Official update

Risk Management Guidelines For Licensed 'A', 'B' and 'C' class Banks and Financial Institutions, 2026

२९ भदौ २०८३29 Bhadra 20831 PDF

Issued by

Office of the Prime Minister and Council of Ministers

More from this department

Risk Management Guidelines For Licensed 'A', 'B' and 'C' class Banks and Financial Institutions, 2026
www.nrb.org.np/contents/uploads/2026/09/Risk-Management-Guidelines-2026.pdf

Risk-Management-Guidelines-2026.pdf

OpenDownload
Page 1 of 48: Risk-Management-Guidelines-2026.pdf
1 / 48
Page 2 of 48: Risk-Management-Guidelines-2026.pdf
2 / 48
Page 3 of 48: Risk-Management-Guidelines-2026.pdf
3 / 48
Page 4 of 48: Risk-Management-Guidelines-2026.pdf
4 / 48
Page 5 of 48: Risk-Management-Guidelines-2026.pdf
5 / 48
Page 6 of 48: Risk-Management-Guidelines-2026.pdf
6 / 48
Page 7 of 48: Risk-Management-Guidelines-2026.pdf
7 / 48
Page 8 of 48: Risk-Management-Guidelines-2026.pdf
8 / 48
Page 9 of 48: Risk-Management-Guidelines-2026.pdf
9 / 48
Page 10 of 48: Risk-Management-Guidelines-2026.pdf
10 / 48
Page 11 of 48: Risk-Management-Guidelines-2026.pdf
11 / 48
Page 12 of 48: Risk-Management-Guidelines-2026.pdf
12 / 48
Page 13 of 48: Risk-Management-Guidelines-2026.pdf
13 / 48
Page 14 of 48: Risk-Management-Guidelines-2026.pdf
14 / 48
Page 15 of 48: Risk-Management-Guidelines-2026.pdf
15 / 48
Page 16 of 48: Risk-Management-Guidelines-2026.pdf
16 / 48
Page 17 of 48: Risk-Management-Guidelines-2026.pdf
17 / 48
Page 18 of 48: Risk-Management-Guidelines-2026.pdf
18 / 48
Page 19 of 48: Risk-Management-Guidelines-2026.pdf
19 / 48
Page 20 of 48: Risk-Management-Guidelines-2026.pdf
20 / 48
Page 21 of 48: Risk-Management-Guidelines-2026.pdf
21 / 48
Page 22 of 48: Risk-Management-Guidelines-2026.pdf
22 / 48
Page 23 of 48: Risk-Management-Guidelines-2026.pdf
23 / 48
Page 24 of 48: Risk-Management-Guidelines-2026.pdf
24 / 48
Page 25 of 48: Risk-Management-Guidelines-2026.pdf
25 / 48
Page 26 of 48: Risk-Management-Guidelines-2026.pdf
26 / 48
Page 27 of 48: Risk-Management-Guidelines-2026.pdf
27 / 48
Page 28 of 48: Risk-Management-Guidelines-2026.pdf
28 / 48
Page 29 of 48: Risk-Management-Guidelines-2026.pdf
29 / 48
Page 30 of 48: Risk-Management-Guidelines-2026.pdf
30 / 48

Showing the first 30 of 48 pages. Open the full PDF

Attachments

  • Risk-Management-Guidelines-2026.pdfPDF · 815 KBOpenDownload

Text extracted from the PDF

This text was extracted from the attached PDF by machine and may contain errors. The attached PDF is the authoritative version.

