and the black-box problem necessitate enhanced transparency and novel security modeling.
- Cybersecurity: fintech expands entry points and third-party reliance, increasing cyber risk exposure for financial institutions and central banks.

### Implications for central bank governance and organization
- Central bank risk governance and having an operationally effective risk management unit are prerequisites for managing fintech-related risks.
- Many central banks lack staff with the right skill sets for fintech developments; supervisory frameworks and capacities need alignment with the evolving financial landscape.
- Examples of training initiatives include the European Commission Horizon2020 program facilitating technical training for central banks/supervisors.
- Central banks should avoid overcomplicating reporting lines and should ensure clear reporting on fintech issues to decision-makers.
- Central banks should balance reducing external dependencies with selectively seeking external fintech and cybersecurity expertise (e.g., TA from IMF or WB, peer review from IORWG, BIS Innovation Hubs).

### Five key recommendations for central banks (verbatim emphasis retained)
1) Ensure the central bank has a dedicated, independent risk management function:
   - Establish a risk management function independent of business departments and internal audit.
   - Integrate transversal second line of defense risks (operational, compliance, data protection, IT/cyber).
   - Develop a clearly articulated and communicated risk event escalation matrix.
   - Conduct a Strategic Risk Assessment (SRA) to inform strategic planning and resource prioritization.
   - Liaise with organizations such as the IMF and the IORWG to incorporate best practices, including Enterprise-wide Risk Management (ERM).

2) Ensure updated fit and proper requirements, and facilitate (ongoing) training of central bank staff and key decision-makers on relevant fintech issues:
   - Keep staff and decision-makers up to date with fast-paced fintech developments.
   - Provide fintech training for nonexecutive decision-makers to support strategy-setting and oversight.

3) Have clear reporting lines on fintech-issues to central bank decision-makers:
   - Avoid overly bureaucratic or complicated reporting that creates information asymmetries or bottlenecks.
   - Find balance to ensure identification, mitigation, reporting, and monitoring without duplication.

4) Ensure an integrated fintech approach involving business departments and lines of control:
   - Promote close cooperation between business departments (notably financial supervision), organizational departments (HR, BCM, IT/cybersecurity), and lines of control (risk management, internal audit).
   - Integrate fintech approach into mid- to long-term strategic planning.

5) Improve cyber resilience and security posture of central bank infrastructure, procedures, technologies, and skillset:
   - Conduct a security posture assessment (preferably by an independent third-party specialist) to identify gaps.
   - Measure cyber resilience by maturity of internal processes such as asset, change, configuration, risk, external dependency, and vulnerability management.

### Practical risk-management guidance
- The central bank risk management function should map fintech and cybersecurity risks to specific central bank functions and internal organization, ex ante identify relevant technologies, and produce a basic risk matrix to inform management and business departments.
- Consider external expertise in pre-identified areas and within specific timeframes (e.g., TA, peer review, bilateral feedback, international organizations).

