Kathmandu. The Nepal Rastra Bank (NRB) has implemented the ‘Risk Management Guidance, 2026’ to make the risk management of banks and financial institutions more effective. The Nepal Rastra Bank (NRB) has implemented the ‘Risk Management Directive, 2026’ with the objective of further strengthening the risk management system of banks and financial institutions.
The new directive has widened the scope of risk management by incorporating the technical, climate and systemic risks seen in the banking sector in recent times.
The new directive has replaced the provisions related to risk management issued by the Rastra Bank in 2018. In view of the rapid expansion of digital technology, cybercrime, climate change and uncertainty in the global economy, banks have to systematically manage new types of risks along with traditional risks.
The new directive has further clarified the responsibility of identifying, evaluating, monitoring and mitigating risks on banks and financial institutions. The role of the Board of Directors in risk management should be strengthened and the concept of ‘Three Lines of Defence’ should also be institutionalized.
The new guidelines consider the risks posed by climate change as significant financial risks in the banking sector. Banks will have to take into account the direct impact of natural disasters such as floods, landslides, droughts to the impact on business due to the transition to a low-carbon economy.
For this, banks and financial institutions will have to form a ‘Climate Risk Committee’. The committee will meet at least quarterly to review climate risk issues and make recommendations to the board of directors on necessary policies and strategies.
Banks will have to assess the climate risk while investing loans in sectors that are most vulnerable to climate change, especially in agriculture, hydropower and infrastructure. It also provides for annual stress testing in various scenarios to test the impact of potential risks.
Similarly, the directive has also tightened technology risk management to address the increasing cyber risk with the expansion of digital banking. Banks should arrange a Security Operation Center (SOC) to continuously monitor cyber risks and a Cyber Security Incident Response Team (CIRT) to respond immediately in case of a cyber attack.
The bank will have to determine the downtime limit of how long mobile and other digital banking services can be blocked due to technical problems. The recovery time objective (RTO) will also have to specify the time within which the service and data will be restored and retrieved in the event of a problem in the system, and the same should be reported to the Rastra Bank. While the use of AI and machine learning is increasing, banks will also have to pay attention to the aspects of risk, transparency, security and responsible use while using such technology.
The new guidelines have also made credit risk management more systematic. Debt rescheduling or restructuring cannot be used as a means of prolonging problematic loans. While restructuring a loan, the clear reason, business feasibility and actual condition of the borrower should be assessed. Such a decision has to be approved by the Board of Directors or the competent authority.
The provisions related to Expected Credit Loss (ECL) under NFRS-9 will have to be followed for loan loss management. Banks should also set up a separate recovery unit as per the requirement to make the recovery of problematic loans effective.
Similarly, a separate risk management department has been set up to make risk management within the bank more independent. The directive provides that the department should be kept away from the direct influence of the management and business expansion unit.
The Chief Risk Officer (CRO) who heads the risk management department will have access to the Board of Directors and the Risk Management Committee. This is expected to strike the necessary balance between the expansion of the bank’s business and risk control.
Similarly, the Rastra Bank has also clarified the provisions related to the transfer and responsibility of the employees working in the internal audit to strengthen the internal control system of the bank. According to the directive, the employees of the internal audit department should generally not be transferred for less than 2 to 3 years and the same person should not be kept in the same responsibility for more than 5 to 7 years.
The guidelines also cover the operational and human resource risks that may arise after the merger or acquisition of banks and financial institutions. Institutions that are jointly operated after merger and acquisition will not be allowed to discriminate between the employees of the existing institutions. The principle of equality and non-discrimination should also be adopted in the case of employee cuts, voluntary retirement schemes (VRS), service facilities and career development opportunities.
The NRB has also given priority to the use of modern technology in the risk identification and monitoring related to Money Laundering and Prevention of Terrorist Financing (AML÷CFT). Banks should not rely only on traditional systems but also develop the capacity to identify unusual transactions and potential risks using machine learning, AI and other modern technologies.
Similarly, the provisions related to liquidity management have also been further clarified by the Rastra Bank so that the regular transactions of the bank are not affected in the event of a sudden liquidity shortage in the market. Banks will have to prepare their liquidity management strategy while maintaining sufficient high quality liquid assets. Long-term liquidity plans should be made keeping in mind indicators such as Liquidity Coverage Ratio (LCR) and Net Stable Funding Ratio (NSFR).
Similarly, in case of an emergency liquidity crisis, banks will have to prepare a ‘Contingency Funding Plan’ covering how to conduct their business. The new guidelines also provide for regular testing of such schemes.






प्रतिक्रिया दिनुहोस्