## _cr15295

## Source details

**Canonical URL:** [_cr15295](https://www.imf.org/-/media/websites/imf/imported-full-text-pdf/external/pubs/ft/scr/2015/_cr15295.pdf)

## Other formats

- [Markdown version](/-/media/websites/imf/imported-full-text-pdf/external/pubs/ft/scr/2015/_cr15295.pdf.md)
- [Structured JSON version](/-/media/websites/imf/imported-full-text-pdf/external/pubs/ft/scr/2015/_cr15295.pdf.json)

---

### INTRODUCTION — scope and focus
- Stand‑alone Report on the Observance of Standards and Codes undertaken by the IMF and World Bank during March of 2015 at the request of the Bulgarian authorities.
- Assessment reflects the regulatory and supervisory framework in place as of the date of completion of the assessment.
- Not intended to assess the response to the 2014 banking crisis or represent an analysis of the state of the banking sector or crisis management framework.
- Key supervisory governance observations:
  - Majority of supervisory powers vested in the Deputy Governor for banking supervision — risk of concentration of authority and limited transparency/accountability.
  - Governing Council issues regulations but is at arms’ length from supervisory decision‑making and lacks rights to compel transparency or ensure enforcement consistency.
  - No legal possibility for enforcement powers to be delegated if the Deputy Governor position falls vacant unexpectedly.
- Resource and capability constraints:
  - Material concerns that the BNB is too resource constrained to deliver effective minimum levels of supervision.
  - Additional demands from EU legislative transposition, AML/CTF supervisory mandate, and consumer protection tasks resourced from the supervisory department.
  - Consequences: strain on scope/scale of inspections, limited proactive investigations, under‑supervision of the local segment (~a quarter of the market).
  - Specialist skills lacking/under‑represented: IT, market risk, quantitative skills.
  - BNB staff diverted by dealing with a banking failure and liquidity stress in 2014, adversely affecting planned supervisory programs.

### METHODOLOGY
- Assessment used the BCBS BCP methodology issued September 2012; authorities opted to be assessed against both essential and additional criteria.
- Revised Core Principles contain 247 separate essential and additional criteria.
- Assessment process included review of laws, rules, guidance and extensive meetings with BNB, Finance Ministry, FIU, auditors, professional bodies and banks.
- Standards evaluated proportionately to Bulgaria’s financial system sophistication and complexity.

### INSTITUTIONAL AND MARKET STRUCTURE — overview and key statistics
- Financial system size and composition:
  - Financial system assets as at June 2014: 141.5 percent of GDP; banking sector represents 76 percent of this.
  - Banking system risk profile largely focused on credit risk.
- Non‑bank assets (Source: BNB Quarterly Bulletin on Banks):
  - Insurance Companies: 5.5 BGN bn
  - Supplementary pension insurance funds: 7.6 BGN bn
  - Local investment funds: 0.8 BGN bn
  - Non-bank investment firms: 4.6 BGN bn
  - Vehicle finance corporations: 1.5 BGN bn
  - Leasing companies: 4.3 BGN bn
  - Specialized lenders: 2.6 BGN bn
- Ownership/market structure (end‑December 2014 unless stated):
  - Domestic banks market share: 23 percent.
  - Subsidiaries with EU parents: 73 percent.
  - Greek‑owned subsidiary banks: approximately 24 percent.
  - Number of banks: 28 (excluding one recently failed bank), of which 6 are branches.
  - Banking establishments from outside the EU: less than 1.5 percent of the system.
- 2014 stress events:
  - June 2014: two bank failures following runs on deposits; BNB placed two banks into conservatorship.
  - A third domestic bank experienced depositor run and received emergency liquidity (state aid approved by the EC).
  - Bulgaria operates a currency board arrangement (CBA) introduced July 1997; BGN 1.95583 equals €1.
- System‑wide capital and liquidity (as of end‑2014 / stated dates):
  - System CAR (Dec 2014): 22 percent.
  - Tier 1 capital ratio: 19.9 percent.
  - CET1 ratio: 19.5 percent.
  - Capital conservation buffer imposed since May 2014: 2.5 percent.
  - Systemic risk buffer applied: 3 percent of total risk weighted exposures located within the country (Article 92 (3) Regulation 575/2013/EC).
  - Liquid assets‑to‑liabilities ratio (as at end‑January): 31.8 percent.
  - EU LCR not yet fully in force; implementation timetable to October 2015.
- Non‑performing loans:
  - Reported system wide gross NPLs (excluding failed bank) as of end‑September 2014: 18.1 percent.

### PRECONDITIONS FOR EFFECTIVE BANKING SUPERVISION — institutional context
- Supervisory responsibilities split:
  - BNB: banks.
  - Financial Supervision Commission (FSC): non‑banks and markets.
- Financial Stability Advisory Council (FSAC):
  - Composition: Minister of Finance, Governor of the BNB, Chairman of the FSC; advisory/coordination role; meets quarterly.
- Macro‑prudential capacity:
  - Macro‑prudential Supervision and Financial Stability Directorate created in 2014 (merger of two units) — performs stress tests and proposes macro‑prudential instruments.
- Legal & judicial framework concerns:
  - External perceptions of judicial independence weak; Global Competitiveness Report 2014‑15 ranks Bulgaria 126th/144 on judicial independence.
- Accounting/audit framework:
  - IFRS applied since 2003; all credit institutions subject to International Accounting Standards.
  - External audits follow ISA and Law on Independent Financial Audit; Commission for Public Oversight on Statutory Auditors (CPOSA) established.

### CRISIS MANAGEMENT, RESOLUTION, AND PUBLIC SAFETY NET
- Pre‑BRRD transposition legal framework had essential weaknesses; KTB collapse in 2014 revealed major weaknesses (no good bank/bad bank option).
- BNB pre‑transposition powers included special supervision and conservatorship; if conservatorship failed BNB could withdraw license and petition court for bankruptcy.
- Transposition of BRRD (2014/59/EC) into Bulgarian law in progress at assessment time — expected BNB would be designated Resolution authority and BDIF as Resolution fund; transposition expected by end‑2015 (note: in later text transposition and implementing acts entered into force 14 August 2015).
- Bulgarian Deposit Insurance Fund (BDIF):
  - Established 1998 Law on Bank Deposit Guarantee.
  - Coverage: depositors’ funds up to BGN 196,000 (EUR 100.000).
  - BDIF processed claims of 104,640 depositors of KTB through nine participating banks for a total amount of BGN BGN 3,5 billion (EUR 1.7 billion).

### SUPERVISORY GOVERNANCE, INDEPENDENCE AND RESOURCING (Principles 1–2)
- Legal governance and decision‑making:
  - BNB Governing Council composed of Governor, three Deputy Governors and three non‑executive members.
  - Deputy Governor heading Banking Supervision exercises supervision (Article 20(3) Law of the BNB); wide delegation of powers to single individual observed.
  - Deputy Governor (supervision) dismissal noted (dismissed 21 January 2015); LBNB lacks contingency for sudden unavailability.
- Assessment of Principle 2: Materially Non Compliant.
- Key resource and operational constraints:
  - Funding primarily from currency reserve operations; salary scales not differentiated for supervisory staff; recruitment/retention challenges.
  - No formal skills‑gap mapping or individualized development plans; internal IT project limited to restoring lost functionality.
  - Recommendations include: revise governance to avoid vesting significant powers in a single individual; ensure Governing Council timely informed; increase resources and specialist skills (IT, quantitative, IFRS); upgrade supervisory IT capability; map skills and address gaps; ensure legal cost coverage for staff.

### SUPERVISORY POWERS, LICENSING, AND CONSOLIDATED SUPERVISION (Principles 3–7)
- Legal powers to set/enforce prudential standards:
  - LBNB and LCI provide framework; LCI Art. 103(2) enables administrative sanctions up to licence revocation.
  - Pillar 2 legal basis: LCI art.79 (c) and art.103 (2); BNB can impose additional capital/liquidity requirements.
- Licensing and fit & proper:
  - Minimum initial capital: at least BGN 10 million (EURO 5 million).
  - Applicants must provide extensive documentation including names/addresses of 20 largest shareholders and origin of funds for persons subscribing 3 percent and above.
  - LCI lacks explicit definition of Ultimate Beneficial Owner (UBO); AML law captures UBO concept.
  - Recommendation: include clear UBO definition in LCI consistent with AML law and enhance due diligence on origin of funds.
- Transfer of significant ownership and approvals:
  - Prior approval required when holdings reach thresholds of 20, 33 or 50 percent (Art. 28 LCI); notification/60‑day due diligence by Legal and Administrative Directorate.
  - Over past 5 years: 16 requests for transfer of significant ownership approved; one license revoked (6 November 2014).
  - Gaps: no formal post‑license follow‑up inspection mechanism; limited powers over shareholders who cease to meet suitability.
- Consolidated and cross‑border supervision:
  - BNB empowered to carry out consolidated supervision (LCI art.89); participates in supervisory colleges and signed MOUs with several EU and third‑country supervisors.
  - Assessment of Principle 3: Largely Compliant; some MoUs outdated (e.g., with FIA/FID and BDIF) and recommended revisions.

### SUPERVISORY REVIEW (SREP), TOOLS, ON‑SITE / OFF‑SITE MIX (Principles 8–10)
- SREP and Risk Assessment System (RAS):
  - SREP required by law (Art 79c(1) LCI); RAS uses CAMELOS (on‑site) and CAEL (off‑site) frameworks; component ratings 1–5 with composite RAS rating.
  - SREP covers capital, assets, management, earnings, liquidity, operational risk, market sensitivity, governance, AML, etc.
- On‑site inspections:
  - Target inspection cycle: 18 to 24 months (not always maintained due to resource constraints).
  - Inspection teams: five teams of ~5 staff each; inspection composition and rotation not formalized.
  - On‑site types: complete supervisory inspection and targeted inspection; SSD conducts AML on‑site inspections.
- Supervisory reporting:
  - LCI Article 80 grants broad information‑gathering powers; FINREP/COREP templates in use; harmonized EU reporting transition underway.
  - BNB validation processes in place; external experts may be appointed (though not commonly used).
- Principle 9 Assessment: Largely Compliant but resource and coordination weaknesses constrain implementation.
- Recommendations include: improve inter‑directorate information sharing; introduce horizontal reviews; upgrade IT/data integration and “next generation score‑carding”; use external experts more readily.

### CORRECTIVE ACTIONS, SANCTIONS, RESOLUTION (Principle 11)
- Available measures:
  - Written warnings, written orders, additional capital requirements, prohibition of dividends, dismissal of board members, special supervision/conservatorship, licence withdrawal.
  - LCI art.115: special supervision where bank “at risk of insolvency”; conservator term 6 months (examples: KTB and VCB in June 2014).
- Deficiencies and assessment:
  - Deputy Governor has wide discretion; absence of collegial decision process risks inconsistency.
  - Limited use of coercive measures and escalation for persistent non‑compliance; lack of internal guidelines for sanction selection and quantum.
  - Assessment of Principle 11: Materially Non Compliant.
- Recommendations: introduce internal guidelines and escalation framework; apply gradual response with escalation; broaden circumstances for special supervision; strengthen recovery and resolution framework post‑BRRD.

### CORPORATE GOVERNANCE, RISK MANAGEMENT, INTERNAL CONTROLS (Principles 14–15, 26)
- Corporate governance:
  - Legal instruments: LCI, Ordinance 7, Ordinance 10, Ordinance 20 and BNB‑derived guidance (EBA‑based).
  - Board responsibilities and committees prescribed; nomination, audit, risk, remuneration committees expected.
  - Assessment of Principle 14: Materially Non Compliant — evidence of limited systematic Board engagement, insufficient powers to require board composition changes, and resource constraints for frequent governance assessments.
  - Recommendations: strengthen BNB powers to require Board changes; require banks to notify BNB of material issues affecting fitness/propriety; refresh Ordinance 10 and RAS Manual; institute systematic senior‑level contact with Boards.
- Risk management (Principle 15):
  - ICAAP and ILAAP expectations set; SREP links risk to capital (Pillar 2); stress testing requirements exist and are supervised.
  - Assessment: Largely Compliant.
  - Recommendations: reallocate resources to risk management oversight; horizontal reviews; refresh RAS Manual and Ordinance 10.

### CAPITAL ADEQUACY, BUFFERS, INTERNAL MODELS (Principle 16)
- Regulatory minima under CRR:
  - CET1: 4.5 percent; Tier 1: 6.0 percent; Total capital: 8 percent (CRR Article 93 thresholds cited).
- Bulgarian implementation:
  - Applied capital conservation buffer: 2.5 percent.
  - Systemic risk buffer: 3 percent.
  - Resulting practical CAR expectation: 13.5 percent (8 + 2.5 + 3).
  - System ratios (Sep 30 / latest data cited):
    - total capital ratio: 22.16 percent;
    - lowest individual bank ratio: 14.57 percent;
    - CET1: 19.47 percent;
    - T1 ratio: 19.91 percent.
- Subordinated debt:
  - Percentage of subordinated debt in capital in the banking system on average: 8.69 percent.
  - BNB approach: apply full grandfathering under CRR until 2022.
- Assessment of Principle 16: Compliant.
- Notes: BNB has Pillar 2 powers (Art.103 (2), point 5 LCI) but had not systematically operationalized formal Pillar 2 add‑ons for problem assets at time of assessment.

### CREDIT RISK, PROBLEM ASSETS, PROVISIONS (Principles 17–18)
- Credit risk framework:
  - LCI Art 73 and Ordinance 7 set requirements for credit policies, documentation, collateral valuation and internal methodologies.
  - BNB on‑site inspections target review of ~20–25 percent of loan portfolios.
- Asset classification and provisioning:
  - Transitioning to FINREP/ITS on forbearance and NPEs (EBA/EC implementing rules adopted Jan/Feb 2015); removal of Ordinance 9 released ~BGN 2bn in capital system‑wide.
  - Identification/valuation challenges: slow collateral realization environment; misclassification and under‑provisioning identified in inspections; BNB retained informal Pillar 2 approach.
- Assessment Principle 17: Compliant. Principle 18: Largely Compliant.
- Recommendations: operationalize Pillar 2 approach for problem exposures; consider horizontal reviews on NPL management.

### CONCENTRATION RISK, LARGE EXPOSURES, RELATED PARTIES (Principles 19–20)
- Large exposure regime:
  - General cap: exposure to a counterparty or group of connected counterparties cannot exceed 25 percent of eligible capital.
  - Board approval requirements: exposures >10 percent of capital require Board action; >15 percent require unanimous decision.
- Identified weaknesses:
  - KTB collapse revealed supervisory shortcomings in concentration and related‑party lending (e.g., KTB related‑party exposures 33.5 percent of capital at end‑June 2014).
  - Difficulty in determining economic relatedness due to opaque ownership structures, including offshore entities.
  - LCI does not explicitly list all transaction types that give rise to related‑party exposures; no explicit power to deduct related‑party exposures from capital.
- Assessment: Principle 19 — Materially Non Compliant; Principle 20 — Materially Non Compliant.
- Recommendations: conduct horizontal review of LEL compliance; refine definitions/coverage of related‑party transactions; enhance surveillance and legal/regulatory powers to address circumvention; improve UBO identification.

### MARKET RISK, IRRBB, LIQUIDITY, OPERATIONAL RISK (Principles 21–25)
- Country & transfer risk (Principle 21):
  - No specific national regulation; EBA SREP Guidelines to be implemented. Assessment: Materially Non Compliant. Recommendation: adopt regulation on country/transfer risk and include in stress testing.
- Market risk (Principle 22): Compliant — exposures low; no banks use internal model for market risk capital.
- Interest rate risk in banking book (Principle 23): Compliant — IRRBB considered extremely significant; supervisory testing in ICAAP.
- Liquidity risk (Principle 24): Compliant — BNB early adopter of Basel 2008 liquidity standards; enhanced reporting and stress testing; maintained Ordinance 11 until EU LCR phased in.
- Operational risk (Principle 25): Largely Compliant — Ordinance 7 and 10 require OR frameworks, BCP/DRP; recommend more systematic on‑site OR surveillance, stronger IT expertise and mandatory incident notification.

### INTERNAL AUDIT, EXTERNAL AUDIT, FINANCIAL REPORTING, AND DISCLOSURE (Principles 26–28)
- Internal audit and internal controls (Principle 26): Largely Compliant — Ordinance 10 in place but high‑level; recommendations to revise Ordinance 10 and deepen internal control supervisory testing.
- External audit (Principle 27): Materially Non Compliant — BNB lacks access to auditors’ working papers and management letter; cannot require auditor rotation; market concentration of audit firms noted.
  - Recommendations: where consistent with EU framework, seek rights to access audit working papers, require auditor rotation/change, establish regular dialogue with auditors, and strengthen BNB IFRS expertise ahead of IFRS 9.
- Disclosure and transparency (Principle 28): Compliant — banks required to publish financial statements; BNB publishes extensive aggregate and bank‑level data; CRR Pillar 3 framework applied.

### AML/CFT SUPERVISION (Principle 29)
- Dual supervision:
  - Primary AML/CFT supervisory responsibility legally with FID‑SANS; BNB has Special Supervision Directorate (SSD) with AML powers and on‑site inspection authority; cooperation governed by an MoU (signed 2003) pending revision.
- SSD resourcing and scope:
  - SSD staff: 14 staff, 8 operational for AML/CFT oversight.
  - In practice SSD performs AML and non‑AML tasks (transparency of products, deposit insurance compliance) — diversion of resources.
  - BNB‑led AML inspections: 16 in 2014 (18 in 2013).
- Findings and concerns:
  - Weaknesses in CDD and UBO identification for legal entities overseas; record‑keeping 5 years minimum.
  - Enforcement: FID fines limited (cap BGN 50,000 / €25,000); BNB has not frequently used art.103 enforcement for AML.
  - Integration gap: AML/CFT not fully integrated into overall prudential SREP.
- Assessment: Largely Compliant.
- Recommendations: refocus SSD on core AML mandate; finalize MoU with FID; integrate AML findings into prudential supervision; increase sanctions for recurrent violations; require banks to strengthen UBO identification and share AML inspection reports with external auditors where permitted.

### AGGREGATE RECOMMENDATIONS — priority actions summarized
- Governance and independence:
  - Revise internal governance to avoid concentration of supervisory powers in one individual; ensure delegation and contingency arrangements.
  - Ensure Governing Council receives timely supervisory information.
- Resourcing and capabilities:
  - Increase resource allocation to supervision; recruit IT, quantitative, model, and IFRS expertise; conduct skills mapping and training.
  - Upgrade supervisory IT systems and data integration.
- Legal/regulatory reforms:
  - Transpose BRRD and adopt recovery/resolution framework; update deposit guarantee law and MoUs (BDIF, FID, CPOSA).
  - Consider amending LCI to define UBO, strengthen powers over internal organization changes and auditor oversight, and enhance enforcement powers and recovery tools.
- Supervisory processes:
  - Operationalize Pillar 2 to address problem exposures; formalize escalation and sanction guidance; increase use of horizontal reviews and external experts.
  - Strengthen consolidated supervision perimeter and cross‑border oversight, including fit & proper reviews for non‑financial holding company owners.
- AML/CFT:
  - Refocus SSD, finalize cooperation MoU with FID, integrate AML into SREP, increase sanctions where warranted, and require better UBO identification.

*Source: _cr15295 — IMF/World Bank Detailed Assessment (March 2015) — selected INTRODUCTION and related sections.*

### INTRODUCTION  __________________________________________________________________________________  5

### _cr15295 - INTRODUCTION  __________________________________________________________________________________  5

### INTRODUCTION
- This assessment is a stand-alone Report on the Observance of Standards and Codes undertaken by the International Monetary Fund (IMF) and the World Bank during March of 2015 at the request of the Bulgarian authorities.
- The assessment reflects the regulatory and supervisory framework in place as of the date of the completion of the assessment.
- The assessment is not intended to assess the response to the 2014 banking crisis, and it is not intended to represent an analysis of the state of the banking sector or crisis management framework.
- Key governance and supervisory observations:
  - The Bulgarian National Bank (BNB) vests the majority of supervisory powers in the Deputy Governor for banking supervision, exposing the supervisory function to risks related to concentration of authority and lack of transparency and accountability.
  - The Governing Council issues regulations that articulate supervisory standards but is at arms’ length from the supervisory process and lacks rights to compel transparency of decision making or impose a framework to ensure consistency in enforcement.
  - There is no legal possibility for enforcement powers to be delegated if the Deputy Governor position falls vacant unexpectedly, creating uncertainty in supervisory activities.
- Resource and capacity concerns:
  - Material concerns that the BNB is too resource constrained to deliver effective minimum levels of supervision.
  - Additional demands include implementation of international regulatory reforms transmitted through the EU legislative and convergence program, the supervisory mandate for AML/CTF, and consumer protection tasks, all resourced from the supervisory department.
  - Consequences include strain on scope and scale of supervisory inspections, limited ability to launch proactive investigations, and under-supervision of the local segment representing nearly a quarter of the market.
  - Certain specialist skills are lacking or under-represented at the BNB, including IT, market risk, and quantitative skills.
  - BNB staff were diverted by dealing with a banking failure and liquidity stress in 2014, adversely affecting planned supervisory programs and timely scrutiny and follow-up.
- Legal and regulatory constraints:
  - Gaps in the legal framework restrict the BNB’s locus, including inability to instruct banks to change internal organization or Board composition, inability to insist on a change of external auditor, and limitations from legal protections for BNB staff.
  - Delays in transposition of the Directive on Bank Recovery and Resolution (BRRD) have prevented the BNB from carrying out tasks related to preparation for orderly resolution procedures.
- EU framework impacts:
  - As an EU Member State, Bulgaria’s regulatory framework is based on EU legislation and architecture.
  - The Capital Requirements Regulation (CRR) caps the minimum capital adequacy ratio at 8 percent (the BNB previously applied a minimum 12 percent).
  - The BNB has “frontloaded” capital buffers: the capital conservation buffer and the systemic risk buffer are both currently in force.
  - CRR and implementing technical standards removed the BNB’s former power to set supervisory provisions against problem exposures; the BNB retains power to set higher capital requirements for problem assets and is currently closely monitoring relevant portfolios and exercising an “informal Pillar 2 approach.”
  - The BNB needs to be ready and able to apply additional capital requirements through Pillar 2 in future.
- Supervisory approach and risks:
  - The BNB employs a risk-based approach and sound methodologies for analysis and assessment of individual banks and banking groups, supported by the macro-prudential and financial stability directorate.
  - Supervisory reliance on on-site inspections is undermined by scarcity of resources limiting breadth and frequency of inspections.
  - Recommended internal measures include conducting an internal skills audit and strategy, reviewing internal organization to maximize efficiency and communication, and greater use of supervisory techniques such as horizontal assessments.
  - System-wide vulnerabilities include credit risk concentration, related party and connected lending, and corporate governance weaknesses.
  - Enhanced transparency in ownership structures of clients—especially legal entities located overseas with undisclosed ultimate beneficial owners—is of paramount importance.
  - The BNB could employ horizontal inspections and issue requirements for more robust processes to determine connectedness between customers or groups of affiliated parties.

### METHODOLOGY
- Ratings are not directly comparable to previous assessments; this assessment used the BCP methodology issued by the Basel Committee on Banking Supervision (BCBS) in September 2012.
- The authorities opted to be assessed against both essential and additional criteria.
- The last BCP assessment of Bulgaria was conducted in 2002; the methodology has been revised twice since then (2006 and 2012). An FSAP update in 2008 did not include a BCP assessment.
- The 2012 revision strengthened requirements for supervisors, approaches to supervision, and supervisors’ expectations of banks, adding new principles, essential criteria (EC), and additional criteria (AC).
  - Altogether, the revised Core Principles contain 247 separate essential and additional criteria.
  - The revised BCPs emphasize the powers supervisors should have and heightened focus on actual use of powers in a forward-looking approach through early intervention.
- Assessment process:
  - The assessment team reviewed laws, rules, and guidance and held extensive meetings with BNB officials and additional meetings with the Finance Ministry, the Financial Intelligence Unit (FIU), auditing firms, professional bodies, and banking sector participants.
  - Authorities provided a comprehensive self-assessment and detailed responses to additional questionnaires and facilitated access to supervisory documents and files on a confidential basis.
  - The team reported very high quality of cooperation from the authorities despite concurrent domestic and international initiatives.
- Proportionality and judgment in assessment:
  - Standards were evaluated in the context of Bulgaria’s financial system sophistication and complexity; a proportionate approach is applied in assessments.
  - The assessment recognizes supervisory practices should be commensurate with complexity, interconnectedness, size, risk profile, and cross-border operations of banks.
  - Assessments require judgments and are not an exact science; adherence to a common methodology provides an internationally consistent measure of supervisory quality relative to the revised Core Principles.

### INSTITUTIONAL AND MARKET STRUCTURE—OVERVIEW
- Banking is the most significant sector of Bulgaria’s financial system:
  - As at June 2014, financial system assets in Bulgaria accounted for 141.5 percent of GDP with the banking sector representing 76 percent of this.
  - The financial system has relatively low exposure to external markets and little use of external market financing.
  - The banking system’s risk profile is largely focused on credit risk.
- Non-banking sector asset distribution (Source: BNB Quarterly Bulletin on Banks):
  - Insurance Companies: 5.5 BGN bn
  - Supplementary pension insurance funds: 7.6 BGN bn
  - Local investment funds: 0.8 BGN bn
  - Non-bank investment firms: 4.6 BGN bn
  - Vehicle finance corporations: 1.5 BGN bn
  - Leasing companies: 4.3 BGN bn
  - Specialized lenders: 2.6 BGN bn
- Ownership and market structure:
  - Bulgaria is predominantly a host state to EU banking groups.
  - Less than a quarter of market share, 23 percent, is held by domestic banks.
  - 73 percent is held by subsidiaries with EU parents.
  - Approximately 24 percent of market share is held by Greek-owned subsidiary banks. (Data as of end-December 2014.)
  - There are 28 banks in Bulgaria (excluding one recently failed bank), of which 6 are branches.
  - Banking establishments from outside the EU represent less than 1.5 percent of the banking system.
- 2014 stress events:
  - Stress emerged in June 2014 with two bank failures following runs on deposits; the BNB put two banks into conservatorship.
  - A third domestic bank experienced a depositor run and was supported by emergency liquidity (state aid approved by the EC).
  - Bulgaria operates a currency board arrangement (CBA) introduced in July 1997; the BNB’s Lender of Last Resort function is limited to excess coverage of the arrangement.
- System-wide capital and liquidity:
  - Capital adequacy has been calculated under the EU Capital Requirements Regulation since January 2014.
  - As of December 2014, the system CAR stood at 22 percent, and the Tier 1 capital ratio was 19.9 percent.
  - The system wide CET1 ratio was 19.5 percent.
  - The BNB imposed the capital conservation buffer of 2.5 percent since May 2014 and applied a capital buffer for systemic risk of 3 percent of total risk weighted exposures located within the country calculated in accordance to Article 92 (3) of Regulation 575/2013/EC.
  - Reported liquidity indicators are strong: the liquid assets-to-liabilities ratio in the banking system, as at end January, reached 31.8 percent.
  - The EU equivalent of the Basel Liquidity Coverage Ratio (LCR) was not yet fully in force and would not be until October 2015 according to the EU timetable; the BNB maintained its prior liquidity regime requiring banks to avoid maturity mismatches over a range of maturity bands and used daily reporting for monitoring.
- Non-performing loans:
  - Reported system wide gross NPLs, excluding the failed bank, stood at 18.1 percent as of end-September 2014, representing an increase of 15 percent of total loans since the global financial crisis began in 2008.

### PRECONDITIONS FOR EFFECTIVE BANKING SUPERVISION
- The document begins the section titled "PRECONDITIONS FOR EFFECTIVE BANKING SUPERVISION" following the institutional overview; detailed content of this section continues beyond the supplied excerpt.

*International Monetary Fund / World Bank Detailed Assessment (March 2015) — INTRODUCTION section*

### 21.      Bulgaria’s supervisory credibility came under scrutiny in 2014, following the banking

### _cr15295 - 21.      Bulgaria’s supervisory credibility came under scrutiny in 2014, following the banking

### Overview
- Bulgaria experienced banking failures in 2014 that undermined supervisory credibility and led to a sharp deterioration in the fiscal stance.
- Political turbulence and unaddressed governance issues increased concerns about macroeconomic and financial policy direction and strained the economic outlook.
- The currency board arrangement (CBA) has served as an effective policy anchor since 1997; under its rules the aggregate amount of the Bulgarian National Bank’s monetary liabilities may not exceed the equivalent in Bulgarian levs of the gross foreign exchange reserves. The Bulgarian lev is fixed to the euro (BGN 1.95583 equals €1).

### Institutional and Legal Setting
- Supervision responsibilities:
  - BNB: banks.
  - Financial Supervision Commission (FSC): non-banks and markets.
- FSC established on March 1, 2003 under the Financial Supervision Commission Act; reports to the National Assembly; responsible for regulation and supervision of the non-banking financial sector (markets, insurance, pensions).

### Financial Stability Coordination (FSAC)
- The BNB, FSC, and Ministry of Finance cooperate within the Financial Stability Advisory Council (FSAC), established under the Financial Supervision Commission Act (FSCA).
- FSAC composition: Minister of Finance, Governor of the BNB, Chairman of the FSC.
- FSAC features:
  - Established initially in 2003; enhanced in 2010 via FSCA amendments.
  - Chairs: Minister of Finance; adopts Rules on its Operation; takes decisions by consensus.
  - Functions: advisory and coordination, exchange of information, assessment of financial system status, prevention and management of financial crises, approval of a national action plan in event of crisis.
  - Meets quarterly (or more frequently) and is supported by a standing committee.
  - Discusses proposals arising from ESRB recommendations or warnings.

### Macro‑prudential Responsibilities and Analytical Capacity
- BNB: responsible for assessment of systemic risks facing the banking system; analytical input from the Macro-prudential Supervision and Financial Stability Directorate (created in 2014 through merger of two units).
- FSC: responsible for non-bank financial sector systemic risk assessment.
- Directorate objectives: achieve synergies between financial stability and prudential supervision; align with EU supervisory architecture and ESRB recommendations.

### Public Infrastructure: Legal and Judicial Framework
- Company law and business legislation:
  - As an EU member, subject to EU First, Second, Fourth, Seventh, and Eighth Company Law Directives; Transparency Directive; IAS Regulation; Banks and Insurance Accounts Directives.
  - European Commission monitoring (January 2012): Bulgaria had notified and been examined on implementation of 90 percent of applicable Company Law and Anti-Money Laundering Directives.
  - Prevailing national laws cited: Commerce Act, Bank Bankruptcy Act, Obligations and Contracts Act, Consumer Protection Act, Ownership Act, Consumer Credit Act.
- Judiciary:
  - Formally independent per Constitution (Article 117); independent budget; Judiciary System Act Article 7 guarantees fair and open trial.
  - External perceptions: 2015 EU Justice Scoreboard indicates perceived independence of justice in Bulgaria decreased; Bulgaria jointly shares the worst rating in the EU.
  - Global Competitiveness Report 2014-15 rankings: 126th out of 144 on judicial independence, 124th on efficiency of legal framework in settling disputes and challenging regulations, 110th on protection of property rights.
  - Government actions: new judicial strategy adopted December 2014; preparing amendments to the Judicial System Act.
- Administration of justice:
  - Three-instance system for civil, criminal, administrative cases; governed by the Judicial System Act.
  - Supreme Judicial Council: highest administrative authority for judiciary management and independence.
- Legal professions and prosecution:
  - Public prosecution structure includes the Prosecutor-General and National Investigation Service; Prosecutor-General appointed/removed by the President on proposal from Supreme Judicial Council for a period of seven years, not eligible for a second term.
  - Prosecutors acquire tenure after five years subject to positive appraisal.
  - Investigators are magistrates; investigative bodies include NSlS, provincial investigation departments, and Specialized Prosecutor's Office.
  - Judges acquire tenure after five years by decision of the Supreme Judicial Council.
  - Attorney-at-law governed by Constitution and Bulgarian Bar Act; Supreme Bar Council maintains register of attorneys-at-law.
  - Registration judges perform property register functions and act only in their district.

