Our approach is to proactively identify, evaluate,
and mitigate risks to ensure stability.
The Organizational Risk Management Policy at Kapital Bank OJSC is guided by the Law on Banks of the Republic of Azerbaijan, Corporate Governance Standards for Banks, as well as the Regulation on Operational Risk Management in Banks of the Central Bank of the Republic of Azerbaijan, relevant documents of the Basel Committee, and other international standards and principles.
This policy ensures the effective risk management within the strategic and business framework of the Bank and provides a holistic and comprehensive approach to risk management. The policy aligns with the Bank's approved risk limits, the Risk Appetite Statement, and the Bank's business strategy. All risks within the Bank are managed according to this Policy.
There are two main objectives of adopting the Risk Management Policy:
Create an environment that encourages the risk identification and their effective and efficient management, while utilizing potential opportunities for development and innovation.
Develop a risk culture that allows for effective management of uncertainties and challenges, covering all Bank operations.
By adopting and adhering to a forward-looking and methodical approach to risk management, the Bank protects itself from potential uncertainties, ensuring its long-term operations, stability, and prosperity.
To identify risks at the Enterprise Level, the Bank develops a long list of risks and assesses their materiality in its operations. The material risks identified by the Bank are as follows:
Credit risk — the risk arising from the possibility of a borrower or counterparty failing to meet its contractual obligations.
In order to manage credit risks, the Bank analyzes its portfolio using specialized tools:
• Risk-exposed portfolio;
• Expected loss (EL) and its components;
• Vintage analysis;
• Stress testing models;
• Scenario analysis / “What-if?” analysis;
• Transition matrices;
• Monitoring system analysis;
• Retrospective modeling and forecasting;
• Special provisions are created to cover potential losses on assets (based on IFRS and CBA standards).
Market risk — the risk that may arise due to changes in interest rates, exchange rates, and prices of securities and banking products in the financial market.
• Foreign exchange risk: the risk of financial losses for the Bank related to changes in the foreign currency exchange rates.
• Interest rate risk: the risk of financial losses for the Bank related to adverse changes in the present value of securities and derivative financial instruments due to changes in the market interest rates.
• Market volatility risk: the risk of sharp and rapid fluctuations in the prices of financial assets over a short period of time.
• Credit spread risk: the risk of loss of profit or economic value due to changes in the credit spreads on instruments held in non-trading “books”.
In order to manage market risks, the Bank carries out the following activities:
• The potential changes in the economy and banking sector are studied and their possible impact on credit, asset and liability management are determined;
• The interest rate risk, changes in interest rates and/or breaches of assumed volatility are assessed:
• Economic value of equity approach;
• Net interest income approach;
• Repricing gap analysis is performed;
• Investment risks: the changes in the value of equities and bonds, yield curves, etc. are evaluated, and the value at risk driven by market risks of securities is calculated;
• The potential adverse impacts of market risks on financial institutions are assessed;
• The impact of risks arising from changes in exchange rates and commodity prices on the Bank’s assets is assessed;
• The stress testing is performed;
• The scenario analysis is performed, etc.
Liquidity risk — the risk of the inability to timely and effectively fulfill planned and unforeseen obligations, attract additional liquid funds, as well as a reduction in the ability to immediately realize the Bank’s assets with minimal losses.
The Bank manages liquidity risk in the following ways:
• The liquidity risk management methods and models are selected and applied;
• The risk indicators reflecting internal and external risk drivers are analysed;
• Liquidity stress testing and shock event analysis are performed;
• The funding concentration is determined;
• The quick ratio, liquidity coverage ratio, net stable funding ratio, and other indicators are calculated and analysed;
• The maturity profiles and liquidity gaps are analysed;
• The liquidity and payments by currency are analysed, etc.
Concentration risk — the risk of losses associated with uneven distribution of exposures across major counterparties and groups of counterparties, economic sectors, or geographic regions.
Capital adequacy risk — the risk of the Bank’s inability to meet its obligations in the long term.
Operational risk — the risk of losses resulting from inadequate or failed internal processes, people, systems, or external events.
• Risk of errors in internal control processes: the risk arising from deficiencies and violations in the internal control system, including breaches of internal rules for executing transactions and operations.
