Regulators around the world are targeting culture reforms. It is driven by both the “hardware” (e.g. policies and processes) and “software” (e.g. beliefs and values) in an organisation. As part of an effort to instil a strong culture of responsibility and ethical behaviour in financial institutions (“FIs”), the Monetary Authority of Singapore (MAS) released the Guidelines on Individual Accountability and Conduct (the “IAC Guidelines”) on 10 September 2020, which took effect on 10 September 2021.

The IAC Guidelines set out five high-level outcomes that financial institutions should achieve on individual accountability and conduct. FIs should implement measures to promote the individual accountability of senior managers, strengthen oversight over material risk personnel and reinforce standards of proper conduct amongst all employees.

How are these outcomes achieved?

The key purposes of the IAC Guidelines are to reinforce FIs' responsibilities in three areas:

  1. Promoting individual accountability of senior managers

  2. Strengthening the oversight of employees in material risk functions (“MRFs”)

  3. Implementing standards of proper conduct amongst all employees

To achieve these objectives, the MAS has adopted an outcome-based approach. The IAC Guidelines set out five outcomes that FIs are expected to work towards.


Outcome 1: Senior managers responsible for managing and conducting the FI's core functions are clearly identified.

Individuals who fall within the definition of "senior managers" are those who are employed by, or acting for or by arrangement with, the FI in an executive capacity and are principally responsible for the day-to-day management of the FI. These include, but are not limited to, the senior managers performing "core management functions" (CMF), such as the following persons: Chief Executive Officer, Chief Financial Officer, Chief Risk Officer, Chief Data Officer, Head of Compliance, Head of Internal Audit etc.

In assessing the core management functions that apply to their businesses, FIs should consider the following factors:

  • the relevance of those functions in the context of the FI’s growth strategy and business;

  • whether those functions have, or could potentially have, a significant impact on the FI’s risk profile. The board of directors or the head office should take ownership in identifying the appropriate core management functions that apply to their businesses.

FIs should identify senior managers who are responsible for core management functions and have actual decision-making authority and oversight of each such function, and clearly specify their individual accountabilities.

Apart from the CEO who is directly accountable to the board of directors or head office, senior managers should in general have direct reporting lines to the CEO or equivalent and, where relevant to the performance of that function, to the board of directors or head office as appropriate (see figure in following card). Senior managers may be based in or outside Singapore.



Outcome 2: Senior managers are fit and proper for their roles and held responsible for the actions of their staff and the conduct of the business under their purview.

and

Outcome 3: The FI's governance framework supports senior managers' performance of their roles and responsibilities with a clear and transparent management structure and reporting relationships.

In assessing senior managers’ fitness and propriety, FIs may apply the guiding criteria set out in the Guidelines on Fit and Proper Criteria and other factors that the FI determines to be relevant to its circumstances and the particular role.

FIs should also ensure that the criteria for assessing senior managers’ fitness and propriety are aligned with the expectations that the board of directors has of senior managers. Likewise, it is for FIs to determine the appropriate frequency and approach for review to satisfy themselves of senior managers’ fitness and propriety on an ongoing basis.

As a general guide, such reviews should minimally be conducted on an annual basis, or as and when any matters arise which could have implications on or call into question a senior manager’s fitness and propriety.


 

The board of directors or head office of the FIs should ensure that the FIs:

  • have robust standards and processes to assess the fitness and propriety of senior managers, prior to the appointment and on an on-going basis;

  • clearly specify each senior manager's area of responsibility (including in management committees);

  • appropriately delineate the FI's overall management structure, including reporting relationships among senior managers and management committees, between senior managers or management committees and the board of directors, and across entities within the group, as applicable;

  • have each senior manager acknowledge his or her specified roles, responsibilities and reporting lines;

  • have board or head office approval of each senior manager's roles and responsibilities and the FI's overall management structure, and maintain documentation of the same, including timely updates where there are material changes;

  • put in place appropriate incentive, escalation and consequence management frameworks that hold senior managers accountable for the effective performance of their specified roles and responsibilities; and

  • put in place a succession plan that is regularly reviewed and updated.