### Accounting, Auditing, and Financial Reporting
- Accounting standards:
  - Listed EU companies must prepare consolidated accounts under IFRS.
  - Bulgaria has applied IFRS since 2003; listed companies, banks, insurance companies, mutual funds, and other financial institutions required to prepare consolidated financial statements using IFRSs since 2003.
  - Obligation to report consolidated and individual company financial statements in place since 2005.
  - National Financial Reporting Standards for SMEs apply to entities under de minimis criteria; such entities may adopt International Accounting Standards.
  - All credit institutions subject to International Accounting Standards regardless of listing status.
- External audit framework:
  - Annual financial reports of banks subject to independent financial audit under the Law on Accountancy; audit must follow ISA’s and the Law on Independent Financial Audit.
  - Audits of public financial reports conducted per International Auditing Standards (Article 2 of Law on Independent Financial Audit).
  - Annual financial statements and supervisory reports under LCI subject to audit and certification by a specialized auditing company registered under Law on the Independent Financial Audit.
  - Commission for Public Oversight on Statutory Auditors (CPOSA) established in compliance with Directive 2006/43/EC.
  - Registered Auditors: protected title; statutory audit and consulting services reserved to Registered Auditors.
  - 2011 statistics: over 600 qualified professionals and over 90 specialist auditing companies; new trainees accepted at approximately 150 per year.
  - Auditor qualification: pass professional exams and two years’ professional experience as assistant auditor.
  - Institute of Certified Public Accountants responsible for registration of auditors.

### Payment, Clearing, and Securities Settlement Systems
- BNB responsibilities: assist in establishment and oversee functioning of efficient payment systems and supervise payment system operators under the Law on the Bulgarian National Bank (LBNB).
- Systems and chronology:
  - BISERA (Banking Integrated System for Electronic tRAnsfers) introduced in 1992 for customer transfers settled at a designated time.
  - BISERA7-EUR (ancillary system for interbank client payments in euro) put into operation in 2010 and joined TARGET2 on February 1, 2010.
  - TARGET2-BNB national component launched on February 1, 2010. Membership of TARGET2 not yet mandatory as Bulgaria is not yet a Eurozone member.
  - BORICA (Bank Organization for Payments Initiated by Cards) established in 1995 for card payments.
  - Government Securities Depository (GSD) established in 1992; Central Depository AD (CDAD) in 1996.
  - RTGS system RINGS launched in June 2003 providing final settlement for all payments.

### Framework for Crisis Management, Recovery, and Resolution
- Existing legal framework (pre-BRRD transposition) had essential weaknesses and did not grant authorities sufficient scope for effective crisis management; collapse of Corporate Commercial Bank AD (KTB) in 2014 revealed major weaknesses, including absence of a good bank/bad bank option.
- BNB powers pre-transposition:
  - Can subject problem banks to special supervision regime.
  - Governing Council appoints conservators who take measures under BNB authority to redress the bank.
  - If conservatorship fails to improve solvency or liquidity, BNB can withdraw license and petition court for bankruptcy proceedings.
- Transposition of BRRD (EU Directive 2014/59/EC) into Bulgarian legislation expected to provide a recovery and resolution framework through amendments to the Law on Credit Institutions, the Law on Bank Bankruptcy, and the Law on the BNB.
  - At time of assessment it was expected BNB would be designated as Resolution authority and BDIF as Resolution fund.
  - Transposition in progress and expected to come in force by end of 2015.3

### Adequacy of Systemic Protection (Public Safety Net)
- Bulgarian Deposit Insurance Fund (BDIF):
  - Established by 1998 Law on Bank Deposit Guarantee.
  - Protects depositors’ funds in banks up to BGN 196,000 (EUR 100.000) and creditors’ interests in bank bankruptcy proceedings.
  - Entering transition phase amid revision of the law on bank deposit guarantee and BDIF transposition to EU Bank Recovery and Resolution Directive.4
  - BDIF expects more powers regarding funds management and new approaches for banks’ contribution calculation; new law to address weaknesses revealed by KTB crisis, including facilitating timelier payout of insured deposits.5
  - BDIF processed claims of 104,640 depositors of KTB through nine participating banks for a total amount of BGN BGN 3,5 billion (EUR 1.7 billion).

### Key Findings and Issues
- Supervisory credibility weakened in 2014 following bank failures; fiscal stance deteriorated.
- CBA remains key policy anchor but relies on sound macro-financial policies and buffers and progress on EU convergence.
- Institutional arrangement for financial stability comprises BNB, FSC, and FSAC with defined roles but FSAC decisions are by consensus and largely advisory.
- Significant legal and operational gaps existed in crisis management and resolution prior to BRRD transposition; legislative changes underway.
- External perceptions of judicial independence and efficiency are weak, with poor rankings in international indicators.
- Strong adoption of IFRS and established audit oversight (CPOSA) but capacity and market perceptions vary.

*International Monetary Fund — Bulgaria Financial System Assessment as provided in the source content*

### 40.      Transparency in banks’ ownership structures is a reducing concern. The Banking

### 40.      Transparency in banks’ ownership structures is a reducing concern.

### Findings on ownership transparency
- The Banking Supervision Department of the BNB expressed doubts on transparency in a few banks, including one in which three companies with qualifying shareholdings were located in off-shore centers with undisclosed UBO.
- Further analysis was performed to collect information to establish the true identity of the beneficial owners and lift any reservation about the transparency of the institutions.
- The BNB told the mission that it is confident about the transparency of ownership structure in banks.

### BNB actions and due diligence
- The BNB has fostered its due diligence by sending every year a letter requesting shareholders (holding more than 3 percent of share or voting rights) to confirm information about:
  - their business,
  - type of investments (shares, bonds),
  - audited financial statements.
- The BNB conducted further analysis to establish the true identity of beneficial owners where concerns existed (for example, qualifying shareholders located in off-shore centers with undisclosed UBO).

### Related supervisory context (from the same section)
- The Internal Manual on Banking Supervision Process sets the governing structure of the Banking Supervision Department and describes responsibilities of separate directorates.
- Supervision and monitoring over the implementation of the AML/CFT requirements is placed under the oversight of both the BNB and the Financial Intelligence Directorate (FID) [the Financial Intelligence Unit located within the State Agency for National Security (SANS)]. The primary responsibility for the supervision of AML/CFT measures for banks rests with FID-SANS, but the BNB is also empowered to conduct on-site AML inspections either on its own—through its Special Supervision Directorate within the Banking Supervision Department (BSD)—or jointly with the FID.
- The Special Supervision Directorate (SSD) was originally established for AML/CFT supervision only but has been assigned additional activities including transparency of products related issues and compliance with deposit insurance rules to be performed together with AML.
- Employees of SSD are frequently asked to assist law enforcement authorities and Bulgarian Courts in investigations of ML cases.

### Ancillary note from the document
- The Bulgarian Law on Bank Deposit Insurance uses the withdrawal of a bank’s license as the only trigger for pay-out of guaranteed deposits. Both the European Commission and the European Banking Authority have claimed that this situation is in breach of the EU Deposit Guarantee Scheme Directive (DGSD).

*Source: _cr15295 - 40. Transparency in banks’ ownership structures is a reducing concern.*

### conclusion that these activities should continue to be addressed efficicently by ensuring additional

### _cr15295 - conclusion that these activities should continue to be addressed efficicently by ensuring additional

### EC3 — Supervisor powers to set/enforce prudential standards
- Legal framework: LBNB and LCI provide main general framework for supervisor to set and enforce prudential standards for banks and banking groups.
- Legal basis for pillar II type measures: LCI art. 79 (c) and art. 103 (2); LCI art. 103 (2) (subparagraph 5) allows the BNB to impose additional capital and/or liquidity requirement based on risk to which the bank is exposed or risks the bank poses to the financial system.
- Deputy Governor (DG) authority: LBNB art. 20 (3) empowers the Deputy Governor to “apply, separately and at his own discretion, the actions and penalties as provided for by law” on Credit Institutions — inference that DG can subject banks to increased prudential obligations based on risk profile.

### EC4 — Updating laws, regulations and public consultation
- Reforms since 2008: Legal and regulatory framework updated several times; most prominent changes relate to EU Regulations.
- EU instruments cited: EU Directive 2013/36, EU Regulation No575/2013 entered into force on January 1, 2014.
- Bulgarian ordinances and law changes: Led BNB to issue Ordinance No7 on the Organization and Risk management in Banks and Ordinance No8 on the Formation of Capital Buffers; amendments to Ordinance No4, Ordinance No11, Ordinance No20 and the Law on Credit Institutions (LCI) published in the State Gazette on March 25, 2014.
- Ordinance changes and notable item: The most significant change in Ordinance No4 refers to the implementation of a requirement to the size of the variable elements in the remuneration not to exceed 100 percent of the size of the constant elements in the total remuneration.
- Consultation practice: BNB generally consults on draft regulations (e.g. ordinance) with “unofficial” consultations with the Association of Banks in Bulgaria; no legal obligation to do so. For EU transposition, MoF sets up inter-institutional working groups involving BNB, Banking Association, FSC and other stakeholders.

### EC5 — Access to banks, consolidated/group supervision, foreign banks
- (a) Access powers: LBNB art. 4 (1) empowers BNB to “demand from banks to submit any documents and information, and may also carry out the requisite examinations.” LCI art. 80 (1) and art. 80 c grant broad powers including on-site inspections, free access to premises and information systems, demand documents, attend meetings of managing and controlling bodies and record opinions in minutes.
- (b) Consolidated supervision: LCI art. 89 (1) empowers BNB to carry out supervision on a consolidated basis over banks, banking groups, financial holding companies, mixed financial holding companies and mixed holding companies; parent and subsidiaries required to implement arrangements, processes and mechanisms and produce relevant data.
- (c) Foreign banks: Foreign banks incorporated in Bulgaria are subject to the same degree of regulation and supervision; locally incorporated operations of foreign banks are treated as local banks.

### EC6 — Corrective actions, sanctions, license revocation, resolution cooperation
- (a), (b), (c): LCI art. 103 (1) sets out measures BNB can take when banks do not comply; art. 103 (2) sets out administrative sanctions including written warnings to revoking the licence. BNB can dismiss individuals authorized to manage and represent the bank and members of management/supervisory boards; power does not extend clearly to other key staff (risk officers, Compliance, RM, AML and credit Officers).
- Limitation: LCI, Art. 103 (2) empowers BNB to change bank’s internal rules and procedures but not its internal organization or structure — assessors view changing internal organization/structure as an important power to have.
- Special Supervision: LCI art. 115 allows BNB to establish special supervision if bank is “at risk of insolvency”; a conservator appointed for 6 months. Example: June 2014 decisions to place Corporate Commercial Bank AD (‘KTB’) and Victoria Commercial Bank EAD (‘VCB’) under conservatorships and special supervision for a period of three months.
- Fines: BNB can impose fines under art. 152 of the LCI.
- (d) Resolution powers: Art. 121a LCI empowers BNB to prepare a plan for “orderly resolution of each bank, licensed in the Republic of Bulgaria, which might be applied if the bank is in financial difficulties.” However, post-KTB collapse in 2014, resolution regime exhibited major weaknesses. Bulgaria is in the process of transposing the EU Bank Recovery and Resolution Directive (BRRD) into national law; final transposition of BRRD framework for banks is set to August 2015.
- Consequence: Conditions for cooperation and collaboration with relevant authorities for orderly resolution are still to be determined and implemented.

### EC7 — Supervisory review of parent and affiliates
- BNB empowered to carry out consolidated supervision and has free access to all relevant information to determine impact of parent and affiliated companies on bank safety and soundness.

### Assessment of Principle 1
- Largely Compliant.

### Comments and recommendations (Principle 1)
- SSD duties and mandate:
  - SSD originally for AML/CFT supervision but now has additional responsibilities including transparency of products, monitoring consumer trends and oversight of deposit insurance compliance; SSD staff frequently assist law enforcement and courts in ML investigations.
  - Recommendation: Refocus the Special Supervision Directorate on its core AML mandate by assigning non-AML related activities to other relevant BNB departments.
  - Recommendation: Consider renaming the department to avoid confusion with “special supervision” regime.
- Enforcement powers:
  - BNB has broad supervisory tools under LCI Art. 103 (2) including administrative compulsory measures and penalties; can force change of internal rules and procedures but not internal organization or structure.
  - Recommendation: Explore possible amendments to the LCI to provide the BNB with additional powers including the possibility to impose changes in banks’ internal organization and structure.

### Principle 2 — Independence, accountability, resourcing and legal protection
- EC1: Governance and operational independence
  - BNB governed by Governing Council composed of Governor, three Deputy Governors and three non-executive members (Law of the BNB Art 19; Art 12 Law on BNB).
  - Each Deputy Governor responsible for one of the three “basic” departments; Deputy Governors proposed by Governor and elected by National Assembly for a term of 6 years.
  - Deputy Governor heading Banking Supervision exercises supervision (Article 20(3) Law of the BNB); Deputy Governor may delegate authority.
  - Article 151 (1) LCI: Governor and Deputy Governor jointly present to Governing Council decisions on license, revocation or appointing a conservator or placing a bank into special supervision.
  - At assessment time, Deputy Governor with responsibility for supervision had been dismissed by National Assembly on 21 January 2015; LBNB does not address sudden unavailability contingencies.
- EC2: Appointment/removal transparency
  - Deputy Governor proposed by Governor, elected by National Assembly (Art 12(1) LBNB). Governing Council members must be persons of highest integrity and qualifications (Art 11(3), Art 11(4) LBNB). Term of office of Deputy Governor heading Banking Supervision is six years (Art 12 (4) LBNB).
  - Article 14 (1) LBNB conditions for relief from office; no legal requirement for reason for dismissal to be publicly disclosed within LBNB (disclosure required under rules of procedure of National Assembly).
- EC3: Publication of objectives and accountability
  - Objectives/responsibilities set in BNB law and LCI. Performance reflected in semi-annual and annual BNB reports to Parliament; BNB annual report published in Bulgarian and English, adopted by Governing Council (LBNB Art 1 (2) and Art 51).
- EC4: Internal governance and escalation
  - Manual for the banking supervision process (dated June 2010) sets roles and functions. Manual lacks a described “four eyes” process and lacks specified rapid escalation procedures; in practice Governing Council met daily as needed during crises.
  - Permissible for a member of Banking Supervision Department to hold shares in a bank but must declare interest.
  - LBNB conflict of interest provisions for Governing Council and staff detailed (Art 11(4), Art 12(5) and (6), Art 17(4), Conflict of Interest Prevention and Ascertainment Act).
- EC5: Credibility, conflicts of interest and professional secrecy
  - Staff appointed by transparent competition; professional secrecy obligations in LCI and LBNB (Art 23(2), Art 61(2), Arts 63 and 64 LCI). Violations sanctioned under Art 152(1) LCI.
  - BNB Code of Conduct Art 9 and related provisions require declarations, avoidance of conflicts and other restrictions.
- EC6: Resources and funding
  - Funding: BNB financed mainly by revenues from its currency reserves operations; annual budget approved by Governing Council and published (LBNB Art 51). BNB has full discretion on internal re-distribution of its own budget and the ceiling of its expenditures.
  - Salary scales: Remunerations determined by Governing Council but cannot be lower than average remunerations of employees with respective functions in other banks (Art 23(3) LBNB). Salary scales not differentiated for supervisory staff. Recruitment/retention challenges noted.
  - External experts: BNB has right to appoint external independent experts and external auditor for a bank (Art 80(3)(3) and (4) LCI); professional secrecy applies.
  - Training: Manual requires directorates to identify training needs and budget annually; no formal individualized skills-gap process.
  - IT: Project in train to enhance IT tools to address changes from CRR and CRDIV; project aimed at replacing lost functionality rather than introducing new developments.
  - Travel: Budgeting processes exist but limited numbers sometimes prevent attendance at all EU legislative meetings; BNB met commitments for supervisory cooperation and colleges.
- EC7: Skills planning
  - Annual planning includes training needs but no formal process to map skills gaps or individual development plans.
- EC8: Risk-based allocation
  - Frequency and intensity of inspections depend on size, systemic importance, volume and complexity; annual supervisory plan updated and adaptable.
- EC9: Legal protection
  - BNB, its bodies and persons authorized are not liable for damages in exercising supervisory functions unless they have acted with intent (Art 79(8) LCI).
  - Governing Council can decide to cover legal costs case by case; precedent decision covers costs of Governing Council members, including Deputy Governors; no formal decision yet taken for other staff.

### Assessment of Principle 2
- Materially Non Compliant.

### Comments and key concerns (Principle 2)
- Internal governance concern:
  - Concentration of supervisory enforcement powers in single individual (Deputy Governor for supervision) creates risks: lack of internal checks and balances, potential inconsistency, susceptibility to undue pressure, and absence contingency for sudden unexpected unavailability.
  - Governing Council issues regulations but is at arms length from most supervisory decision-making; insufficient mechanisms for timely transparency, scrutiny, or challenge of Deputy Governor decisions.
- Resources and skills:
  - Resources insufficient for effective supervision given increased demands from international regulatory reform; budget envelope for supervisory function largely static over last 5 years leading to constraints on staff numbers, training and IT capabilities.
  - Noted lack of specialist skills: IT and quantitative skills.
  - IT project limited to reinstating lost functionality; recommendation for more ambitious integration of quantitative and qualitative databases.
  - No formal mapping of skills needs; recommendation to carry out skills mapping and strategy.
- Legal protection:
  - Only Governor has explicit option to challenge dismissal at the European Court of Justice (Art 3(4) LBNB); Deputy Governors do not have this option.
  - BNB has safeguards but coverage of legal costs for staff lacks formal policy.

### Recommendations (Principle 2 and related)
- Revise internal governance design of the BNB for banking supervision, through legal amendment as necessary, to ensure that significant powers are not vested in a single individual. Ensure clear checks and balances in decision making processes, including transparency and challenge processes. Ensure that the absence or unavailability of any one individual will not prevent the full and effective use of all of the BNB’s supervisory powers.
- Ensure that the Governing Council is supplied with timely information in respect of major developing supervisory issues including advance information on any changes of control or corrective actions, so that it is well placed if becomes necessary to make major decisions at critical junctures – including licensing, revocation, conservatorship and issuance of prudential regulation.
- Increase resource allocation to banking supervision to: ensure sufficient skilled personnel available to conduct a full program of on-site inspections; ensure sufficient representation of skill-sets, including IT, quantitative and models analysis and IFRS - training and recruitment will both be needed.
- Upgrade the IT capability available to supervisory staff so that they can effectively and efficiently make use of the range of data and information that is submitted to the BNB. This upgrade should be more than replacing functionality that was lost due to the regulatory changes.
- Carry out a mapping of the skills that are needed in its supervisory process, taking into account the fact that the nature and volume of demands required in supervision are continuing to increase and evolve, not least as a result of the international regulatory reform agenda. Identify a clear current and projected assessment of any skills gaps and put in place a strategy to address such gaps.
- Ensure that the reasons for the dismissal of the Governor and the Deputy Governor are publicly disclosed, ie on a mandatory not discretionary basis.
- Ensure that the BNB will cover the legal costs faced by a staff member should a lawsuit be brought against the staff member.

*Source: _cr15295 - conclusion that these activities should continue to be addressed efficicently by ensuring additional*

### part in these inspections. Conversely, the BNB can make the same request and ask the Host authority

### _cr15295 - part in these inspections. Conversely, the BNB can make the same request and ask the Host authority

### Cross-border cooperation and consolidated supervision
- BNB empowered to sign written coordination and cooperation arrangements with competent supervisory authorities of Member States (LCI, art. 87 and 92).
- BNB may take responsibility for additional supervisory tasks by agreement with competent authorities of Member States; conversely, BNB may delegate to the parent supervisor responsibility for supervising a Bulgaria-licensed subsidiary controlled by a credit institution in another Member State.
- For consolidated supervision, BNB has signed MOUs with competent authorities of: Austria, Cyprus, Greece, Italy, The Netherlands, Slovenia, France, Romania, and Hungary.
- BNB is the host authority for 9 subsidiaries and one significant branch; BNB has signed multilateral agreements based on the EBA Template and participates in 10 Supervisory Colleges.
- Supervisory Colleges (SCs) used to collect information on groups’ structure and shareholdings; BNB used SCs to request recovery plans from home supervisors for two foreign banks that had not accommodated BNB requests.
- Cross-border cooperation provisions in LCI also address:
  - addressing situations of disagreement with measures taken by other NCAs,
  - sending alerts to other relevant NCAs regarding insufficient liquidity,
  - how to undertake on-site inspections in the relevant country,
  - how to determine fines with the home/host authority if a local foreign branch is significant,
  - how to exchange regular information or information on measures imposed on significant branches (See Art. 87, paragraphs 3 to 13, and articles 87a to 87d of LCI).
- A reviewed cooperation agreement included provisions on authorization and licensing, ongoing supervision of cross-border establishments, on-site inspections, financial crime, exchange of information in emergency situations, corrective actions, confidentiality requirements, requests for additional information, ongoing coordination, visits for information purposes, and exchange of expert staff.

### Regional cooperation and cooperation with non-EU countries
- LCI Art. 88: BNB may conclude agreements with other central banks or supervisory authorities of third countries on cooperation and information exchange on a reciprocal basis, committing to keep bank and professional secrecy.
- Memoranda of Understanding signed with third countries, e.g., Turkey, Kosovo, Macedonia, Albania, and other South Eastern Europe countries.
- Bulgaria is a member of the Group of Banking Supervisors from Central and Eastern Europe (BSCEE); BSCEE members include: Albania, Austria, Belarus, Federation of Bosnia and Herzegovina, Bulgaria, Croatia, Czech Republic, Estonia, Hungary, Latvia, Lithuania, Macedonia, Montenegro, Poland, Romania, Russia, Serbia, Slovak Republic, Slovenia, Ukraine, and Moldova.
- Bulgaria is a member of the South Eastern Europe Initiative (members e.g., Albania, Armenia, Greece, the Federation of Bosnia and Herzegovina, Cyprus, Georgia, Moldova, Montenegro, Macedonia, Romania, Serbia); an MoU among members includes provisions on information exchange, convergence of supervisory practices, monitoring banking groups’ systems and controls, crisis management, cooperation in the field of AML/CFT and confidentiality requirements.
- Existing multilateral and regional arrangements aim to promote cooperation, information exchange, supervisory technique sharing, and integration into the European banking supervisory system.

### Confidentiality and information exchange (EC3 and EC4)
- LCI defines professional secrecy (Art. 63 (1)) distinct from bank secrecy (art. 62); professional secrecy applies to information the BNB obtains or generates for banking supervision whose disclosure could damage commercial interest or reputation.
- Conditions under which professional secrecy can be lifted are strictly defined; BNB staff can share information with: Bulgarian Deposit Insurance Fund, State National Security Agency (in particular for AML/CFT purposes), liquidators of banks in bankruptcy proceedings, auditors of credit institutions, and other relevant counterparties.
- LCI describes conditions for sharing confidential information with foreign counterparties and supervisory authorities, including authorities responsible for oversight under bankruptcy, liquidation or similar proceedings, deposit-guarantee scheme administrators in Member States, the ECB, and the European Systemic Risk Board (ESRB).
- Conditions for providing information to non-EU supervisory authorities (Article 66 items 1-4 and Article 88 - LCI):
  - (i) conditions for exchange are stipulated in an agreement for cooperation;
  - (ii) recipient ensures at least the same level of protection of information as provided in the LCI;
  - (iii) recipient is authorized and agrees to provide information of the same type to the BNB, where needed;
  - (iv) information exchange is intended for supervisory purposes; and
  - (v) recipient has justified the needs for the requested information.
- Persons and bodies empowered to request/receive professional secrecy must keep it confidential and may use it only for the purpose for which it was requested or provided, according to law or agreements.
- Art. 65: BNB staff shall use information received from Member States’ competent supervisory authorities only for:
  - (i) to check if conditions for granting a bank license have been met,
  - (ii) to facilitate supervision on a consolidated or solo basis (monitor liquidity, solvency, large exposures, managerial and accounting procedures, internal control mechanisms),
  - (iii) to apply measures and sanctions in accordance with this Law, or
  - (iv) in proceedings for appeal against administrative acts of the BNB in administrative or judicial procedures.
- Confidential information may be provided by the BNB to Member States’ competent supervisory authorities, ESRB, EBA, and ESMA as long as those authorities are also bound by professional secrecy.
- Art. 65(3): information from a foreign body may be disclosed or provided only with express consent of the competent body which provided the information and, where applicable, only for the purpose for which consent was given.
- On-site examination information obtained in a Member State may not be provided without the express written consent of the competent supervisory authority of that Member State.
- Where the supervisor is legally compelled to disclose confidential information received from another supervisor, the supervisor promptly notifies the originating supervisor, indicating what information it is compelled to release and the circumstances; where consent to passing on is not given, the supervisor uses all reasonable means to resist or protect confidentiality.

### Recovery and resolution (EC5)
- Bulgaria has not yet developed a single legal framework for recovery and resolution of credit institutions and has not established a Resolution authority.
- When the Bank Recovery and Resolution Directive (BRRD, 2014/59/EU) is transposed into domestic law, Bulgaria will have processes allowing resolution authorities (likely the BNB) to undertake recovery and resolution planning and actions, as required by EC5.
- The authorities confirmed this point during a meeting with the MoF.

### Assessment of Principle 3 and key comments
- Assessment: Largely Compliant.
- Key observations:
  - BNB can exchange information and cooperate effectively with home supervisors over Bulgaria-based subsidiaries of foreign banks via bilateral MOUs; adequate information sharing arrangements exist with relevant domestic authorities.
  - Some MoUs are outdated or pending revision:
    - The MoU with the Financial Intelligence Agency (FIA) signed in 2003 has not been revised after the FIA was transformed into the Financial Intelligence Directorate (FID) within the State Agency for National Security (SANS) pursuant to the Law on State Agency for National Security (LSANS) in 2008; a revised draft has been in preparation for three years and authorities are encouraged to finalize it.
    - The cooperation mechanism between BNB and BDIF was signed in November 1999 and is outdated; a new draft law is being prepared to transpose EU directive 2014/49 on deposit guarantee schemes, and once BRRD is enacted BDIF will exercise new responsibilities as Resolution Fund while BNB will likely be designated resolution authority, warranting thorough revision of the MoU.
  - Commission for Public Oversight on Statutory Auditors (COPSA) established following amendments of the Independent Financial Audit law adopted in June 2008; establishing cooperation and information-sharing mechanisms between BNB and CPOSA would be beneficial.
  - No formal mechanism of cooperation between the BNB and the MoF particularly for bank resolution; enactment of proper legal regime for bank resolution, designation of an official resolution authority, and development of procedures are required.
  - Financial Stability Advisory Council (FSAC) actions:
    - FSAC approved members of the Permanent National Standing Group on Financial Stability in March 2011 and entrusted it with developing a National Financial Crisis Action Plan; in July 2011 FSAC approved the plan.
    - During the KTB crisis in June 2014, BSD’s actions—activation of daily reporting framework and continuous analysis—were in accordance with the plan’s main provisions.
- Authorities are satisfied with current cooperation quality and effectiveness, but improvements are needed in the areas noted above.

### Recommendations issued by assessors
- Establish mechanisms for cooperation between the BNB, the MoF and other financial institution regulators to undertake recovery and resolution planning.
- Speed up the revision of the MOU with the Bulgarian Deposit Insurance Fund.
- Finalize the new MoU between the BNB and the Financial Intelligence Unit.
- Cooperate with the Commission for Public Oversight on Statutory Auditors (CPOSA), in particular on policy issues or information that is publicly available, and sign an MoU in due course.

### Permissible activities and licensing (Principles 4 and 5)
- Principle 4 (Permissible activities) assessment: Compliant.
- EC1 (Definition of "bank"): LCI (art. 2) defines a bank as a legal entity accepting deposits or their equivalents (other repayable funds) and extending loans and other financing on its own account and risk; LCI also uses "credit institution" versus "financial institutions" (LCI, art. 3).
- EC2 (Permissible activities): Art. 2, subparagraph2 lists permissible financial activities, including ancillary/supplemental; Art. 5 states a bank may not engage in financial activities not included in the authorization; BNB Ordinance No2 on Licences, Approvals and Permissions specifies license confers right to conduct only specified activities; Special Supervision Directorate conducts inspections for unauthorised banking activities.
- EC3 (Use of the word "bank"): Art. 6 (1) states no one shall use the word 'bank' or derivative without a banking license; Art. 6(3) stipulates a bank’s name may not resemble the name of another bank operating in the Republic of Bulgaria.
- EC4 (Taking deposits reserved): Art. 2 (5) sets that taking deposits from the public can be carried out only by:
  - (i) a person granted a bank license by the BNB;
  - (ii) a bank with a seat in a third country granted a license by the BNB to conduct bank activities through a branch in the Republic of Bulgaria;
  - (iii) a bank authorized by the competent authorities of a Member State to carry out bank activities, providing services in the Republic of Bulgaria directly or via a branch.
- EC5 (Public list of licensed banks): Licenses recorded in a register (Article 15, para 5 of the LCI); BNB maintains a list of current licensees accessible on its website (BNB http://www.bnb.bg).
- Principle 5 (Licensing criteria):
  - Assessment of licensing authority: LCI (art. 13) grants BNB exclusive right to issue bank licenses; BNB may reject applications if criteria in law or BNB Ordinance No 2 are not fulfilled or if information is inadequate (art. 16); BNB can issue limited licenses.
  - Initiation for granting a license is joint competence of the Governor and Deputy Governor: art. 151, para. 1 requires a motion presented by the Deputy Governor in charge of Banking Supervision Department, jointly with the Governor, to the BNB Governing Council for issuance, rejection or revocation of a license.
  - Power to withdraw license belongs to the Governing Council; LCI art. 36-38 sets withdrawal conditions including insolvency, unsound practices, license obtained on false information, failure to commence operations within twelve months after license, no longer meeting license conditions, or not ensuring security of entrusted assets.
  - Example: In November 2014 the BNB revoked the license of the Corporate Commercial Bank on the ground that external audit reports indicated the institution had a negative own capital.

*Source: _cr15295 (excerpt).*

### 3.75 billion levs ($2.4 billion/1.9 billion euro) as of September 30, and no longer met the relevant

### _cr15295 - 3.75 billion levs ($2.4 billion/1.9 billion euro) as of September 30, and no longer met the relevant

### Licensing authority powers and legal framework (EC2)
- Laws and regulations give the licensing authority the power to set criteria for licensing banks; the licensing authority can reject an application if criteria are not fulfilled or information is inadequate, and can revoke a license if it was based on false information.
- Criteria for licensing banks are prescribed by the LCI. Art. 13, 14, 15 and 16 of the LCI set requirements to obtain authorization for banking business.
- The law grants the BNB power to set additional requirements and necessary information to be provided while applying for a banking license. Relevant provisions are also in BNB Ordinance No2.
- Key information applicants must provide:
  - article of association;
  - appropriate information about fitness and propriety of administrators;
  - documents containing information on the paid in capital of the bank;
  - information about the 20 largest shareholders (name, address and professional activity over the past 5 years);
  - origin of funds for persons with subscription of 3 percent and above of the capital;
  - a business plan with exhaustive description of the activities to be performed, customer and product structure, objectives, policy and strategy of the bank, financial forecast of development over a three-year period;
  - a description of the managing and organizational structure including the activities of individual organizational units, distribution of responsibilities among managing directors and other administrators, organization and management of the bank’s information system;
  - a description of the internal control systems and the risk management systems, and a program of anti-money laundering measures;
  - the names and addresses of the members of the supervisory and management boards (board of directors) of the bank, and detailed written information concerning their qualifications and professional experience.
- Prior to delivering a license, the BNB reviews the validity and accuracy of materials provided by the applicant. Under art. 14, the license will be issued if additional conditions are met, including that:
  - the activities the applicant intends to carry out ensure the required soundness and financial stability;
  - members of the management board and supervisory board are not subject to a legal injunction to hold such a position;
  - in case of groups, the parent undertaking will not place obstacles to conducting consolidated supervision;
  - there is no evidence that the existence of close relations between the bank and other persons can hinder the efficient exercise of banking supervision.
- The LCI allows the BNB to reject an application with incomplete, contradictory or unreliable information. Example: one rejection in 2008 due to lack of key information (criminal records and professionalism). Over the past five years, one license was revoked (decision of the GC dated November 6, 2014) due to the insolvency of the institution.
- The BNB can issue a limited license and limit the scope of activities if the applicant is not prepared to carry on all planned activities.
- There is no formal mechanism (no written procedures) for a follow-up inspection visit to newly established banks to ascertain compliance with license terms and conditions.
- Administrative responsibilities: the Legal Services and Administration Directorate (LSA) carries out administrative activities related to issuing licenses, approvals, maintaining license files and data about the current status of banks and registers, and passportisation when notified by an EU Member State. Three staff of the LSA are assigned to these activities and they cooperate with the Credit Institution Supervision Directorate and the Special Supervision Directorate (for checks on shareholding structure and UBO determination).

### Consistency between licensing criteria and ongoing supervision (EC3)
- Necessary requirements for licensing are broadly consistent with those applied in ongoing supervision.
- Criteria include complying with shareholding limits; executives (including Board members) meeting fit and proper criteria; the entity meeting prudential standards; having adequate internal control and risk management systems; and adequate human resources.