• Operational risk of payment system: Risk of providing payment infrastructure services that do not meet the requirements for the provision of services as a result of the appearance of failures, failures and accidents in the work of information and technological systems, shortcomings in the organization and performance of technological and management processes, errors or illegal actions of personnel, or as a result of emergency situations, erroneous or illegal actions of third parties.
• External service provider risk: the risk arising from third parties (vendors, suppliers, intermediaries, etc.) that may affect the Bank’s ability to process transactions and/or provide services or result in legal liability for damages caused to third parties (e.g., customers and other stakeholders).
• Fraud risk: the risk of intentional (deliberate) unlawful (illegal) actions by any person to obtain material or non-material benefits for personal gain, as well as concealment of such actions.
• Digital fraud risk: the risk of obtaining material, non-material, or other benefits through unauthorized use of payment cards via physical, contactless, electronic, or digital channels, access to card data, fraudulent transactions, or counterfeiting of cards in physical or digital form.
• Personnel risk: the likelihood of operational disruptions, financial losses, and reputational damage due to human factors (high staff turnover, employee behavior, security errors, unethical conduct, etc.).
• Project risk: the risk arising from deficiencies and violations in the project management processes aimed at changing banking operations and operational systems.
• Legal risk: the risk of losses arising from breaches of contractual obligations by the Bank and/or its counterparties, legal errors in operations, deficiencies in the legal system, counterparties’ violations of regulations, and the presence of the Bank’s counterparties in the jurisdictions of different states.
• Data risk: the risk arising from the failure to ensure accuracy, reliability, completeness, and timely availability of risk data aggregation and usage processes.
Information security and cyber risk — the risk of material or non-material losses for the Bank due to the realization of information security threats arising from deficiencies in the information security processes, including technological and other measures, software deficiencies in computerized systems and programs, and misalignment of such processes with the Bank’s operations, as well as external attacks, vulnerabilities, and data breaches resulting from these threats targeting IT systems and data.
In order to manage information security, the Bank carries out the following activities:
• Asset management;
• Network access control;
• Access control;
• Establishing data handling rules and applying encryption requirements;
• Investigation of information security incidents, etc.
Information systems risk — the risk of malfunction and/or disruption of information systems used by the Bank and/or mismatch of their functional capabilities and characteristics with the Bank’s requirements.
Artificial intelligence risk — risks that may arise from the use of artificial intelligence models. The Bank defines artificial intelligence risk as an emerging risk and assesses its materiality.
Compliance risk — the risk of application of legal, administrative, or disciplinary sanctions to the Bank, as well as the risk of significant financial losses or reputational damage due to non-compliance with local and international laws and regulatory requirements, codes of conduct, best practice standards applicable to financial activities, or instructions of the executive body, in particular directives issued by the supervisory authority.
• AML/CFT risk: the risk of significant legal and regulatory consequences for the Bank, including fines and reputational damage, due to non-compliance with requirements of regulations on anti-money laundering and counter-terrorism financing.
• Sanction and embargo risk: the risk related to violation of laws, regulations, rules, and standards concerning sanctions that are forming a comprehensive overview of sanctions.
• Conflict of interest risk: the risk of potential or actual conflict between an employee’s personal interests and the interests of the Bank or its clients.
• Corruption and bribery risk: the risk of committing corruption offenses or offenses creating conditions for corruption.
• Data privacy risk: the risk of data breaches due to lack of proper procedures ensuring information confidentiality and internal control.
• Regulatory risk: the risk faced by the Bank due to failure or partial failure to comply with legal act and regulatory requirements governing banking and financial activities (including regulatory decisions).
• Professional ethics risk: the risk associated with ethical behavior, practices, or values, including organizational practices, employee conduct, and cultural aspects that may cause harm to internal or external stakeholders.
• Conduct risk: the risk of the Bank engaging in actions that harm consumers/investors or negatively affect market stability or competition.
Reputational risk — the current or potential risk to the Bank’s income, equity, or liquidity arising from damage to its reputation.
Model risk — the risk of model error arising from decisions based on incorrectly developed and/or applied models, or from incorrect use of model outputs and reporting, as well as model uncertainty related to the model itself and/or the uncertainty of the reality the model attempts to measure.
Strategic risk — the risk of losses arising from failures of strategic initiatives, including acquisitions, mergers, launching new products, entering new markets, etc.
