Risk Management Guidelines For Licensed 'A', 'B' and 'C' class Banks and Financial Institutions, 2026
२९ भदौ २०८३29 Bhadra 20831 PDF
Office of the Prime Minister and Council of Ministers
More from this departmentRisk Management Guidelines For Licensed 'A', 'B' and 'C' class Banks and Financial Institutions, 2026
www.nrb.org.np/contents/uploads/2026/09/Risk-Management-Guidelines-2026.pdf






























Showing the first 30 of 48 pages. Open the full PDF
Attachments
Text extracted from the PDF
This text was extracted from the attached PDF by machine and may contain errors. The attached PDF is the authoritative version.
Risk-Management-Guidelines-2026.pdf
Risk Management Guidelines
For
Licensed 'A', 'B' and 'C' class
Banks and Financial Institutions
Nepal Rastra Bank
Banks and Financial Institutions Regulation Department
2026
Contents
I - Risk Management Guidelines .................................................................................................... 1
1.1 Overview ............................................................................................................................... 1
1.2 Scope and Objectives of the Guidelines ............................................................................... 1
1.2.1 Scope ............................................................................................................................. 1
1.2.2 Objectives ..................................................................................................................... 2
1.3 Dimensions of Risk Management ...................................................................................... 2
1.3.1 Risk Culture .................................................................................................................. 2
1.3.2 Risk Strategy and Risk Appetite ................................................................................. 3
1.3.3 Risk Governance and Organization ............................................................................ 3
1.3.4 Risk Assessment and Treatment .................................................................................... 4
1.4 Risk Management Framework ........................................................................................... 6
1.4.1 Active Board and Senior Management Oversight ..................................................... 6
1.4.2 Risk Management Department(s) and Various Committees .................................... 6
1.4.3 Policies and Procedures ............................................................................................... 7
1.4.4 Appropriate Management Information System (MIS) .............................................. 7
1.4.5 Comprehensive Internal Controls and Limits ............................................................ 7
II – Credit Risk Management .......................................................................................................... 9
2.1 Overview ............................................................................................................................... 9
2.2 Appropriate Organizational Structure ............................................................................... 9
2.3 Credit Risk Strategies, Policies and Procedures ............................................................. 10
2.4 Credit Limits and Indicators ............................................................................................. 11
2.5 Credit Granting Processes ................................................................................................ 11
2.6 Credit Risk Monitoring ..................................................................................................... 12
2.7 Remedial actions ............................................................................................................... 13
2.8 Recovery process .............................................................................................................. 13
2.9 Provisioning Process ......................................................................................................... 13
III – Liquidity and Funding Risk Management ............................................................................ 14
3.1 Overview ............................................................................................................................. 14
3.2
Organizational Structure ............................................................................................... 14
3.3 Strategies, Policies and Procedures..................................................................................... 15
3.4 Limits and Early Indicators ................................................................................................. 16
3.5 Measurement and Monitoring ............................................................................................. 17
3.6 Reporting............................................................................................................................. 17
3.7 Contingency Funding Plan.................................................................................................. 17
IV – Operational Risk Management ............................................................................................. 19
4.1 Overview ............................................................................................................................. 19
4.2 Organizational Structure ................................................................................................... 20
4.3 Strategies, Policies and Procedures ................................................................................. 21
4.4 Assessment and Measurement ......................................................................................... 22
4.5 Monitoring and Reporting ................................................................................................ 23
4.6 Contingency Planning ....................................................................................................... 24
4.7 Money Laundering (MF) / Terrorism Financing (TF) Risk Management .................... 24
V – Market Risk Management ...................................................................................................... 26
5.1 Overview ............................................................................................................................. 26
5.2 Organization Structure ........................................................................................................ 27
5.3 Strategy Policies, and Procedures ....................................................................................... 28
5.4 Limits and indicators........................................................................................................... 28
5.5 Measurement and Monitoring ............................................................................................. 29
5.6 Control of market risk ......................................................................................................... 30