### Legal, managerial, operational and ownership structures; consolidated supervision (EC4)
- The LCI, BNB Ordinance No2 on Licenses, Approvals and Permissions, and Ordinance No20 on the Issuance of Approvals to the Members of Board of Directors and Supervisory Board enable the BNB to determine that proposed legal and managerial structures will not hinder effective supervision on a solo and consolidated basis.
- The BNB vets organizational structure during licensing, including management structure, capacity for sound risk management and internal control systems, and reviews the business plan (including three-year financial forecast).
- The BNB examines suitability of shareholders (3 percent sharing and above) and their links to related parties, paying attention to:
  - persons with significant shareholdings not hampering bank safety and soundness by activities or influence;
  - absence of close relations that would hinder efficient exercise of banking supervision.
- For consolidated supervision the BNB verifies:
  - the applicant’s charter does not contain provisions hindering corporate management principles and best practices;
  - the parent undertaking (financial holding company, mixed financial holding company or mixed holding company) will not place obstacles to conducting consolidated supervision;
  - third country regulations or administrative acts will not impede efficient conduct of banking supervision.
- LCI art.24 on mutual recognition: where a bank with a seat in Bulgaria carries out activities in a member state or is a subsidiary or jointly owned by two or more banks licensed in Bulgaria, the BNB shall exercise consolidated supervision and monitor shareholders’ structure following a BNB-defined procedure.
- The assessment team found no indication that the BNB determines, where appropriate, that these structures will not hinder effective implementation of corrective measures in the future.

### Identification and suitability of major shareholders and ultimate beneficial owners (EC5)
- Legal basis: LCI art. 13 (2) paragraphs 7 and 8, and BNB Ordinances No2 and No20.
- Requirements and procedures:
  - Prospective bank must provide name and address of persons who have directly or indirectly subscribed for 3 percent and above of voting shares; same information required for persons holding 10 percent or more of bank’s capital and specifically for the 20 largest shareholders (LCI art. 14 (3)).
  - BNB determines if qualification, experience (during the past five years), integrity and reliability of shareholders with significant interest are appropriate and whether they can provide additional financial support when needed.
  - Shareholders must inform the BNB in writing about the origin of funds used to acquire 3 percent and above of the capital to ascertain transparency and legitimacy and whether shareholders used their own resources to acquire holdings.
  - BNB assesses whether major shareholders’ financial capacity is commensurate with the scale and activities of the bank (Art. 14, par. 3, p. 12 of the LCI).
- For a legal entity holding 10 percent and more of voting rights, Ordinance No2 requires submission of:
  - structure of the capital and its allocation between the shareholders (partners);
  - article of association;
  - auditor’s reports and financial statement for the last three years;
  - balance sheets, income statement;
  - detailed information about the structure of the group in which the applicant participates.
- For license grants to a foreign bank, the BNB will consult the home supervisor to obtain information about the shareholders (art. 13 (6)).
- The BNB is empowered to request any additional information deemed necessary for judging suitability of shareholders with significant interest (art. 13 (2) 9).
- On indirect holdings and beneficial ownership:
  - The LCI does not provide a specific definition of UBO; art. 13 (2) subparagraph 8 requires for licensing purposes “a document of registration and written data about the persons holding shares or equity in their capital or property, or controlling them – for legal persons under item 7 [i.e., shareholders holding 3 percent and above of voting rights].”
  - Additional provisions apply where the applicant is a trust (see quoted provision beginning “In case the applicant is a trust…” in the source).

### Operational observations and historical outcomes
- All banks in Bulgaria follow a traditional universal banking model and are set up as Joint Stock Companies; there are no other types of banks (e.g., cooperative banks, mutual saving companies) in the country.
- The BNB has used its rejection and revocation powers: one application rejected in 2008 for lack of key information (criminal records and professionalism); one license revoked (decision dated November 6, 2014) due to insolvency.
- Shell banks shall not be licensed (Reference document: BCBS paper on shell banks, January 2003).

*International Monetary Fund — Bulgaria supervisory assessment (excerpts provided in source content).*

### 2. the names and addresses of the persons up to the ultimate owner who are beneficial owners of the legal entity.

### 2. the names and addresses of the persons up to the ultimate owner who are beneficial owners of the legal entity.

### UBO concept and disclosure
- The LCI has no explicit reference to the concept of UBO; the latter is captured only in the AML law.
- The LCI refers several times to the concept of indirect holdings or indirect acquisition but does not provide an explicit definition of the ultimate beneficial owner.
- Ordinance #2, art 19 (4) appears to apply only in the case where the acquisition of bank shares is done by a trust.
- The mission noted that it is not clear whether the obligation to disclose the true identity of the ultimate beneficial owner applies in case of a person applying for a license.
- Recommendation excerpt: Include in the LCI a clear definition of UBO in consonance with the definition provided by the AML law.

### Suitability, fit and proper assessments (BNB processes)
- The Legal Services and Administration Directorate performs assessment of suitability on the basis of “fit and proper” criteria for members of managing bodies of credit institutions.
- The Special Supervision Directorate (SSD) conducts detailed analysis of banks’ ownership structures and control to minimize risks related to actions of major shareholders and understand their influence on individual banks.
- SSD reports reviewed: one from 2012 assessing financial status of shareholders of a few banks; another from 2014 analyzing shareholding structure and ownership in context of the Act on the Economic and Financial Relations with Companies Registered in Preferential Tax Regime Jurisdictions, the Persons Related to Them and Their Beneficial Owners.
- SSD concerns included:
  - (i) the poor financial conditions of major shareholders (some exhibiting important losses or having no real activity at all);
  - (ii) the absence of clarity on their ultimate owners, some located in off-shore centers.
- According to BNB discussion, most –if not all– of the missing information have been collected by the SSD.

### Minimum initial capital and qualification requirements (EC6–EC9)
- EC6: The LCI y stipulates that banks must have a minimum initial capital of at least BGN 10 million (EURO 5 million).
- EC7 (fit and proper criteria):
  - Fit and proper criteria include: (i) skills and experience in relevant financial operations commensurate with the intended activities of the bank; and (ii) no record of criminal activities or adverse regulatory judgments that make a person unfit to uphold important positions in a bank.
  - BNB Ordinance No20 (28 April 2009) and LCI art. 11 establish fit and proper requirements including qualification, work experience, reputation and probity (absence of criminal background).
  - Due diligence includes assessing academic background and past professional experience (e.g., at least 5 years of professional experience as manager in a bank or in a company comparable to a bank).
  - Prospective administrators must fill the “Fitness and Propriety Test Question Form”; the form does not require information about administrator’s income and assets.
  - The Ordinance requires a written declaration that own resources have been used for subscribed shares and states origin of funds, but there is no further due diligence beyond analysis of financial statements and the written declaration.
  - There is no specific requirement for individual Board members or the Board collectively to have a sound knowledge of the material activities the bank intends to pursue and associated risks.
- EC8 (review of strategic and operating plans):
  - LCI, art. 14 (3) subparagraph 14: applicants must submit (i) a business plan with exhaustive description and financial forecast over a three-year period; (ii) organizational structure; (iii) a description of the AML internal program; and (iv) information on internal audit and risk management functions.
  - Art. 15 requires confirmation that internal control rules have been drafted, an internal control office established with qualified personnel, and sound internal management rules commensurate with bank’s operations.
  - The law does not contain particular requirement on oversight of proposed outsourced functions.
- EC9 (financial projections and principal shareholders):
  - LCI, art. 13 (2) subparagraph 3: BNB collects financial projections for the first three years of operations.
  - Qualifying shareholders (holding 10 percent and above of the capital) are assessed as to financial capacity and prospective capacity to provide additional capital (LCI, art. Art. 14, par. 3, p. 12). Each such prospective qualifying shareholder must provide financial information demonstrating an appropriate level of financial capacity (BNB Ordinance 2).

### Cross-border applicants and licensing conditions (EC10–EC11)
- EC10:
  - Bulgaria is an EU Member State; the principle of Mutual Recognition applies.
  - If applicant is licensed in a Member State and plans activities in Bulgaria through a branch, a license is not needed if activities are covered by its license and the competent authority has notified the BNB (LCI, art. 20).
  - Subsidiaries of banks from Member States follow licensing under Art. 13–15 with preliminary consultations with home supervisory authority (LCI, art. 13, par. 4).
  - Third-country (non EU-Member) banks must apply for a license before operating in Bulgaria through a branch; written consent for opening of a branch issued by the home supervision authority is a precondition (Art. 17).
  - Required enclosures for third-country applicants include: verified copy of registration certificate; verified copy of license; verified copy of the Charter; business plan; organizational structure of the branch; financial annual reports for the past three years; written consent for opening a branch by home authority; written statement of home supervisor containing information on bank’s financial status and commitment for cooperation with the BNB; data about persons entrusted with the management of the branch.
  - Additional conditions: (i) home supervisor supervises effectively the bank and its branches abroad; (ii) supervisory cooperation agreement concluded; (iii) home country legislation does not create obstacles to consolidated supervision; (iv) bank’s financial status is sound and stable; organizational structure aligned with projected activities; managers meet professional expertise and reputation requirements.
- EC11:
  - BNB is entitled to monitor progress of new entrants as it monitors all other banks and may undertake measures if bank does not meet license criteria.
  - LCI, art. 36: BNB can revoke a license if the bank fails to commence its activity within 12 months after getting the license.
  - There is no specific mechanism whereby BNB staff monitors progress of new entrants in meeting their business and strategic goals; mission suggests on-site visit right after license to assess implementation of approved business plan.

### Transfer of significant ownership and notification requirements (Principle 6, EC1–EC2)
- EC1:
  - LCI and BNB Ordinance No 2 empower BNB to approve transfers of significant ownership, lay out criteria, stipulate grounds for rejection, and describe sanctions for ownership interests gained without regulatory process.
  - Art. 28 LCI: preliminary approval of the BNB is needed when holdings of a natural or legal person, as well as persons acting in concert, reach or exceed the thresholds of 20, 33 or 50 per cent of the shares or voting rights.
  - There is no specific definition of “qualifying interest” in the law but it is understood that any acquisition of share above 10 percent provides such qualification.
  - A controlling interest is understood by BNB as ownership directly or indirectly of the majority of shares or voting rights (more than 50 percent) and de facto determination of policies or practices of the institution, or control in any way the election, appointment and dismissal of the majority of the bank’s administrators.
  - LCI applies definitions of EU Regulation 575/2013 by virtue of the Additional provisions of LCI - § 1. (1) points 6 and 7.
  - LCI does not define “significant ownership” but it is assumed any person holding 10 percent or more of the voting rights has significant ownership.
  - Definition of “action in concert” found in LCI (additional provisions (i) 4 (a)).
  - Art. 32 LCI: where a person has acquired 3 or more than 3 per cent of the shares or voting rights, the Central Depository shall notify the BNB of the person’s name and address following recording of acquisition in the book of shareholders. The acquirer is obliged to submit, at BNB request, a series of documents comparable to those required to get a license (e.g., name and address of subscribers, professional experience, origin of funds).
- EC2:
  - Ordinance No. 2, Art.18: any person intending to acquire holding in the capital of a bank must notify the BNB by submitting an application specifying whether acquisition is:
    - a primary acquisition or an increase of the holdings in the capital,
    - a direct or indirect acquisition,
    - made by the acquirer on his own, or with other persons acting in concert.
  - Applications must include data on bank shares owned, number of shares planned to be acquired and which thresholds are to be achieved and/or exceeded.
  - For indirect acquisition, data on manner of implementing planned acquisition must specify:
    - by acquiring qualifying holding or its increase in the capital of a shareholder who exercises control over the bank, or
    - by acquiring control over a shareholder owning qualifying holding in the bank.
  - For acquisitions made in concert, application must contain detailed information about legal and actual grounds of actions taken in concert with other persons.
  - Once BNB receives application for transferring significant ownership, the Legal and Administrative Directorate will perform due diligence within a timeframe of 60 days, including assessment of good standing, financial soundness and willingness to provide financial support if needed.
  - Special attention in due diligence is given to:
    - (i) whether group structure would impede implementation of prudential banking supervision;
    - (ii) absence of obstacles for exchanging information between supervisory authorities and clear distribution of responsibilities among them;
    - (iii) no reasonable grounds to suspect money laundering or terrorist financing activity.

### Assessment, gaps and recommendations
- Assessment of Principle 5: Largely Compliant.
- Identified gaps and comments:
  - No explicit reference in the LCI to the concept of UBO; alignment with the AML law is advisable.
  - Types of supporting information to establish legitimacy of funds for capital contributions are not specified in law or ordinance.
  - In practice there is no further due diligence beyond analysis of financial statements and the general written statement by the applicant; mission recommends enhancing BNB due diligence (e.g., approaching the FIU, police criminal records registry, Interpol office, and other financial sector supervisors).
  - Ordinance #2 requires “preliminary consultations” with the Deputy Governor but does not specify purpose and objectives; consultations occur before formal application and a representative could attend in lieu of prospective applicant.
  - No mandatory provision requiring interviews after formal submission of the application; interviews are optional at Deputy Governor’s discretion.
  - No explicit requirement for individual Board members or the Board collectively to have sound knowledge of the material activities and associated risks.
  - No formal procedure subjecting newly licensed institutions to more intensive supervision during their first year of operation.
- Recommended actions (verbatim from source):
  - Include in the LCI a clear definition of UBO in consonance with the definition provided by the AML law;
  - Enhance BNB due diligence with respect to the origin of funds used for disbursement of capital;
  - Include in the relevant regulation a provision requiring the individual Board members or the Board collectively to have a sound knowledge of the material activities that the bank intends to pursue, and the associated risks;
  - Establish formal procedures to subject the newly established bank to follow up on-site inspection to ascertain that the bank is performing according to the terms and conditions of the license;
  - Establish formal mechanism for interviewing applicants after the application is formally submitted to the BNB. The content and objective of these interviews should also be specified and made mandatory; and
  - Include in the Fitness and Propriety Test Question Form information about administrator’s income and assets.

*International Monetary Fund — content unit: _cr15295 - 2. the names and addresses of the persons up to the ultimate owner who are beneficial owners of the legal entity.*

### 1. the full name of the applicant, citizenship, identity card number, permanent and present address;

### _cr15295 - 1. the full name of the applicant, citizenship, identity card number, permanent and present address;

### Required information from prospective acquirers (individuals)
- 1. the full name of the applicant, citizenship, identity card number, permanent and present address;
- 2. a certificate showing no previous conviction or relevant criminal records;
- 3. details on qualifications and professional experience;
- 4. information about previous compulsory administrative measure/disciplinary actions.
- The BNB will capture information about the financial condition of the acquirer in terms of assets (revenues and earnings, including their sources, property owned) and liabilities (pledges, mortgages in favor of third parties, issued guarantees and other commitments).
- The BNB will check for possible financial linkages or interests of the applicant with affiliated persons of the bank, including bank shareholders, members of the board or controlling bodies, or with any person that may cause conflict of interest with the bank.

### Required information and documents where the applicant is a legal entity
- a certified transcript of the Articles of Association;
- a list of the shareholders (associates/partners) of the applicant up to the ultimate owner;
- the structure and allocation of its capital among the shareholders (associates/partners);
- a list containing the names and addresses of the persons who manage or represent the applicant, together with detailed written data on their qualifications and professional experience;
- a description of the group structure if the applicant participates in a group as a subsidiary or as a parent entity, along with its organizational and intra-group corporate structure, specifying relevant participation shares of the other persons in the group, as well as a description of the business activity of the group;
- the annual financial statements of the applicant for the last three years.

### Required information and documents where the applicant is a trust
- 1. the names and addresses of the persons who will manage the assets of the trust under the terms and procedure of the contract establishing the trust and their respective shares in distribution of the asset management income;
- 2. the names and addresses of the persons up to the ultimate owner who are beneficial owners of the legal entity.

### Information required concerning the target bank (LCI art. 19b)
- 1. data on the overall aim of the acquisition, the total number of shares acquired; the nominal and total value of the shares, the single and total acquisition price of the shares and their amount in the total capital, in percentage;
- 2. a written declaration concerning the origin of the financial funds for the acquisition;
- 3. a declaration and documents on the financing of the acquisition specifying the source of the funds and the means used to provide (transfer) funds for the acquisition.
- The quantity of information required increases according to the level of targeted holding (less than 20 percent, between 20 and 50 percent).
- Pursuant to Art. 32, where a person has acquired 3 or more than 3 per cent of the shares or the voting rights, the Central Depository shall notify the BNB of the person’s name and address following the recording of acquisition in the book of shareholders.

### Processing, decision-making and supervisory powers
- Requests for transferring significant ownership are processed by the Legal Directorate, which can request additional information if needed.
- A memo with an opinion is drafted and presented to the Deputy Governor (DG) in charge of banking supervision for review.
- The DG makes the determination and signs an official order for approval; the DG has full discretion to approve or reject any request for change in shareholding irrespective of the amount of targeted holding.
- The approval takes the form of an official order of the DG which “ascertaines that the conditions for issuance of the approval are met.” The order is an individual administrative act and can be challenged before the administrative court.
- If a change in significant ownership is based on false information, the supervisor has the power to reject, modify or reverse the change in significant ownership (EC3).

### Supervisory reporting and verification (EC4)
- Banks licensed in the Republic of Bulgaria shall notify the BNB within 7 days from becoming aware of any acquisition or disposal of shares of their capital, as a result of which the shareholders’ holdings exceed or fall below any of the thresholds contemplated in the law (Article 28, paragraph 1).
- On a monthly basis, banks are required to submit to the BNB reports detailing bank’s shareholders who hold qualifying holdings; reports should indicate the name of the shareholders and the size of their holding.
- The BNB verifies the quality of shareholders’ participation primarily through on-site inspections and, discretionally, by requiring additional information for off-site supervision purposes; every year, all changes in ownership structure of banks are assessed by the SSD using banks’ reports and data from the Central Depository.
- Assessors identified gaps and missing information, in particular on the true identity of UBOs located overseas.

### Enforcement powers (EC5)
- LCI provisions allow the BNB to:
  - suspend the voting rights attached to shares wrongly acquired;
  - issue a written order to force the sale of shares acquired without prior permission;
  - declare transactions, decisions and actions concluded and taken without BNB preliminary approval null and void (including acquisitions based on false or partial information);
  - suspend voting rights or instruct disposal of wrongly acquired shares where there are reasonable grounds to suspect money laundering or terrorist financing related to the acquisition.
- The Officer in charge of the Trade register is informed to ensure that new acquisitions have received BNB approval.

### Gaps and outcomes observed
- Over the past 5 years, 16 requests for transfer of significant ownership have been approved. There were no formal refusals. After prior consultations with the DG of the BNB in charge of Bank supervision department (as required according to BNB regulation #2), some intentions for acquisitions were withdrawn.
- The LCI does not require banks to notify the supervisor as soon as they become aware of any material information which may negatively affect the suitability of a major shareholder or a party that has a controlling interest (EC6).
- The mission reviewed an acquisition: 100 percent acquisition by KTB of a French subsidiary (CB Victoria, former name Crédit Agricole, Bulgaria EAD) in June 2014. The collapse of KTB almost concomitant to the purchase raises questions about the adequacy of BNB internal processes for change of control and acquisitions; in assessors’ opinion, due diligence was not robust or intrusive enough to ascertain that the acquirer had the risk management capacity to properly manage the subsidiary.
- An earlier share of that bank (renamed CB Victoria) accounted for a mere o.45 per cent of banking system assets by June 2014.
- Assessment of principle 6: Materially Non Compliant.

### Recommendations (from mission)
- Establish stronger mechanism to ascertain that the new owner, beyond its financial soundness, has the risk management capacity to properly manage the acquisition.
- Institute a mechanism whereby external auditors’ opinions are sought before approving a major transfer of significant ownership.
- Provide BNB more powers over shareholders who no longer meet the requirement for holding equity in banks.
- Include in the law a provision requiring banks to notify the supervisor as soon as they become aware of any material information which may negatively affect the suitability of a major shareholder or a party that has a controlling interest.

### Major acquisitions framework (Principle 7 — EC1 and EC2)
- EC1:
  - Art. 28 of the LCI: a bank may not, without preliminary approval by the BNB, directly or indirectly acquire shares or voting rights in another bank licensed in the Republic of Bulgaria if as a result of such acquisition their holding becomes qualifying or reaches or exceeds thresholds of 20, 33 or 50 per cent of the shares or voting rights.
  - Preliminary approval is also required where holdings become qualifying or thresholds are reached or exceeded as a result of acquisition of shares on a stock exchange or another regulated market of securities.
  - Opening a branch in a third country is subject to BNB approval (Art. 29, para. 1, point 1 of the LCI).
  - The same obligation applies to acquisitions realized through merger and acquisition of control over a bank with a seat abroad (Art. 29, para. 1, point 8).
  - To obtain approval, the bank shall notify the BNB via a written proposal and attach all necessary documents specified in BNB No 2 on “Approvals and Permissions Granted by the Bulgarian National Bank According to the Law on Credit Institutions.”
  - Acquisitions of banks in a non-financial company do not require notification and thus are not subject to supervisory approval; Bulgaria applies Art. 89 of Regulation (EU) No. 575/2013 for qualifying holdings outside the financial sector.
  - Art. 26 of BNB Ordinance No. 7: the bank may not have qualifying holdings in an entity outside the financial sector that exceeds the individual limit of 15 percent of eligible capital and the aggregate limit of 60 percent of eligible capital.
  - The BNB states there is no case for which notification after the acquisition or investment is sufficient.
- EC2:
  - The conditions for judging individual proposals for major acquisitions are laid out in the LCI and in ordinance No 2.
  - The assessment shall be based on each of the following criteria:
    - 1. the reputation of the proposed acquirer;
    - 2. the financial soundness of the proposed acquirer, in particular in relation to the type of business pursued and envisaged;
    - 3. the reputation, knowledge, skills and experience of the members of the management boards (boards of directors) and board of supervisors, as well as senior management, who will direct the business of the bank as a result of completion of the proposed acquisition;
    - 4. whether the bank will be able as of the moment of acquisition to comply and continue to comply with the prudential requirements based on the effective legislative framework, including the LCI.

*Italic: Source — _cr15295 - 1. the full name of the applicant, citizenship, identity card number, permanent and present address;*

### 5. whether there are reasonable grounds to suspect that, in connection with the proposed

### _cr15295 - 5. whether there are reasonable grounds to suspect that, in connection with the proposed

### Due diligence and approval process for major acquisitions
- BNB may request additional information from the applicant during consideration of an application for major acquisition; decision within a three-month period after receipt.
- BNB can reject an acquisition if submitted documents contain incomplete, inconsistent, improper or untrustworthy information.
- For acquiring control over a bank with residence abroad (art. 29 and 30 of BNB Ordinance No. 2) required supporting documents include:
  - (i) data about the type, number, single and total nominal value of the shares that will be acquired, their portion in the bank’s capital and acquisition price;
  - (ii) data about the type, number, single and total nominal value of the shares, already possessed, their portion in the bank’s capital and acquisition price;
  - (iii) documents and data about the bank to be acquired;
  - (iv) a certified transcript from the Commercial Register with current information on the bank’s name, registered office and head office address, legal organizational structure and persons who represent and manage the bank;
  - (v) audited financial statements of the foreign bank for the last two years;
  - (vi) a certified transcript of the Articles of Association (Act of Association) of the bank;
  - (vii) information about bank’s related persons;
  - (viii) an economic substantiation of the reasons to acquire a bank with residence abroad.
- Legal Directorate leads analysis of major acquisition projects, reviewing prudential reports, purchaser’s financial conditions, liquidity reports on solo and consolidated basis, ability to cover additional CAR, and strategy changes (e.g., change of business model, closing of branches). Legal seeks Credit Institution Directorate inspectors’ opinion before submission to the Deputy Governor for final decision.

### EC3: acquisitions, undue risk and supervisory authority scope
- Supervisor objective: ensure any new acquisitions and investments do not expose the bank to undue risks or hinder effective supervision; also determine these will not hinder effective implementation of corrective measures in the future.
- BNB performs due diligence and ascertains acquisitions do not expose the bank to undue risks; for foreign acquisitions pays attention to Regulation (EU) No 575/2013 regarding group structure and information exchange among competent authorities.
- Mission could not find a specific provision requiring BNB to determine, where appropriate, that new acquisitions/investments will not hinder effective implementation of corrective measures in the future.

### EC4–EC5: resources, non-banking activities, limits and gaps
- Notification (application) triggers approval procedure for major acquisition; BNB determines adequacy of financial, managerial and organizational resources to handle acquisition.
- Acquisitions of banks in a non-financial company are not subject to supervisory approval; Bulgaria applies Art. 89 of Regulation (EU) No. 575/2013 for qualifying holdings outside the financial sector.
- Concerns:
  - No particular BNB process to monitor that a bank acquiring non-financial companies complies with individual limit of 15 percent of eligible capital and aggregate limit of 60 percent of eligible capital.
  - In absence of formal BNB approval, no means to determine whether such investments pose risk to the group or whether the bank can manage the risk; deduction from CET 1 will be applied in case of breach.
- Past: BNB regulation #17 (now repealed) contained sectoral restrictions (e.g., real estate).

### Additional Criteria AC1 and practice
- BNB does not usually approve major acquisitions/investments by other entities in the banking group; such investments are rare and mostly for ancillary service companies.
- Activities of such entities are checked predominantly within supervisory review, on-site inspections, and supervisory colleges for cross-border groups.
- BNB has had meetings to discuss planned acquisitions of non-bank companies mainly to determine consolidation in financial reports and effect on corporate structure.

### Assessment of Principle 7 — Largely Compliant
- Recent major acquisitions: three in the past five years; two involved Bulgarian bank acquiring 100 percent of a Bank in the Republic of Macedonia and 75.961 percent of a bank in Russia.
- Final decision on approvals rests with the Deputy Governor in charge of banking supervision only; consultation with Bulgarian Commission on Protection of Competition exists but no formal protocol defined.
- Follow-up review of approved acquisitions is not clearly documented; Credit Institution Directorate understood responsible but no evidence of material follow-up mechanism.

Recommendations (Principle 7)
- Subject any major acquisition to a formal follow up mechanism to ascertain new activities do not expose the bank to undue risks.
- Subject major acquisitions in non-financial companies to enhanced BNB scrutiny, particularly on compliance with the limits and to ensure structure will not bring additional risks and actions can mitigate risks.
- Explore possibility to set restrictions for major acquisitions in non-financial sectors deemed to pose particular concern.
- Establish an explicit provision by which the supervisor determines, where appropriate, that new acquisitions and investments will not hinder effective implementation of corrective measures in the future.

### Principle 8 — Supervisory approach: methodology and forward‑looking assessment
- Since 2014 BNB legally obliged to evaluate risks banks are or might be exposed to and risks banks pose to the financial system (Art 79c(1)LCI); SREP is the primary methodology.
- SREP (part of Pillar 2) links risk to appropriate capitalization and includes qualitative assessment of risk management and ICAAP.
- SREP includes assessment of:
  - level, structure and stability of regulatory capital;
  - credit risk, including concentration risk;
  - market risk;
  - operational risk;
  - interest rate risk in the banking book;
  - liquidity risk;
  - ability to generate profit;
  - organisational structure, corporate governance and internal control;
  - financial measures against money laundering and terrorism, financial crimes and reputational risk;
  - level and allocation of internal capital depending on the bank’s risk profile.
- SREP updated at least on an annual basis; frequency and intensity determined by size, systemic importance, nature, scale and complexity.
- Risk Assessment System (RAS) is core tool:
  - Two methods: CAMELOS (on-site) and CAEL (off-site).
  - CAMELOS components: C, A, M, E, L, O, S (Capital, Assets, Management, Earnings, Liquidity, Operational risk, Sensitivity to market risk).
  - CAEL components: C, A, E, L (Capital, Asset quality, Earnings, Liquidity).
  - Component ratings 1 to 5; composite RAS rating 1 best, 5 worst; ratings are forward-looking.

### EC3–EC8 findings under Principle 8
- BNB required to supervise on consolidated basis (Arts 89-101 LCI).
- Macro-prudential Supervision and Financial Stability Directorate (est. April 2014) performs stress tests, proposes macro-prudential instruments, monitors indebtedness and collects forward-looking data (including rejected credit applications).
- Cooperation frameworks: Financial Stability Advisory Council (FSAC) with Minister of Finance, Governor of BNB and Chairman of FSC; FSAC meets quarterly.
- Resolvability:
  - LCI (Art 121a) requires BNB to prepare resolution plans; banks required to submit recovery plans by end November 2014 (not all met deadline).
  - BRRD (2014/59/EU) transposition into Bulgarian law not completed at time of assessment; resolvability concept not yet formalized in Bulgarian law.
  - LCI Art 103(2) provides powers to address business strategy, managerial/operational/ownership structures and internal procedures.
- Crisis management: BNB has formal written framework; powers include requiring rehabilitation plan, appointing conservators, placing bank under special supervision (Art 103(2)(21),(23),(24)); records/documentation maintained.
- Bank-like activities outside perimeter: LCI Art 79(9) allows investigation; LCI Art 3a and Ordinance 26 require registration as financial institution if lending, granting guarantees or acquiring loan portfolios; financial register and Central Credit Register used to monitor.

Assessment of Principle 8 — Largely Compliant
- Sound methodologies and extensive analytical resources exist; work on resolvability is lagging due to BRRD transposition delay, resource constraints and 2014 crisis.

### Principle 9 — Supervisory techniques and tools: on-site/off-site mix and processes
- On-site and off-site functions integrated into Credit Institutions Supervision Directorate (CISD) since 2009.
- Off-site analysis: regular quarterly timetable (monthly and quarterly returns); intensity can be increased for enhanced supervision.
- On-site inspection cycle target: 18 to 24 months (not always maintained).
- Inspection teams: five teams of approximately 5 staff each; portfolio rotation ~ every 3 years; team composition not subject to formal rotation requirements.
- Two types of on-site inspections:
  - Complete supervisory inspection — entire CAMELOS risk profile assessed.
  - Targeted supervisory inspection — focused topics identified via trend analysis or off-site triggers; Special Supervision Directorate also performs on-site inspections including AML and outsourcing.

EC2–EC4 process findings
- Art 80a LCI requires annual supervisory examination program aligned with SREP; plan indicates banks to be examined and those subject to enhanced examination.
- Off-site organization supported by internal supervisory manual; on-site guided by RAS manual.
- Sources of information for off-site include monthly/quarterly/annual financial statements, ad-hoc supervisory reporting, BNB Credit Register, public financial statements, ICAAP responses, other supervisors, Central Credit Register, monetary statistics, rating agency reports, financial press and dialogue with banks.
- Business model analysis performed during on-site inspections; stress tests reviewed under Pillar 2 and ICAAP.

EC5–EC12 findings and tools
- MPSFS performs surveys and stress tests; top-down stress tests quarterly since 2002; additional credit risk stress test since 2009 using IMF methodology for GDP–classified loans correlation.
- One-off 2014 stress test combined ECB/EBA scenarios (three-year horizon) with top-down and bottom-up approaches; baseline tested credit and market risk; adverse added sovereign and funding risk.
- Liquidity stress testing: 5-day shock and test of sufficiency of liquid assets to cover substantial outflow.
- Development of specialized macroprudential reporting: three forms in development since 2014; first introduced January 2015 monthly (currency, residential status, exposures to parent banks); second (quarterly) to cover LTV, LTI, PTI and flow of newly granted/renegotiated loans; third (annual) on credit migration between past-due categories.
- Internal audit evaluation occurs on-site against Ordinance 10; BNB uses internal audit reports for reference but does not rely on them to outsource supervisory judgment.
- Internal audit assessment elements include independence, staffing (incl. at least one IT specialist), quality of reports, risk-orientation, audit plan and implementation, annual activity report, major violations, compliance with Regulation No 10 frequency, and head of internal audit participation limits.
- Communication: primary contact allocated for each bank; inspection wrap-up meeting followed by 7 working days for bank reply (inspection teams) and 14 days for Special Supervision Directorate reports; BNB has legal right to meet supervisory board without executive management but not systematic.

Assessment of Principle 9 — Largely Compliant
- Strengths: meaningful risk-based approach, extensive analytical work, good substantive communications.
- Concerns:
  - Resource constraints and heavy EU reform agenda impacting inspection cycle and depth, particularly for smaller banks.
  - Internal coordination gaps and siloing across directorates; inconsistencies and variability in inspection report quality.
  - Limited use of horizontal reviews and of external experts.
  - IT/reporting systems upgrading in progress; supervisory staff lack unified formats and interrogation tools; supervisory information via VPN not integrated with CIBS.