*Source: IMF staff (Box 2, “Cloud Computing”), wpiea2021105-print-pdf.*

### APPENDIX I. BALI FINTECH AGENDA

### APPENDIX I. BALI FINTECH AGENDA

### Principle IX: Ensure the Stability of Domestic Monetary and Financial Systems
- Explore applications of fintech innovations to central banking services, while safeguarding financial stability, expanding if needed safety nets and ensuring effective monetary policy transmission.
- Rapid fintech developments are reshaping financial markets and their structures. Fintech is progressively blurring the boundaries between intermediaries and markets, as well as between digital service providers moving into the financial space, nonbank financial companies, and banks. These developments could affect central banks’ capacity to implement monetary policy and the ability of supervisory agencies to safeguard financial stability, raising both challenges and opportunities.
- The potential impact of fintech on monetary transmission and the effectiveness of policy needs further consideration. In many countries, monetary policy is transmitted by changing the marginal price of liquidity—central bank reserves—available to large commercial banks, which in turn is transmitted to lending and deposits rates, as well as inducing a repricing of bonds, the exchange rate, and other assets. Fintech innovations can change any segment of this transmission.
  - The balance-sheet channel could be affected by how households and firms react to new financial products or delivery methods.
  - The bank-lending channel could be reshaped by changes in the composition of bank financing.
  - Fintech may alter the risk-taking behavior of both bank and nonbank intermediaries with implication for monetary transmission.
  - Fintech could also affect the role of banks in payments and could thus affect their need for central bank liquidity.
- Policymakers will need to think through the impact of specific fintech innovations, and—if necessary—adapt operational frameworks of monetary policy to ensure effective transmission.
- Fintech offers central banks the opportunity to explore new services, while having to consider new risks:
  - a) Some central banks are considering the possibility of issuing CBDCs, reflecting such issues as the rapid decline of cash use in their systems, maintaining demand for central bank money, reducing the cost of maintaining printed cash, and improving financial inclusion by reducing transaction costs. The design of CBDCs by central banks could have implications for the sources of commercial bank funding in the future—an issue that would call for careful examination.
  - b) Some central banks are exploring new fintech applications to improve and expand access to payments systems. Applications, such as DLT, are being examined closely to ascertain their capacity to increase the efficiency and resilience of payments systems.
  - c) Safeguarding financial stability could increasingly become a challenge. Fintech could impact the nature of systemic risks. For example, fintech-enabled multiple payment systems could improve the resilience of payments flows and reduce counterparty risk but could also become conduits amplifying risks at times of stress. Similarly, the determination of what constitutes a systemically important entity, from a stability perspective, may need to be expanded not only to a wider set of nonbank financial institutions but also, possibly, to entities providing critical fintech infrastructure.
  - d) Central bank support and the role of the LOLR in times of crisis might need to be re-examined. Fintech activities could lead to a decentralization and shift of activities outside the perimeter of the traditional banking sector. Although such shifts are not a new phenomenon, the speed and intensity with which these developments take place raise issues for central banks, financial supervisors, and other agencies to consider—including any potential need for adjustments to their legislative and regulatory frameworks may be needed.
  - e) Implications for other financial safety net arrangements might need to be considered as well. This could include analysis of the nature of “deposit” insurance, as well as its scope and coverage, and issues relating to crisis management and resolution of systemic fintech firms.

### Principle X: Develop Robust Financial and Data Infrastructure to Sustain Fintech Benefits
- Develop robust digital infrastructure that is resilient to disruption and that supports trust and confidence in the financial system by protecting the integrity of data and financial services.
- Robust financial and data infrastructure is necessary to provide operational resilience and to preserve confidence. Strong standards of operational resilience help market participants and infrastructures to withstand and rapidly recover from disruptions, thus supporting confidence in the continuity of services and preserving the “safety and soundness” and the integrity of the financial system.
- Fintech innovation increases IT dependencies and operational risks that should be carefully managed. Effective governance structures and risk-management processes are important to identify and manage risks associated with the use of fintech. The greater reliance on such technologies leads to new operational risks and more interdependencies among service providers (financial institutions, technology providers, and others) that may threaten the operational resilience of financial and data infrastructures. Financial institutions are increasingly partnering with or providers. In such cases, the associated risks for those operations and delivery of the financial services remain with incumbents. As many third-party providers fall outside the regulatory perimeter, increased emphasis on managing operational risks and ensuring robust outsourcing arrangements is key to preserving financial stability.
- Economies of scale may increase concentration risks. Economies of scale may motivate greater consolidation among financial firms or third-party service providers, increasing interconnectedness, and accentuating the potential for concentration and network risk. The provision of key infrastructure services by one or a few dominant players raises risks (both domestic and cross-border) that would need to be carefully managed and addressed by information-sharing, cooperation, and macroprudential policies as needed.
- Cybersecurity is paramount. Cybersecurity is a vital element of overall operational resilience, recognizing that financial services infrastructures are only as strong as the weakest link. Increased digitalization of finance encouraged by financial innovation places even more pressure on the importance of strong cybersecurity. It is thus important that cybersecurity be fully integrated into the development of new processes from the start. Robust standards are needed to achieve a minimum level of cyber resilience across the entire financial services supply chain to maintain the safety and soundness of the financial system and integrity of data.
- Robust business continuity and recovery plans are essential. A key component of strong resilience is the ability to withstand and rapidly recover from operational disruption. This necessitates robust back-up systems, incident response plans, and arrangements that are regularly tested with realistic failure scenarios.
- The increased digitalization of finance increases the need for strong frameworks to protect individual and institutional data. As more entities gain access to large volumes of personal and proprietary data, efforts to gain improper access to this information will increase. Robust data governance frameworks are essential to sustain the trust and confidence of users and to deliver the benefits of fintech. Important components of such frameworks include:
  - (1) clarity of data ownership;
  - (2) safeguards to protect data confidentiality, availability and integrity, while encouraging appropriate regulatory information sharing;
  - (3) privacy considerations; and
  - (4) the ethical use of data.
- Processes will be needed to ensure that data controllers and processors implement effective data protection mechanisms and retain accountability for data breaches.
- The following steps may be helpful for authorities to strengthen operational resilience:
  - a) Encourage financial firms and technology providers to embed cybersecurity and operational risk management into an enterprise-wide risk-management framework and to promote technical standards on cyber and information security. Build upon industry standards issued by SSBs [Standard-Setting Bodies] to set expectations for operational risk management and governance that include monitoring of compliance with applicable regulatory requirements when introducing new products.
  - b) Promote robust outsourcing arrangements that address technology dependence and apply strong disaster-recovery and business-continuity principles and standards for digital infrastructure. Market players should have robust processes for due diligence, risk management, and monitoring of any operation outsourced to a third party. Contracts should outline the responsibilities of each party, agreed service levels, and audit rights.
  - c) Monitor and manage domestic and cross-border concentration risk, because economies of scale could lead to large financial or technology firms becoming increasingly important in the provision of key infrastructure services, thus increasing vulnerability to systemic disruption.
  - d) Ensure that robust data-governance frameworks are in place to address issues of data ownership, privacy, confidentiality, integrity, availability, and the ethical use of data. Priorities are the protection of consumer and institutional data and the integrity of the financial services industry infrastructure.
  - e) Additional capacity and specialized skills may be needed to supervise operational and cybersecurity risks.