VI – Management of Interest Rate Risk in Banking Book ........................................................... 31
6.1 Overview ............................................................................................................................. 31
6.2 Organization Structure ........................................................................................................ 31
6.3 Strategies, Policies and Procedures..................................................................................... 32
6.4 Limits .................................................................................................................................. 32
6.5 Risk Measurement .............................................................................................................. 32
6.6. Risk Monitoring and Reporting ......................................................................................... 33
6.7 Internal Control ................................................................................................................... 34
VII – Technology Risk Management ............................................................................................ 35
7.1 Overview ............................................................................................................................. 35
7.2 Organization Structure ........................................................................................................ 35
7.3 Strategies, Policies and Procedures..................................................................................... 35
7.4 Risk Identification, Assessment and Measurement ............................................................ 36
7.5 Monitoring and Reporting................................................................................................... 36
7.6 Contingency Planning and Business Continuity Management ........................................... 36
VIII – Climate Risk Management ................................................................................................. 38
8.1 Overview ............................................................................................................................. 38
8.2 Organization Structure ........................................................................................................ 38
8.3 Strategies, Policies and Procedures..................................................................................... 39
8.4 Risk Identification, Assessment and Measurement ............................................................ 39
8.5 Internal Control ................................................................................................................... 40
8.6 Monitoring and Reporting................................................................................................... 40
8.7 Contingency Planning ......................................................................................................... 40
Annexures ..................................................................................................................................... 41
Annexure 1: Sample Template - Risk Appetite and Risk Tolerance ............................................ 41
List of Abbreviations
AI
Artificial Intelligence
ALCO
ALM
AML
BCBS
BCP
BFIs
BOD
CDD
CFP
CFO
CIO
CIRT
CISO
CRO
CTO
DRP
EaR
EDD
ESRM
EVE
FATF
FIU
FMI
FSB
GRI
ICAAP
ICT
IRRBB
ISO
ISSB
IT
KPI
KRI
LCR
Asset Liability Management Committee
Asset Liability Management
Anti-Money Laundering
Basel Committee on Banking Supervision
Business Continuity Plan
Banks and Financial Institutions
Board of Directors
Customer Due Diligence
Contingency Funding Plan
Chief Financial Officer
Chief Information Officer
Cybersecurity Incident Response Team
Chief Information Security Officer
Chief Risk Officer
Chief Technology Officer
Disaster Recovery Plan
Earnings-at-Risk
Enhanced Due Diligence
Environmental and Social Risk Management
Economic Value of Equity
Financial Action Task Force
Financial Intelligence Unit
Financial Market Infrastructure
Financial Stability Board
Global Reporting Initiative
Internal Capital Adequacy Assessment Process
Information Communication Technology
Interest Rate Risk in the Banking Book
International Organization for Standardization
International Sustainability Standards Board
Information Technology
Key Performance Indicator
Key Risk Indicator
Liquidity Coverage Ratio
LTV
Loan to Value
MIS
ML/TF
NFRS
NII
NRB
NSFR
ORM
RCSA
RMC
Management Information System
Money Laundering/ Terrorism Financing
Nepal Financial Reporting Standards
Net Interest Income
Nepal Rastra Bank
Net Stable Funding Ratio
Operational Risk Management
Risk and Control Self-Assessment
Risk Management Committee
RPO
RTO
SIEM
SOC
SOL
TF
TRM
UNSC
VRS
Recovery Point Objective
Recovery Time Objective
Security Information and Event Management
Security Operations Center
Single Obligor Limit
Terrorism Financing
Technology Risk Management
United Nations Security Council
Voluntary Retirement Scheme
I - Risk Management Guidelines
1.1 Overview
Taking risk is an integral part of financial intermediation and banking industries in order to realize
sustainable returns on their investments. On the other hand, risks assumed have the potential to wipe
out expected returns and may result in losses for the institutions, which may endanger the soundness
of individual financial institutions and affect the stability of the overall financial system. Hence,
setting an appropriate risk management strategy, risk tolerance/appetite level and a holistic risk
management approach with effective reporting lines to the senior management enables financial
institutions to take risks knowingly and treat risks appropriately.
Risk management is a part of internal governance involving all areas of financial institutions. There
is a strong link between good corporate governance and sound risk management. Without proper risk
management, the various functions in a financial institution cannot work together to achieve the
institution’s objectives. It is an essential part in helping the financial institution grow and conserve
sustainability and resilience.
The emergence of new risks to the financial sector continues to threaten global financial stability.
Escalating climate change has prompted central banks, financial regulators and international
supervisory bodies all over the globe to set out principles, guidelines and regulations for combating
climate and environment-related risks. The rapid adoption of digitalization, increasing reliance on
data-driven technologies, and advancement of cutting-edge innovations such as artificial intelligence
(AI) have significantly enhanced the efficiency, accessibility, and innovation of the financial system.
At the same time, these developments have introduced new and evolving risks related to data
confidentiality, cyber security, operational resilience, and the safety and integrity of payment systems
and financial markets. As financial institutions become more interconnected and technologydependent, strengthening risk management frameworks is essential to harness the benefits of
technological innovation while effectively managing the associated risks.