Recommendations (Principle 9)
- Improve information sharing between banking supervision directorates, with stock-take and review of common issues.
- Initiate more intensive program of communication with supervisory and management boards; present key findings to Supervisory Board (see CP14).
- Ensure inspection team composition does not remain static; introduce additional quality assurance procedures for inspection teams.
- Deploy horizontal reviews on key risks.
- Reconsider policy of not using external experts to support supervisory analysis.
- Prioritize major upgrade to supervisory IT systems; integrate supervisory data and develop “next generation score-carding.”
- Establish unit or committee to review supervisory processes and practices, ideally concurrent with IT/data system upgrade.
- Require banks to notify BNB in advance of substantive changes in activities, structure or condition, or as soon as they become aware of material adverse developments, including breach of legal or prudential requirements.

### Principle 10 — Supervisory reporting: powers, standards and practices
- LCI provides strong information-gathering powers (Article 80(1),(2),(3)); banks must submit solo and consolidated financial statements (Art 75(2)); group consolidated statements required for subsidiaries and holding companies (Art 80(1)LCI).
- Harmonised EU supervisory reporting covers solvency, financial information, large exposures, leverage ratio, liquidity, asset encumbrance and supervisory benchmarking; some implementing regulations not yet adopted (e.g., leverage and LCR).
- BNB requires some FINREP IFRS templates on solo level with monthly frequency (LCI, Article 80 (1)); supervisory reporting consistent across banks per ITS thresholds.
- Accounting standards: banks prepare annual financial statements on IFRS basis (Accountancy Act Article 22a(2)); FINREP reporting templates based on IFRS (CRR Article 99(2)).
- Valuation and governance: LCI Arts 73, 76 and Ordinances 7 and 10 require sound governance, risk management, internal controls and auditor opinions; valuation rules follow IFRS (IAS 39, IFRS 13). BNB can require capital increases where internal models are insufficient (Art 103(2)(5); Art 103(1)(11)).
- Frequency: collection and analysis carried out with same frequency for all banks; intensification possible for system-wide or institution-specific vulnerabilities (e.g., daily liquidity reporting during crisis).
- Data comparability: FINREP and COREP standardized templates used; reporting timeframe, dates and periods uniform across banks.
- BNB has authority to request information from parent companies and wider group for consolidated supervision (Art 69; Art 80).
- Access powers: Article 80(3) provides access to accounting and other documentation, on-site visits, attendance at management and supervisory meetings, and rights to collect evidence.
- Enforcement: penalties for violations include financial penalties from BGN 50,000 to BGN 200,000; repeated violations from BGN 200,000 to BGN 500,000 (Art. 152, para. 2 LCI). No history of penalties applied for reporting non-observance.
- Reporting timeliness: BNB noted reporting period extended from 15 days to 45 days (context in source truncated).

*Source: _cr15295 - 5. whether there are reasonable grounds to suspect that, in connection with the proposed*

### introduction of the EU supervisory reporting regime. Lateness of returns has not been an issue.

### _cr15295 - introduction of the EU supervisory reporting regime. Lateness of returns has not been an issue.

### Supervisory reporting: transition to harmonized EU regime
- The supervisory reporting requirements are now predominantly governed by a harmonized EU regime; the reporting regime is going through a transitional phase placing heavy demands on supervisors and banks alike.
- The BNB was fielding many queries on how to comply with the new instructions; the supervisory authority is not permitted to interpret the ITS.
- In practice the BNB consults with the EBA, but this is not immediate because the EBA has its own procedures before posting responses on its official website.
- Potential reporting issues may stem from the learning curve presented by the new regime, possibly affecting accuracy of reporting.
- The BNB has an internal Q&A platform organized by topic with cross references to staff involved and the contact/institution that lodged the question; the Supervisory Policy Directorate maintains the platform and is engaged in responses.

### Validation, verification, and external experts (EC9–EC12)
- EC9: BNB applies a careful validation process on returns to ensure consistency and integrity of data; on-site examinations inspect preparation of supervisory reporting and may check internal audit and sample loan files and reconcile data back to supervisory reports.
- Additional checks reconcile financial reporting validated by external auditors with supervisory reports.
- EC10: LCI (Art 80(4, 5)) permits appointment of external experts by the BNB; at the time of assessment BNB had not exercised this power but might in the future.
- EC11: Law requires external auditors to inform the BNB immediately of circumstances known during audit that are breaches of the law or might affect the bank (Art 77(1) LCI); the law does not impose a similar obligation on an external expert engaged by the BNB.
- EC12: Since June 2014 a review of the adequacy of collected information for macroprudential supervision and financial stability is carried out regularly with respect to format, content and frequency.

### Assessment — Principle 10 (Supervisory reporting)
- Assessment: Compliant
- Key observations:
  - Harmonized reporting acknowledges Bulgarian data role in EU-wide analysis.
  - BNB places strong emphasis on analytical work and validation (formal logical checks for internal consistency and coherence).
  - Experience with the bank failure in 2014 indicates more resources need to be dedicated to data validation; increased assurance on validity of reported data is particularly important post crisis.
  - Recommendation: amend laws/regulations to ensure external experts must promptly report material shortcomings identified during supervisory work.

### Corrective and sanctioning powers (Principle 11) — description and findings
- EC1 (timely engagement and follow-up)
  - Constant dialogue between CISD teams and bank representatives; intensity depends on risk profile, size and systemic importance.
  - On-site wrap up meeting presents findings and proposed corrective actions; bank given a 7 working days period for reply, objections and explanations.
  - Time limit for finalizing the inspection report: 10 working days from final meeting; reports approved by CISD director and, depending on severity, by deputy governor.
  - For serious deficiencies the CISD Director prepares a Memo to the Deputy Governor; possible outcomes include official letter (written warning) or written order (individual administrative act subject to appeal). Monitoring ensured through regular written progress reports and quarterly CISD reports to the DG.
- EC2 (range of supervisory tools)
  - Legal basis: LCI, art. 103 (1) and (2), art. 152–152d.
  - Measures include written warnings, written orders, restrict/suspend activities, impose additional capital, prohibit dividends, force changes to internal rules, dismiss board members, forbid related-party transactions.
  - BNB can place an institution under “Special Supervision” for a period of 6 months and appoint conservators (powers determined by DG and Governor).
  - Example: KTB and CB Victoria placed under special supervision per Governing Council decision on June 20th; conservators appointed; execution of obligations and activities suspended; management and supervisory boards dismissed; voting rights of shareholders holding more than 10 percent revoked; special supervision used for 3 months in that instance.
  - License withdrawal permitted; KTB license revoked on November 2014 prior to insolvency proceedings.
  - Administrative penalties range from BGN 1000 (approx. 566 $) to BGN 10 million (approx. US 5 millions); persistent breaches can increase fines.
- EC3 (power to act when below thresholds)
  - BNB can act early, issue written orders to require additional capital or improvements; written orders can result from off-site analysis or stress tests.
  - Special supervision/conservatorship can be applied when risk of insolvency (e.g., CAR below minimum threshold, insufficient liquid assets).
- EC4 (broad range of measures and application)
  - LCI Art. 103 (2) empowers the BNB to impose corrective actions; over past years BNB employed measures including raising prudential limits, placing two banks under special supervision and withdrawing a bank license.
  - Pecuniary sanction example: one fine of approx. US$ 25K applied for non-observance of BNB instructions to increase capital.
  - Enforcement has mainly consisted of written orders; limited use of coercive measures and limited escalation for persistent offenders noted.
  - All supervisory measures are recorded in a Central bank register.
- EC5 (sanctions on management and board)
  - Penalties can be imposed on both legal entity and bank managers/administrators (Article 152 LCI); sanctions issued by Deputy Governor or authorized official. Sanctions do not apply to other bank staff (e.g., compliance, AML, risk management officers).
- EC6 (ring-fencing and limits on group actions)
  - Art. 103 (2) par. 18 allows prohibition of transactions with related persons and other ring-fencing measures.
  - BNB examples: instructed a Greek parent to stop deleveraging actions in its Bulgarian subsidiary; ring-fencing measures for Greek banks operating in Bulgaria included requirements to maintain highly liquid assets at 30 percent of attracted funds from non-credit and non-financial institutions, enterprises, and individuals, in addition to minimum reserves of 20 percent with the BNB; limits on balances with parent bank; not to invest in non-investment grade securities; functional independence from parent; daily reports to BNB.
- EC7 (cooperation on orderly resolution)
  - No local legal framework for recovery and resolution at time of assessment; BNB can subject banks to special supervision and must withdraw license and petition court for bankruptcy if conservatorship ineffective.
  - KTB case highlighted lack of legal basis for options such as bad bank/good bank.
  - Transposition of BRRD (Directive 2014/59/EC) into Bulgarian legislation and appointment of resolution authority was in progress and expected to come into force by end of 2015.

### Assessment — Principle 11 (Corrective and sanctioning powers)
- Assessment: Materially Non-Compliant
- Main deficiencies and comments:
  - Deputy Governor (DG) has full discretion in determining measures; absence of collegial decision-making risks inconsistency.
  - No internal guidelines to assist DG in selecting appropriate remedial measures or setting fine quantum; lack of link between specific violations and sanctions may allow undue delay or unequal treatment.
  - Enforcement approach historically favored moral suasion; limited escalation and insufficient deterrence for persistent offenders.
  - Special supervision power limited to insolvency risk; assessors consider broader application desirable (e.g., management fraud, major AML problems).
  - Lack of recovery and resolution framework (pre-BRRD transposition) left gaps exposed by KTB collapse.
- Recommendations encouraged by assessors:
  - Set internal guidelines to assist the Deputy Governor in determining appropriate responses for breaches or violations.
  - Apply a gradual response and increase intensity when banks do not comply with BNB recommendations.
  - Take more forceful action against persistent offenders.
  - Consider broadening circumstances under which a bank can be placed under Special supervision regime.

### Consolidated supervision (Principle 12) — key findings
- Assessment: Largely Compliant
- Structure and reporting:
  - Ten banking groups operate in Bulgaria reporting consolidated financial statements; banks are principal entities; a holding company with mixed activity exists; no financial conglomerate.
  - Requirements for consolidated supervision derive from CRR, CDRIV and LCI (Art. 89); BNB responsible for consolidated supervision of banks, banking groups, financial holding companies, mixed financial holding companies and mixed holding companies.
  - LCI empowers BNB to require detailed ownership structure information and prior submission of plans to modify group structure for assessment.
  - BNB collects annual information on balance sheet, profit and loss and nature of activities; supervisory reporting includes COREP and FINREP (Regulation No 680/2014 on supervisory reporting).
- On- and off-site practices:
  - Off-site analysis uses COREP and FINREP for capital adequacy, liquidity, large exposures, lending limits at group level.
  - On-site inspections evaluate organizational structure and activities of group members; BNB can request documentation from parent and subsidiaries and perform counter-inspections.
- Legal/audit arrangements:
  - BNB Ordinance #14 requires auditors to include consolidated FINREP information in supervisory audit reports.
  - Art. 89(5) LCI: banks in groups must present annual information on group structure, including changes within 30 business days after calendar year end.
- Observed gaps and suggested improvements:
  - Perform more frequent visits to branches and subsidiaries in and outside the EU.
  - Capture leasing, factoring and consumer finance companies into the perimeter of consolidation for mixed holding companies.
  - Identify authority to conduct ongoing fit and proper reviews of owners and senior management of non-financial holding companies.

### Home–host relationships (Principle 13) — key findings
- Assessment: Compliant
- Role and participation:
  - BNB predominantly a host supervisor; participates in 10 supervisory colleges (9 for subsidiaries, 1 for a significant branch).
  - Memoranda of understanding and multilateral cooperation agreements (EBA template) are used within EU colleges; BNB has bilateral MoUs with EU and some non-EU countries.
- Information sharing and coordination:
  - Colleges and MoUs facilitate timely exchange of material information, supervisory assessments, inspection reports, internal models, capital plans and proposed supervisory measures.
  - Where BNB is consolidating supervisor it must develop communication strategies and coordinate in going-concern and emergency situations (Art 92(1) LCI).
- Crisis cooperation and resolution:
  - Framework for cross-border crisis cooperation is contained in MoUs; BRRD had not been implemented at time of assessment, so some arrangements expected to change once transposed.
  - BNB obligated under Art. 121a LCI to prepare a plan for orderly resolution of each bank licensed in Bulgaria.
- Host-supervisor requirements:
  - Subsidiaries and branches in Bulgaria must comply with same prudential and reporting requirements as local banks; branches supervised by home Member State but BNB retains competencies on liquidity, reporting, access to data and on-site inspections (Art 81 LCI).
  - Legislation prohibits establishment of booking offices or shell branches in Bulgaria.
- Operational cooperation:
  - BNB has good cooperation with home supervisors (examples with Greek and Austrian supervisors on AML/CFT inspections); joint on-site inspections conducted when requested.
  - In urgent cases BNB may act without prior consultation but must notify without delay after action (Art 95 LCI).

### Corporate governance (Principle 14) — legal framework and supervisory approach
- Legal instruments and guidance:
  - Legal framework includes LCI, Commercial Law, Ordinance on Organisation and Risk Management of Banks (Ordinance 7), Ordinance on Internal control in Banks (Ordinance 10) and Ordinance 20 on approvals of management and supervisory board members and requirements for performing duties.
  - BNB requires banks to follow Guidelines on Internal Governance (EBA-derived) and Guidelines on assessment of suitability of management body and key function holders; these are notified to banks by letters setting expectations.
  - Article 73 (1) LCI requires competent managing body to adopt and regularly review governance elements in accordance with best internationally recognised practices.
- Specific corporate governance expectations:
  - Board responsibilities include approving and overseeing strategic objectives, risk strategy and internal governance (Management oversight — Article 5, 6, 8 Ordinance No10).
  - Management body must ensure integrity of accounting and financial reporting systems (Ordinance No10 Articles 5, 6, 7, 8, 13, 14).
  - Management body oversees disclosure and communications (Ordinance No10 Article 8; Ordinance No7 Article 3 (5)).
  - Chairman of the management body must not simultaneously be CEO unless justified and authorised (Commercial Law Articles 241, 244).
  - Nomination committee and related requirements per Article 73c LCI and Article 12 Ordinance 20.
- Supervisory assessment and outreach:
  - BNB assesses corporate governance during on-site inspections as part of CAMELOS risk assessment and within SREP; corporate governance identified explicitly as a risk to assess.
  - BNB organized high-level seminars for senior management in past (last was May 2012) and published Basel Committee recommendations and other guidance.
- Governance structures and committees:
  - Fitness and propriety assessments use questionnaire annex to Ordinance 20; Deputy Governor or authorized persons may interview applicants and consult EBA database of administrative penalties.
  - Required committees: nominations committee (non-executive members), audit committee (per Law on Independent Financial Audit — Art 40f), risk committee (Ordinance 7 Art 6(1) and (3)), remuneration committee (Ordinance 4 Art 6(1)).
  - Some banks, particularly locally owned, faced challenges implementing requirements for independent non-executive members on committees; progress reported but not complete.

*Source: _cr15295 - introduction of the EU supervisory reporting regime. Lateness of returns has not been an issue.*

### 1. the bank’s organisation structure;

### 1. the bank’s organisation structure;

### Key organizational elements and procedures
- 1. the bank’s organisation structure;
- 2. the procedure for defining and delegating the administrators’ powers and responsibilities;
- 3. the bank’s strategy and action plan;
- 4. the strategies and policies for taking up, managing, monitoring and mitigating the risks the bank is or might be exposed to, including those posed by the macroeconomic environment in which it operates in relation to the status of the business cycle;
- 5. the procedure for generating and the scope of the management information;
- 6. the operational control organisation, including rules and procedures for approving, carrying out and reporting transactions;
- 7. the internal rules and procedures for risk management and control systems efficiency and for reporting the established weaknesses in the organisation and work of structural units;

* _cr15295 - 1. the bank’s organisation structure; *

### 8. systems for prevention against the risk of money laundering.

### 8. systems for prevention against the risk of money laundering.

### Ordinance 10 — internal controls and conflicts of interest
- Board (competent management body) must segregate duties where conflicts of interest may occur and no individual may hold more than one function related to the authorization, performance and reporting of an activity (Art 6).
- Review of these requirements is performed during on-site inspections as part of overall management and corporate governance assessment.
- Banking supervision inspectors follow the internal RAS Manual to review internal documents related to strategy, risk appetite and related documents, discuss deficiencies with Board representatives and stay informed about Governing Council-approved changes.

### EC6 — Board oversight, fit and proper standards, succession and performance monitoring
- BNB on-site Management and Corporate Governance review uses tools in the RAS Manual to evaluate internal policies, rules and procedures related to senior management performance.
- Inspectors review internal documentation, meet responsible bank representatives and assess compliance with internally set standards; this forms part of the Management and Corporate Governance component of the CAMELOS composite ratings.
- Under the LCI (Art 73(3)), BNB must make recommendations/prescriptions for improving corporate governance in accordance with best internationally recognised practices and monitor implementation.
- On-site team meets management board (and sometimes supervisory board) at least twice per visit and reports inspection findings to executive directors. Senior-level BNB contact typically at Deputy Governor level.

### EC7 — Board oversight of compensation systems
- Compensation reviewed during on-site inspections as part of Management and Corporate Governance review; inspectors assess Board implementation of Ordinance 4 on the Requirements for Remunerations in Banks.
- RAS Manual guides inspectors to evaluate remuneration policies against CEBS/EBA Guidelines and good banking practices, including transparency and whether policy encourages risk-taking beyond defined risk tolerance.
- Ordinance 4 (Art 8) requires variable remuneration linked to performance via assessments of individual, business unit and overall bank results; assessments must be multi-year and measurement must include adjustments for current and future risks, cost of capital and liquidity.
- Law on credit institutions, Article 73b: banks shall adopt and implement a remuneration policy promoting sound risk management and not conducive to risk taking beyond the bank's risk profile; policy must be consistent with business strategy and long-term objectives.

### EC8 — understanding operational structure and risks, including non-transparent structures
- Legal framework requires risk committees composed of non-executive members with appropriate knowledge (Art 6(3), Ordinance 7).
- Management board must devote sufficient time to risk-related issues and ensure adequate resources for management of material risks (Art 3(1), Ordinance 7).
- Management body must understand purpose, structure and risks of special-purpose or related structures and accept only if risks will be appropriately managed (Guidelines on Internal Governance, Paragraph 7 Non-standard or non-transparent activities, point 1).
- Board must approve and periodically review strategies and policies for taking up, managing and mitigating risks (Art 73(1)(3), Art 2 Ordinance 7). Reporting rules and access to external expert advice for non-executive members and risk committee are required.

### EC9 — power to require Board composition changes
- Under Art 103(1) and (2) of the LCI, BNB may require dismissal of individuals authorized to manage and represent the bank and members of management board, board of directors or supervisory board for direct violations of the LCI, CRR or other acts including BNB guidelines.
- BNB guidelines include Guidelines on internal governance (Ordinance 10) and Guidelines on assessment of suitability of management body members and key function holders (Ordinance 20).
- Article 103(1) terms do not clearly encompass weak performance of a Board member or failure to meet the suite of corporate governance standards in this principle.

### Additional criteria AC1 — notification obligations
- Internal audit management must forthwith inform BNB of “any violations found out in the bank’s governance, which have resulted or may result in substantial damages for the bank.” (Art 74(2)).
- Head of internal audit must immediately notify BNB of violations or malpractices in bank’s management that have led or may lead to material damages (Art 28(1), Ordinance 10).
- LCI provisions do not directly address requirement for a bank to notify BNB of material concerns affecting fitness and propriety of a Board member or senior management.

### Assessment of Principle 14 — summary and comments
- Assessment: Materially Non Compliant.
- BNB staff demonstrate strong awareness of corporate governance practices and recent Basel Committee developments; corporate governance remains a work in progress in the Bulgarian market, with best practices largely in local subsidiaries of major international banks.
- BNB uses inspection process to determine corporate governance status and oversight; resource constraints limit frequency of on-site inspections and create vulnerability in governance assessment.
- Contact with Supervisory Boards is not systematic or close; senior-level contact may occur without supervisory teams being aware.
- Inspection reports present limited evidence of deep determinations on corporate governance; inspectors routinely review committee minutes and provide summary assessments for CAMELOS management component.
- RAS Manual is less developed for corporate governance testing than for internal controls; corporate governance, risk management and internal controls are treated together, with corporate governance techniques less developed.
- Unclear that BNB has adequate powers to require Board composition change for members failing to discharge corporate governance responsibilities effectively.
- Unclear that banks are required and individuals are legally protected to notify BNB of material issues affecting fitness and propriety of Board members or senior management.

### Recommendations (Principle 14)
- Ensure the BNB has the requisite powers to require changes to the composition of a Board where an individual or individuals have failed to discharge their corporate governance responsibilities effectively.
- Ensure banks are required to notify the BNB and that – as necessary – legal protections are in place to protect individuals who notify the BNB if there are material issues that would affect the fitness and propriety of the Board member or member of senior management.
- Refresh Ordinance 10 to elaborate more clearly on the BNB’s requirements and expectations in the field of corporate governance.
- Institute systematic senior level contact between the BNB and the Boards of the banks, to reinforce priority messages, deepen assessment of Boards’ qualities and capacities and, as necessary, to challenge the banks; make Boards aware that primary responsibility for safety and soundness rests with them.
- Increase frequency of corporate governance assessment; given resource constraints consider a horizontal review.
- Deepen the RAS Manual to provide greater guidance to inspectors in testing corporate governance quality and how to reflect findings in analysis, ratings and supervisory actions.

---

### Principle 15 — Risk management process (overview)
- Scope: supervisor determines banks have a comprehensive risk management process covering identify, measure, evaluate, monitor, report and control/mitigate all material risks, assess capital and liquidity adequacy, and develop contingency/recovery arrangements; process commensurate with risk profile and systemic importance.

Key findings and legal framework
- Article 73 LCI places key obligations on Boards to adopt and review risk strategies and policies and establish rules/procedures for risk management and reporting; Art 73(5) requires application of technical criteria in Ordinance 7.
- Articles 79(1) and 79c LCI impose obligations on BNB to supervise banks’ safe and sound management and review strategies/processes for risk management.
- RAS Manual draws on EBA recommendations; inspectors must verify quality of risk management strategies, internal rules and that they are adequate to nature, size and complexity of bank.
- ICAAP Manual clarifies statutory requirements and expectations for ICAAP; banks must define risks to be covered with internal capital and report to management and supervisor (item 3.2, item 3.6).

EC highlights (selected)
- EC1: Board-approved risk management strategies and risk appetite requirements enforced via on-site inspections and RAS Manual.
- EC2: Banks required to have comprehensive bank-wide risk management processes (Article 73(1)(4), Art 73a(1)-(2)); differentiation between EU-group subsidiaries and locally owned smaller banks noted; local skills shortage in risk management.
- EC3: Risk management documentation and review requirements (Article 72 LCI; RAS Manual); banks must submit statutes, regulations and documents within 10 days of adoption/amendment.
- EC4: Boards/senior management must obtain sufficient information on risks and relation to capital/liquidity; BNB ICAAP Manual and RAS Manual guide supervisory assessment; ILAAP approach under development.
- EC5: Internal processes for capital and liquidity adequacy assessed via Pillar 2 SREP; SREP performed at least annually.
- EC6: Use of internal models requires BNB prior approval under CRR; validation and stress testing requirements set out in CRR (Art174(d), Art 177(2)); model reviews at least every three years (Art 80c LCI). At assessment time two IRB approvals granted and one AMA application under assessment.
- EC7: Information systems obligations under Article 67 LCI and Ordinance 7(Art 3(2)-(3)); on-site inspections assess MIS effectiveness, coverage and business continuity.
- EC8: New product approval policies required under BNB Guidelines on Internal Governance (based on EBA); risk control function involvement required; EBA “Product oversight and governance” guidelines under consultation at time of assessment.
- EC9–EC10: Risk management function independence and CRO requirements set out in Ordinance 7 and Ordinance 10; proportionality allows combined roles in smaller banks; CRO removal requires prior approval of supervisory board or non-executive board members; no explicit public disclosure or requirement to discuss removal with BNB.
- EC11: Standards for credit, market, liquidity, interest rate in banking book and operational risk set out in Ordinance 7 (Chapter Three sections) and Ordinances 8 and 11; BNB applies EBA standards and issued multiple supervisory guidelines.
- EC12: Recovery plans required by LCI (Article 73d) and Ordinance 7 (Chapter Six, Art 25); plans must be submitted to BNB which may require changes; BNB requested recovery plans by end of 2014 and was in process of assessing them.
- EC13: Stress testing requirements in CRR (Article 177) and LCI (Article 79c); stress tests integral to ICAAP and assessed by BNB; RAS Manual includes stress testing across risk types; BNB identified weaknesses in stress testing in some banks.
- EC14: Banks must account for risks (including liquidity impacts) in internal pricing and new product approval; Ordinance 7 (Art 6(6)) requires remedy plans where prices do not reflect risks; BNB guidelines for allocation of costs/benefits related with liquidity issued.
- AC1: Banks required to consider other material risks (strategic, macroeconomic, reputational) in ICAAP; ICAAP Manual item 4.2.10 lists strategic risk, macroeconomic risk and reputational risk among other risks.

### Assessment of Principle 15
- Assessment: Largely Compliant.
- Comments: Reliance on on-site inspections creates gaps for less systemic institutions; inspectors pay attention to structures but may not sufficiently test substance over form; BNB progress on recovery plans noted but assessments incomplete at time of review.

### Recommendations (Principle 15)
- Consider reallocation of BNB resources to dedicate greater focus to risk management and internal control in on-site programs.
- Conduct horizontal reviews across the system to disseminate better practices and assist both banks and inspectors.
- Revise Ordinance 10 to confirm and enhance supervisory requirements in risk management.
- Review and refresh RAS Manual to provide greater guidance to inspectors in testing quality of risk management and reflecting findings in analysis, ratings and supervisory actions.

### Principle 16 — Capital adequacy (selected legal and numeric requirements)
- Bulgaria implements Basel III via CRR and CRD IV; CRD IV transposed into national legislation March 2014 and entered into force on March 25, 2014.
- Banks required to calculate and maintain minimum own funds to cover credit risk, trading book risk, operational risk, foreign-exchange risk, additional capital requirements (qualifying participations) and requirements due to exceed of large exposure limits.
- Banks obliged to have ongoing strategies/processes to assess and maintain internal capital adequate for risks (LCI, art. 73a).
- CRR Article 93 own funds thresholds:
  - CET1 4.5 percent;
  - Tier 1 capital ratio of 6.0 percent;
  - Total capital ratio of 8 percent.
- CRR Article 26 defines Common Equity Tier 1 items; Article 51 defines Additional Tier 1 items and Article 52 sets requirements for them; Tier 2 items defined in CRR.

*Source: _cr15295 - 8. systems for prevention against the risk of money laundering.*

### 62. On average, the percentage of subordinated debt in capital in the banking system is 8.69 percent.

### 62. On average, the percentage of subordinated debt in capital in the banking system is 8.69 percent.

### Subordinated debt and grandfathering
- On average, the percentage of subordinated debt in capital in the banking system is 8.69 percent.
- Capital instruments issued before end of 2011 and disqualified as capital instruments according to CRR can, under certain conditions, be grandfathered according to CRR.
- The approach chosen by the BNB is to apply the full grandfathering period available under the CRR (until 2022).

### Basel Committee RCAP findings for the EU implementation
- The Basel Committee RCAP process on the implementation of the Basel II and III framework in the EU was assessed as:
  - Largely Compliant for: definition of capital; standardized approach for credit risk; securitization framework; standardized approach for market risk.
  - Materially Non Compliant for: the IRB approach for credit risk.
  - Non Compliant for: the counterparty credit risk framework.

### Pillar 2, supervisory inputs, and powers of the BNB
- Article 103 (2), point 5 of the LCI provides BNB the ability to impose a specific Pillar 2 capital charge based on a bank’s risk profile and rating.
- The Pillar 2 process occurs at least annually and uses inputs including:
  - results from supervisory activities throughout the year;
  - ICAAP;
  - annual accounts;
  - report from the external auditor;
  - results of the BNB’s stress testing;
  - analysis of supervisory reporting.
- In the context of the SREP, BNB assesses all inputs and places a degree of reliance upon the ICAAP and the bank’s calculation of required capital.
- If internal capital allocations by type of risk exceed approved limits, banks must implement a clear action plan to restore risk levels to acceptable values.
- In cases of non-compliance with own funds requirements, BNB is empowered to impose supervisory measures (LCI, art. 103 (1)) and sanctions, including:
  - restricting distributions of dividends (art. 103 (2), point 12));
  - limiting certain activities (art. 103 (2), points 9 and 10));
  - imposing capital increase (Article 103 (2), point 11).
- In practice, breaches of the regulatory minimum or situations warranting an increase of capital have led the BNB to take supervisory actions as explained in CP 11.

### Capital buffers, Bulgarian implementation of CRD IV / Basel III
- Bulgaria transposed CRD IV into its regime via Ordinance No. 8 of 24 April 2014 on Banks’ Capital Buffers.
- The Bulgarian capital regime contemplates:
  - a Capital conservation buffer (Section 1 of Ordinance No.8);
  - a Countercyclical capital buffer (Section 2);
  - a G-SIFI-buffer (Chapter 3 of Ordinance No.8);
  - a Systemic risk buffer (Chapter 4).
- As of the source text, only two capital buffers apply:
  - Capital conservation buffer: 2.5 percent total risk exposure amount out of Common Equity Tier 1 capital.
  - Systemic risk buffer: 3 percent of total risk weighted exposures located within the country out of Common Equity Tier 1 capital.
- The systemic risk buffer entered into force in October 2014, pursuant to Decision No61 of the BNB Governing Council of 24 May 2014.
- Banks must calculate these buffers in conformity with art. 3, 12 and 13 of Regulation No8 of BNB on banks' capital buffers and present them in quarterly COREP reporting.
- Since none of the Bulgarian financial groups are identified as global SIFI, the G-SIFI capital buffer is not relevant currently.
- Unlike other EU countries, Bulgaria applied the conservation buffer in full immediately, not phased in gradually.

### Regulatory minima and aggregate capital requirements
- In conclusion, banks are subject to a CAR of 13.5 percent (8 percent minimum + 2.5 percent capital conservation buffer + 3 percent for systemic risk buffer).
- In practice, system-wide capital ratios as of September 30, 2014:
  - total capital ratio for the whole banking system: 22.16 percent.
  - lowest individual bank ratio: 14.57 percent.
  - actual risk-adjusted capital ratios (latest data available at source):
    - CET1: 19.47 percent;
    - T1 ratio: 19.91 percent;
    - total capital ratio: 22.16 percent.

### ICAAP, internal models, and supervisory review (SREP)
- CRR/CRD rules apply to all banks uniformly; definitions of capital, risk coverage, method of calculation and thresholds are defined in the CRR/CRD framework.
- Art. 73a of the LCI requires credit institutions to perform an ICAAP to ensure adequate capital and internal procedures to measure and manage risks and to keep sufficient own funds on an ongoing basis.
- The BNB evaluates ICAAPs annually (art. 73c of the LCI) and discusses ICAAP during onsite inspections; stress-testing is part of the review.
- The ICAAP practical manual requires banks to:
  - examine whether Pillar 1 requirements reflect true risk profile and, if insufficient, determine a capital buffer or better approach;
  - determine additional capital for Pillar 2 to cover risks not fully covered by Pillar 1 (e.g., residual risk from CRM techniques, securitisation risk).
- The BNB is responsible for determining whether banks’ own funds and liquidity ensure sound management and coverage of risks (LCI art 79 (2)) and can take appropriate action if SREP shows weaknesses.
- BNB’s powers include:
  - imposing higher capital charges via written order, considering quantitative and qualitative aspects, adequacy of rules and supervisory outcomes (LCI, article 79c (7));
  - requiring specific provisioning policies or asset treatment for own funds purposes;
  - limiting particular activities;
  - requiring improvements to internal control and risk management frameworks;
  - withdrawing a license under certain LCI circumstances, including where own funds are negative (LCI, Article 36 (2)).
- Regarding internal models:
  - BNB reviews banks’ compliance with approaches at least every 3 years and can revoke or limit permission to use internal approaches if requirements are not met.
  - One CISD team evaluates, approves and oversees internal models (team composed of 4 economists at time of source).
  - Authorizations in Bulgaria (as of source):
    - one bank authorized in 2014 to use AIRB for credit risk;
    - one bank using FIRB since 2010 and awaiting AIRB approval;
    - two banks authorized to use AMA for operational risk (in 2011 and 2014);
    - a third bank’s AMA request is under review;
    - no banks use internal model approach for market risk capital requirements.

### Stress testing and forward-looking capital management
- BNB requires banks to adopt a forward-looking approach in ICAAP, including stress-testing and capital planning consistent with strategic plans (expected growth, dividend policy, future funding).
- Stress tests must be complied with per BNB requirements and results fed into capital planning; additional capital may be required based on stress test and capital plan outcomes.
- CISD verifies the quality of banks’ stress-testing at least annually through on-site visits.

