Risk Management Framework for Shari’ah Compliant Banking
Para. 5.1Status unknownSaudi ArabiaRegulation
Issued by Saudi Central Bank (SAMA) Rulebook
Principle 1.0 : Banks conducting Shari'ah compliant banking activities shall have in place a comprehensive risk management framework, including appropriate board and senior management oversight, to identify, measure, monitor, report and control all relevant risks arising from Shari'ah compliant banking activities, taking into account compliance with Shari'ah rules and principles. Board of Directors (Board) Oversight: 5.2 Board must have active oversight of their risk management activities, including risks arising from Shari'ah compliant banking activities. The Board or the delegated committee of the Board shall approve the risk management objectives, strategies and policies, risk appetite and risk tolerance of the bank, taking into consideration the overall economic and financial conditions. Shari'ah compliant banking activities conducted by the bank shall be consistent with the risk appetite and within the risk tolerance level approved by the Board or the delegated committee. 5.3 Board or the delegated committee shall ensure that there is an effective risk management structure and policies and procedures governing the conduct of Shari'ah complaint banking activities, including adequate systems for measuring, monitoring, reporting and controlling risk exposures commensurate with the scope, size and complexity of the bank's business and operations. 5.4 Board or the delegated committee shall review the effectiveness of the risk management practices periodically and make appropriate changes as and when necessary. 5.5 Board or the delegated committee must ensure that the risk management function is independent from risk taking functions and is reporting directly to the Chief Executive officer/General Manager. The Chief Risk Officer shall have independent report and access to the Risk Management Committee. Senior Management Oversight: 5.6 Senior management must ensure that the policies and procedures clearly establish roles and responsibilities, and lines of accountability of various functions within the bank for managing, monitoring and reporting risk arising from Shari'ah compliant banking activities. 5.7 Senior management must ensure that there are well defined policies and procedures managing risks arising from Shari'ah compliant banking activities, in line with the risk appetite and risk tolerance approved by the Board or the delegated committee, and ensure that these policies and procedures are effectively implemented. 6. Risk Management Requirements 6.1 Banks must have in place sound processes for identification, measurement, mitigation, monitoring and reporting of risks associated with Shari'ah compliant banking activities. Risk management processes for Shari'ah compliant banking activities should be integrated with the overall risk management framework, where relevant, to ensure the bank have an overall view of risk exposures and interlinkages with other activities and functions within the bank. 6.2 Banks must ensure that there are adequate system of controls and processes for monitoring compliance with the established policies and limits, Shari'ah rules and principles and other regulatory requirements, as applicable. The state of compliance should be reported to the Risk Management Committee and Senior management periodically or more frequently, when necessary. 6.3 Banks must ensure that effective management information systems (MIS) are in place to support their risk management activities, decision making, facilitate compliance with internal and SAMA' prudential and supervisory reporting requirements.
The Arabic text is the legally binding version. The English translation is provided for guidance only.
Freshness not yet recorded