Following the global financial crisis, risk management in financial institutions has evolved from a
compliance-driven function to a top-level comprehensive activity relevant at the highest levels of
decision-making and strategy setting. While the extent of the risk management function performed
and the structure kept in place depend on the size and complexity of individual financial institutions,
risk management is most effective when basic principles and elements of risk management are
applied consistently throughout the financial institution. Additionally, each financial institution
should implement a comprehensive risk management program tailored to its needs and the
circumstances under which it operates.
1.2 Scope and Objectives of the Guidelines
1.2.1 Scope
Nepal Rastra Bank has issued these guidelines to provide guidance to all financial institutions on
minimum standards for risk management. These guidelines are not intended to be exhaustive. A
financial institution may, depending on its size, complexity, level of risk exposure and
interconnectedness with other financial institutions, establish a more advanced framework than
outlined in this document. Financial institutions are in fact encouraged to self-assess their risk profile
and operational context, and customize their risk management framework and approach to attain
organizational goals while meeting the minimum requirements and standards set out in the guideline.
While these guidelines provide a summary outline of risk management, financial institutions should
1
also adhere to the guidelines issued by global standard setters for prudential regulation, such as the
BCBS and FSB (e.g., revisions to the principles of sound management of Operational risks,
Framework for Internal Control Systems in Banking Organizations, the internal audit function in
banks, the compliance functions in banks and so on).
This guideline provides guidance on the management of the major risks that financial institutions
may face, namely: Credit Risk, Liquidity Risk, Operational Risk, Market Risk, Interest Rate Risk,
Technology Risk and Climate Risk. However, financial institutions may, if deemed necessary, apply
the guideline to all other risks that they are exposed to, in addition to the risks mentioned in the
document.
1.2.2 Objectives
In publishing this guideline, the objectives of the Nepal Rastra Bank are:
a) To promote better risk culture at all levels of the financial institution.
b) To provide minimum standards for risk management practices.
c) To improve the financial soundness of individual financial institutions and the stability of the
overall financial sector.
d) To encourage financial institutions to adopt and implement a sound risk management
framework.
e) To introduce important risk management tools and techniques for assessment and necessary
treatment of various risks.
1.3 Dimensions of Risk Management
1.3.1 Risk Culture
Every financial institution should develop an integrated and institution-wide risk culture, based on a
full understanding of the risks it faces and how they are managed, considering risk tolerance and
appetite. Since the business of financial institutions involves risk taking, it is fundamental that risks
are appropriately managed. A sound and consistent risk culture throughout a financial institution is a
key element of effective risk management. An institution will develop its risk culture through policies,
examples, communication, and training of staff regarding their responsibilities for risk and every
member of the financial institution should be fully aware of his or her responsibility regarding risk
management. Additionally, risk management should not be confined to risk specialists or to control
functions only. Business and operational units should be primarily responsible for managing risk on a
day-to-day basis, and should consider risk tolerance and risk appetite (according to the format as
specified in the Annexure of the Guideline), in line with the financial institution’s risk policies and
procedures.
Risk culture and its impact on effective risk management must be a major concern for the board and
senior management. A sound risk culture encourages effective risk management, promotes sound risktaking and ensures that risk-taking activities beyond the institution’s risk appetite are recognized,
assessed, reported, and addressed in a timely manner. Weaknesses in setting the risk culture are often
the root cause of the occurrence of significant risk events, financial institution failures, and financial
crises.
The Board of Directors (BoD) of the institution sets the tone for the desired risk culture. The risk
culture can be strengthened through:
2
a) Enabling an open and respectful atmosphere in which employees feel encouraged to speak up
when observing new or excessive risks;
b) Clarifying the range of acceptable risks using an embedded risk appetite statement and various
forms of communication and training; and
c) Aligning incentives with objectives and clarifying how breaches of policies/procedures will
be addressed.
1.3.2 Risk Strategy and Risk Appetite
Risk tolerance and risk appetite are terms often used interchangeably: Risk appetite means the
aggregate level and types of risk a financial institution is willing to assume within its risk capacity
to achieve its strategic objectives and business plan; risk appetite describes the absolute risks a
financial institution is a priori open to take; while risk tolerance relates to the actual limits within its
risk appetite that a financial institution pursues.
A financial institution’s strategy details the long-term, and in some cases, short-term goals and
objectives, as well as how progress toward their achievement is measured. Along with business goals,
the financial institution must have risk goals and risk strategies that enable it to achieve the desired
risk profile.
The board of directors sets the strategies and senior management is responsible for implementing those
strategies and communicating them throughout the organization. The risk appetite statement plays an
important role in cascading the risk strategy throughout the institution. It includes metrics and
indicators concerning specifi…
Source: National Portal of Nepal
DigiNepal mirrors public notices for easier reading. DigiNepal is independent and is not affiliated with or endorsed by the publisher. Check the original source for the official record.