### Assessment, implementation observations, and supervisory challenges
- Assessment of Principle 16: Compliant.
- Bulgaria applies capital requirements as set forth in EU CRR and transposed CRDIV through LCI and Ordinance No. 8.
- The assessors note the RCAP findings for the EU but consider elements contributing to RCAP findings not strongly pertinent to the Bulgarian market.
- The EU framework changes removed some supervisory flexibility: previously BNB applied a minimum CAR of 12 percent; the Capital Requirements Regulation caps the statutory minimum at 8 percent.
- To offset this cap, BNB “frontloaded” capital buffers so the capital conservation buffer and systemic risk buffer are in force during heightened systemic stress.
- Historical supervisory challenge: a case in 2004 where an institution repeatedly failed to comply with BNB orders to address capital problems; assessors suggest BNB needs to take more forceful and persistent measures in such cases.
- Example of KTB audit findings: an external comprehensive audit (commissioned by BNB in June 2014) of KTB’s capital adequacy revealed that a significant portion of the capital increase between October 2011 and March 2014 was financed through loans originating from KTB itself; national regulation until end-2013 did not forbid this practice; BNB subsequently required banks to confirm capital was not stemming from depositors’ money.

Italic source: IMF Staff Report text unit _cr15295 - 62. On average, the percentage of subordinated debt in capital in the banking system is 8.69 percent.

### 1. exposures to individual obligors;

### _cr15295 - 1. exposures to individual obligors;

### Legal and regulatory framework for credit risk management
- LCI Art 73(1) requires the competent managing body of each bank to adopt and regularly review policies “in accordance with the best internationally recognized practices for corporate governance of banks” covering:
  - organizational structure; procedures for defining and delegating powers and responsibilities;
  - strategies and policies for taking up, managing, monitoring and mitigating the risks the bank is or might be exposed to, including those posed by the macroeconomic environment in relation to the status of the business cycle;
  - procedure for generating and the scope of the management information;
  - operational control organisation, including rules and procedures for approving, carrying out and reporting transactions;
  - internal rules and procedures for risk management and control systems efficiency and for reporting established weaknesses.
- LCI Art 73(4) and Ordinance 7 (Art 2, Art 7) set detailed requirements for credit origination and internal rules, including at minimum:
  - the information required from the credit applicant;
  - method of assessing creditworthiness (applicant and guarantors);
  - method of evaluating offered collateral;
  - method of evaluating the efficiency of the project to be funded;
  - decision making methodology for extension of a credit, in accordance with its type;
  - intended use and repayment of the credit;
  - controls over use of the credit, borrower and guarantor financial position, and adequacy of collateral;
  - types of credit, sanctions and sanctioning procedures.
- Ordinance 7, Art 7(2) mandates internal methodologies enabling assessment of:
  1. exposures to individual obligors;
  2. securities positions;
  3. securitisation exposures; and
  4. credit risk at the portfolio level.
- Ordinance 7, Art 7(5-7) and related provisions:
  - internal methodologies shall not rely solely or mechanically on external credit ratings;
  - where capital requirements are based on an ECAI rating or unrated status, banks must additionally consider other relevant information for internal capital allocation;
  - diversification of credit portfolios must be adequate given the bank’s target markets and overall credit strategy.
- LCI Art 68: banks must create and keep credit files containing customer data, grounds, terms and conditions, collateral, competent authority decision, and other contract/performance information.
- LCI Chapter Six (Arts 51-54) addresses conflicts of interest; Art 45 governs related party lending.

### Supervisory powers, processes and guidance
- LCI Art 72(1): banks must submit to the BNB copies of Statute, regulations, instructions, and other documents regarding operations, capital and internal organisation within 10 days following adoption or amendment.
- LCI Article 80 grants the BNB rights to require submission of all relevant accounting and other documents, information on activities, conduct on-site inspections, and free access to premises and information systems.
- The BNB refers to Basel Principles of Corporate Governance for Banks and OECD principles as best practice benchmarks.
- Internal RAS Manual provides guidance for inspectors assessing risk management systems, internal controls, and consistency with business objectives, and prescribes specific questions for onsite inspections.

### Onsite and offsite inspection practices and scope
- Core onsite credit risk inspections review extensive samples of credit files; at the time of assessment the BNB indicated that approximately 20 to 25 percent of the loan portfolio would be reviewed.
- Pre-inspection letters request extensive reports and data; banks must provide additional information and specific loan files during inspection.
- Onsite inspections seek compliance with regulations and bank policies and typically include:
  - review of credit policy and selected credit procedures (individual and collective impairment, collateral valuation, handling of weak exposures, risk classification);
  - meetings with board of management, credit department management, and employees working on IRB matters (relevant in only two banks with IRB authorization);
  - assessment of risk appetite, credit procedures, and organizational changes.
- Off-site analysis aims to identify credit risk quantitatively (growth rates, trends, asset structure changes) and to analyze reasons for significant changes.
- Inspectors are expected to assess strategy, internal controls, approved competencies and limits, and management’s ability to identify and manage risks in a timely manner.

### Supervisory evaluation criteria (EC2–EC7) — descriptions and findings
- EC2: Supervisor determines that Board approves and regularly reviews credit risk management strategy and significant policies for assuming, identifying, measuring, evaluating, monitoring, reporting and controlling or mitigating credit risk (including counterparty credit risk and associated potential future exposure) consistent with the Board-set risk appetite; senior management implements the Board-approved strategy. Ordinance 7 (Art 2) requires Board approval and periodic review of strategies and policies.
- EC3: Supervisor requires policies/processes establishing an appropriate credit risk environment, including:
  - (a) well documented and effectively implemented strategy and sound policies without undue reliance on external credit assessments;
  - (b) well defined criteria and processes for approving new exposures and renewals/refinancing with appropriate approval authority;
  - (c) effective credit administration policies/processes including borrower repayment capacity analysis, monitoring of documentation/covenants/collateral, and an appropriate asset grading/classification system;
  - (d) effective information systems for accurate and timely identification, aggregation and reporting to Board and senior management;
  - (e) prudent and appropriate credit limits consistent with risk appetite, profile and capital strength;
  - (f) exception tracking and reporting ensuring prompt action at appropriate senior management or Board level;
  - (g) effective controls around model use, data quality and validation procedures.
- Findings on EC3: law and ordinances provide a sound framework though with potential gaps; assessors reviewed inspection files and noted references, discussions and recommendations covering elements of the criterion.
- EC4: Supervisor determines banks have policies/processes to monitor total indebtedness of entities and risk factors that may result in default, including significant unhedged FX risk.
  - LCI Art 56: BNB maintains a database of customers’ financial obligations to banks, persons, payment institutions and electronic money institutions; banks have right of access.
  - Threshold for reporting a credit to the register is 1000 Bulgarian leva.
  - There are over 4 million exposures registered, providing significant coverage; BNB checks register usage by banks.
  - Internal RAS Manual prescribes questions for inspectors on whether banks maintain detailed/updated information on total indebtedness, whether credit officers understand structure and repayment schedules, whether banks monitor cash outflows and liquidity, and whether specific ratios such as credit debt / equity are used.
  - FX risk in the Bulgarian system is minimal and addressed through risk weighting of the net open position.
- EC5: Supervisor requires credit decisions free of conflicts of interest and on an arm’s length basis.
  - LCI Arts 51-54 require disclosure of relationships and business interests; persons with potential conflicts should be excluded from negotiations; banks must ensure customer interests take precedent; violations can render transactions null and void and may lead to dismissal by the BNB.
  - Internal RAS Manual details how inspectors examine conflicts of interest; supervisors must report cases where limits for internal or large exposures are broken and analyze concentrations indicating informal connections; identification of informal connections reduces management rating.
- EC6: Supervisor requires credit policy to prescribe Board or senior management decision for major exposures exceeding a certain amount or percentage of capital, and for exposures especially risky or outside mainstream activities.
  - LCI Art 44 requires Board approval where a credit exceeds 10 percent of capital (threshold set by CRR Art 392 “definition of a large exposure”); where exposure exceeds 15 percent of the capital base approval must be unanimous.
  - Banks typically set absolute and relative approval limits in credit policies; conformity checked during on-site inspections.
- EC7: Supervisor has full access to information in credit and investment portfolios and to bank officers involved in credit risk management.
  - LCI Article 80 grants BNB rights to request documents and conduct on-site inspections; for consolidated supervision the BNB may require parent companies and subsidiaries to provide all relevant documents/information and free access.
  - The BNB has the right to free access to office premises and information systems of persons conducting banking activity.

### Supervisory focus areas and inspector expectations
- Inspectors focus on:
  - the adequacy of credit risk policy and processes through on-site inspections and inspection reports;
  - management role and board oversight; assessors noted criticism of management and supervisory boards in inspection reports;
  - analysis of trends, changes and growth rates in lending, effectiveness of internal policies/procedures/controls, methods to identify potential/existing problems, internal self-assessment, and applied provisioning policy;
  - both the level of risk taken and quality of internal controls and management systems, adjusted by inspection approach (on-site qualitative assessment; off-site quantitative assessment).

*Source: _cr15295 - 1. exposures to individual obligors;*

### 2. demand documents and collect information in relation to the performance of the task assigned;

### _cr15295 - 2. demand documents and collect information in relation to the performance of the task assigned;

### Supervisor investigatory and information-gathering powers
- Demand documents and collect information in relation to the performance of the task assigned.
- Appoint external independent experts (at the expense of the bank).
- Appoint an external auditor for a bank, who will carry out a financial or other type of audit (at the expense of the bank).
- Conduct counter examinations in other bank and non-bank undertakings.
- Attend the meetings of the managing and controlling bodies of banks and express opinions that are to be written down in the minutes of the meeting.
- Demand copies of documents verified by the persons under Article 10, paragraph 1 or a person authorised by them and determine the term of their submission.
- Require explanations from banks and persons referred to in paragraph 6 as well as of their agents or employees.
- Ask questions of any other person who consents to, in order to gather information related to the subject of the inspection.

### Stress testing requirements and supervisory practice (re EC8)
- CRR (Art 177) requirements:
  - All banks must have sound stress testing processes for use in the assessment of capital adequacy.
  - Testing must involve identifying possible events or future changes in economic conditions that could have unfavourable effects on an institution's credit exposures and assessment of the institution's ability to withstand such changes.
  - Each institution must regularly perform a credit risk stress test to assess the effect of certain specific conditions on its total capital requirements for credit risk.
  - Tests are chosen by the institution and are subject to supervisory review.
  - Tests are required to be meaningful and consider the effects of severe, but plausible, recession scenarios.
  - An institution must assess migration in its ratings under the stress test scenarios.
  - Stressed portfolios must contain the vast majority of an institution's total exposure.
- BNB supervisory actions:
  - BNB can and has required banks to be more stringent in assessment of credit risk, for example by issuing letters on behalf of the Deputy Governor in charge of the Banking Supervision Department based on comparisons between top-down and bottom-up stress-test outcomes.
  - BNB issued Guidelines on Stress Testing, based on GL32 issued by CEBS.
  - Stress testing programmes should encompass all material risks (both on and off-balance sheet) relevant for the banking group.
  - Stress testing should consist of a multi-layered approach; scope may vary by proportionality principle from simple portfolio sensitivity analyses to comprehensive firm-wide scenario stress testing.
  - Stress scenarios should address all material risk types (e.g., credit risk, market risk, operational risk, interest rate risk and liquidity risk).
  - Various stress tests on credit risk performed by banks are subject to on-site and off-site checks.
  - BNB applies macro prudential stress tests to examine vulnerabilities in the credit system in Bulgarian banks.

### Assessment of supervisory oversight of credit risk (Principle 17) — summary findings
- Assessment outcome: Compliant.
- Observations:
  - Credit risk is the most significant risk factor in the Bulgarian banking sector.
  - Framework of laws and requirements are comprehensive.
  - Inspection teams have a close focus on the entire credit risk function; assessors praised the experience, quality and assiduousness of BNB inspectors.
  - Inspectors routinely identify anomalies, breaches of internal policies and regulatory violations.
- Vulnerabilities noted (addressed under related Core Principles):
  - Quality of board engagement and oversight of credit risk activity (CP14).
  - Presence and potential impact of related party lending and concentrations and breaches of limits (CP20 and CP19).
  - Possible inconsistency in BNB inspection practices across teams due to the organization of inspection teams (CP9).

### Problem assets, provisions and reserves (Principle 18) — EC1 to EC9 findings

- EC1 — Policies and processes for identifying and managing problem assets
  - Legal and supervisory requirements:
    - Ordinance 7 on organisation and risk management of banks, Art 7 (3) requires effective systems for ongoing administration and monitoring, including identifying and managing problem credits and making adequate value adjustments.
    - Loan loss provisioning based on IAS/IFRS framework applied on a mandatory basis under the Law on Accountancy.
    - BNB considers problem assets in SREP and has power to require additional capital under Pillar 2 (legal basis: LCI Article 103 (2), point 20).
    - BNB uses ITS on Forbearance and non-performing exposures criteria in assessing problem loans.

- EC2 — Adequacy of banks’ grading, classification and provisioning processes
  - On-site and off-site activities focus on whether banks implement adequate policies and conservative provisioning.
  - Standardized pre-inspection information requests include copy of provisioning policy, description of procedures applied for impairment calculation in IAS 39, collateral types and discounting rates, and information about forbearance exposures.
  - RAS Manual requires inspectors to assess:
    - Asset quality and loan portfolio (Share of NPL (overdue more than 90 days), conformity with rating system, degree of impairment of NPL (coverage ratio), internal systems for timely identification and collection).
    - Loan portfolio distribution by internal rating, migration matrix, share of loans with good ratings and provisioning levels.
  - Supervisory analysis based on comprehensive assessment of trends, growth rates, lending aspects, internal controls, self-assessment, and provisioning policy.
  - On-site inspection documentation expectations include distribution by rating classes, default rate, impairment methodology, migration matrix, and mandatory review of minutes of Credit Committee, Provisioning Committee, Risk Committee.
  - BNB does not use external expert support in assessing banks’ internal policies and procedures.

- EC3 — Treatment of off-balance sheet exposures in classification and provisioning
  - BNB adopts EU treatment from ITS on Forbearance and non-performing exposures (draft finalized by EBA July 2014 and adopted by EC February 2015; applied by BNB since Q3 2014).
  - ITS defines “exposures” to include loans, advances, debt securities and off-balance sheet exposures (except held for trading); off-balance sheet exposures include loan commitments given, financial guarantees given, and other commitments given.
  - BNB uses on-site inspections to determine treatment of off-balance sheet commitments; banks must provide list of all off-balance sheet commitments for review; such exposures are at a low level in the Bulgarian banking system.

- EC4 — Timeliness and realism of provisions and write-offs
  - Assessment carried out through on-site review.
  - Pre-inspection information requests include rules, policies and procedures for lending management, hierarchy for granting, negotiation and restructuring, rules for evaluation and provisioning of risk exposures and collateral policy.
  - BNB and market participants confirm environment for realizing collateral is poor in Bulgaria, leading to extended legal work-out and discouraging banks from acting on problem loans.
  - BNB challenges banks in meetings with chief credit risk officers on timely recognition and realistic recovery values.

- EC5 — Early identification and oversight of deteriorating assets; treatment testing
  - RAS Manual sets out extensive documentation required from banks for assessment and evaluation.
  - Inspectors examine minutes from risk committees and workout units during on-site inspection.
  - Banks must provide lending rules, scale of competence for granting/negotiation/restructuring, rules for assessment and provisioning and collateral policy.
  - Additional documents required during on-site inspections:
    - Summary report on the activity of the unit collecting past due obligations.
    - Plans for the activity of the workout (deteriorated assets management) and collection units for the recent year.
    - Information on legal proceedings and tenders for sale of real estate.
    - Summary report on distribution of internal ratings of borrowers.
    - Information on existing programs for renegotiation and restructuring of loans including parameters and duration; plans for portfolio restructuring.
    - Information on “performing forbearance exposures” and “non-performing forbearance exposures.”
  - Verification of quality of banks’ processes is made during on-site inspection.
  - Banks expected to have Risk and Provisioning Committees, workout units; BNB indicated all banks have a work out unit.
  - BNB identified misclassification in on-site work and issued follow up reports and recommendations requiring remedy.

- EC6 — Supervisor access to classification and provisioning information; documentation requirements
  - Since September 2014 data submitted according to FINREP and the ITS (Regulation 680/2014) i.e., table 19 of FINREP.
  - Transitional parallel run: banks had to submit specific provisions for credit risk according to standards in repealed Ordinance 9 covering end 2013 to end 2014, including description of reasons leading to reduction according to banks’ individual reduction plans.
  - Information on distribution of loans by product type and exposure classification.
  - Supporting documentation reviewed in context of on-site inspections.

- EC7 — Supervisor power to require adjustments and remedial measures
  - RAS Manual prescribes steps to assess whether asset classification and provisioning are adequate for prudential purposes.
  - Supervisor assesses allocation of accrued impairment losses (IAS) through direct examination of a sample of credit files focused on:
    - Analysis of sources of income (incl. volume of turnover and the amount of average daily balances on current accounts of customers within the bank).
    - Utilization and targeted spending of the credit (tracking cash flow, availability of invoices/other documents for target utilization, ongoing monitoring of investment projects).
    - Analysis of financial position of the company; availability of past due obligations; quality of ongoing monitoring of credit transactions.
  - Based on findings, supervisor may recommend increased provisioning or adjustment to asset classification; if bank does not consent, supervisor must submit written report to DG responsible for Banking Supervision Department, who has the right to undertake remedial measures.
  - BNB aims to review 20 to 25 percent of the loan portfolio; misclassification is regularly identified with five years of formal and informal measures reviewed by assessors showing repeated identification of misclassification.

- EC8 — Valuation of risk mitigants and collateral
  - CRR requirements apply, including Chapter 4 – Credit Risk mitigation; CRR requires regular checks on valuation of credit risk mitigants (e.g., Art 207(4)(d) for financial collateral).
  - Eligible assets for funded credit risk mitigation limited to assets in EBA RTS pursuant to Art 194(10) of the CRR.
  - On-site inspection of credit files reviews collateral documentation, last appraisal and insurance of accepted collateral.
  - Real estate is predominant collateral in Bulgaria; banks use real estate agencies or internal units for appraisals.
  - Guarantees are little used and are not accepted for credit risk mitigation unless sovereign guarantees.
  - For IRB-approved banks, inspectors verify eligible collateral (market and realization values) and confirm existence of insurance per Articles 197 -199 and 208 of the CRR.
  - Inspectors require a range of collateral valuation information from banks prior to inspection and apply techniques to check valuations.

- EC9 — Criteria for problem asset identification and reclassification
  - Identification and reclassification criteria based on ITS on forbearance and non-performing exposures.
  - Final draft ITS submitted to European Commission by EBA was adopted on 9 January 2015 and published in the Official Journal on 20 February 2015.
  - Interim “draft” version had been in use in Bulgaria and other EU member states; texts are almost identical except for reference to applicable accounting framework and Article 178 of the CRR.
  - EBA FINAL draft Implementing Technical Standards on Supervisory reporting on forbearance and non-performing exposures under article 99(4) of Regulation (EU) No 575/2013 referenced.

*Source: _cr15295 - 2. demand documents and collect information in relation to the performance of the task assigned;*

### 156. Exposures may be considered to have ceased being non-performing when all of the following

### _cr15295 - 156. Exposures may be considered to have ceased being non-performing when all of the following

### Criteria for cessation of non-performing status
- Exposures may be considered to have ceased being non-performing when all of the following conditions are met:
  - (a) the exposure meets the exit criteria applied by the reporting institution for the discontinuation of the impairment and default classification;
  - (b) the situation of the debtor has improved to the extent that full repayment, according to the original or when applicable the modified conditions, is likely to be made;
  - (c) the debtor does not have any amount past-due by more than 90 days.

- The ITS on reclassification: Commission Implementing Regulation (EU) 2015/227 of 9 January 2015 (which amends Implementing Regulation (EU) 680/2014) restates the same conditions:
  - (a) the exposure meets the exit criteria applied by the reporting institution for the discontinuation of the impairment and default classification;
  - (b) the situation of the debtor has improved to the extent that full repayment, according to the original or when applicable the modified conditions, is likely to be made;
  - (c) the debtor does not have any amount past-due by more than 90 days.

- Additional clarifications:
  - An exposure shall remain classified as non-performing while those conditions are not met, even though the exposure has already met the discontinuation criteria applied by the reporting institution for the impairment and default classification according to the applicable accounting framework and Article 178 of CRR respectively.

### ITS on Non-performing exposures (template 18 definition)
- For the purpose of template 18, non-performing exposures are those that satisfy any of the following criteria:
  - (a) material exposures which are more than 90 days past due;
  - (b) the debtor is assessed as unlikely to pay its credit obligations in full without realisation of collateral, regardless of the existence of any past due amount or of the number of days past due.

- Note: Article 178 of the CRR sets out when the default of an obligor is considered to have occurred and includes the concepts of:
  - the lending institution considering that the obligor is unlikely to pay; and
  - where the obligor is past due more than 90 days on any material credit obligation to the institution, the parent undertaking or any of its subsidiaries.
- The CRR permits some national discretion e.g. in relation to residential mortgage loans, SMEs, commercial real estate and public sector entities.

### EC10 — Board information on asset portfolio
- Supervisor expectation:
  - The bank’s Board obtains timely and appropriate information on the condition of the bank’s asset portfolio, including classification of assets, the level of provisions and reserves and major problem assets.
  - Information includes, at a minimum, summary results of the latest asset review process, comparative trends in the overall quality of problem assets, and measurements of existing or anticipated deterioration in asset quality and losses expected to be incurred.

- Findings:
  - Banks are expected to have Risk and Provisioning Committees (or similar) which usually include members of the bank’s Board and which deal with the management of provisions.
  - Extracts from the minutes of the meetings of these Boards are examined during on-site inspections.
  - Internal RAS Manual requires inspectors to assess the MIS during on-site examinations, including information flow to the Management Board concerning credit risk and asset quality.

### EC11 — Individual assessment for significant exposures
- Supervisor requirement:
  - Valuation, classification and provisioning, at least for significant exposures, are conducted on an individual item basis. Supervisors require banks to set an appropriate threshold for identifying significant exposures and to regularly review the level.

- Findings and standards:
  - According to IAS 39 banks are required to assess whether there is objective evidence of impairments on their loans. The assessment shall be made individually for all loans of significant size.
  - According to ITS on forbearance and non-performing exposures, materiality shall be assessed in accordance with Article 178 of the CRR, which states (Art 178(2)(d)):
    - “(d) materiality of a credit obligation past due shall be assessed against a threshold, defined by the competent authorities. This threshold shall reflect a level of risk that the competent authority considers to be reasonable;”
  - The materiality threshold is set out in Ordinance No.7, Article 28:
    - 1. 5 percent of the installment due, but no more than BGN 100 for retail exposures;
    - 2. 5 percent of the installment due, but no more than BGN 1000 for all other exposures.
  - On-site inspections conduct in-depth analysis of provisioning policies including all thresholds and provisioning rules for loans of significant size. On-site inspections identified concerns relating to the performance and management of significant exposures in banks’ portfolios.

### EC12 — Top-down assessment of sectoral risk and provisions
- Supervisor activity:
  - The supervisor regularly assesses trends and concentrations in risk and risk build-up across the banking sector in relation to banks’ problem assets, considers concentration in risk mitigation strategies, and the adequacy of provisions and reserves at the bank and system level.

- Findings:
  - Credit risk is subject to top-down stress testing performed by Macro-prudential Supervision and Financial Stability Directorate (MPSFS) since 2002.
  - Techniques for top-down stress testing have been updated regularly. In 2009 a ST simulation was added based on the correlation between GDP growth rate and the dynamic of adversely classified loans.
  - On several occasions credit risk stress testing used country specific stressed parameters (PDs, LGDs or LRs) provided by ECB under EBA EU-wide stress tests. The latest simulation of this type was organized by MPSFS in the second half of 2014.

### Assessment of Principle 18 (Asset classification, provisioning and credit risk control)
- Assessment: Largely Compliant
- Comments and observations:
  - The BNB does not have direct power to reclassify assets, other than through prudential reporting and/or increase provisions, although it may recommend that banks should do so. The BNB may not overrule a provisioning decision made by the bank.
  - BNB’s remaining powers include reclassifying assets for prudential purposes or applying higher capital using a Pillar 2 process, which to date the BNB has not exercised, although inspection reports reflected concerns with under provisioning in individual banks.
  - With CRR/CRDIV and associated RTS and ITS, the BNB revoked former Ordinance 9 which governed asset classification and provisioning for prudential purposes; the Ordinance lapsed at end 2014.
  - The transition from Ordinance 9 to the IFRS approach released approximately 2bn Leva in capital in the banking system.
  - BNB informed banks at the end of 2013 that it did not expect banks to make use of the uplift in their capital until the underlying problem exposures had been fully resolved. BNB will continue to monitor these loans and is retaining some data submission on the Ordinance 9 format for macro prudential purposes.
  - The environment for valuing and realizing collateral in Bulgaria is difficult: legal proceedings are slow, incentives exist for banks to hold loans in hopes collateral values will increase, real estate values have only recently been stabilizing and demand remains weak. Commercial real estate was not accepted as collateral until the introduction of the CRR.
  - The limitations on BNB’s former powers, coupled with changes to reported data (FINREP on forbearance and problem assets), increase the importance of on-site examinations to ensure correct identification, migration and valuation of assets and timely foreclosure/execution of collateral.
  - BNB inspectors have identified issues related to NPLs and provisioning: misclassification, inappropriate and lack of timely valuation of collateral, and resistance to foreclosing on loans.
  - BNB has a thorough approach to on-site inspection and is adjusting to EU regulatory changes. So far BNB has not applied additional capital requirements in respect of problem loans under CRDIV, though it operates a de facto informal Pillar 2 process.
  - Given monitoring and instruction to banks that former supervisory provisions must not be drawn upon, the approach is likely reasonable, but BNB should consider sooner rather than later how to operationalize its Pillar 2 approach for problem loans.
  - Issues of identifying concentrations/large exposures, related parties and potential inconsistency between on-site teams are critical for effective oversight.

- Recommendations:
  - Assess, and be ready to operationalize the Pillar 2 approach for banks which are demonstrating weaknesses in respect of problem exposures.
  - Consider the use of horizontal reviews into the state of NPL management in banks, paying particular attention to any banks whose data indicates that they are outliers in terms of performance.

### Principle 19 — Concentration risk and large exposure limits (intro)
- Principle: The supervisor determines that banks have adequate policies and processes to identify, measure, evaluate, monitor, report and control or mitigate concentrations of risk on a timely basis. Supervisors set prudential limits to restrict bank exposures to single counterparties or groups of connected counterparties.

### EC1 — Laws, regulations or supervisor requirements on concentration risk
- Essential criterion: Laws, regulations or the supervisor require banks to have policies and processes that provide a comprehensive bank-wide view of significant sources of concentration risk. Exposures arising from off-balance sheet as well as on-balance sheet items and from contingent liabilities are captured.

- Description and findings:
  - Provisions on concentration risk and large exposures limits are laid out in norms. LCI, art. 44 states that a decision resulting in a large exposure shall be adopted by the board of directors.
  - Under the current regime, a bank's exposure to a counterparty or a group of connected counterparties cannot exceed 25 percent of the eligible capital.
  - As directive 2006/48 was replaced by EU regulation 575/2013, the 800 percent own funds aggregate limit was abolished and currently this limit does not apply to Bulgarian banks. According to the BNB, a survey showed that only one bank was close to this limit.
  - If exposure exceeds 15 per cent of the own funds, the decision shall be taken unanimously.
  - Banks are obliged to notify the BNB in writing within 10 days of decisions made regarding any large exposure (LCI, art. 71, para. 1, point 5).
  - For exposures in the banking book, any breach of the limit should be immediately reported.
  - The limits can be exceeded only for exposures in the trading book under certain conditions stipulated in EU regulation 575/2013. Depending on the excess, additional capital requirements are imposed.
  - The BNB told the mission that all Bulgarian banks apply...

*Source: _cr15295 - 156. Exposures may be considered to have ceased being non-performing when all of the following*

### part IV of regulation 575/2013 and the respective reporting forms from the EU Regulation 680/2914

### part IV of regulation 575/2013 and the respective reporting forms from the EU Regulation 680/2914

### Regulatory framework and definitions
- EU Regulation 575/2013 (Part Four) and EU Regulation 680/2914 (Annex 8 and 9) apply to large exposures and related reporting forms.
- “Close links” (per EU Regulation 575/2013) include:
  - participation in the form of ownership, direct or by way of control, of 20 percent or more of the voting rights or capital of an undertaking;
  - control;
  - a permanent link of both or all of them to the same third person by a control relationship.
- “Group of connected clients” (per EU Regulation 575/2013) includes:
  - two or more natural or legal persons who, unless shown otherwise, constitute a single risk because one directly or indirectly has control over the other(s);
  - two or more natural or legal persons who, while not in a control relationship, are so interconnected that financial problems of one would likely cause problems for the others.
- LCI (Bulgarian Law) definitions referenced:
  - “connected persons” include spouses, relatives and collateral relatives up to the fourth degree of consanguinity and relatives by marriage up to the third degree of affinity; partners; persons where one participates in management of the other’s undertaking or subsidiary; persons with common members of management or controlling bodies; an undertaking and a person who holds more than 10 per cent of an undertaking’s stakes or voting shares; persons who jointly control a third person or its subsidiary, etc.
  - LCI art 45 (6) and art. 44 referenced for large exposure limitations and obligations to not exceed established ratios of LEL.

### BNB Guidelines on concentration risk and institutional responsibilities
- Institutions are expected to:
  - adequately address concentration risk in governance and risk management frameworks;
  - assign clear responsibilities;
  - develop policies and procedures for identification, measurement, management, monitoring and reporting of concentration risk.
- Management body duties:
  - understand and review how concentration risk derives from the overall business model;
  - ensure existence of appropriate business strategies and risk management policies.
- Institutions should adopt an integrated approach covering intra- and inter-risk concentration and identify risk drivers that could be sources of concentration risk.
- Coverage of concentrations must include on- and off-balance sheet positions and committed and uncommitted exposures, across risk types, business lines and entities.
- Concentration risk must be accounted for within ICAAP and capital planning frameworks, including assessment of capital adequate to hold given concentration risk levels.

### Supervisory requirements, reporting and information systems (EC2, EC3, EC4)
- EC2: Supervisory expectation
  - Banks are required to have internal policies and procedures to identify, assess, monitor and verify exposure portfolio concentrations; concentration risk management policy must be documented.
  - BNB verifies that banks’ information systems provide adequate information on risk concentration and exposure limitations through off-site and on-site diligences.
  - Prior to on-site visits, BNB requests summary reports of limits by economic sectors/industries, by clients and groups of connected clients, by type of products, by type of collateral, copies of tracking reports, and information on breaches.
  - On-site inspections assess quality of identification, ongoing monitoring, risk analysis and control processes; accuracy, timeliness and efficiency of management information and risk monitoring systems; availability of internal systems for identification of large exposures and adequacy to bank limits (RASM p. 61).
- EC3: Thresholds and governance
  - Banks must develop and apply frameworks to manage and monitor concentration risk, including internal rules and limits depending on bank credit policies and risk appetite.
  - BNB Internal Guidelines require institutions to set practical definitions of material concentration aligned with risk tolerance, determine concentration risk tolerance by business model, size and geographic activity, and monitor sectoral concentration (including collateral and guarantees).
  - No fixed sectoral limits: levels determined case by case.
  - On-site assessment includes review of board minutes (approvals of “large operations”), management information systems completeness and usefulness, ongoing monitoring and control of concentration risks, and communication of strategy/policy to relevant staff (RASM pp. 35, 59, 60).
- EC4: Reporting and supervisory review
  - Banks are subject to reporting obligations on concentration risks, broken down by geographic locations, currency, etc.
  - BNB inspection teams require lists of connected counterparties by sector and currency and a summary of sectoral/industry limits and related tracking.
  - Art. 71, para.1, point 5 of the LCI: banks obliged to notify the BNB for new large exposures.
  - Supervisory analysis supplemented by ongoing dialogue with bank management on diversification strategy.