Risk-Management-Guidelines-2026.pdf
Risk Management Guidelines For Licensed 'A', 'B' and 'C' class Banks and Financial Institutions Nepal Rastra Bank Banks and Financial Institutions Regulation Department 2026 Contents I - Risk Management Guidelines .................................................................................................... 1 1.1 Overview ............................................................................................................................... 1 1.2 Scope and Objectives of the Guidelines ............................................................................... 1 1.2.1 Scope ............................................................................................................................. 1 1.2.2 Objectives ..................................................................................................................... 2 1.3 Dimensions of Risk Management ...................................................................................... 2 1.3.1 Risk Culture .................................................................................................................. 2 1.3.2 Risk Strategy and Risk Appetite ................................................................................. 3 1.3.3 Risk Governance and Organization ............................................................................ 3 1.3.4 Risk Assessment and Treatment .................................................................................... 4 1.4 Risk Management Framework ........................................................................................... 6 1.4.1 Active Board and Senior Management Oversight ..................................................... 6 1.4.2 Risk Management Department(s) and Various Committees .................................... 6 1.4.3 Policies and Procedures ............................................................................................... 7 1.4.4 Appropriate Management Information System (MIS) .............................................. 7 1.4.5 Comprehensive Internal Controls and Limits ............................................................ 7 II – Credit Risk Management .......................................................................................................... 9 2.1 Overview ............................................................................................................................... 9 2.2 Appropriate Organizational Structure ............................................................................... 9 2.3 Credit Risk Strategies, Policies and Procedures ............................................................. 10 2.4 Credit Limits and Indicators ............................................................................................. 11 2.5 Credit Granting Processes ................................................................................................ 11 2.6 Credit Risk Monitoring ..................................................................................................... 12 2.7 Remedial actions ............................................................................................................... 13 2.8 Recovery process .............................................................................................................. 13 2.9 Provisioning Process ......................................................................................................... 13 III – Liquidity and Funding Risk Management ............................................................................ 14 3.1 Overview ............................................................................................................................. 14 3.2 Organizational Structure ............................................................................................... 14 3.3 Strategies, Policies and Procedures..................................................................................... 15 3.4 Limits and Early Indicators ................................................................................................. 16 3.5 Measurement and Monitoring ............................................................................................. 17 3.6 Reporting............................................................................................................................. 17 3.7 Contingency Funding Plan.................................................................................................. 17 IV – Operational Risk Management ............................................................................................. 19 4.1 Overview ............................................................................................................................. 19 4.2 Organizational Structure ................................................................................................... 20 4.3 Strategies, Policies and Procedures ................................................................................. 21 4.4 Assessment and Measurement ......................................................................................... 22 4.5 Monitoring and Reporting ................................................................................................ 23 4.6 Contingency Planning ....................................................................................................... 24 4.7 Money Laundering (MF) / Terrorism Financing (TF) Risk Management .................... 24 V – Market Risk Management ...................................................................................................... 26 5.1 Overview ............................................................................................................................. 26 5.2 Organization Structure ........................................................................................................ 27 5.3 Strategy Policies, and Procedures ....................................................................................... 28 5.4 Limits and indicators........................................................................................................... 28 5.5 Measurement and Monitoring ............................................................................................. 29 5.6 Control of market risk ......................................................................................................... 30 VI – Management of Interest Rate Risk in Banking Book ........................................................... 31 6.1 Overview ............................................................................................................................. 