|
Guidelines for Internal Control of Commercial BanksPBOC and banking supervisor
|
Commercial banks operating in China |
Board-approved risk tolerance, control responsibilities, internal-control evaluation, internal audit, emergency arrangements and tracked correction of deficiencies. |
|
Source
|
|
Commercial Bank Law and Banking Supervision FrameworkPBOC and NFRA
|
Commercial banks and supervised banking institutions |
Prudent operations, governance, risk controls, supervisory reporting, examination evidence and corrective measures. |
|
Source
|
|
Guidelines for Governance of Listed CompaniesCSRC
|
Companies listed on Chinese securities markets |
Board and committee accountability, internal controls, risk oversight, disclosure, audit supervision and follow-up of governance issues. |
|
Source
|
|
Cybersecurity LawCAC
|
Network operators and critical information infrastructure operators within scope |
Security governance, risk controls, monitoring, incident plans, response, reporting and supply-chain oversight. |
|
Source
|
|
Rules on Data Security of Banking and Insurance InstitutionsNFRA
|
Banking and insurance institutions within the Rules’ scope |
Data-security governance, classification, risk assessment, access controls, third-party data risk, security incidents, audit and supervisory reporting. |
|
Source
|
|
Personal Information Protection LawCAC
|
Personal-information handlers within the Law’s scope |
Processing records, impact assessment, security controls, processor governance, breach response and corrective action. |
|
Source
|