### Definition and control of connected counterparties (EC5, EC6)
- EC5: Definition of groups of connected counterparties
  - Bulgaria uses EU Regulation 575/2013 definitions of “close links” and “group of connected clients” and LCI definitions of “connected persons.”
  - LCI and Guidelines on implementation of the revised large exposures regime further define “persons acting in concert” and persons “economically related.”
- EC6: Limits and monitoring of large exposures
  - All Bulgarian banks apply Part Four of EU Regulation 575/2013.
  - General principle: a bank's exposure to a counterparty or a group of connected counterparties cannot exceed 25 percent of own funds.
  - “Exposures” means any asset or off-balance sheet item referred to in Part Three, Title II, Chapter 2 of Regulation 575/2013, without applying risk weights or degrees of risk.
  - BNB Guidelines require documentation and reporting of exceptions; procedures for independent monitoring of breaches of policies and concentration limits.
  - On-site inspection methodology (RASM p.31, p.35) includes assessment of systems/rules for identifying, monitoring, assessing and controlling credit and concentration risk and management’s ability to manage credit risk in all stages of lending.

### Stress testing and concentration (EC7)
- EC7:
  - BNB requires banks to include the impact of significant risk concentrations into their stress-testing programs for risk management purposes.
  - BNB Guidelines mandate stress-test exercises including on impact of significant risk concentrations.
  - Supervisors assess whether concentration risk is adequately captured in firm-wide stress testing and may perform or request additional stress tests.

### Additional criteria, Large Exposure Limits (AC1) and supervisory assessment
- AC1:
  - For credit exposure to single counterparties or groups of connected counterparties:
    - (a) ten per cent or more of a bank’s capital is defined as a large exposure; and
    - (b) twenty-five per cent of a bank’s capital is the limit for an individual large exposure to a private sector non-bank counterparty or a group of connected counterparties.
  - LCI art 45 (6): “a bank’s total exposure to a person [under paragraph 1], which is not a credit institution or an investment intermediary, may not exceed 10 per cent of its own funds.”
  - The same article sets aggregated limits: “the total amount of all exposures of a bank to persons under the first sentence may not exceed 20 per cent of the bank’s own funds.”
- Assessment of Principle 19: Materially non-compliant
  - Regime derives from EU Directive and CEBS principles. A bank's exposure cannot exceed 25 percent of eligible capital.
  - Board approval required for decisions resulting in a large exposure; exposures exceeding 15 per cent of eligible capital require unanimous board decision.
  - During on-site inspection, about 30 percent of the loan portfolio is reviewed, with priority to Large Exposures and connected lending.
  - Inspectors perform due diligence to ascertain conformity with requirements for exposures to persons connected to the bank and art. 44 LCI obligations not to exceed established LEL ratios.
  - Inspectors focus on identification of concentration risk in banking and trading books and whether banks allocate additional capital for concentration risk.
  - BNB has powers to instruct banks to mitigate excessive concentration risk.
  - Mission review found inspection reports detecting major deficiencies in at least two banks:
    - Bank A: (i) absence of analysis of informal concentrations; (ii) large part of credit portfolio to offshore or foreign-registered companies hindering identification of connections; (iii) flaws in control and risk management of concentration risk.
    - Bank B: large concentrations from exposures of credit borrowers connected to shareholders; conclusion that “concentration risk is not a priority to the Bank’s management.”
  - Practical concerns:
    - KTB collapse in summer 2014 revealed supervisory shortcomings in supervision of concentration risk and related-party lending.
    - Banks have used strategies to circumvent LEL regulation and exceed concentration limits as evidenced in BNB reports.
    - Determination of economic relatedness between customers is difficult; lack of transparency in ownership structures (sometimes overseas) undermines identification of connected lending and concentration risks.
  - Recommendation highlights:
    - Conduct a horizontal review across the industry to verify degree of conformity with LEL requirements.
    - Instruct the industry to increase efforts in establishing clear understanding of customers’ ownership structure.
    - Take forceful measures to enforce more effectively observance of risk concentration limits (including issuance of recommendations and application of sanctions).

### Related parties framework (Principle 20, EC1)
- Principle 20 summary:
  - Supervisor requires banks to enter into transactions with related parties on an arm’s length basis; to monitor, control or mitigate risks; and to write off exposures to related parties in accordance with standard policies and processes.
- EC1 (description and findings):
  - Bulgarian regime does not define “Related Parties” per se but LCI lists series of persons to whom a bank can have exposure under certain conditions (art.45 (1) referenced).

*Source: part IV of regulation 575/2013 and the respective reporting forms from the EU Regulation 680/2914*

### 1. administrators of the bank;

### _cr15295 - 1. administrators of the bank;

### Definitions and scope of related parties / connected clients
- Enumerated related persons (as listed):
  1. administrators of the bank;
  2. shareholders holding more than 10 percent of voting shares;
  3. a shareholder whose representative is a member of a managing or supervisory body of the bank;
  4. spouses, brothers, sisters and relatives of direct lineage up to third degree including those related to the persons listed above;
  5. legal persons in which the persons under items 1–4 are involved;
  6. companies in which the bank or person under item 1-4 participate in the management or has qualified equity;
  7. third persons acting on behalf of the persons under items 1–6.
- The LCI (in its additional provisions) defines “administrators” as:
  - (i) a member of a supervisory or management board (board of directors) of a bank;
  - (ii) a “procurator79” of a bank and any person whose position includes management and control of operational units; and
  - (iii) the management of the specialized internal control office.
- The LCI defines “economically related persons” as two or more persons regarded as constituting a single risk because they are so interrelated that, if one experienced financial problems (in particular in funding or repayment of obligations), the other or all others would also be likely to encounter funding or repayment difficulties.
- Under EU Regulation 575/2013 banks should also apply the definition of group of connected clients (art. 4, par.1, point 39), which has two aspects: control through ownership or similar relations and economic interconnectedness.80
- BNB additionally uses other types of relationships that may indicate connectivity, for example:
  - (i) a borrower who is provider of outsourced activities or is contract counterparty of the bank;
  - (ii) borrowers with common collateral;
  - (iii) borrowers with a common source of repayment of the debt;
  - (iv) borrowers with a common registered office;
  - (v) borrowers with common auditor with the bank or if they have been audited by the same auditor as the borrowers over the last three years; etc.80

### Declarations, timing, and internal requirements
- Any administrator shall, upon taking office, declare in writing to the management board (board of directors) the names and addresses of the persons economically connected to him or members of his family and the business interests both the administrator and the members of his family have with the bank at the time of the declaration.
- Upon a change in the declared circumstances, the administrator shall file a new declaration within 7 days after such a change takes effect.
- Under Art. 51 of LCI, para.4 any administrator who has a business interest in the conclusion of a particular transaction with the bank shall not participate in the negotiations or in the discussion and decision on its conclusion.
- The law stipulates that in performing their functions, administrators and other employees of a bank shall be obliged to place the interests of the bank and its customers before their own interests.

### Supervisor practices, information sources, and case-by-case assessment
- The authorities reported that the BNB applies discretion in using the definition of related parties during on- and off-site reviews:
  - If the inspector considers that there is a contract with related parties which was misrepresented, the BNB could prescribe a corrective treatment through its supervisory powers.
  - The level of concentration with RPs is analyzed case by case for each bank separately, depending on its business and risk appetite.
- BNB information sources to establish relatedness include:
  - full access to internal registers that banks must maintain on RP and connected lending;
  - external public sources (e.g., commercial register, private providers) for corporate ownership structures and possible financial linkages;
  - letters of “relatedness” signed by the borrower;
  - on-site analysis of “informal relatedness” (e.g., several parties sharing the same address).
- The Special Supervision Directorate (SSD) of BNB:
  - is responsible for keeping a register of all the shareholders of credit and financial institutions authorized or registered by the BNB;
  - performs annual assessment of the financial status and interconnectedness of key shareholders to establish their ability to support financially the bank.

### Prohibitions and treatment of preferential terms
- Laws, regulations or the supervisor require that transactions with related parties are not undertaken on more favorable terms (e.g., in credit assessment, tenor, interest rates, fees, amortization schedules, requirement for collateral) than corresponding transactions with non-related counterparties.81
- As stated in LCI art. 45 (1), a bank may establish relations with affiliated parties only based upon an “unanimous decision of the managing body.”
- According to LCI art. 45 para.4, banks may not give preferential conditions to the “affiliated” persons defined in art. 45 (1). This includes, inter alia, collecting interest, fees or other payments due or accepting collaterals, which are lower than those required from other customers in similar cases.
- Monitoring aspects during on-site visits include pricing of the loan, possible abuse of grace period and any other favorable conditions.
- An exception may be appropriate for beneficial terms that are part of overall remuneration packages (e.g., staff receiving credit at favorable rates).81

### Board approval, conflicts of interest, and gaps identified
- The supervisor requires that transactions with related parties and the write-off of related-party exposures exceeding specified amounts or otherwise posing special risks are subject to prior approval by the bank’s Board.
- The supervisor requires that Board members with conflicts of interest are excluded from the approval process of granting and managing related party transactions.
- Description and findings:
  - As stipulated by the law, exposure to related parties require an unanimous decision of bank’s managing body (art. 45(1)).
  - However, neither the law nor the BNB define the concept of exposures that are subject to this unanimous decision or stipulate any restrictions in case of write-off.
  - It is not clear whether the restriction that an administrator with a business interest shall not participate in negotiations extends to all relevant approval and write-off processes.

*Source: _cr15295 - 1. administrators of the bank;*

### conclusion of a particular transaction” also applies, in the case of loans, to any decision/resolution

### _cr15295 - conclusion of a particular transaction” also applies, in the case of loans, to any decision/resolution

### Related-party transactions (Principle 20) — findings
- Legal/regulatory framework:
  - LCI art. 45 limits: total exposure of a bank to affiliated parties (person or entities) which is not a credit institution or an investment intermediary is limited to 10 percent of total “own funds”.
  - Total amount of all exposures of a bank to connected persons may not exceed 20 per cent of the bank’s own funds (LCI, art. 45 (6)).
  - Certain related-party transactions acceptable under conditions:
    - exposure to persons listed in art. 45 (1) items 1 to 4 does not exceed its annual remuneration;
    - exposure to persons listed in art. 45 (1) items 2, 3, 5, 6, and 7 is less than 1 per cent of the bank’s own funds but not exceeding BGN 300,000 (approx. US$140 K).
- Supervisory practice:
  - BNB on-site inspections verify favorable conditions, review minutes of credit committees, and ascertain absence of conflicted decision-makers.
  - BNB Risk Assessment System (RAS) Manual requires inspectors to check corporate values/procedures prohibiting or strictly limiting conflicts of interest and preferential treatment (page 66 of manual). Transactions by an administrator in violation are null and void.
  - BNB assesses identification, monitoring and reporting of exposures to affiliated parties during on-site inspections; inspection teams request registers of related parties and rules/policies electronically in advance (RASM p.42).
  - BNB SREP manual emphasizes risk monitoring/management systems’ ability to cover risks from exposure to groups of connected persons and concentration risk reviews.
- Reporting and surveillance:
  - Banks required to notify BNB in writing within 10 days of decisions regarding any exposure to related party (LCI art. 71 (1)).
  - Repealed Ordinance No. 7 on large exposures until end-2014; banks now report aggregated exposures to related parties using FINREP templates.
  - In response to KTB collapse, BNB developed new reporting templates disclosing broader relatedness (e.g., same address or same collateral). On January 24, 2015 the BNB sent a formal letter requiring use of the same level of detail as COREP large exposures reporting (elements: name, LEI code, residence, sector, NACE code, type of counterparty, gross exposure, net exposure after eligible credit risk mitigation, by type of exposure - direct or indirect, balance sheet or off balance sheet, etc.). FINREP reporting form 31 provides further details (reporting under IAS 24 rules).
  - Share size and functions of administrators are not regular reporting items; share size available at BNB register; functions checked via on-site inspections.
- Identified weaknesses and past failures:
  - LCI does not define the types of transactions that give rise to related-party exposures; absence of explicit scope (on-balance sheet, off-balance sheet, service contracts, asset purchases/sales, construction contracts, lease agreements, derivative transactions, borrowings, write-offs not specified).
  - Internal control and risk management ordinances (Ordinance No 10 on Internal Control; Regulation 7 on Risk management) are silent on related-party activities; BNB “banking supervision process manual” contains no reference to related parties.
  - Exposures to related parties are not integral to internal control reviews and internal audit; internal control function and management body reviews do not consistently include related-party exposures.
  - Audit profession difficulties: external auditors not obliged to assess/report on “economic related person” or groups with economic inter-linkages; Moneyval (2013) flagged difficulties identifying beneficial owners.
  - KTB collapse (2014) revealed significant shortcomings: KTB’s related-party exposure at end-June 2014 amounted to 33.5 percent of its capital base (increase from 3.9 percent at end-2013 due to auditors’ reclassification). Auditor found large connectedness between debtors and majority shareholder; BNB found prolonged circumvention of limits.
  - Industry-wide concern: need for transversal inspection across industry to ascertain that related-party exposures and interconnectedness are captured by banks’ risk management systems; special attention to cash flows between related parties.
- Supervisory powers and gaps:
  - No explicit requirements allowing BNB to deduct related-party exposures from capital when assessing capital adequacy or to require collateralization. BNB believes it could impose supervisory measures under art. 103 of LCI prior to end of compliance deadline, including:
    - para. 2, point 3: written order to cease the violation;
    - point 5: require the bank to hold own funds in excess of the requirements;
    - point 20: require special provisioning.

### Related-party transactions — recommendations
- Define in regulation or guidelines the types of transactions giving rise to related-party exposures (explicitly include on-balance sheet and off-balance sheet credit exposures and claims, dealings such as service contracts, asset purchases and sales, construction contracts, lease agreements, derivative transactions, borrowings, and write-offs).
- Enhance surveillance of related-party transactions across the industry via a transversal inspection.
- Provide recommendations to industry to be more diligent in identifying customers up to the ultimate owner (particularly for legal entities located overseas).
- Consider legal revisions to allow external auditors to report on any “economic related person.”
- Consider issuing supervisory guidelines to clarify treatment of exposures (e.g., conditions for write-offs of related-party transactions) given limited secondary legislation beyond LCI.

### Country and transfer risk (Principle 21) — findings
- Regulatory context:
  - Bulgaria does not have a regulation specifically on country and transfer risks; banks should follow sovereign risk requirements set in EU regulation 575/2013.
  - Under EBA Guidelines for the SREP process (published December 2014), BNB responsible to assess concentration within all types of exposures to country risk and to assess transfer risk linked to cross-border foreign currency lending for material cross-border lending and foreign currency exposures.
- Supervisory practice:
  - Country risk assessment normally performed during on-site inspections as part of credit risk or as part of ICAAP evaluation.
  - BNB has taken measures for banks with exposure to Greece: directions included (i) maintain highly liquid assets at 30 percent of attracted funds from non-credit and non-financial institutions, enterprises, and individuals in addition to minimum reserves of 20 percent with the BNB; (ii) prohibition to maintain excessive balances with the parent bank and its group, and invest in securities of issuers with non-investment grade rating; (iii) ensure functional independence from the parent bank; (iv) submit daily reports to the BNB.
  - BNB monitors Greek banks and other single bank cases (e.g., massive exposure to Hungarian parent) under close scrutiny.
- Risk management and governance at banks:
  - No explicit legal requirement that banks’ Management Board approve strategies/policies concerning country and transfer risk, though obligations are implicitly covered by Ordinance #7 (2014) for overall risk management.
  - No specific provision in Internal ICAAP Manual dedicated to country and transfer risk; country/transfer risk are considered within general process for each material risk (identification, measurement, monitoring, management; limit setting; self-assessment; reporting).
  - BNB determines during on-site inspections whether banks have information systems, risk management systems and internal control systems to ensure effective monitoring and timely reporting of country risk exposures and compliance with country exposure limits.
- Stress testing and provisioning:
  - BNB Guidelines on Stress testing require banks with activities in more than one country to perform stress testing on business unit level by geographical region, industry sector or business line. However, no concrete requirement to include scenarios reflecting country and transfer risk explicitly in BNB’s Guidelines on Stress testing.
  - There are no explicit requirements for provisioning against transfer risk under current regulatory and accounting framework; country risk measured under Regulation 575/2013 for government and central bank exposures; banks make impairments and provisions under IFRS 36, 37 and 39.
- Information and reporting:
  - Main source of information for country risk is COREP template 9.3. BNB receives quarterly reporting by bank on capital requirements for country risk and exposure to currency risk with details on on- and off-balance-sheet exposure by obligor type, country, currency.
- Identified weaknesses:
  - Assessors judged regime for country and transfer risks has several flaws: absence of specific regulation; stress testing requirements not sufficiently addressing transfer risk; incomplete implementation of EBA SREP Guidelines; BNB internal SREP manual revision envisaged but not finalized.
  - Bulgarian legislation does not explicitly require Management Board approval of strategies/policies concerning country and transfer risk, although covered by overall risk management requirements.

### Country and transfer risk — assessment and recommendations
- Assessment of Principle 21: Materially Non Compliant
- Recommendations:
  - Adopt a regulation on country and transfer risks.
  - Include country and transfer risk in banks’ stress testing (explicit scenarios reflecting country and transfer risk).
  - Implement the EBA Guidelines for the SREP process to ensure proper and timely country risk coverage.

### Market risk (Principle 22) — findings (selected)
- Ordinance 7 of BNB on organization and risk management of banks sets market risk standards and requires banks to:
  - implement policies and processes for identification, measurement and management of all material sources and effects of market risks;
  - have adequate internal capital to cover material market risks not subject to capital requirements under Article 92 of Regulation (EU) No 575/2013.
- Under Ordinance 7 (Chapter III, Section III Market risk), Article 13 paragraphs 2 and 3 set additional requirements concerning position risk and internal capital against the risk of loss which exists between the time of the initial commitment and the following working day.

*Source: _cr15295 - conclusion of a particular transaction” also applies, in the case of loans, to any decision/resolution*

### Chapter IV of Ordinance 7 is for Internal Approaches for Calculating Capital Requirements for Credit

### _cr15295 - Chapter IV of Ordinance 7 is for Internal Approaches for Calculating Capital Requirements for Credit

### Market risk governance and framework
- Chapter IV / Section III (Market risk) of Ordinance 7 requires banks to implement policies and processes for identification, measurement and management of all material sources and effects of market risks (Art 12).
- Law on Credit Institutions (LCI) requirements: Article 73 (1) items 4-7, Article 73a (1) and (2) require the competent managing body to adopt and regularly review strategies and policies for taking up, managing, monitoring and mitigating risks, including those posed by the macroeconomic environment and business cycle; procedures for management information; operational control organisation; internal rules and procedures for risk management and control systems efficiency.
- Under the LCI banks must have sound, effective and complete strategies and processes on an ongoing basis to assess and maintain internal capital adequate to cover the nature and level of all risks; strategies/processes are subject to regular internal review and must be proportional to the bank’s nature, scale and complexity.

### Onsite inspection as primary supervisory tool
- Onsite inspections are the main tool to verify Board approval and implementation of market risk policy; they examine internal organization, reporting, segregation of duties, internal controls, valuations, market limits and adherence to limits.
- Inspection teams meet Board members responsible for market risk, internal auditors, front office, back office, treasury and risk management.
- Frequency: onsite inspections of market risk area are usually conducted every 2-3 years in line with the risk-based approach.
- Resource note: BNB does not have a dedicated market risk specialist; each inspection team includes one member more specialized in market risk.

### Market risk exposures and instruments
- Banks’ exposure to market risk: described as low or low-medium depending on bank size and activities.
- Main instruments used by banks in Bulgaria: interest rate products, capital instruments, government bonds and FX deals.
- At assessment time: market risks were at a very low level; predominant portfolios consisted of Bulgarian government bonds; derivatives are usually limited and used for hedging.
- Allocation between trading and banking book is material for only one bank (one bank is above the de minimis limit for having a trading book).

### Valuation, models and model governance
- EC4 requirements: systems and controls to ensure frequent revaluation of marked-to-market positions; timely capture of transactions; independent function for valuation and model validation; valuation adjustments for concentrated, less liquid, and stale positions.
- BNB requires banks to establish detailed rules/procedures for market activities including systems, controls, methods and models; inspectors verify quality and deliver requirements/recommendations when necessary.
- Challenges noted: low trading volumes, daily prices not always available; Bulgarian government debt not traded on exchange.
- Use of parental models: subsidiaries of EU parents often use parental models (eg value at risk models) for internal business and risk management; no bank is approved for internal model recognition for market risk capital calculations.

### Capital, ICAAP and market risk capital treatment
- Ordinance 7 (Art 13(1)) requires banks to hold adequate internal capital to cover market risks not subject to capital requirements under Article 92 of the Regulation.
- BNB examines the ICAAP annually during onsite inspection to assess allocation of capital against unexpected market risk losses and valuation adjustments.
- Comment: no bank uses internal approach for market risk capital; market risk constitutes a relatively low percentage of total capital requirements for banks in Bulgaria.

### Assessment summary for Principle 22 (Market Risk)
- Overall assessment: Compliant.
- Comment highlights:
  - Market risk not a major factor in system risk profile, but significance should not be underestimated.
  - Models are used for internal purposes even if not for regulatory capital; BNB needs to engage and challenge design, specification, governance and use of such models.
  - Current BNB staff skill and familiarity with market risk likely sufficient for current needs, but lack of dedicated specialist could become an issue if market develops or a bank seeks internal modeling recognition.

### Interest rate risk in the banking book (Principle 23)
- Guiding documents: BNB Guideline on Management of Interest Rate Risk in the banking book (based on CEBS/EBA) and Practical ICAAP Guidelines.
- Banks’ options for assessing internal capital needs for IRRBB:
  - Calculation of potential loss caused by a parallel shift of 200 basis points in the yield curve (detailed procedure in BNB Guidance on management of interest rate risk arising from non-trading activities).
  - Use of bank-owned methodology (eg VaR or PV) with argumentation for suitability to bank’s needs.
- Supervisory practice:
  - Compliance monitored mainly by on-site inspections and off-site analysis through ICAAP.
  - BNB treats IRRBB as extremely significant; currently analysis is annual via ICAAP and no Pillar 2 add-on applied given high system capital levels.
  - Recommendation: BNB should place more emphasis on developing the quality of off-site analysis.
- Regulatory trigger: under Ordinance 7 (Art 8(2)) banks whose economic values decline by more than 20 percent of their own funds as a result of a sudden and unexpected change in interest rates of 200 basis points or other change determined under applicable guidelines, should take immediate corrective action and must notify the BNB within a reasonable time-frame.
- Assessment of Principle 23: Compliant.

### Liquidity risk framework and supervisory requirements (Principle 24)
- EU LCR implementation schedule (as set out in the CRR and delegated acts):
  - 60 percent from 1 October 2015
  - 70 percent from 1 January 2016
  - 80 percent from 1 January 2017
  - 100 percent from 1 January 2018
- Bulgaria maintains framework set out in Ordinance 11 until full EU application (expected in late 2018); BNB has not moved ahead of the CRR timetable.
- Ordinance 11 features and BNB powers:
  - Sets internal liquidity management system, MIS, maturity ladder, reporting to supervisory authority, on- and off-site supervisory assessment, supervisory measures and sanctions.
  - Enforcement powers for failure to adhere: setting minimum liquidity asset ratios for limited time, administrative measures and sanctions under LCI (Art 103(2)).
  - BNB issued letters requiring additional and more frequent liquidity reporting in practice.
- Liquidity ratios and thresholds under Ordinance 11:
  - Liquid assets ratio: recommended minimum ratio of a bank’s liquid assets to total household and corporate deposits set by BNB each financial year is 20 percent.
  - Maturity ladder: liquidity deemed acceptable if liquidity ratios by maturity time bands are not under 1 at least for the first two maturity time bands.
- BNB guidance and tools:
  - Published guidelines related to liquidity buffers and survival periods (based on CEBS/EBA 2009) and on liquidity costs and benefits allocation.
  - Macro-prudential Supervision and Financial Stability directorate conducts at least once a year system-wide stress test simulations focusing on liquidity risks.
  - Internal RAS Manual follows Basel practices for liquidity management structure, core liquidity evaluation, contingency plans, currency liquidity management, internal control, market discipline and supervisory assessment.
- Historical note: pre-CRR supervisory reporting provided daily and intra-day data that was valuable during the KTB crisis in 2014.

### Liquidity management practices and supervisory assessment
- Requirements for liquidity management are in Ordinance 11 (Articles 1-11) and reinforced by internal RAS and SREP manuals.
- Board responsibilities: set liquidity risk tolerance, position limits and buffers; regular review (at least annually) required.
- Supervisory assessment methods: on- and off-site analysis, guided by RAS Manual and SREP manual; inspectors review ALCO minutes, funding sources, maturity ladders, quality of MIS and contingency plans.

### Liquidity stress testing, contingency and buffers
- Ordinance 11 requires banks to:
  - Establish methodology for identification, measurement, management and monitoring of funding positions including projected cash flows and possible reputational impacts (Art 3(1)(5)).
  - Maintain liquidity management systems for going concern and contingency plans for liquidity crisis.
  - Conduct periodic stress tests, scenario analyses and liquidity assessment under adverse circumstances including off-balance sheet items and contingent liabilities (use results to determine level/composition of liquidity buffers and update contingency plans).
- Reporting: mandatory monthly reporting form updated to enable micro- and macro-level monitoring; since November 2011 banks report outflows by maturity using Conservative and Behavioral approaches.
  - Conservative approach treats borrowings without fixed maturity as immediate outflow (“On demand- up to 7 days..”) and undrawn commitments as immediate outflow (up to 7 days).
- Supervisory stress testing:
  - BNB Macro-prudential department uses quarterly in-house liquidity stress tests: a 5-day shock and measurement of sufficiency of liquid assets to cover substantial outflow; aggregated results support quarterly risk analysis presented to BNB Governing Council and individual results shared with supervisory teams.
- Contingency funding plan expectations:
  - Formalized, documented plans with lines of responsibility, communication plans including communication with supervisor, regular testing and updating.
  - Three key liquidity sources under stress identified by BNB: parental funding/shareholder support, sale of liquid/eligible assets, sale of loan portfolios.
  - Practical constraints in Bulgaria: scarcity of Government debt (insufficient Level 1 assets to meet LCR), underdeveloped market for loan sales/securitization; therefore shareholder support is critical.
  - Lender of Last Resort is circumscribed due to the Currency Board and cannot be relied upon in contingency plans.

### Foreign currency liquidity and encumbered assets
- FX context: Bulgaria operates a Currency board where 1.95583 BGL is equal to 1 EURO; FX risk arises from exposures denominated in currencies other than euro.
- Ordinance 11 requires banks to hold foreign currency assets corresponding to currency and maturity structure of funding (Art 3(5)-(6)); monthly reporting (Art 9(1)) provides BNB with foreign currency positions.
- BNB notes future requirement to report LCR and NSFR on a currency basis will be difficult for banks.
- AC1 on encumbered assets: Ordinance 11 (Art 3(3)) requires banks to distinguish pledged and unencumbered assets, account for legal entity and country of record, eligibility and mobilization timing.
- EBA reporting on encumbered assets entered into force in January (date unspecified in the excerpt).

### Supervisory assessments, findings and recommendations
- Assessments:
  - Principle 22 (Market risk): Compliant.
  - Principle 23 (IRRBB): Compliant.
- Key supervisory findings:
  - Market risk exposures are low; market risk capital requirements are a small share of total capital requirements.
  - BNB relies heavily on onsite inspections to verify governance, models, valuation, limits and stress testing.
  - IRRBB treated as significant; tested via ICAAP annually; no Pillar 2 add-on applied at assessment time due to high system capital.
  - Liquidity framework aligned with CRR timetable; Ordinance 11 and internal manuals provide comprehensive supervisory tools.
- Recommendations / supervisory priorities (from text):
  - BNB should engage actively with banks using parental models to avoid “black box” usage and to challenge model design, specification and governance.
  - Given no dedicated market risk specialist, BNB should consider specialization if market modelling adoption grows.
  - BNB should place more emphasis on developing the quality and consistency of off-site analysis for IRRBB.

*Source: https://www.imf.org/-/media/websites/imf/imported-full-text-pdf/external/pubs/ft/scr/2015/_cr15295.pdf*

### 2015. Broadly it is the smaller local banks with encumbrance. The BNB was able to confirm to the

### _cr15295 - 2015. Broadly it is the smaller local banks with encumbrance. The BNB was able to confirm to the

### Liquidity risk (Assessment of Principle 24)
- Assessment: Compliant
- Findings:
  - The BNB’s understanding and oversight of liquidity risk was tested in 2014 when deposit runs on a number of banks took place.
  - Based on the frequency and quality of prudential data, the BNB was well placed to identify systemic linkages and this information was important in negotiating state aid for the liquidity support of one domestic bank.
  - The BNB was an early adopter of the Basel 2008 standards on liquidity risk management.
  - Banks have been subject to enhanced liquidity reporting since the EU sovereign crisis of 2011 and daily reporting since the liquidity stress of 2014.
  - Banks in Bulgaria are required to report data based on EBA templates for the LCR, but the final templates are not yet available and the LCR will not be in place in the EU until October 2015, starting at a 60 percent level of required compliance.
  - The EU framework permits Member States to maintain existing reporting and liquidity requirement metrics until the LCR is fully in place (Art 412(5) CRR).
  - Data on the NSFR is also being reported, using EBA reporting templates.
  - The BNB is maintaining the liquidity requirements and reporting under Ordinance 11 until the LCR is fully in force.
  - The BNB has carried out periodic simulations to assess the LCR and NSFR for individual banks and the system.
- Comment:
  - ESRB work indicated encumbered assets is not a systemic issue but could affect individual institutions.

### Operational risk (Principle 25 — Essential Criteria EC1–EC8 and Additional Criteria AC1)
- Overall assessment: Largely compliant
- EC1 — Legal/regulatory requirements for operational risk strategies, policies, processes:
  - Regulatory basis: BNB Ordinance #7 on Organisation and Risk Management of Banks (Art 15(1), Art 16), BNB Ordinance No 10 on internal control.
  - Requirements include evaluation and management of exposure to operational risk, including model risk and low-frequency high-severity events; contingency and business continuity plans; internal control unit with at least one IT and OR expert.
  - Off-site capture via CAMELOS / CAEL Risk Assessment System; CAMELOS rating is annual and covers operational risk; OR reporting reviewed quarterly.
  - Supervisory Macro Analyses and Strategies Directorate prepares quarterly analytical products including stress test results on operational risks.
  - On-site methodology: Risk Assessment System Manual (RASM dated August 2014) with questionnaires and guidance for OR assessment.
  - OR assessment criteria include: (i) size and complexity of organizational structure, (ii) number and complexity of products/services and transactions, (iii) scale and frequency of changes, (iv) number/quality/security/efficiency of IT systems and recovery capacity.
- EC2 — Board approval and oversight of OR strategies/policies:
  - Legal basis: LCI art. 73; Ordinance #7 (art.2, art.3) requires Board adopt and periodically review risk strategies/policies, devote sufficient time to risk-related issues, and ensure adequate resources and reporting to the Board.
- EC3 — Implementation by management and integration into bank-wide risk management:
  - Assessment mainly via on-site inspections using RASM questionnaires covering responsibilities, internal control review, MIS inputs, Board reporting, and documentation (operational risk policies, self-assessment rules, event registers, stress tests, Key Risk Indicators, minutes).
- EC4 — Disaster recovery and business continuity plans (BCP/EP):
  - Legal basis: Art. 16 of Ordinance #7 requires contingency and business continuity plans.
  - On-site inspections use detailed questionnaires; examiners verify documented BCP/EP, Board approval, internal control review, scenarios (natural disaster, power supply, server/telecom failures), staff training, annual testing, outcomes of stress tests, IT EP content, existence of back-up warehouse.
  - BNB recommendation: have premises for contingency and backup systems outside Sofia.
- EC5 — IT policies/processes and infrastructure:
  - RASM and on-site questionnaires cover physical/logical security, end-user security, antivirus, banking applications, backup procedures, staffing and qualifications for IT, organization/independence of IT unit, segregation of responsibilities, IT planning and emergency action plans, internal control and audit follow-up.
  - Specific documentation requested at start of on-site inspections: reports on IT units/committees, IT development strategy, security policy, protection mechanisms.
- EC6 — Information systems to monitor/compile/analyze operational risk data and support reporting:
  - No explicit general requirement for incident information gathering across all banks; complex banks using AMA must maintain incident information systems.
  - BNB performs due diligence on incurred losses database and measures taken; MIS assessed during on-site visits via reports, minutes, and RASM checkpoints.
  - Minimum MIS deliverables include operational risk reports of varying frequency.
- EC7 — Reporting mechanisms to keep supervisor apprised of operational risk developments:
  - Banks obliged to report quarterly on operational risk for Pillar I (COREP) and annually for Pillar II (ICAAP).
  - AMA banks required to inform/seek permission for major changes in AMA.
  - No explicit legal requirement to notify supervisor of major operational risk events; BNB expects notification for significant failures such as long-term power outages, significant IT disruptions or external attacks, major fraud schemes, severe weather damage, robberies causing significant losses.
- EC8 — Outsourcing policies and processes:
  - No specific Bulgarian legislative provision on outsourcing; BNB published guidelines (deriving from CEBS/EBA) recommending policies, contingency plans, exit strategies, due diligence, written contracts and SLAs.
  - RASM contains examiner questionnaire to assess outsourcing decisions, Board approval, supplier financial/competence checks, and outsourcing contract scope/terms/confidentiality/oversight.
- AC1 — Identification of common points of exposure:
  - BNB regularly reviews vulnerabilities to common operational risks (outsourced IT to common providers, settlement service failures) based on sector information.
- Recommendations (from assessors):
  - Make Operational Risk on-site surveillance more systematic and issue a regulation subjecting banks to have appropriate reporting mechanisms to keep the supervisor apprised of developments affecting operational risk
  - Increase the level of expertise of BSD staff, especially in the area of IT
  - Require banks to notify the supervisor in case of major operational risk event
- Comments:
  - OR inclusion in routine on-site visits is not systematic; frequency depends on inspection scope.
  - No staff specialized in OR with IT skills; some inspectors more often assigned than others.
  - Consider establishing a stand-alone on-site examination program for operational risk.