Outcome 4: Material risk personnel are fit and proper for their roles, and subject to effective risk governance, and appropriate incentive structures and standards of conduct.

“Material risk personnel” (“MRP”) refer to individuals who have the authority to make decisions or conduct activities that can significantly impact the FI’s safety and soundness, or cause harm to a significant segment of the FI’s customers or other stakeholders.

FIs are required to identify MRP and subject them to necessary oversight. The board of directors and senior management should ensure that appropriate standards and processes are in place to:

  • identify MRPs, including establishing the relevant criteria for identifying MRPs;

  • assess the fitness and propriety of MRPs, prior to their appointment and on an on-going basis;

  • facilitate effective risk governance, including subjecting MRPs to the appropriate mandates, decision-making authority, risk limits and supervisory oversight;

  • subject MRPs to standards of proper conduct, continuous training and an appropriate incentive structure.

The board of directors and senior management should ensure that MRPs in risk management and control functions are accorded the necessary stature and authority. MRPs in risk management and control functions should have the authority to participate in the decision-making processes of business functions.

MRPs in risk management and control functions should also be suitably trained and possess the relevant experience and expertise with regards to the monitoring and management of the FI’s risks and internal control environment.

In addition, MRPs in risk management and control functions should be independent from the business functions of the FI to ensure proper checks and balances. Hence, the compensation structure should be designed in such a way as to minimise potential conflicts of interest and ensure that their independence is not compromised.

Outcome 5: The FI has a framework that promotes and sustains among all employees the desired conduct.

The FI’s conduct framework should be integrated with HR processes over the employee life cycle, from hiring and on-boarding, to regular training, monitoring, performance reviews, incentives and compensation, and consequence management, and eventually, departure or termination.

The board of directors and senior management should ensure that such framework addresses:

  • the standards of conduct expected of all employees;

  • consistent and effective communication of the expected standards;

  • the appropriate policies, systems and processes to enforce the expected standards, including a monitoring, reporting and escalation framework, an incentive structure, a consequence management system and a formalised whistle-blowing channel; and

  • engagement strategies with key stakeholders.

The board of directors and senior management are expected to notify the MAS of material adverse developments such as misconduct, lapses in risk management and controls, or breaches in legal or regulatory requirements that have the potential to cause widespread disruption to the FI and/or significantly impact the FI's customers and other stakeholders or the safety and soundness of the financial system in Singapore.

The MAS should also be notified in a timely manner of any information that may have a material negative impact on the fitness and propriety of senior managers or MRPs.

To whom do the IAC Guidelines apply?

The IAC Guidelines apply to banks, merchant banks, finance companies, insurers, capital markets services licensees, financial advisers, trust companies, registered fund management companies, payment services providers and systemically important infrastructures (approved exchanges and clearing houses).

For locally incorporated banks and insurers, as well as approved exchanges and approved clearing houses that operate as a single group, the Guidelines apply on a group basis. Even where an FI or its group operates overseas, and may already be subject to overseas requirements similar to the IAC Guidelines, the IAC Guidelines still apply specifically to the FI’s operations in Singapore.

Commensurate implementation

FIs should implement the IAC Guidelines in a manner proportionate to the nature, size and complexity of their operations. The board of directors and senior management are responsible for overseeing FIs’ implementation of the IAC Guidelines.

FIs with less than 50 employees will not ordinarily be expected to adopt the specific guidance described in the IAC Guidelines but should still achieve the five outcomes. Nonetheless, MAS may require them to adopt specific guidance if there are potential gaps in accountability and oversight, or where their operations are complex.

FIs with 50 or more employees are expected to comply with the IAC Guidelines as a framework and best practice for achieving the outcomes. Nonetheless, they do not necessarily need to adopt specific guidance where they have assessed this to be irrelevant to their businesses.

Stories you might be interested in...