Country risk — credit risk associated with a state/sovereign counterparties.
• the risk arising from a possibility that an event affecting an entire country (e.g., a natural encounter or socio-political event) can lead to default by a large group of borrowers (collective borrower risk).
• the risk associated with the cross-border lending in foreign currency and currency risks for significant cross-border lending.
ESG risk — the risk that the Bank may face due to non-compliance with environmental, social, and governance components.
To identify operational risks, the Bank shall use the following ways:
All identified risks within the Bank shall be recorded in the Risk and Control Matrix.
Risk assessment in the Bank shall be conducted on an annual basis. The assessed significant risks shall be approved by the Bank's senior management, the Supervisory Board.
Organizational risk assessment in the Bank shall be conducted through the following three approaches:
During stress testing, the Bank shall evaluate the impact of significant risks on its capital adequacy, financial and operational stability, and its potential to maintain its risk profile, operations, and development strategy. Stress tests shall be conducted at least on a biannual basis, and the results shall be submitted to Senior Management and relevant stakeholders.
After a comprehensive assessment of risks and identification of various risks that may impact the Bank, it is essential to adopt risk governance strategies to ensure the safety and sustainability of the organizational environment. When governing its risks, the Bank shall consider the approved risk limits, risk tolerance, and risk appetite. The identified and assessed risks within the Bank shall be collected and monitored in the Bank's Risk and Control Matrix (RCM).
The Bank governs the risks in 4 ways:
The main objective of risk monitoring is to ensure that the risks identified by the Bank and to which it is exposed remain within the Bank’s risk appetite and risk limits. When monitoring its risks, the Bank uses the Risk Appetite Statement, Key Risk Indicators (KRI), the Incident Management System, and the Risk and Control Matrix.
Risk reporting is the process of regularly collecting, analyzing, and presenting the risks faced by the Bank according to defined indicators, to management, regulatory bodies, and other relevant stakeholders.
The Bank prepares its overall risk profile on a monthly, quarterly, semi-annual, and annual basis and submits reports to the Chief Risk Officer, the Risk Management Committee, the Management Board, and the Supervisory Board. Also, the Bank submits the required risk-related reports to regulators.
The Senior Management of the Bank is responsible for the following tasks related to Risk Management (but not limited to):
Supervisory Board:
Risk Management Committee (RMC):
Executive Board:
Chief Risk Officer (CRO)
The three lines of defense model is used to establish a system for effective risk management and control. This model helps ensure that risks are appropriately identified, assessed, and managed while promoting transparency, accountability, and compliance with requirements.
Risk culture is a set of norms, attitudes and behaviours related to risk identification, risk acceptance and management, as well as decision-making regarding risks. Considering the Bank's risk appetite, it must foster a comprehensive understanding and holistic assessment of the risks it faces, as well as the ways in which these risks are addressed, promoting a risk culture at the organizational level.
The management of the Bank's risks shall not be limited to internal control or risk management functions. Under the management's oversight, all structural units shall be responsible for managing risks on a daily basis, considering the organization's risk appetite and risk profile, and adhering to the organization's policies, procedures, and control tools.
Therefore, the Organizational Risk Management Policy requires the creation of a sound risk culture, where all lines of defense take on only acceptable risks when making daily decisions in their operations.
The organization's risk culture, a key element of effective risk management, must be strong and sustained to ensure that the organization makes well-founded and informed decisions.
Understanding and evaluating risk culture within the Bank is crucial in identifying strengths, weaknesses, and areas for improvement. Therefore, by conducting a comprehensive assessment of the Bank's risk culture, the Bank takes steps to create a risk-aware and resilient environment, encourage making the most effective decisions in risk management, and improve overall organizational performance.
To accelerate the process of enhancing the risk culture and improving communication across defense lines, a Risk Coordinator is appointed for each structural unit. The Risk Coordinator is responsible for coordinating and overseeing risk management activities within their structural unit. Their role is to ensure the effective implementation of risk management policies, procedures, and strategies within their structural units, in line with the organization's objectives and goals.
- The Bank develops a Business Continuity Management Policy in order to minimize
financial losses, ensure uninterrupted service to customers and minimize the negative
consequences of emergency events for the strategic development of the Bank, and plan
the restoration of activities on critical functions in cases where the Bank's information
systems and information technologies are damaged, destroyed or compromised.