### Internal control and audit (Principle 26)
- Overall assessment: Largely Compliant
- EC1 — Framework for internal control:
  - Legal/regulatory basis: LCI, Ordinance 10, Guidelines for internal controls in banks.
  - LCI Articles 74(3) and 73(1) assign Board responsibility to adopt and review internal control organization, delegation of authority, procedures for approvals, reporting of weaknesses.
  - Ordinance 10 Article 2(1) defines internal control as a permanent process; objectives include achievement of aims, efficient use of funds, adequate risk control, safeguarding assets, reliable financial/management information, compliance with law and procedures.
  - Missing or high-level only elements: clarity of delegation, decision-making policies/processes, explicit accounting reconciliation requirements, explicit dual controls/cross-checking.
  - IT controls and safeguarding assets addressed at a high level (Ordinance 10 Art 12(1)(3), Art 14).
- EC2 — Balance of skills and resources in back office/control functions:
  - High-level requirements exist (Article 3(2), Articles 5 and 6 of Ordinance 10) for organizing internal control and staff training; expectation of balance of skills is present though not explicit in law.
  - Supervisory determination through SREP and RAS Manual during on-site inspections; RAS Manual addresses HR management and professional standards.
- EC3 — Compliance function:
  - Compliance function expected under Guidelines on Internal Management in Banks (section 27), proportionate to bank size/complexity; may be combined with risk control; reporting to Board.
  - Supervisory assessment integrated into SREP and on-site inspections; Summary Report and Action plan of Compliance unit required during inspections.
- EC4 — Internal audit function:
  - Legal basis: LCI Article 74(1) requires internal audit; management appointed/dismissed by Shareholders’ General Meeting.
  - Ordinance 10 Articles 13–19 define internal audit role, functions, independence, access rights, audit planning and reporting.
  - RAS Manual part 6 provides detailed supervisory expectations for internal audit assessment.
- EC5 — Internal audit adequacy (resources/independence/methodology/access/plan/outsource oversight):
  - Resources/expertise: Article 15(1) of Ordinance 10 requires professional skills; Article 16 sets requirements for head of internal audit.
  - Independence/status: Article 13(1) and Article 14 require independence and prohibit involvement in other duties.
  - Kept informed/full access: Articles 14(2), 18 grant unimpeded access to premises, assets, management decisions, accounting and information systems; direct contact with management bodies.
  - Methodology/audit plan: Article 19(2) requires all subjects covered within up to two years; Article 17 requires annual audit plan approved by management body; Article 24 requires annual report on activities to management body and shareholders’ general assembly.
  - Outsourced functions: Outsourcing contracts must allow internal audit and external auditor full access to provider databases and BNB access to provider premises/databases.
  - Information requirements for BNB ahead of on-site inspections include summary internal audit activity reports, annual work plans, internal audit reports, IT qualifications in internal audit, operational risk and IT-risk internal audit reports.
- Comments and recommendations:
  - Ordinance 10 dates from 2003 (updated 2006) and is high level; supervisory practice supplemented by CEBS/EBA guidelines and RAS Manual.
  - Limitation on inspection frequency and light commentary in some reports indicates quality of work may be starting to lag.
  - Recommend:
    - Revise Ordinance 10 to confirm and enhance supervisory requirements in internal controls
    - Refresh the RAS Manual in respect of internal controls

### Financial reporting and external audit (Principle 27 — Essential Criteria EC1–EC9)
- EC1 — Board and management responsibility for financial statements:
  - Legal basis: Article 75 of LCI; Law on Accountancy Article 24 assigns management bodies responsibility for drawing up, timely preparation, contents and publishing of financial reports and annual activity reports.
  - All banks must prepare public financial statements on the basis of IAS/IFRS as adopted by Regulation (EC) No 1606/2002.
  - Banks and banking groups must submit individual and consolidated financial statements to the BNB; subsidiaries in groups must submit consolidated group financial statements.
  - Recordkeeping requirements reflected in Article 67 of LCI and Law on Accountancy (Chapter Six – Storing of the accounting information).
- EC2 — External audit of annual financial statements:
  - Legal basis: Article 76(1) of LCI requires annual financial statements and supervisory reports to be audited and certified by a registered auditing company under the Law on the Independent Financial Audit (LIFA).
  - Article 38 of Law on Accountancy requires independent financial audit.
  - Audits conducted in accordance with International Auditing Standards (Article 2 of LIFA).
- EC3 — Valuation practices and independent verification:
  - Banks prepare and submit annual financial statements using IFRS and IAS; valuation rules based on IFRS and IAS; same valuations used for financial reporting and regulatory purposes as a starting point.
  - For regulatory purposes different haircuts are used for impairments and solvency needs.
  - Under Article 103(2)(20) of LCI the BNB may require special provisioning policy or treatment through capital requirements (not presently used).
  - CRR Article 105 and EBA RTS on Prudent Valuation referenced; CRR provisions do not explicitly require independent verification/validation of fair value estimates though inspectors assess valuation techniques.
- EC4 — Supervisor powers on scope/standards of external audits:
  - BNB does not have the power to establish scope of external audits or standards; external auditors follow IAS.
  - Article 80(4) of LCI permits BNB to appoint independent experts to evaluate assets in supervisory exercises and require banks reflect results in financial statements or supervisory reports.
- EC5 — Audit scope coverage (loan portfolio, provisioning, valuations, trading, derivatives, securitizations, consolidation, internal controls):
  - Article 11 of LIFA requires audit scope compliant with prevailing legislation and International Auditing Standards covering elements of this criterion.
- EC6 — Power to reject/rescind appointment of external auditor:
  - BNB can object to auditor appointment. Art 76(4) LCI requires banks consult BNB in advance of appointing an auditor.
  - Art 76(5) LCI: an auditor must not have been in breach of LCI or implementing regulations during previous three years.
  - BNB must notify objections within 14 days; absence of objection within 14 days is deemed approval (Article 76(6) LCI).
- EC7 — Auditor rotation:
  - BNB cannot require auditor rotation. Law on the Independent Financial Audit (Article 40m) mandates rotation of the senior partner after 5 years; the partner may return after two years.
- EC8 — Meetings with external audit firms:
  - BNB conducts ad-hoc meetings with external auditors on particular issues; no framework for regular dialogue with external audit profession exists.
  - When communication occurs, participants include the Director of CISD, the Deputy Governor, and relevant inspection team members.
- EC9 — External auditor reporting to supervisor of material significance:
  - Legal basis: Article 77(1) of the LCI: auditors shall forthwith and in writing inform the BNB about any circumstances that have become known to them during the audit and which [text truncated in source at this point]

*Source: IMF staff report content unit _cr15295 (2015) provided in the source PDF excerpt.*

### 1. are breaches of the laws, by-laws and the BNB’s acts which regulate banking activities;

### _cr15295 - 1. are breaches of the laws, by-laws and the BNB’s acts which regulate banking activities;

### Enumerated events or conditions
- 1. are breaches of the laws, by-laws and the BNB’s acts which regulate banking activities;
- 2. affect or might affect the bank’s normal operation;
- 3. lead or might lead to a situation where the bank is unable to fulfil its monetary obligations;
- 4. make the auditor refuse to certify the financial statements or express his dissent upon certifying 
the financial statements;
- 5. are related to actions of the bank’s administrator that cause or might cause substantial damages to 
the bank or its customers;

*Content unit: _cr15295 - 1. are breaches of the laws, by-laws and the BNB’s acts which regulate banking activities;*

### 6. are related to untrue or incomplete data in the statements and reports that banks regularly

### _cr15295 - 6. are related to untrue or incomplete data in the statements and reports that banks regularly

### Access to external auditors’ working papers (AC1) — description and findings
- The only documentation to which the BNB has access is the annual audit report and any reports presented to the Audit Committee.
- Under Article 77(2) of the LCI auditors, upon the BNB’s written request, submit to the BNB the relevant documentation and any other information or documents obtained during the audit in relation to issues covered in Article 77(1) such as:
  - breaches of the law;
  - issues which might affect the bank or cause substantial losses to the bank or its customers;
  - the risk that the bank will not be able to fulfill its obligations; and
  - the risk that the auditor would have to refuse to certify the financial statements.
- The BNB’s powers are only triggered in the event of breaches of Article 77(1); the BNB has no general entitlement to auditors’ working papers or the management letter submitted to the audited bank.

### Assessment of Principle 27 — status and key comments
- Assessment: Materially Non Compliant
- Key comments and findings:
  - The BNB has some powers and authority with respect to external auditors but important deficiencies exist.
  - The BNB has no access to auditor working papers, including the management letter.
  - There is no authority to insist on rotation of an auditor (firm or senior partner), although the law provides a backstop rotation requirement for the senior partner.
  - Market concentration concern: one firm alone is responsible for the audit of over half the banking system.
  - The right to refuse reappointment of an auditor exists under the LCI (Article 76 (5) together with 76 (4) and (6)) but circumstances for use are unclear (e.g., systemic breaches, failure to perform rigorous analysis, professional negligence, misleading statements). The legal provision is not clearly specified and in practice would likely deter BNB from using it except in the most egregious cases.
  - Supervisory practice: the BNB has had a somewhat remote relationship with the external audit community; it has not been common practice to meet auditors bilaterally, trilaterally, or collectively.
  - Article 76 (7) and (8) of the LCI gives the BNB the right to require external auditors to provide a report addressing reliability of a bank’s internal control systems and compliance of the bank’s supervisory reports. The obligation for a report on banks' supervisory reports fell away with the introduction of the CRR; the BNB is awaiting submission of reports on internal controls, but has not found them strongly useful.
  - Several commentators indicated the depth of understanding of IFRS throughout BNB supervisory staff may not be strong enough; challenges will increase with the introduction of IFRS 9. The BNB has access to high quality external advice on IFRS but needs internal resources.
  - Current practice: BNB inspection reports may include matters for external auditors but auditors are not independently notified that an inspection has taken place or that reports contain recommendations addressed to them; banks may be uncertain whether they may share inspection reports.

### Recommendations addressing AC1 and Principle 27 deficiencies
- Consider relevant domestic amendments where legally allowable within the wider EU framework to address deficiencies, including providing the BNB with:
  - the clear ability to insist on a change of auditor in the wake of poor quality audit or other supervisory concerns;
  - the right to insist on the rotation of the audit firm and of the senior partner;
  - the right of access to audit working papers and the management letter.
- Establish a framework for regular dialogue between the BNB and external auditors, both collectively and at individual institution level; this dialogue is particularly valuable ahead of implementing IFRS 9.
- Include an analysis of IFRS experience and understanding in BNB skills mapping and needs assessment; invest in training and recruitment as required.
- Put in place an administrative practice to ensure external auditors are notified when on-site inspection reports contain recommendations addressed to them (common practice would be to contact the auditor directly).
- Issue a BNB requirement to ensure banks put in place independent verification and validation for fair value estimates, emphasizing the importance of reliable supervisory data and fair value validation in BNB Ordinances.

---

### Principle 28 — Disclosure and transparency (overview)
- Principle 28: the supervisor determines that banks and banking groups regularly publish information on a consolidated and, where appropriate, solo basis that is easily accessible and fairly reflects their financial condition, performance, risk exposures, risk management strategies and corporate governance policies and processes.

### Essential Criterion EC1 — laws/regulations require periodic public disclosures
- LCI (Art 75) requires banks to prepare financial statements according to the Law on Accountancy and BNB requirements.
- Law on Accountancy (Article 40) requires publication of annual financial statement and consolidated financial statement, annual management report and annual consolidated management report adopted by the general meeting.
- LCI Article 70 requires banks to publish their balance sheet and profit and loss account every 6 months in at least one central daily newspaper.
- Audit reports must express an opinion on correspondence between management report and financial statements; annual financial statement must be audited and certified by a specialized auditing company registered under the Law on the Independent Financial Audit.
- CRR Part Eight governs Pillar 3 disclosure; consolidated disclosure carried out once a year in six months term after end of period. CRR Article 433 requires assessment of need for more frequent disclosure given business characteristics.
- Within 6 months of the BCP assessment, the BNB intends to implement EBA Guidelines on materiality, proprietary and confidentiality and on disclosure frequency under Articles 432(1), 432(2) and 433 of CRR.
- Disclosures must be provided through the official website of the bank and in at least one medium or location where feasible.
- Additional EU disclosure rules apply for publicly listed companies (EU Prospectus and Transparency legislation); FSC is responsible authority for implementing that legislation.

### Essential Criterion EC2 — scope/content of required disclosures
- CRR Part Eight, Title II contains extensive technical criteria on disclosure of:
  - own funds, capital requirements, capital buffers, risk management objectives and policies, exposure to counterparty credit risk, credit risk adjustments, exposure to market risk, operational risk, exposure to interest rate risk on positions not included in the trading book, exposure to securitisation positions, governance arrangements, remuneration policy, etc.
- Disclosure requirements are both qualitative and quantitative.
- LCI Article 70(2) requires banks to disclose on official website information about compliance with LCI requirements in corporate governance and remuneration.
- CRR Article 436 requires disclosure regarding scope of application of CRR requirements and differences in consolidation bases.
- Article 70(5) LCI requires parent companies to publish annually description of legal, managing and organisational structure of the group, including persons with close links.
- CRR Article 431 requires banks to adopt a formal policy to comply with Part Eight disclosure requirements and policies for assessing appropriateness, verification and frequency of disclosures; banks must assess need for more frequent than annual disclosure.
- BNB may require public disclosure of additional information (Article 103, paragraph 2, point 19 of the LCI).
- IFRS 7 and other IFRS standards require disclosures on accounting policy, basic business and management; disclosures of aggregate exposures to related parties are prescribed in IFRS.
- In practice, banks’ approaches to disclosure have varied; some provide meaningful qualitative disclosures while others limit qualitative disclosure over competitive concerns.
- Some standardized templates for own funds, encumbered assets, leverage ratio are available and some introduced for 2014 disclosures.
- BNB view: banks’ practices have improved since Pillar 3 disclosures began.

### Essential Criterion EC3 — disclosure of material entities in group structure
- LCI Article 70(6) requires annual consolidated disclosure separately for the Republic of Bulgaria, for other member states and for third countries where the bank has subsidiaries or branches.
- This information is subject to independent financial audit and must be published as an annex to annual financial statements on a solo or consolidated basis.
- BNB indicated satisfaction with quality of banks’ disclosures on group structures.

### Essential Criterion EC4 — review and enforcement of disclosure standards
- Disclosures in annual financial statements are reviewed by external auditors as required by LCI Article 76 (7).
- Auditors must provide an opinion on whether the bank’s financial position is presented truly and on compliance of annual financial statements and supervisory reports with LCI and its ordinances.
- Results of the audit of annual financial statements must be presented in a separate report for supervisory purposes, prepared as required by a BNB ordinance and submitted to the BNB.

### Essential Criterion EC5 — public aggregate information on banking system
- The BNB Banking Supervision Department regularly (on monthly and quarterly basis) publishes aggregate information for the banking system and data for individual commercial banks.
- Dataset includes information on financial statements, liquidity, capital adequacy, loans and advances, securities, attracted funds, and monetary statistics.
- Level of data presentation:
  - Banking system aggregate
  - Distribution of banks by groups: banks assigned to one of three groups based on asset size; group reviewed and amended at end of each reporting period:
    - first group: the five largest banks;
    - second group: remaining banks;
    - third group: branches of foreign banks in Bulgaria.
  - Individual banks
- Types of information published:
  - Balance sheet and income statement of banking system and by groups.
  - Detailed structure of securities, loans and advances, and funding by bank groups.
  - Securities template: investment portfolio in terms of capital and debt instruments and investments in associated companies, subsidiaries and joint ventures.
  - Loans and advances template: loan portfolio structure (loans to credit and non-credit institutions, governments, corporates, retail exposures including residential mortgage loans and consumer loans), FX structure, interest income, impairments.
  - Funding template: funding sources, FX structure of funds, cost of funding.
  - Credit quality and impairments template: gross and net credit exposures, amount of impairments (according to IAS 39) and detailed structure of performing and non-performing loans; non-performing loans presented in three categories: past due 30-90 days, past due 90-180 days, and past due over 180 days.
  - Liquidity position and liquidity buffers in accordance with ordinance No 11 on liquidity management and supervision of banks: amount of liquid assets and liquidity ratio for different maturity intervals.
  - Capital ratios according to the new regulatory framework.
- Publications and frequency:
  - Monthly press release on condition of the banking system.
  - Quarterly bulletin on Banks in Bulgaria.
  - Additional information based on informal agreement: reports based on surveys on economic environment and its impact on banking system, annual survey on aspects of banking activity, survey of quarterly credit activity.

### Additional criteria (AC1) — disclosure of information to understand risk exposures
- LCI Article 70 (6) and (7) require banks to disclose annually on a consolidated basis separately for Bulgaria, other Member States and third countries:
  - name, description of activities and geographical location;
  - size of the turnover;
  - equivalent number of full-time employees;
  - financial result before tax;
  - taxation;
  - return on assets obtained as the ratio of net profit to total assets;
  - government subsidies received.
- This information is subject to independent financial audit and must be published as an annex to the annual financial statements on an individual or consolidated basis.

### Assessment of Principle 28
- Assessment: Compliant
- Comment: The BNB provides public access to a wide range of data, including bank-by-bank breakdown; the quarterly bulletin on the condition of the banks in Bulgaria is frequently praised.

---

### Principle 29 — Abuse of financial services (EC1) — AML/CFT legal and supervisory framework
- Bulgarian AML regime governed by:
  - Law on Measures against Money Laundering (LMML) and Regulation on the Implementation of AML Act (RILMML) — last revision in 2014.
  - Law on Measures against the Financing of Terrorism (LMFT) — passed in 2003.
- Both acts implement the 40 FATF Recommendations and transpose requirements of the Third European AML Directive.
- Supervision of AML/CFT in banks is dual and parallel:
  - Both the BNB and the Financial Intelligence Unit (FID-SANS) are competent for monitoring conformity with AML/CFT obligations in credit institutions.
  - Legally, primary responsibility for AML/CFT supervision rests with the Financial Intelligence Unit (FID-SANS).
  - A memorandum of understanding between the two bodies governing cooperation and information sharing was signed in 2003 and is under revision.
- Role of the BNB:
  - LMML Art.3a and LMFT Art.9a impose obligations on supervisors (BNB) to perform inspections in banks for compliance with AML/CFT legislation.
  - BNB established the Special Supervision Directorate (SSD) within the Banking Supervision Department (BSD). SSD is separate from the directorate performing on-site prudential surveillance, has its own inspection planning and team of inspectors, and can perform on-site visits at the request of the FIU.
  - SSD has no authority over other institutions such as money changers or money transfer services.
  - In case of non-compliance or suspicion related to ML/FT that has not been reported, the BNB is obliged to inform the FID in a timely manner.
  - BNB can take enforcement measures (including pecuniary sanctions) under art. 103 of the LCI.
  - SSD coordinates BNB relationships with the FIU, law enforcement authorities and the Prosecutor’s office.

*Source: _cr15295 - 6. are related to untrue or incomplete data in the statements and reports that banks regularly (IMF PDF).*

### part in the AML-expert groups at the national and the EU-level.

### _cr15295 - part in the AML-expert groups at the national and the EU-level.

### Role of the Financial Intelligence Unit (FID / SANS)
- The Bulgarian State Agency for National Security (SANS) incorporates within its structure a Financial Intelligence Directorate (FID) that "collects, stores, investigates, analyzes and discloses financial intelligence information" under LMML and LMFT.
- The FIU (FID) is empowered to oversee AML/CFT compliance in the banking industry by performing on-site visits, either alone or jointly with the BNB.
- Supervision of AML/CFT implementation in banks is the primary responsibility of the FID but the FIU is supported by the BNB for all banking-related aspects.
- Formal and operational cooperation mechanisms exist between the FIU and the BNB, including annual meetings to decide inspection planning and ongoing interactions during on-site visits.
- Information exchange: BNB shares inspection reports with the FIU; the FIU shares conclusions with the BNB when major problems arise.
- Enforcement: BNB mainly issues written orders; the FIU has applied pecuniary sanctions in rare occasions. There is no coordination between the two bodies on enforcement and sanction application.

### Supervisory expectations and inspection methodology (EC2, EC3, EC4, EC5, EC6, EC7, EC8, EC9, EC10, EC11, EC12, EC13)
- Supervisory expectations are set out in the LMML and LMFT and BNB guidelines (notably the 2012 guideline for uniform practices).
- For high risk customers, banks have to review customer files every month.
- Banks are required to:
  - establish proper due-diligence policies and methods including KYC (art.9);
  - set up internal control mechanisms to detect unusual activities;
  - refuse anonymous accounts or accounts under a fictitious name;
  - apply enhanced scrutiny for high risk customers (e.g., PEPs, correspondent accounts, foundations, Trusts, customers residing in off-shore centers);
  - establish procedures to report suspicions to the FIU;
  - appoint an AML officer to communicate transactions to the FID.
- LCI Art. 73 (1): competent managing body must adopt and regularly review systems for prevention against the risk of money laundering "in accordance with the best internationally recognized practices for corporate governance of banks."

On-site inspection process and documentation
- BNB SSD uses a detailed methodology (about 150 pages), offering guidance to inspectors; SSD requests comprehensive materials before on-site visits.
- Documents requested for risk assessment include: list of high-risk accounts; the KYC and CDD program; list of accounts missing legally required information; list of credit and banks where "reliance on third party" principle is applied.
- Documents requested related to STRs: copies of STRs files and accompanying documentation sent to the FID; analysis/position on suspicious cases not reported to the FID; description of monitoring procedures for high-risk accounts; description of surveillance systems; copies of correspondence between the bank, the FID and law enforcement/judicial authorities.
- In the field, SSD inspectors use detailed questionnaires for interviews with Compliance Officers and other key personnel and use transaction samplings to analyze payments.

FID supervision methodology and inspection types
- FID supervision uses a risk assessment considering: number of STRs received, findings of inspections by supervisory authorities (the BNB), number and amount of cash transactions under Art. 11, Para 2 of the LMML. Entities are grouped as ”low–risk,” “medium–risk” and “high-risk.”
- FID carries three types of inspections:
  - incidental inspection (based on motivated written request by another SANS directorate, supervisory authority or other state authority requiring urgent action);
  - planned inspection (on grounds of a preliminary prepared and approved three-month plan);
  - thematic inspection (checking implementation of certain LMML requirements related to use of the financial system for ML/TF).

Reporting obligations and cooperation
- There is no requirement in Bulgarian regime for banks to report to the banking supervisor suspicious activities and incidents of fraud when material to safety, soundness or reputation (EC3). BNB had not received such reports; in 2014 a bank informed BNB about a fraud scheme and attempt for ML which BNB disseminated as an alert.
- Art. 3a (1) (2) of the LMML requires BNB to provide information to the FIU when the supervisor discovers operations or transactions suspected to stem from money laundering; such reports have been made in the recent past (EC4).
- Art. 15 of the LMML provides legal protection to bank staff who reports suspicious activity in good faith either internally or directly to the relevant authority (EC11).
- Practical collaboration between FID-SANS and BNB is governed by "Instructions for cooperation and information exchange" and an MoU that is no longer valid; a revised draft has been in the making for three years (EC12). Authorities are encouraged to finalize it.
- BNB cooperates efficiently with enforcement authorities (prosecutor’s office, national investigative authorities, special units for investigation, police authorities) and provides expert assistance in complex cases.

Customer Due Diligence (CDD), beneficial ownership and record keeping
- LMML and LMFT contain provisions on CDD requiring banks to adopt control mechanisms to prevent/detect ML/TF. Requirements include verification of beneficial owner, understanding purpose and nature of relationship, and enhanced due diligence for high-risk customers.
- For legal entities engaged in entrepreneurship, banks must obtain full name, legal form, address of headquarter, UIC, original or notarized copy of official statement of good standing, certified copy of articles of association, etc.
- BNB guidelines require banks to perform due diligence in relation to UBO; for high-risk customers banks must confirm data from a reliable and independent source.
- In practice, banks struggle to collect beneficial ownership data; notable numbers of companies located overseas (sometimes in off-shore centers) have ultimate beneficial ownership not clearly established.
- Record keeping: documentation must be kept for a period of not less than five years. There is no legal basis for keeping records for longer than 5 years when necessary, unless properly required by a competent authority.
- Banks must pay special attention to ML threats from new/developing technologies (e.g., e-banking) under art. 5c LMML and art. 8b RILMML.
- On PEPs: banks must adopt procedures to mitigate risks and determine if client is a PEP or related person; systems can use declarations and internal/external databases. It seems banks are not required to identify beneficial owners who are PEPs and apply enhanced scrutiny.

Controls, staffing, tools and training
- BNB's Department for Banking Supervision has a Special Supervision Directorate (SSD) of 14 staff, but only 8 staff are operational for AML/CFT oversight.
- About 50 per cent of the banking sector is subject to an AML inspection every year by the BNB. In 2013, 18 banks were inspected and 16 in 2014. Inspections can span 4 to 5 weeks depending on the size of the bank.
- SSD staff have long experience (working in SSD for 14 years) and relevant expertise; inspectors are viewed as professional and thorough.
- Banks have established dedicated AML units (sometimes comprising up to 15 people) and appointed AML officers in addition to compliance officers.
- Anti-money laundering software is used in 90 percent of the licensed banks and foreign banks’ branches in the Republic of Bulgaria.
- BNB provides annual trainings for banks’ staff, especially compliance officers; BNB staff have taken part in seminars/workshops organized by IMF, Joint Vienna Institute, Banque de France, Deutsche Bundesbank and De Nederlandsche Bank.

Sanctions and enforcement powers
- FID sanctions for LMML infringements include fines (with a cap of 50,000 BGN (€25,000)), written warnings and power to compel corrective actions. The maximum fine level does not appear sufficiently dissuasive; in practice each violation carries a separate sanction and total fines may be much higher for multiple breaches.
- FID enforcement record (number of banks inspected and fines applied):
  - FID inspection program (since 2011):
    - 2011: 4 banks — 2 thematic and 2 full-scope
    - 2012: 8 banks — 1 joint with BNB and 7 thematic
    - 2013: 8 banks — 4 thematic, 3 joint with BNB, 1 planned
    - 2014: 5 banks — 1 thematic, 3 joint with BNB, 1 full-scope
  - FID fines applied (years and totals):
    - 2011: Number of banks 2 — Number of fines 5
    - 2012: Number of banks 5 — Number of fines 11
    - 2013: Number of banks 3 — Number of fines 7
    - 2014: Number of banks 3 — Number of fines 8
  - Fines were motivated by breaches such as: no declaration of origin of funds; incomplete identification or no declaration for origin of funds; failure in record keeping; failure to report suspicion on a timely basis; and cash threshold transactions not reported.
- BNB also enjoys a wide range of powers (discussed under CP 11), including administrative compulsory measures and administrative penalties, but BNB has not used art. 103 of the LCI for enforcing AML measures so far.

### Key findings and statistics
- BNB-led AML inspections in banks: "16 AML inspections in banks" for 2014 and "18 for 2013."
- SSD staffing: 14 staff in the Directorate; 8 staff operational for AML/CFT oversight.
- AML units in banks: comprise between 2 to 15 people.
- AML software usage: "Anti-money laundering software is used in 90 percent of the licensed banks and foreign banks’ branches in the Republic of Bulgaria."
- FID inspection program details for 2011–2014 (see above).
- FID fines by year (see above).
- Record retention requirement: "not less than five years."

### Assessment of compliance, main concerns and recommendations
- Assessment of Principle 29: Largely compliant.
- Comments and main concerns:
  - Bulgarian legislation provides adequate supervisory power and detailed SSD inspection methodology; oversight meets most CP 29 requirements.
  - SSD’s scope has expanded beyond AML and includes non-AML activities (e.g., transparency of products, deposit insurance rules), which may not be aligned with current staffing. The same inspection report addresses AML and non-AML topics.
  - Separation between AML oversight (SSD) and prudential supervision (CISD) means ML/TF risks are not integrated into overall prudential risk analysis (quarterly off-site reports, CAMELOS analysis, annual rating reports generally did not reference AML/CFT).
  - Persistent weaknesses in identification of customers and beneficial owners, especially for legal entities located overseas and off-shore structures.
  - Sanctions appear not sufficiently dissuasive: maximum fine under LMML is 50,000 BGN (€25,000); FID has used fines but in limited number and amounts; FID rarely used other powers (3 written warnings in 8 years). BNB has not used certain enforcement powers (art. 103 LCI).
  - MoU between BNB and FIU is no longer valid; revised draft pending for about 3 years.
- Recommendations:
  - Refocus the Special Supervision Directorate on its core AML mandate by assigning non-AML related activities to other relevant BNB departments.
  - Integrate AML/CFT into the overall risk analysis of the Credit Institution Supervision Directorate.
  - Improve the legal framework regarding CDD.
  - Enhance cooperation and information exchange between the Special Supervision Directorate and the Credit Institution Supervision Directorate, including sharing AML reports with CISD staff and discussing enforcement approaches to maximize effectiveness.
  - Increase sanctions in case of recurrent violations of AML/CFT regulation by the same institution; consider sanctions on directors and senior management in severe cases.
  - Instruct the industry to establish more robust mechanisms to ascertain the true identity of their customers, especially for legal entities located overseas with undisclosed UBO.
  - Recommend banks to share the BNB AML inspection reports with their external auditors (if permitted by law).
  - Finalize the revision of the MoU with the FID.

*Source: _cr15295 - part in the AML-expert groups at the national and the EU-level.*

### 1. Responsibilities, objectives and

### 1. Responsibilities, objectives and powers

### Responsibilities and scope (LC)
- Within the Banking supervision Department, the Special Supervision Directorate (SSD) has been assigned multiple activities (e.g., inter alia, transparency of products and monitoring of consumer trends) that go beyond its primary objective of ensuring integrity in the banking sector.
- These non-supervisory activities do not permit an adequate allocation of resources for supervision purposes and distract SSD staff from its core objectives.
- The BNB is not empowered to require a bank to change its internal organization or structure.
- The power to dismiss senior management does not seem to apply to other staff, particularly to risk officers and other relevant staff holding important functions in a bank (Compliance, Risk Management, AML and Credit Officers).
- The current legal regime provides the authorities insufficient scope to manage a crisis fully effectively.
- As evidenced during the KTB collapse, the BNB does not have sufficient options in order to cooperate and collaborate to achieve the orderly resolution of a bank.

### Independence, accountability, resourcing and legal protection for supervisors (MNC)
- The internal governance procedures of the BNB with respect to banking supervision place weight on a single individual – the Deputy Governor for Supervision.
- The internal governance procedures do not ensure clarity of communication and escalation of issues when problems emerge and do not ensure transparency and appropriate checks and balances in the overall decision making process.
- The legal structure of the governance arrangements provides no options for the effective delegation of supervisory powers if the Deputy Governor for Supervision becomes unavailable or incapacitated for whatever reason.
- The supervisory staff of the BNB enjoys a high, and in the view of the assessors, a deserved reputation for their professional skills and dedication.
- Resources are insufficient for the range and nature of the tasks the BNB must carry out for effective supervision.
- This insufficiency adversely affects the numbers of staff as well as their continued training and the IT capabilities that are available to them.
- There are some specialist skills, notably IT and also quantitative, that are in too short supply.
- There is currently no mapping of the skills that are needed in the evolving supervisory processes and assessing the skills of the staff against these needs and ensuring that a strategy is in place to remedy any such gaps.
- While legal protections are in place the BNB is not obliged to cover the legal costs faced by a staff member should a lawsuit be brought.