*APPENDIX I. BALI FINTECH AGENDA*

### APPENDIX II. CASE EXAMPLES87F

### APPENDIX II. CASE EXAMPLES

### A. Indonesia
- Fintech sector trends and scale:
  - Transaction value grew by 18.3 percent from US$22.4 billion in 2018, to a predicted value of US$26.5 billion in 2019—most of which (95.67 percent) comes from digital payments.
  - Number of fintech players grew from 140 players by 2016, to 189 players by February 2019.
  - Among those players, 34 percent focused on payment systems.
- BI (Bank Indonesia) mandate and organizational response:
  - BI’s mandate: regulate and maintain the stability of payment system and to achieve an efficient, safe, and reliable payment system while considering expansion of financial access and consumer protection.
  - BI’s five roles: regulator, licenser, operator, facilitator, and supervisor of the payment system.
  - BI established a fintech function under the Payment System Department with nine full time employees from diverse backgrounds (economist, accountant, mathematician, legal, IT).
- Regulatory sandbox design and rules:
  - Sandbox purpose: controlled environment for innovative products to nurture innovation while safeguarding consumer protection, risk management, and prudential principles.
  - Duration of participation: limited to six months, though extension for another six months is possible.
  - Requirements for participation: registration at BI; payment systems-related business; innovative products; benefits to customer; non-exclusive and scalable businesses; risks identified and mitigated.
  - BI set up a regulatory sandbox expert panel comprising experts from regulation, licensing, information technology, risk management, law, and supervision units to assess participant risks.
- Risk control and compliance:
  - BI requires all fintech payment systems to be registered at BI and limits collaboration by licensed providers with unregistered fintech companies.
  - BI requires all fintech companies to comply with Indonesia’s AML/CFT Act and relevant regulations and to report any suspicious transactions.
  - Crypto-currencies are not legal tender in Indonesia; payment service providers (including fintech companies) are currently prohibited to process transactions using crypto-currencies.

