PFRDA circular PFRDA/2024/04/Sup-CRA/01 · 21 Feb 2024
Official title
Risk Management Framework for the Central Recordkeeping Agencies (CRAs) under NPS architecture
Summary
Check the official recordThe Pension Fund Regulatory and Development Authority (PFRDA) has mandated that all registered Central Recordkeeping Agencies (CRAs) under the National Pension System (NPS) architecture must design, develop, and implement a comprehensive Risk Management Framework. This framework aims to ensure high service standards, protect subscriber interests, and mitigate operational, fraud, and legal risks. CRAs are required to establish a Risk Management Committee, adopt robust internal controls, and implement specific security measures, including cyber-resilience protocols and fraud prevention mechanisms. CRAs must submit their developed framework to the Authority within 120 days of the circular's issuance. The framework must be reviewed annually and incorporate principles from the National Critical Information Infrastructure Protection Centre and the Digital Personal Data Protection Act, 2023.
What you must do
Key dates
Who is affected
Exceptions
If you do not comply
Circular No: PFRDA/2024/04/Sup-CRA/01 Date: 21st February 2024
To / प्रति The CEOs of the registered CRAs/ पजं ीकृत सीआरए के सीईओ
Subject: Risk Management Framework for the Central Recordkeeping Agencies (CRAs) under NPS architecture विषय: एनपीएस स्थापत्य के अंिर्गि कें द्रीय अभिलेखपाल अभिकरणों (सीआरए) हेिुजोखिम प्रबंधन ढांचा
This circular is issued in exercise of powers conferred under Sec 14(1) read with Sec 14(2) clause (e) of the Pension Fund Regulatory and Development Authority Act, 2013 and Regulation 26(2)(c) of PFRDA (Central Recordkeeping Agency) Regulations, 2015.
यह पररपत्र, पेंशन तिधि वितियामक और विकास प्राधधकरण अधधननयम, 2013 की धारा 14(1) के साथ पठित िारा 14(2) िंड (ङ) और पीएफआरडीए (कें द्रीय अभिलेखपाल अभिकरण) विननयम, 2015 के विननयम 26(2)(र्) के अंिर्गि प्रदत्त शक्ततयों का प्रयोग करतेहुए जारी ककया गया है।
In order to ensure that the CRAs render, at all times, high standards of service, exercise due diligence, ensure proper care in their operations and protect the interests of subscribers in terms of Section 14 (2) (e) of the PFRDA Act, 2013, PFRDA hereby lays down, the following Risk Management Framework as per Annexure I for the guidance of the CRAs and to be designed, developed and implemented by them.
यह सनुनक्चचत करनेके लिए कक, पीएफआरडीए अधधननयम, 2013 की धारा 14(2)(ङ) के अिरूु प, सीआरए द्िारा सेिा केउच्च मानक सदैि प्रदान ककए जाएं, उधचत पररश्रम ककया जाए, उिके संचाििों में उधचत साििािी बरिी जाए और अभिदािाओं के ठहतों का संरक्षण ककया जाए, पीएफआरडीए एतद्दद्दिारा सीआरए के मागगदशगन केलिए अनिु ग्नक I के अनसु ार तिम्िािसु ार जोखिम प्रबंधन ढांचा ननधागररत करता है, जजसे सीआरए द्िारा संरधिि, विकलसत और कायागक्वित ककया जािा है।
The risk management framework emphasizes on the importance of internal control systems, procedures and safeguards to be built into the CRA systems for safeguarding the interests of the subscribers.
यह जोखिम प्रबंधन ढांचा, अभिदािाओं के ठहतों के संरक्षण के लिए सीआरए प्रणालियों में तिभमगि ककए जािे िाले आंतररक ननयंत्रण प्रणालियों, प्रकियाओं और सरुक्षा उपायों के महत्त्ि पर बल देता है।
The risk management framework to be developed by the CRAs as envisaged under this circular shall be submitted to the Authority within 120 days from the date of the issuance of this circular. Any exception to the timelines stipulated shall be supported with cogent reasons and with prior approval of the Authority.
