CRA-6.1.10

Licensees must establish and maintain a risk management function that operates independently and which has sufficient authority and resources, including access to the Board of Directors, to facilitate the carrying out of the following tasks:

(a) The implementation of the risk management framework and maintenance of effective systems and controls referred to in Paragraph CRA-6.1.6;
(b) The provision of reports and advice to senior management;
(c) The development of the licensee's risk strategy; and
(d) Direct communication with the Board of Directors, independently from the licensee's senior management, regarding concerns, where specific risk developments affect or may affect the licensee, without prejudice to the responsibilities of the Board of Board in its supervisory and/or managerial functions.
Amended: April 2023
Added: April 2019