### B. Luxembourg
- Institutional approach and coordination:
  - BCL does not have a separate fintech unit; fintech developments are dealt with across departments (market infrastructure and payment systems and oversight, financial stability, economics and research, market operations, operational risk management and IT).
  - The BCL Governor tasked a staff member in the European and Internal Coordination Unit to actively follow fintech developments and ensure coordination.
  - An internal working group on Blockchain/DLT provides a forum to discuss fintech-related developments across departments.
  - Prudential supervision of fintech service providers is undertaken by Luxembourg’s financial supervisor (a separate entity).
- Monitoring and risk focus:
  - Market Infrastructure and Payment Systems Unit follows fintech and DLT at Eurosystem committees and work groups; examines function, operational reliability, and legal setup vis-à-vis users.
  - Cybersecurity, auditability and traceability, and IT management are evoked but the unit lacks full competence and capacity to assess responses.
- Risk Prevention Unit and operational risk management (ORM):
  - Risk Prevention Unit deals with ORM including BCM, information security (cybersecurity), and compliance; acts as the BCL’s second line of defense.
  - BCL defines technology risk as “any potential for technology failures or incidents to disrupt the business, such as breaches of agreed service availability, loss of data integrity or data corruption, architectural risk that exposes significant single points of failure, or an inability to recover technology enablers supporting critical processes. It is the risk of the inability to operate critical processes within a reasonable timeframe due to technology failures.”
  - BCL covers explicit fintech elements such as cloud computing, cybersecurity, and mobile computing.
- Current use and future intent:
  - At this stage, BCL does not yet use fintech for its own benefit; DLT and AI/ML are not used in supervisory tasks; the central bank does not use cloud services.
  - The Risk Prevention Unit analyzes these technologies and is involved in cyber-risk assessment; BCL participates in Eurosystem groups and OECD Expert Group on Finance and Digitization.
- Planned fintech contributions to internal risk management (near future expectations):
  1) Improved automation and computerization of the ORM process by implementing an advanced software GRC solution;
  2) In the BCL Management Team: interfacing the GRC tool with IT technical solutions;
  3) Improved translation of cyber and technical risks into business terms and risks—resulting in quicker response times and higher operational resilience;
  4) Better targeted and increasingly empowered risk assessments of operational risks, including cyber and technical risks by the second line of defense;
  5) Significant improvements in the accuracy, efficiency, and security of processes across payments, clearing, and settlement;
  6) Contributing to identifying the best options for mitigating risks and the respective strategies;
  7) Real-time information on all types of risk;
  8) Mitigation of the effects of cyber-attacks (internal or external), by continuous monitoring of the data environment;
  9) Continuous monitoring and auditing of processes and systems that are vulnerable to threats, including alerting, responding, and eradicating threats.
- Topics under study for possible future application:
  1) Improvement of fraud detection by measuring and monitoring anomalies and abnormal activities (internal and external fraud, cyber-attacks; possible applications in the context of SWIFT payment messages);
  2) Data mining, including use of statistical and artificial intelligence tools for data-analytics to assess risk of internal fraud, management fraud, occupational fraud, and support fraud audits;
  3) Detection of front office behaviors and emerging behavioral patterns to predict latent risks and detect links between employees;
  4) Detection of money laundering by analyzing large datasets;
  5) Control of operational risks using effective Workflow Management;
  6) Analyzing best ways to protect systems through AI/ML analysis;
  7) Process-automation to accelerate routine tasks, minimize human error, and improve efficiency and security;
  8) Setting-up early-warning systems by defining Key Risk Indicators, Key Performance Indicators, Key Control Indicators enriched by appropriate models for detecting abnormal behavior;
  9) Identifying patterns using tools for complex data structures involving non-linear relationships;
  10) Applying simulation models for analysis of more complex problems;
  11) Modelling complex phenomena based on experts’ perceptions by modeling uncertainty and related events to enable development and forecasting through simulations;
  12) Automation of the classification of risk events;
  13) Automation of taxonomies and risk libraries by standardization, centralization, and elimination of redundancies;
  14) Allowing for automatic links between historic incidents with the corresponding risk event(s) to prevent similar risks in the futures;
  15) Combining loss data with risk reports to ensure improved prediction of risk events, and therefore a more accurate prediction of future losses.
- Identified challenges to address:
  1) The availability of suitable data;
  2) Data held in separate silos, different systems;
  3) Data kept as informal knowledge;
  4) Transparency and ethics (regulatory compliance).