31 6.2 Organization Structure ........................................................................................................ 31 6.3 Strategies, Policies and Procedures..................................................................................... 32 6.4 Limits .................................................................................................................................. 32 6.5 Risk Measurement .............................................................................................................. 32 6.6. Risk Monitoring and Reporting ......................................................................................... 33 6.7 Internal Control ................................................................................................................... 34 VII – Technology Risk Management ............................................................................................ 35 7.1 Overview ............................................................................................................................. 35 7.2 Organization Structure ........................................................................................................ 35 7.3 Strategies, Policies and Procedures..................................................................................... 35 7.4 Risk Identification, Assessment and Measurement ............................................................ 36 7.5 Monitoring and Reporting................................................................................................... 36 7.6 Contingency Planning and Business Continuity Management ........................................... 36 VIII – Climate Risk Management ................................................................................................. 38 8.1 Overview ............................................................................................................................. 38 8.2 Organization Structure ........................................................................................................ 38 8.3 Strategies, Policies and Procedures..................................................................................... 39 8.4 Risk Identification, Assessment and Measurement ............................................................ 39 8.5 Internal Control ................................................................................................................... 40 8.6 Monitoring and Reporting................................................................................................... 40 8.7 Contingency Planning ......................................................................................................... 40 Annexures ..................................................................................................................................... 41 Annexure 1: Sample Template - Risk Appetite and Risk Tolerance ............................................ 41 List of Abbreviations AI Artificial Intelligence ALCO ALM AML BCBS BCP BFIs BOD CDD CFP CFO CIO CIRT CISO CRO CTO DRP EaR EDD ESRM EVE FATF FIU FMI FSB GRI ICAAP ICT IRRBB ISO ISSB IT KPI KRI LCR Asset Liability Management Committee Asset Liability Management Anti-Money Laundering Basel Committee on Banking Supervision Business Continuity Plan Banks and Financial Institutions Board of Directors Customer Due Diligence Contingency Funding Plan Chief Financial Officer Chief Information Officer Cybersecurity Incident Response Team Chief Information Security Officer Chief Risk Officer Chief Technology Officer Disaster Recovery Plan Earnings-at-Risk Enhanced Due Diligence Environmental and Social Risk Management Economic Value of Equity Financial Action Task Force Financial Intelligence Unit Financial Market Infrastructure Financial Stability Board Global Reporting Initiative Internal Capital Adequacy Assessment Process Information Communication Technology Interest Rate Risk in the Banking Book International Organization for Standardization International Sustainability Standards Board Information Technology Key Performance Indicator Key Risk Indicator Liquidity Coverage Ratio LTV Loan to Value MIS ML/TF NFRS NII NRB NSFR ORM RCSA RMC Management Information System Money Laundering/ Terrorism Financing Nepal Financial Reporting Standards Net Interest Income Nepal Rastra Bank Net Stable Funding Ratio Operational Risk Management Risk and Control Self-Assessment Risk Management Committee RPO RTO SIEM SOC SOL TF TRM UNSC VRS Recovery Point Objective Recovery Time Objective Security Information and Event Management Security Operations Center Single Obligor Limit Terrorism Financing Technology Risk Management United Nations Security Council Voluntary Retirement Scheme I - Risk Management Guidelines 1.1 Overview Taking risk is an integral part of financial intermediation and banking industries in order to realize sustainable returns on their investments. On the other hand, risks assumed have the potential to wipe out expected returns and may result in losses for the institutions, which may endanger the soundness of individual financial institutions and affect the stability of the overall financial system. Hence, setting an appropriate risk management strategy, risk tolerance/appetite level and a holistic risk management approach with effective reporting lines to the senior management enables financial institutions to take risks knowingly and treat risks appropriately. Risk management is a part of internal governance involving all areas of financial institutions. There is a strong link between good corporate governance and sound risk management. Without proper risk management, the various functions in a financial institution cannot work together to achieve the institution’s objectives. It is an essential part in helping the financial institution grow and conserve sustainability and resilience. The emergence of new risks to the financial sector continues to threaten global financial stability. Escalating climate change has prompted central banks, financial regulators and international supervisory bodies all over the globe to set out principles, guidelines and regulations for combating climate and environment-related risks. The rapid adoption of digitalization, increasing reliance on data-driven technologies, and advancement of cutting-edge innovations such as artificial intelligence (AI) have significantly enhanced the efficiency, accessibility, and innovation of the financial system. At the same time, these developments have introduced new and evolving risks related to data confidentiality, cyber security, operational resilience, and the safety and integrity of payment systems and financial markets. As financial institutions become more interconnected and technologydependent, strengthening risk management frameworks is essential to harness the benefits of technological innovation while effectively managing the associated risks. Following the global financial crisis, risk management in financial institutions has evolved from a compliance-driven function to a top-level comprehensive activity relevant at the highest levels of decision-making and strategy setting. While the extent of the risk management function performed and the structure kept in place depend on the size and complexity of individual financial institutions, risk management is most effective when basic principles and elements of risk management are applied consistently throughout the financial institution. Additionally, each financial institution should implement a comprehensive risk management program tailored to its needs and the circumstances under which it operates. 