Internal Control Systems
By virtue of Bank of Greece Governor's Act 2577/ 9 March 2006, the operational principles and criteria for the evaluation of the organisation and the Internal Control Systems (ICS) of credit and financial institutions at both individual and group levels were adapted to current conditions. The list of instruments making up the institutional framework of this section is presented below. The main adjustments brought about by this Act chiefly relate to the following areas:
- All credit institutions are obliged to establish an independent Risk Management Unit, in order to effectively monitor all forms of risk, including operational risk. In addition, depending on the size and complexity of credit institutions' activities, they are required to establish a Risk Management Committee.
- A compliance function must be established, responsible for credit institutions' compliance with the current legislative and regulatory framework, with special reference to AML/CFT issues.
- The Board of Directors must have adequate knowledge and experience in the main activities of the credit institution, so that it will be able to supervise all functions of the credit institution.
- The importance of ensuring the quality of services provided to customers and transaction transparency is amplified, as an integral part of operational risk management.
- The basic principles for outsourcing (including collection of debts and card management) are laid down.
For the smooth implementation of the Act, the competent Department for the Supervision of Credit and Financial Institutions was authorised to make technical adjustments, especially for small banks or financial institutions, without departing from the basic principles and guidelines of the Act.
List of Instruments
Governor's Act 2577/9 March 2006: Framework of operational principles and criteria for the evaluation of the organisation and Internal Control Systems of credit and financial institutions, and relevant powers of their management bodies
Governor's Act 2597/31 October 2007: Amendments to Bank of Greece Governor’s Act 2577/2006 "Framework of operational principles and criteria for the evaluation of the organisation and Internal Control Systems of credit and financial institutions, and relevant powers of their management bodies”
Annex 1
Outsourcing
Annex 2
Principles of safe and effective operation of IT systems in the context of credit institutions' operational risk management.
Annex 3
Contents of an ICS assessment report by independent external auditors.
Annex 4 (repealed by Banking and Credit Committee decision 281/5/26.3.2009)
Prevention of money laundering and terrorist financing.
Banking and Credit Committee decision 231/4/13 October 2006: "Supplementation of Bank of Greece Governor's Act 2577/2006 on the operational principles and criteria for the evaluation of the organisation and Internal Control Systems of credit and financial institutions, and relevant powers of their management bodies"
Banking and Credit Committee decision 242/4 May 2007: "Amendment to Annex 4 of Bank of Greece Governor's Act 2577/9 March 2006, specifying the principles and the evaluation criteria of the organisational structure of an Internal Control System (ICS) concerned with the prevention of money laundering and terrorist financing".
Banking and Credit Committee decision 257/4/22 February 2008: "Amendment to Annex 4 of Bank of Greece Governor's Act 2577/9 March 2006, as currently in force".
Annex 5
Establishment of the criteria that must govern credit institutions' Internal Capital Adequacy Assessment Process (ICAAP) and Supervisory Review Process (SRP) by the Bank of Greece (Pillar 2)
Governor's Act 2595/20 August 2007
Annex 6
Conflicts of interests and "PERSONAL TRANSACTIONS" rules in the course of providing investment services for the purposes of the implementation of Articles 12 and 13 of Law 3606/2007.
Governor's Act 2597/31 October 2007: "Amendments to and supplementation of Bank of Greece Governor’s Act 2577/2006 on the framework of operational principles and criteria for the evaluation of the organisation and Internal Control Systems of credit and financial institutions, and relevant powers of their management bodies”
Annex 7
Safekeeping of customers' assets
Governor's Act 2597/31 October 2007: "Amendments to and supplementation of Bank of Greece Governor’s Act 2577/2006 on the framework of operational principles and criteria for the evaluation of the organisation and Internal Control Systems of credit and financial institutions, and relevant powers of their management bodies”
Annex 8
Record keeping
Governor's Act 2597/31 October 2007: "Amendments to and supplementation of Bank of Greece Governor’s Act 2577/2006 on the framework of operational principles and criteria for the evaluation of the organisation and Internal Control Systems of credit and financial institutions, and relevant powers of their management bodies”
Banking and Credit Committee decision 258/14/2004
Framework governing credit institutions' transactions with persons with which they maintain a "special relationship"