- In order to implement this Policy, the Bank develops Emergency Plans, which are
designed in accordance with its size, direction of activity and the volume and complexity
of its operations and are based on IT and non-IT scenarios to which the Bank is
vulnerable.
- In order to manage IT emergencies, the Bank defines steps for the warning, activation
and deactivation stages.
- Emergency Plans describe which business processes are affected by the emergency,
the extent of that impact, the distribution of roles and responsibilities and activation
processes, and the measures to be taken by the relevant structural units in the event of
an emergency.
- Emergency Plans are reviewed at least once a year when the Bank's operating
conditions change (expansion of the Bank's branch, department or representative office
network, change in the Bank's executive structure, emergence of new areas of activity
of the Bank, etc.) and in cases arising from the requirements of the legislation.
- Organizes visual, online and practical trainings within the Bank at least once a year to
increase awareness of Business Continuity Management.
- All newly hired employees participate in business continuity training.
The Crisis Management Groups for managing the business continuity process are as
follows:
• Emergency Commission
• Damage Assessment Group
• Business Recovery Group
• IT Recovery Group
• FH Communication Group
- The Bank prepares scenarios for the following non-IT emergencies:
• Damage to the Bank's premises due to fire, explosion
• Earthquake, flood, storm, natural disasters, severe weather (damage to the Bank)
• Damage to power outages
• Damage to the Bank due to pandemics and mass spread of infectious diseases
• Robbery, robbery and attack on the Bank's collection brigade
• Possible scenarios related to war, terrorist incidents, mass riots scenarios
- The Bank prepares scenarios and a Disaster Recovery Plan for the following IT
emergencies (but not limited to):
• Failure/failure of Critical Information Systems used in critical business processes
that are essential for the Bank's strategic business goals and obligations to
customers;
• Loss of availability on the Bank's Main network line;
• Complete loss of availability in the Bank's Main data center;
• Loss of availability in the Bank's Backup data center;
• Encryption of data or violation of integrity of malicious code launched from
outside or inside the information resource;
• Loss of availability of information resources as a result of DDOS or DOS attacks
launched from outside or inside the information resource;
• Occurrence of an incident resulting in loss of network connectivity between the
Head Office and the Supplier data center;
• Occurrence of an incident resulting in loss of network connectivity between the
Head Office and the Supplier data center.
- Regular tests are conducted to check the preparedness of the bank's
management and employees for emergency situations, to consolidate and
improve the skills acquired during the training process, and to improve
emergency scenarios.
- A report on the results of emergency situations testing and trials is prepared and
submitted to senior management.
- The bank draws up a Communication Plan that systematically regulates all stages of
activities during emergencies.
- The plan reflects the communication channels, their purpose of use, priority level and
responsible parties.
- For effective communication during a crisis, the internal and external audiences to
which messages are addressed are clearly defined.
- The plan is implemented based on the following principles:
• Speed and accuracy: the situation should be investigated as quickly as
possible, information should be prepared, checked, confirmed and shared
as quickly as possible;
• Transparency and accountability: information in communication should
be explained in a manner that is accurate, transparent, and maintains the
Bank's credibility, not by hiding facts.
• Single message: all communications should be made with a single tone and
message across all communication channels;
• Humanity: All communications made on behalf of the Bank should be in a manner
that preserves the Bank's credibility, while also focusing on the interests of the
customer and society;
• Learning and development: All HR practices should serve to improve
communication skills in the future. For this reason, all cases should be archived.
- During Emergency Situations, internal communication is carried out by the Bank's
Internal Communication function and the Bank's employees are informed.
- External communication regarding emergencies is carried out by providing information to
social media and the media upon the decision of the Bank's Emergency Communication
Group.
- Informing the family members of employees affected by emergencies is carried out by
the Bank's Talent Management function
This Policy shall come into effect upon its approval by the Supervisory Board of the Bank.
All structural units within the Bank are responsible for implementing this Policy in accordance with the provisions outlined in it. Together with the Bank's management, they are responsible for ensuring compliance with the provisions specified in this Policy, as well as for the periodic review and revision of the Policy.
The Bank regularly conducts an external independent assessment of its risk management practices. This is considered essential to ensure that the risk management processes function effectively and that significant risks are managed at acceptable levels.
Updated: 04.06.2026