### C. Sierra Leone
- Sandbox objectives and mandate:
  - The Bank of Sierra Leone (BSL) Regulatory Sandbox Program enables innovative fintech products, services, and solutions to be deployed and tested in a live environment within specified parameters and timeframes prior to market launch.
  - Sandbox supports evidence-based approaches that advance financial inclusion and maintaining financial stability.
  - Mandate derived from the Sierra Leonean Banking Act (2011) and from the Other Financial Services Act (2001), giving BSL authority to issue regulations and guidelines.
- Participation, licensing, and governance:
  - Sandbox framework stipulates eligibility criteria, licenses, and regulatory requirements; participants must be tested and licensed or rejected licensing within the testing period.
  - Licences are issued for a period of twelve months to identify and manage potential risks and contain consequences of failure.
- Organizational arrangements within BSL:
  - Sandbox Steering Committee: representatives from Banking Supervision, Other Financial Institutions Supervision, Financial Stability, Legal Affairs Division, and Financial Inclusion Unit. The Committee provides policy direction and oversight, including recommendations to the governor on licensing decisions.
  - Sandbox Team (project implementation team): experts from Banking Supervision, Financial Stability, and Other Financial Institutions Supervision Departments. Team is housed in Other Financial Institutions Supervision Department; correspondences channeled through the Chairman of the BSL Regulatory Sandbox Committee (Director of Other Financial Institutions Supervision Department), who reports to management and governor.
  - The BSL’s risk management unit is currently not a member of the Committee or the Team; experts from other departments or external parties may be invited as needed.
- Safeguards and participant obligations to mitigate live-environment risks:
  - Conduct thorough “Fit and Proper Persons” assessment on all would-be Board Members and top management to ascertain integrity, sources of funds, and suitability.
  - Require participants to sign written agreements with service providers and disclose to customers that solutions are under testing in the Sandbox.
  - Require Sandbox participants to get customer consent before using personal data to protect privacy.
- Monitoring and testing:
  - A monitoring tracker and testing plan assess risks and mitigation measures and potential impacts arising from:
    - Any test failures;
    - Fintech developments;
    - Regulatory requirements to be relaxed or modified;
    - Testing methodology;
    - Control boundaries; key metrics and outcome indications;
    - Data security requirements, KYC processes and AML/CFT safeguards.

### D. Ukraine
- Pilot project overview:
  - The National Bank of Ukraine (NBU) implemented a pilot project on retail CBDC issuance called E-hryvnia during 2018.
  - The project analyzed international experience on CBDCs, studied related legal issues and macroeconomic effects, and drew up optimum business model versions for e-hryvnia circulation.
  - Pilot included case studies and testing of a blockchain technology platform; a limited amount of e-hryvnias were issued into circulation.
  - Transactions could be initiated via web-wallets or mobile apps for Android and iOS.
  - Transactions were tested by task forces of NBU staff, volunteer companies, and World Bank experts who provided technical assistance.
- Issuance models considered:
  - Centralized model: NBU is the only issuer and the only owner and operator of the blockchain platform; e-hryvnia is a direct claim on the NBU; banks and non-bank financial institutions act as agents for distribution and customer access and services.
  - Decentralized model: banks and non-bank financial institutions are entitled to issue e-hryvnia backed by provisions in the NBU; e-hryvnia is the claim on these banks and non-bank financial institutions, which operate all retail payments; this model aligns with IMF’s definition of synthetic CBDC.
  - For the pilot, the centralized model was chosen as simpler, more comprehensible, and transparent.
- Institutional setup for the pilot:
  - Two working groups:
    1) Internal working group: Payment Systems and Innovations Department (project leader), Strategy and Reforming Department, Information Technologies Department, Security Department, Accounting Department, Operational Department, Legal Department, Monetary Policy and Economic Analysis Department. Project manager and team reported to the Change Management Committee of the NBU.
    2) External initiative group: Ukrainian IT and payment market participants who volunteered (developed blockchain platform and performed agent functions).
- Project purpose linked to financial inclusion:
  - Background strategic context: Financial inclusion is one of the seven strategic objectives in the NBU’s Strategy.
  - World Bank estimation: 37 percent of adults in Ukraine do not have a bank account.
  - Objective: introduce an affordable, cheap, secure, and functional instrument for retail payments by individuals; CBDC research and development activities were committed in the Strategy of Ukrainian Financial Sector Development until 2025.
- Pilot outcomes (risks identification and mitigation):
  - The pilot project allowed the NBU project team to identify risks and ways to minimize them (project documented analyses and case studies as part of the pilot).