### Cooperation and collaboration (LC)
- There is no formal mechanism of cooperation between the BNB and the MoF particularly for bank resolution.
- For AML/CFT related issues, the current MoU governing cooperation and information exchange between the BNB and the Financial Intelligence Directorate (FID) is no longer valid.
- The MoU signed in 2003 with the then Financial Intelligence Agency has not been revised after the establishment of the new authority (FID).
- The current mechanism for cooperation and information sharing between the BNB and Bulgarian Deposit Insurance Fund signed in November 2009 is now outdated.
- In the area of external audit, there is no MoU between the BNB and the Commission for Public Oversight on Statutory Auditors (COPSA).

### Permissible activities (C)
- Rated: C (no additional commentary in source).

### Licensing criteria (LC)
- Regarding the concepts of indirect holding and beneficial ownership, the Law on Credit Institutions (LCI) does not provide a specific definition of Ultimate Beneficial Ownership (UBO).
- There is no provision in the LCI requesting the BNB to determine, where appropriate, that legal, managerial, operational and ownership structures of a bank will not hinder effective implementation of corrective measures in the future.
- For assessing the "propriety" of prospective administrators, the BNB form does not require information about administrator’s income and assets.
- The types of supporting information that the applicant should provide to establish the legitimacy of funds are not specified in the law or the ordinance.
- There is no further due diligence to ascertain the reputable source of funds, beyond the analysis of financial statements and the terms of the written declaration.
- Individual Board members or the Board collectively are not required to have a sound knowledge of the material activities that the bank intends to pursue, and the associated risks.
- There is no formal mechanism for interviewing applicants after the application if formally submitted to the BNB. A “preliminary consultation” is possible during the preparation of the file but not mandatory.
- BNB has not put in place a specific mechanism by which the BNB staff monitors the progress of new entrants in meeting their business and strategic goals.

### Transfer of significant ownership (MNC)
- BNB’s powers appeared limited over shareholders who no longer meet the requirement for holding equity in banks.
- The LCI does not contain a provision requiring banks to notify the supervisor as soon as they become aware of any material information which may negatively affect the suitability of a major shareholder or a party that has a controlling interest.

### Major acquisitions (LC)
- Acquisitions of banks in non-financial companies do not require notification –even ex post- to the BNB and thus are not subject to supervisory approval.
- The BNB has not established any particular protocol or procedures in relation to major acquisition of banks in non-financial companies.
- As a result, the BNB seems to lack the ability to (i) assess compliance with the limits (established by art. 89 of the EU Regulation (EU) No. 575/2013), (ii) determine whether an investment in or a major acquisition of a non-banking company does not pose a risk to the group and (iii) ascertain that the bank has the ability to manage the risk.
- There is no explicit provision whereby the supervisor determines, where appropriate, that new acquisitions and investments will not hinder effective implementation of corrective measures in the future.

### Supervisory approach (LC)
- The BNB employs sound methodologies for the analysis and assessment of individual banks and banking groups.
- This work is strongly enriched by the efforts of the macro-prudential and financial stability directorate.
- The work on resolution is lagging due to late transposition of the BRRD as the tasks around resolution planning cannot be completed until the law is in place.
- It is noted that the BNB has not waited for the BRRD and had already commenced its work.

### Supervisory techniques and tools (LC)
- The supervisory approach in the BNB relies to a very significant, though not inappropriate, extent on determinations and verifications performed by the on-site inspections.
- It is important for the BNB to maximize the effectiveness of its risk based approach to supervision and consider the use of tools and techniques it has not taken advantage of in the past.
- While communication with banks is broadly satisfactory there is scope for enhancement.
- There is particular scope for improvements in the internal organization and processes of the banking supervision function to ensure consistency and quality control as well as internal communication.
- It is questionable that there are sufficient resources available to conduct a fully effective supervisory program, given the greater demands of supervisors stemming from the international regulatory reform agenda and the continuing attention needed to post-crisis events in Bulgaria.
- Lack of sufficient personnel makes the case for a stronger IT capability even more relevant and potentially urgent.

### Supervisory reporting (C)
- The requirements associated with supervisory reporting are now predominantly governed by a harmonized EU regime.
- The reporting regime is going through a transitional phase.
- There are some gaps which are reflected in the associated risk principles.

### Corrective and sanctioning powers of supervisors (MNC)
- Enforcement of prudential regulations is not effective enough. BNB approach has mainly consisted in issuing written orders.
- The BNB response is not increased when a bank ignores repeatedly BNB’s recommendations and written orders.
- There are almost no cases over the past five years where the BNB took sanctions to deter recurrent violations and persistent offenders.
- The BNB does not have in-house methods or criteria that could provide senior management minimum guidance on how to apply criteria for sanctions, particularly for setting the quantum for fines.
- The imposition of sanctions and determination of their amount is judged from the Deputy Governor in accordance to the weight and seriousness of the violation and the whole behavior of the bank.
- There is no link between certain violations and certain sanctions and no remedial action thresholds at which supervisory action is required.
- This does not guarantee a consistent approach and equality of treatment.
- An adequate framework geared towards resolving banks, including the preparation of recovery and resolution plans is still an important missing element.
- As a result, the BNB is not in a position to cooperate and collaborate with relevant authorities in deciding when and how to effect the orderly resolution of a problem bank.

### Consolidated supervision (LC)
- In case of mix holding companies, the leasing, factoring and consumer finance companies are not captured into the perimeter of consolidation.
- The BNB under his capacity of home supervisor has not visited the foreign offices of Bulgarian banks located abroad.
- There is no authority assigned to do fit and proper reviews on an ongoing basis of owners and senior management of non-financial holding companies.

### Home-host relationships (C)
- The BNB’s role is primarily that of a host state supervisory authority within the EU and the supervisor enjoys good relationships with its peer authorities.
- Industry representatives commented favourably on the quality of coordination and decision making between the BNB and other supervisory authorities.

### Corporate governance (MNC)
- Despite the quality of the BNB’s policy awareness of corporate governance in banks, corporate governance practices in the banking sector are still in the process of transition and require closer attention and possibly deepening of the skillset by the BNB.
- This vulnerability affects not only this CP but elements of all the risk focused CPs.
- The BNB does not yet have a policy of systematic Board level contact which is advocated by most advanced jurisdictions.

### Risk management process (LC)
- Risk management is in a state of evolution.
- The BNB has done much to ensure that risk management architecture is being put into place but needs an enhanced focus to ensure that the risk management processes are being fully embedded and effective.
- The BNB has not yet been able to finalize its work on contingency planning and recovery plans with the banks.

### Capital adequacy (C)
- There has been a case where despite multiple orders from the BNB, an institution has failed to comply with the Central Bank instructions.
- In 2004, the BNB warned that despite the capital base increase, the capital adequacy of the said bank would fall below the regulatory minimum level “under an adequate credit risk assesement” and that again, the institution needs to increase its capital.

### Credit risk (C)
- The BNB demonstrates and enjoys a high reputation in the market for the quality of its oversight of credit risk which is the central risk of the banking sector.
- There are a number of vulnerabilities addressed in the relevant associated CPs: corporate governance (14), concentration risk (19), related parties (20) and supervisory techniques (9).

### Problem assets, provisions, and reserves (LC)
- The BNB can no longer require banks to hold supervisory provisions against problem exposures.
- Nevertheless, the BNB is closely monitoring the behavior of banks’ portfolios against which (system wide) BGN 2bn had been held.
- The BNB has not yet adopted the formal use of pillar 2 powers in respect of problem exposures to require banks to hold more capital against problem assets.
- Vulnerabilities noted in CP 17 for credit risk apply here and are addressed in the associated CPs: corporate governance (14), concentration risk (19), related parties (20) and supervisory techniques (9).

### Concentration risk and large exposure limits (MNC)
- The KTB collapse revealed supervisory shortcomings particularly for the supervision of concentration risk and related-party lending in the bank.
- Effectiveness of the LEL regime is still compromised by local practices (e.g banks using several strategies to circumvent the LEL regulation).
- Determination by banks of relatedness between customers connected economically is not optimal.
- Lack of transparency in ownership structure of companies (sometimes located overseas, including in off-shore centers) undermines the understanding of connectedness and as a result of concentration risks.

### Transactions with related parties (MNC)
- The law on credit institutions does not specify the types of transactions that give rise to related parties exposures.
- Banks are not diligent enough in identifying their customers up to the ultimate beneficial owner (particularly for legal entity located overseas); as a result, connectedness between parties or group of affiliates is seriously handicapped.
- The LCI is not clear enough about (i) the conditions to be applied to write-off of related party transactions or (ii) the inclusion of key risk takers such as credit officers, their direct and related interests in the list of related persons.
- It is not clear in the law whether prohibition for any administrator “who has a business interest in the conclusion of a particular transaction” to participate in the decision also applies to any decision/resolution governing the interest rate and repayment of a loan.
- The fact that transactions with related parties must not be undertaken on more favorable terms than corresponding transactions with non-related counterparties is not as explicitly laid out in the law as it should be.

### Country and transfer risks (MNC)
- Bulgaria does not have a regulation on country and transfer risks.
- Banks should stress country risk beyond running a stress test by location and also stress transfer risk as such.
- EBA Guidelines for the SREP process are yet to be implemented.
- A revision of the BNB’s internal manual for the SREP process is envisaged but has not been finalized.
- The legislation framework does not require explicitly that banks’ Management Board approves strategies, and policies concerning country and transfer risk.

### Market risk (C)
- Market risk represents a very small element of the risk profile of the banking system.
- At present the skill set of BNB staff is adequate to assess the prudential risks but it is important for BNB to monitor the need for additional skills in this field very closely.

### Interest rate risk in the banking book (C)
- The BNB regard interest rate risk in the banking book as an extremely significant risk and welcome current Basel Committee work that might lead to a Pillar 1 capital charge.

### Liquidity risk (C)
- The BNB has a good understanding of liquidity risk and was an early adopter of the Basel 2008 standards on liquidity risk management.
- Banks have been subject to enhanced liquidity reporting since the EU sovereign crisis in 2011 and daily reporting since the liquidity stress of 2014.
- The LCR and NSFR are due to come into force according to the timetables set out in the CRR.

### Operational risk (LC)
- The Special Supervision Directorate (SSD) originally set up for AML/CFT oversight has been assigned too many activities not related to supervision (including transparency of products).
- This does not ensure proper allocations of resources and distract the SSD from its core mandate.
- There is limited cooperation and information exchange between the Supervision of Credit Institutions Directorate and the SSD.
- AML/CFT issues are not integrated into the overall supervisory review and evaluation process.
- No sanctions have been applied by the BNB for AML matters and very few by the FID.
- Bank’s practices to establish the true identity of their customers, especially for legal entities located overseas with undisclosed UBO, are questionable.

### Internal control and audit (LC)
- The significance of internal controls is fully recognized by the BNB and is incorporated into the composite risk assessment of the banks.
- The quality of work in this area notably lacks the depth of attention of other risk areas, and is at risk of lagging peers and potentially missing emerging weaknesses in some banks.

### Financial reporting and external audit (MNC)
- The BNB has some powers and authority with respect to external auditors but there are important deficiencies.
- The BNB has no authority to insist on the rotation of an auditor (either of the firm or the senior partner).
- The BNB has no access to the auditor working papers, including the management letter submitted to the audited bank.
- In terms of supervisory practices, the BNB has to date had a somewhat remote relationship with the external audit community.
- The depth of understanding of IFRS throughout the BNB supervisory staff may be not be as strong as needed.

### Disclosure and transparency (C)
- The BNB, as a supervisory authority, provides a wide range of data on the condition of the banking sector, including bank by bank breakdown.
- The quality and utility of the BNB disclosure practices was praised by a number of market participants.

*Source: _cr15295 - 1. Responsibilities, objectives and powers*

### 29. Abuse of financial services LC The Special Supervision Directorate (SSD) originally set

### _cr15295 - 29. Abuse of financial services LC The Special Supervision Directorate (SSD) originally set

### Observations and key findings
- The Special Supervision Directorate (SSD) originally set up for AML/CFT oversight has been assigned too many activities not related to supervision (including transparency of products). This does not ensure proper allocations of resources and distract the SSD from its core mandate.
- There is limited cooperation and information exchange between the Supervision of Credit Institutions Directorate and the SSD.
- AML/CFT issues are not integrated into the overall supervisory review and evaluation process.
- No sanctions have been applied by the BNB for AML matters and very few by the FID.
- Banks’ practices to establish the true identity of their customers, especially for legal entities located overseas with undisclosed UBO, are questionable.

### Recommended actions — overall
- Refocus the activity of the Special Supervision Directorate (SSD) on its core mandate of financial integrity; this can be achieved by assigning non-supervisory activities (e.g., transparency of products, monitoring of contribution to the Deposit Insurance Fund) to other Directorates, preferably outside the Banking Supervision Department.
- Empower the BNB to require banks to change their internal organization or structure and to dismiss staff (other than senior management) such as risk officers and other relevant staff holding important functions in a bank (Compliance, Risk Management, AML and Credit Officers).

### Recommended actions by Basel Core Principle (selected highlights)
- Principle 1
  - Refocus the activity of the Special Supervision Directorate (SSD) on its core mandate of financial integrity; this can be achieved by assigning non-supervisory activities (e.g., transparency of products, monitoring of contribution to the Deposit Insurance Fund) to other Directorates, preferably outside the Banking Supervision Department.
  - Empower the BNB to require banks to change their internal organization or structure and to dismiss staff (other than senior management) such as risk officers and other relevant staff holding important functions in a bank (Compliance, Risk Management, AML and Credit Officers).
- Principle 2 (Independence, accountability, resources)
  - Revise the internal governance design of the BNB for banking supervision, through legal amendment as necessary, to ensure that significant powers are not vested in a single individual. Ensure that there are clear checks and balances in decision making processes, including transparency and challenge processes.
  - Ensure that the Governing Council is supplied with timely information in respect of major developing supervisory issues including advance information on any changes of control or corrective actions.
  - Increase resource allocation to banking supervision to:
    - Ensure sufficient skilled personnel available to conduct a full program of on-site inspections.
    - Ensure sufficient representation of skill-sets, including IT, quantitative and models analysis and IFRS. Training and recruitment will both be needed.
    - Upgrade the IT capability available to supervisory staff so that they can effectively and efficiently make use of the range of data and information that is submitted to the BNB.
  - Carry out a mapping of the skills that are needed in its supervisory process ... Identify a clear current and projected assessment of any skills gaps and put in place a strategy to address such gaps.
  - Ensure that the BNB will cover the legal costs faced by a staff member should a lawsuit be brought against the staff member.
- Principle 3
  - Establish mechanisms for cooperation between the BNB, the MoF and other financial institution regulators to undertake recovery and resolution planning.
  - Speed up the revision of the MOU with the Bulgarian Deposit Insurance Fund.
  - Finalize the new MoU between the BNB and the Financial Intelligence Unit.
  - Explore the possibility to sign an MoU with the Commission for Public Oversight on Statutory Auditors (CPOSA).
- Principle 5
  - Include in the LCI a clear definition of UBO in consonance with the definition provided by the AML law.
  - Enhance BNB due diligence with respect to the origin of funds used for disbursement of capital (including liaising with the FIU and the Police (criminal records registry, Interpol office)).
  - Establish formal mechanism for interviewing applicants after the application if formally submitted to the BNB. The content and objective of these interviews should also be specified and made mandatory.
  - Establish formal procedures to subject the newly established bank to follow up on-site inspection to ascertain that the bank is performing according to the terms and conditions of the license.
  - Include in the relevant regulation a provision requiring the individual Board members or the Board collectively to have a sound knowledge of the material activities that the bank intends to pursue, and the associated risks.
- Principle 6
  - Provide BNB more powers over shareholders who no longer meet the requirement for holding equity in banks.
  - Include in the law a provision requiring banks to notify the supervisor as soon as they become aware of any material information which may negatively affect the suitability of a major shareholder or a party that has a controlling interest.
- Principle 7
  - Subject any major acquisition to a formal follow up mechanism to ascertain that the new activities acquired do not expose the bank to undue risks.
  - Subject major acquisitions in non-financial companies to enhanced BNB scrutiny, in particular with respect to the compliance with limits.
  - Explore the possibility to set restrictions for major acquisitions in non-financial sectors deem to pose particular concern.
  - Establish an explicit provision by which the supervisor determines, where appropriate, that new acquisitions and investments will not hinder effective implementation of corrective measures in the future.
- Principle 8
  - Complete resolution assessments once the BRRD has been transposed.
  - Refresh internal crisis management handling framework ensuring any lessons learned from the events of 2014 have been reflected.
- Principle 9
  - Improve the system for information sharing between the BNB banking supervision directorates, not limited to contact between the directors, but also based on a stock-take and review of common issues and information needs.
  - Initiate a more intensive program of communication with the supervisory and management boards of the banks.
  - Ensure the composition of inspection teams in the credit institution supervision directorate, and special supervision directorate, do not remain static over time.
  - Introduce quality assurance procedures to ensure that the underlying practices and quality of work carried out by the different inspection teams is of sufficiently high standard.
  - Carry out horizontal reviews on key risks identified in the banking sector and ensure key findings are communicated back to the banks as necessary.
  - Consider the use of external experts to support supervisory analysis and insight.
  - Dedicate the resources for a major upgrade to the systems available to the supervisory staff to ensure staff have the ability to interrogate supervisory data more effectively, and to integrate supervisory data automatically with other supervisory systems.
  - Establish a unit or committee mandated to review supervisory processes and practices.
  - Require banks to notify the BNB in advance, not retrospectively, of any substantive changes in their activities, structure and overall condition, or as soon as they become aware of any material adverse developments.
- Principle 10
  - Carry out a review to ensure whether current efforts to determine the validity and integrity of supervisory information are sufficient.
- Principle 11
  - Set internal guidelines to assist the Deputy Governor in determining the most adequate response in case of breach or violation of the laws or regulations.
  - Apply gradual response when a bank is not complying with BNB recommendations.
  - Take more forceful actions against persistent offenders.
  - Consider broadening the circumstances under which a bank can be placed under Special supervision regime.
- Principle 12
  - Perform more frequent visits in branches and subsidiaries of Bulgarian banks located in and outside the EU.
  - Capture leasing, factoring companies and consumer finance companies into the perimeter of consolidation in case of mix holding companies.
  - Identify the authority to do fit and proper reviews on an ongoing basis of owners and senior management of non-financial holding companies.
- Principle 13
  - When the BRRD is transposed, complete any outstanding processes necessary to support cross border resolution planning acting in the capacity of the host state supervisor.
- Principle 14
  - Ensure the BNB has the requisite powers to require changes to the composition of a Board where an individual or individuals have failed to discharge their corporate governance responsibilities effectively.
  - Ensure banks are required to notify the BNB and that – as necessary – legal protections are in place to protect individuals who notify the BNB if there are material issues that would affect the fitness and propriety of the Board member or member of senior management.
  - Refresh Ordinance 10 to elaborate more clearly on the BNB’s requirements and expectations in the field of corporate governance.
  - Institute systematic senior level contact between the BNB and the Boards of the banks.
  - Greater frequency of assessment of corporate governance is needed; consider horizontal review.
  - Deepen the RAS Manual to provide greater guidance to inspectors in testing the quality of corporate governance.
- Principle 15
  - Review the proportion of resource dedicated to risk management – and internal control – in their on-site programs.
  - Consider the use of horizontal reviews into the state of risk management in the banking sector.
  - Revise Ordinance 10 to confirm and enhance supervisory requirements in risk management.
  - Review the RAS Manual to provide greater guidance to inspectors in testing the quality of risk management.
- Principle 16
  - Take proper action over a particular institution to ensure that capital is increased at appropriate level.
- Principle 18
  - Assess, and be ready to operationalize the Pillar 2 approach for banks which are demonstrating weaknesses in respect of problem exposures.
  - Consider the use of horizontal reviews into the state of NPL management in banks.
- Principle 19
  - Conduct a horizontal review across the industry to verify degree of conformity with LEL requirements.
  - Instruct the industry to increase efforts in establishing clear understanding of customers’ ownership structure, especially for companies located abroad.
  - Take forceful measures against banks to promote effective observance of risks concentration limits.
- Principle 20
  - Define in a regulation or guidelines the types of transactions giving rise to related parties exposures.
  - Enhance surveillance of related parties’ transactions across the industry via a transversal inspection.
  - Provide recommendations to the industry to be more diligent in identifying their customers up to the ultimate owner (particularly for legal entity located overseas, including in off-shore centers).
- Principle 21
  - Adopt a regulation on country and transfer risks.
  - Include country and transfer risk in bank’s stress testing.
  - Implement the EBA guidelines for the SREP process to ensure proper and timely country risks coverage.
- Principle 22
  - Review on an annual basis, at a minimum, whether a market risk specialist is required to augment the inspection and analytical capabilities in respect of the major banks who are using internal market risk models, albeit not for regulatory purposes.
- Principle 23
  - Place more emphasis on ensuring the consistency in the quality of off-site analysis.
- Principle 24
  - In due course implement the LCR and NSFR.
- Principle 25
  - Make Operational Risk on-site surveillance more systematic.
  - Issue a regulation subjecting banks to have appropriate reporting mechanisms to keep the supervisor apprised of developments affecting operational risk.
  - Increase the level of expertise of BSD staff, especially in the area of IT.
  - Require banks to notify the BNB in case of major operational risk event.
- Principle 26
  - Revise Ordinance 10 to confirm and enhance supervisory requirements in internal controls.
  - Refresh the RAS Manual in respect of internal controls.
- Principle 27
  - To the extent consistent with the EU framework, ensure the BNB has the clear ability to insist on a change of auditor in the wake of poor quality audit or other supervisory concerns, the right to insist on the rotation of the audit firm and of the senior partner, and right of access to audit working papers and the audit letter to the management.
  - Establish a framework for a regular dialogue, both at a collective level and in respect of individual institution level.
  - Perform a skills mapping and needs assessment for BNB staff in respect of understanding of IFRS and take steps to ensure investment in training and recruitment as required, not least in view of the forthcoming IFRS9.
- Principle 29 (AML/CFT focus)
  - Refocus the Special Supervision Directorate on its core AML mandate by assigning non-AML related activities to other relevant BNB departments.
  - Enhance cooperation and information exchange between the Special Supervision Directorate and the Credit Institution Supervision Directorate, including sharing AML reports with the CISD staff and discuss enforcement approaches to maximize effectiveness.
  - Integrate AML/CFT into the overall risk analysis of the Credit Institution Supervision Directorate.
  - Increase sanctions in case of recurrent violations of AML/CFT regulation by the same institution, and in severe cases, sanctions on directors and senior management may be considered.
  - Instruct the industry to establish more robust mechanisms to ascertain the true identity of their customers, especially for legal entities located overseas with undisclosed UBO.
  - Recommend banks to share the BNB AML inspection reports with their external auditors (if permitted by law).
  - Finalize the revision of the MoU with the FID.

### Authorities’ response — selected extracts (Governing Council of the Bulgarian National Bank)
- The Governing Council appreciates the technical support provided by IMF and World Bank in relation to the BCP assessment and notes the added value of discussions, meetings, inputs, analysis and comments at every stage of the process.
- The Governing Council has taken into account and carefully considered every recommendation and prepared an indicative list of immediate action points or future arrangements towards increasing compliance with the Basel Core principles.
- The Governing Council approves the publication of the full version of the report—i.e., Detailed assessment report (DAR), which includes the BNB’s self-assessment and the assessment and recommendations of the IMF and World Bank, and the compliance grades on the principles (the ratings).
- General remarks:
  - The 2012 update of the Basel core principles introduces important enhancements and represents an essential challenge requiring a long-term approach spanning outside a horizon of 4-5 years.
  - As an EU Member state authority, the BNB is bound to comply with relevant EU legislation and strives to maintain an appropriate balance between full compliance with the EU framework and improving the effectiveness of supervisory approach in deficient areas.

*Source: _cr15295 - 29. Abuse of financial services LC The Special Supervision Directorate (SSD) originally set (IMF detailed assessment excerpt).*

### 3. Reaching maximum convergence with the Basel core principles is an important, but also

### _cr15295 - 3. Reaching maximum convergence with the Basel core principles is an important, but also

### Context and recent actions
- Reaching maximum convergence with the Basel core principles (BCP) is time-consuming and resource-demanding; some principles require rigorous changes in supervisory model and banking business models.
- Degree of compliance with BCP depends on external factors outside immediate supervisor control: the nature of business models in the banking system, ownership structure, current economic conditions, the effectiveness of the judicial system, the intensity of cross-border flow of capital and the phase of the business cycle.
- Removal of such limitations requires persistent efforts and focused actions over a longer time scale; supervisors’ capacity and resources are significantly disproportionate to those of the banking system.
- During the BCP assessment the Bulgarian state, in cooperation with the BNB, accelerated adoption of key sectoral legislation in Deposit protection and Bank recovery and resolution. As of 30-Jul-2015 the implementing acts were voted and adopted by the National Assembly and entered into force as from 14 August, 2015.
- The BNB initiated supervisory initiatives expected to materialize in the mid-term. In 2015-2016 the BNB will carry out a comprehensive analysis of asset quality (AQR exercise) and perform stress tests to analyze valuation of assets and collaterals and reliability of accounting impairments; as a result, measures for capitalization of the banking system will be identified, if necessary.

### 1. Institutional setting of the Bulgarian National Bank and the banking supervision function – powers and functions, independence and accountability, resources, cooperation and collaboration (Principles 1 - 3)
- BNB will review the current role and responsibilities of the "Banking Supervision Department" and take immediate actions to change resource allocation, including appointment of narrow specialists.
- BNB accepts findings on need to strengthen supervisory capacity by attracting additional staff and developing technical tools; noted deficiencies include areas with serious deficiency in staffing.
- Increasing need for expertise in inspection process, risk modelling, simulations, strategic regulatory analysis, impact assessment of new regulations, communication with external institutions, macro-prudential and financial stability analysis and combatting money-laundering; currently covered by very few experts.
- BNB will undertake structural changes in the "Banking Supervision Department," in particular separation of offsite and on-site supervision functions.
- BNB will review the role of the Governing Council of BNB in policy development and supervisory control and its knowledge of supervisory review findings.
- In connection with entry into force in 2015 of the Law on Recovery and Resolution of Credit Institutions, BNB will create a functionally separate unit delegated the functions of a designated resolution authority in accordance with Directive 2014/59/ EU.
- The memorandum of cooperation and understanding with the Bulgarian Bank Deposit Guarantee Fund will be updated.

### 2. Permissible activities, licensing criteria, major acquisitions and transfer of significant ownership (Principles 4 - 7)
- BNB will review legal basis to introduce improvements in examination of the origin of funds.
- BNB will consider creating a legal possibility to use a single definition of "ultimate owner" in Law on Credit Institutions (LCI) and Law on the Measures against Money Laundering (LMML).
- BNB will consider introduction of procedure for conducting interviews with candidates for the Board of Directors or the Supervisory Board, and monitoring of newly licensed banks’ compliance with license conditions.
- BNB will consider provisional requirements for shareholders to qualify for subscription of shares in banks after licensing, and provisional requirements for banks to notify the supervisory authority of material information related to a large shareholder or a person exercising control.
- Supervisory review processes for larger acquisitions or mergers in the banking sector will be enhanced.
- BNB will comply with upcoming Guidelines of the EBA adopted under Article 91, paragraph 12 of Directive 2013/36/EC on appropriate knowledge, skills and experience of the management body as a whole.

### 3. Supervisory process and corrective and sanctioning powers of supervisors (Principles 8, 9 and 11)
- BNB plans to develop administrative capacity for early intervention, recovery and coordination of restructuring measures, including stricter sanctions for non-compliance.
- Steps taken to update internal procedures for exchange of information between directorates in “Banking Supervision Department”; priority to deepen dialogue between BNB and banks’ senior management via mandatory annual meetings and more frequent thematic meetings.
- Rules will be developed for rotation of on-site and off-site inspection team members and changes to supervisory team establishment approach.
- BNB committed to reviewing, updating and harmonizing internal manuals: Manual for the banking supervision process, Manual for supervisory review and evaluation, Manual for risk assessment system and Manual for internal analysis of capital adequacy.
- BNB is considering enhanced use of external experts for asset and collateral valuations, immovable property, impairments, IT audits or other purposes during on-site inspections; cost coverage for these services can be transferred to the bank under examination.
- BNB will reconsider allocation of information resources in the “Banking Supervision Department” and prepare a proposal to streamline introducing new systems, maintenance, storage and use of information.
- Implement enhanced monitoring of banks’ obligation to notify substantial changes in business model, organizational and management structure, risk profile, composition of assets and liabilities, change in strategy, and undertake corrective actions and sanctions if notifications are not made.
- BNB will discuss options for guidance to the Deputy Governor heading "Banking Supervision" on selecting compulsory administrative measures and administrative penalties; envisaged implementation of an escalation approach.
- The regime of special supervision in the LCI will be clarified to cover cases outside resolution measures under the new law on recovery and resolution.

### 4. Consolidated supervision and home-host relationships (Principles 12-13)
- Supervisory process will be extended to additional and ancillary banking services or activities to strengthen BNB’s consolidated supervision.

### 5. Enhancing Corporate governance (Principle 14)
- BNB will take initiative to extend powers to impose requirements on banks related to internal organizational structure changes and power to remove or change members of supervisory and management boards if they don`t meet suitability requirements.
- Risk assessment manual and BNB Ordinance No 10 on internal control in banks will be updated.
- Provide legal protection to the head of internal audit who found significant problems affecting suitability assessment of management body members.
- Increased attention to internal management controls; intensified dialogue between senior management of the BNB and banks’ management or supervisory Boards; onsite examination manual to be updated.

### 6. Capital adequacy and risk management process (Principles 15-16)
- Update Internal analysis of adequacy of capital (ICAAP) manual.
- BNB plans to update its SREP handbook, largely based on EBA and SSM guidelines; emphasis on imposing additional capital requirements under Pillar 2, especially for problem exposures and liquidity management.
- Develop a procedure for prior approval and approval of common equity Tier 1, additional Tier 1 and Tier 2 capital instruments, based on EBA sample models and with specific written clauses required in contracts/prospectus.
- Update and maintain a register with all issued capital instruments.

### 7. Management of risks – credit risk and problem assets, market risk, operational risk, liquidity risk, interest rate risk in the banking book (Principles 17-18, 21-25)
- On-site inspection plans will include thorough review of risk management, credit concentrations and connected parties with detailed procedures to review internal risk management and internal audit.
- Strengthen and improve qualifications of “Banking Supervision Department” employees for management and assessment of risks.
- Strengthen qualifications in operational risk, particularly IT; envisage additional oversight tools for operational risk monitoring and require timely notification by banks of significant operational events.
- BNB will explore active partnership opportunities with supervisors participating in the SSM to access best practices, exchange experience, expertise and technical assistance.
- BNB envisages drafting more detailed requirements regarding management of exposures and instruments and drivers of sovereign risk.

### 8. Credit concentrations and large exposures (Principles 19-20)
- BNB will take steps to introduce possibility of imposing additional capital requirements in cases of suspicion of exceeding large exposure limits, identified excesses, and identified material deficiencies during investigation of interconnectedness among partners; similar provisions concerning qualifying holdings in non-financial sector companies envisaged.
- BNB will analyze expanding scope of Article 45 of the LCI on control of exposures to related parties, both in counterparties and transaction types, implementation of methodological guidelines and communication with banks to avoid circumvention via ownership/control schemes.
- Update Manual on risk assessment system to develop procedure for cross-checks identifying connectivity between parties and include these cross-inspections in supervisory examination plans.

### 9. Internal and external controls/audit, financial reporting and transparency (Principles 26-28)
- Implement measures for mandatory rotation of external auditors of banks.
- Develop additional validation rules for formalized control over inputs connected with additional supervisory reporting.
- Improve Banking Supervision staff qualification with respect to international accounting standards.

### 10. Abuse of financial services (Principle 29)
- Introduce structural changes in "Special Supervision Directorate" to strengthen administrative capacity; modify sanctions regime after transposition into national law of Directive (EC) 2015/849 on prevention of use of financial system for money laundering or terrorist financing.
- Update banking supervision manual to enhance exchange of information between “Special Supervision Directorate” and “Credit Institutions Supervision Directorate”; AML/CFT supervision findings to be included in overall bank risk profiles.
- Examine possibilities to refine and operationalize powers and duties of the structural unit responsible for anti-money laundering, counter-terrorism financing, product transparency and consumer trends monitoring.
- Finalize "Instructions for interaction between the Bulgarian National Bank and the State Agency for National Security" and submit for approval by the Governing Council of the BNB in September 2015.

*Source: _cr15295 PDF chapter/section.*

---


_Source: https://www.imf.org/-/media/websites/imf/imported-full-text-pdf/external/pubs/ft/scr/2015/_cr15295.pdf_