1.2 Scope and Objectives of the Guidelines 1.2.1 Scope Nepal Rastra Bank has issued these guidelines to provide guidance to all financial institutions on minimum standards for risk management. These guidelines are not intended to be exhaustive. A financial institution may, depending on its size, complexity, level of risk exposure and interconnectedness with other financial institutions, establish a more advanced framework than outlined in this document. Financial institutions are in fact encouraged to self-assess their risk profile and operational context, and customize their risk management framework and approach to attain organizational goals while meeting the minimum requirements and standards set out in the guideline. While these guidelines provide a summary outline of risk management, financial institutions should 1 also adhere to the guidelines issued by global standard setters for prudential regulation, such as the BCBS and FSB (e.g., revisions to the principles of sound management of Operational risks, Framework for Internal Control Systems in Banking Organizations, the internal audit function in banks, the compliance functions in banks and so on). This guideline provides guidance on the management of the major risks that financial institutions may face, namely: Credit Risk, Liquidity Risk, Operational Risk, Market Risk, Interest Rate Risk, Technology Risk and Climate Risk. However, financial institutions may, if deemed necessary, apply the guideline to all other risks that they are exposed to, in addition to the risks mentioned in the document. 1.2.2 Objectives In publishing this guideline, the objectives of the Nepal Rastra Bank are: a) To promote better risk culture at all levels of the financial institution. b) To provide minimum standards for risk management practices. c) To improve the financial soundness of individual financial institutions and the stability of the overall financial sector. d) To encourage financial institutions to adopt and implement a sound risk management framework. e) To introduce important risk management tools and techniques for assessment and necessary treatment of various risks. 1.3 Dimensions of Risk Management 1.3.1 Risk Culture Every financial institution should develop an integrated and institution-wide risk culture, based on a full understanding of the risks it faces and how they are managed, considering risk tolerance and appetite. Since the business of financial institutions involves risk taking, it is fundamental that risks are appropriately managed. A sound and consistent risk culture throughout a financial institution is a key element of effective risk management. An institution will develop its risk culture through policies, examples, communication, and training of staff regarding their responsibilities for risk and every member of the financial institution should be fully aware of his or her responsibility regarding risk management. Additionally, risk management should not be confined to risk specialists or to control functions only. Business and operational units should be primarily responsible for managing risk on a day-to-day basis, and should consider risk tolerance and risk appetite (according to the format as specified in the Annexure of the Guideline), in line with the financial institution’s risk policies and procedures. Risk culture and its impact on effective risk management must be a major concern for the board and senior management. A sound risk culture encourages effective risk management, promotes sound risktaking and ensures that risk-taking activities beyond the institution’s risk appetite are recognized, assessed, reported, and addressed in a timely manner. Weaknesses in setting the risk culture are often the root cause of the occurrence of significant risk events, financial institution failures, and financial crises. The Board of Directors (BoD) of the institution sets the tone for the desired risk culture. The risk culture can be strengthened through: 2 a) Enabling an open and respectful atmosphere in which employees feel encouraged to speak up when observing new or excessive risks; b) Clarifying the range of acceptable risks using an embedded risk appetite statement and various forms of communication and training; and c) Aligning incentives with objectives and clarifying how breaches of policies/procedures will be addressed. 1.3.2 Risk Strategy and Risk Appetite Risk tolerance and risk appetite are terms often used interchangeably: Risk appetite means the aggregate level and types of risk a financial institution is willing to assume within its risk capacity to achieve its strategic objectives and business plan; risk appetite describes the absolute risks a financial institution is a priori open to take; while risk tolerance relates to the actual limits within its risk appetite that a financial institution pursues. A financial institution’s strategy details the long-term, and in some cases, short-term goals and objectives, as well as how progress toward their achievement is measured. Along with business goals, the financial institution must have risk goals and risk strategies that enable it to achieve the desired risk profile. The board of directors sets the strategies and senior management is responsible for implementing those strategies and communicating them throughout the organization. The risk appetite statement plays an important role in cascading the risk strategy throughout the institution. It includes metrics and indicators concerning specifi…

Source: National Portal of Nepal

DigiNepal mirrors public notices for easier reading. DigiNepal is independent and is not affiliated with or endorsed by the publisher. Check the original source for the official record.

Related updates