*Source: APPENDIX II. CASE EXAMPLES (content unit: wpiea2021105-print-pdf - APPENDIX II. CASE EXAMPLES87F)*

### 1. The implementation of e-hryvnia may be disruptive for the Ukrainian payment

### 1. The implementation of e-hryvnia may be disruptive for the Ukrainian payment ecosystem

### Key findings and potential impacts
- "E-hryvnia has the potential to become a competitor to existing retail payment instruments and means of payment, such payment cards, electronic money, payment orders."
- Implementation "may change the ecosystem of Ukraine’s payment market and reassign the current roles of market participants instead of replacing cash and including more population into financial system."
- The pilot project "had a limited list of transaction types and a limited range of users, as well as the minor quantity and volumes of executed transactions," therefore "the project did not fully uncover the instrument’s attractiveness and the potential level of involvement of Ukraine's population in using it."
- "Thus, it is hard to predict the number of Ukrainian citizens to become e-hryvnia users if the decision to implement e-hryvnia at a national scale is taken."
- "Significant investments and time are required to modernize the payment infrastructure for a new instrument like retail CBDC, that may be unjustified as Ukrainian payment services market is characterized by high level of competition, concentration, and established infrastructure."

### Roles, models, and operational consequences
- "In case of the centralized model, the NBU would perform non-specific functions for a central bank such as interacting with individuals (including KYC, disputes resolution, AML/CFT)."
- "There is legal uncertainty for the implementation of e-hryvnia as it should be regulated by law."
- "As the full-scale implementation of e-hryvnia in the Ukrainian payment market would require amendments to both Ukrainian legislation and NBU regulations, the pilot project was hold in the framework of the electronic money regulation."

### Technical considerations and technology risk
- "Risk of the proper technology choice: distributed leger technology (DLT, blockchain) can be used as a platform for the issuance and circulation of e-hryvnia."
- "However, the main advantages of this technology, namely: the lack of a single trust center and the possibility of checking any transaction by any person are not used in case of the centralized model of e-hryvnia."
- "Also, for the national level system, private version of the blockchain protocol cannot be used since its updating in accordance with the development of the basic protocol is virtually impossible."

### Integration with other payment innovations
- "Implementation of e-hryvnia in Ukraine’s payment market should be in line with the possible implementation of other innovative payment instruments, including instant payments and new Open Banking instruments to avoid the overlapping of these projects."

### Use cases considered by the NBU
- The NBU is considering the following use cases for e-hryvnia:
  - "Instrument for retail cashless payments by individuals (P2P, P2B);"
  - "Instrument for social welfare payments (G2P);"
  - "Instrument for securities settlements (B2B);"
  - "Instrument for wholesale (interbank) settlements inside the country (B2B);"
  - "Instrument for cross-border settlements (cooperation with other central banks) (B2B, P2P, P2B); and"
  - "Interest bearing instrument (not as means of payment)."

### NBU research, pilot activity, and legislative developments
- "The NBU is currently considering the possibility of issuing e-hryvnia not just from the supply side but also through market demand analysis."
- "At present, the Project Team is focused on exploring the possible areas of usage and potential demand for e-hryvnia."
- "In December 2020, the NBU initiated a Survey on Potential Demand and Consumer Motivations in a form of a questionnaire."
- "The questionnaire includes 30 questions from the perspective of the above-mentioned use-cases and addressed to six target groups of Ukrainian experts: Retail Business and Innovations/Corporate Business/Financial Markets/Digital Transformation of Public Authorities/Virtual Assets."
- "In 2020, the NBU presented the Draft Law of Ukraine on Payment Services intended to regulate the operation of the Ukrainian payments and transfer market."
- "Among others, the draft law contains the definition of CBDC, as well as changes to the existing Law of Ukraine on the National Bank of Ukraine in the part of the NBU’s function to issue digital currency."
- "Currently, the draft law is being revised by the Parliament and voting is expected in 2021."
- "The NBU continues to research the possibility of issuing its digital currency, taking into account the results of the pilot project, the current needs and motivations of the financial market, and the ongoing economic development prospects."

*Source: wpiea2021105-print-pdf - 1. The implementation of e-hryvnia may be disruptive for the Ukrainian payment ecosystem.*

---


_Source: https://www.imf.org/-/media/files/publications/wp/2021/english/wpiea2021105-print-pdf.pdf_