सीआरए द्दिारा विकलसत ककया जाने िािा जोखिम प्रबंधन ढांचा, जो इस पररपत्र के अंिर्गि पररकक्पपत है, को इस पररपत्र के जारी होनेकी तिधथ से120 ठदनों के भीतर प्राधधकरण मेंप्रस्ततु करिा होर्ा। इस ननधागररत समय-सीमा मेंककसी भी अपिाद को िोस कारणों और प्राधधकरण के पिू गअनमु ोदन के साथ रखा जाएगा।
This circular is issued with the approval of the Competent Authority.
यह पररपत्र सक्षम प्राधिकारी केअनमु ोदन सेजारी ककया र्या है।
(K Mohan Gandhi) Chief General Manager
Annexure- I/अनलु ग्नक I
[Image omitted. See the official document.]
RISK MANAGEMENT FRAMEWORK FOR CENTRAL RECORDKEEPING AGENCIES (CRAs)
Ver 1 dt 21st Feb 2024
Page 1 of 15
Table of Contents
Definitions ............................................................................................................................. 3 Framework and Applicability ................................................................................................ 3 Objective of the Risk Management Framework .................................................................... 4 Risk Management Framework: ............................................................................................ 4 Governance and organisation ............................................................................................ 5 Operational Risk Management Policy ................................................................................ 6 Risk Assessment and Control ............................................................................................ 8
Page 2 of 15
RISK MANAGEMENT FRAMEWORK FOR CRAs
Definitions
For the purposes of this risk management framework, the following definitions shall apply:
‘Cyber risk’ includes any reasonably identifiable circumstance in relation to the use of network and information systems, - including a malfunction, capacity overrun, failure, disruption, impairment, misuse, loss or other type of malicious or non-malicious event - which, if materialised, may compromise the security of the network and information systems, of any technology-dependant tool or process, of the operation and process’ running, or of the provision of services, thereby compromising the integrity or availability of data, software or any other component of ICT services and infrastructures, or causing a breach of confidentiality, a damage to physical ICT infrastructure or other adverse effects;
‘Cyber incident’ includes an unforeseen identified occurrence in the network and information systems, whether resulting from malicious activity or not, which compromises the security of network and information systems, of the information that such systems process, stores or transmits, or has adverse effects on the availability, confidentiality, continuity or authenticity of financial services provided by the CRA;
‘Cyber-attack’ means a malicious cyber incident by means of an attempt to destroy, expose, alter, disable, steal or gain unauthorized access to or make unauthorized use of an asset perpetrated by any threat actor;
‘Information and communication technology (ICT)’ risk means the current or prospective risk of losses due to the inappropriateness or failure of the hardware and software of technical infrastructures, which may compromise the availability, integrity, accessibility and security of such infrastructures and of data.
‘Vulnerability’ means a weakness, susceptibility or flaw of an asset, system, process or control that can be exploited by a threat;
A. Framework and Applicability
The Risk Management Framework shall be applicable to all registered Central Recordkeeping Agencies (CRAs) registered with the Authority.
Risk Management Framework for CRAs is an approach to managing risks associated with the operations of CRAs in a measured and a fair measure of reasonableness. The purpose of the framework is to ensure that the operations do not result in any deficiencies in service to customers, prevention of fraud, disruption, or any issues effecting the integrity of recordkeeping, accounting, administration functions of the CRAs, to the extent possible.
As part of the overall risk management framework, a CRA shall adopt best governance practices for risk management in the discharge of its functions and shall constitute a Risk Management Committee for better management of risks emanating from the operations being carried out. The Board of CRA shall constitute such a committee preferably with internal and external specialists who have knowledge of recordkeeping functions or IT systems or audit and accounting or any other related field. The Risk Management Committee shall draw up a Risk Management Policy and place the same before its Board for its approval.