PART 653—FEDERAL AGRICULTURAL MORTGAGE CORPORATION RISK MANAGEMENT Authority: Secs. 8.3, 8.4, 8.6, 8.8, and 8.10 of Pub. L. 92-181, 85 Stat. 583 (12 U.S.C. 2279aa-3, 2279aa-4, 2279aa-6, 2279aa-8, and 2279aa-10). Source: 81 FR 49154, July 27, 2016, unless otherwise noted. § 653.1 Definitions. The following definitions apply to this part: Corporation FCA OSMO § 653.2 General. The Corporation's board of directors must approve the overall risk-appetite of the Corporation and regularly monitor internal controls to provide reasonable assurance that risk-taking activities are conducted in a safe and sound manner. § 653.3 Risk management. (a) Risk management program. (1) Periodically assess and document the Corporation's risk profile. (2) Align the Corporation's risk profile with the board-approved risk appetite and the Corporation's operational planning strategies and objectives. (3) Specify management's authority to carry out risk management responsibilities. (4) Integrate risk management and control objectives into management goals and compensation structures. (5) Comply with all applicable FCA regulations and policies. (b) Risk committee. (1) The risk committee must have at least one member with an understanding of risk management commensurate with the Corporation's capital structure, risk profile, complexity, activities, size, and other appropriate risk-related factors. (2) The responsibilities of the risk committee include, but are not limited to: (i) Periodically assessing management's implementation of the enterprise-wide risk management program; (ii) Recommending changes to the risk management program to keep the program commensurate with the Corporation's capital structure, risk appetite, complexity, activities, size, and other appropriate risk-related factors; and (iii) Receiving and reviewing regular reports directly from personnel responsible for implementing the Corporation's risk management program. (c) Management of risk. (1) Identifying and monitoring compliance with risk limits, exposures, and controls; (2) Implementing risk management policies, procedures, and risk controls; (3) Developing appropriate processes and systems for identifying and reporting risks, including emerging risks; (4) Reporting on risk management issues, emerging risks, and compliance concerns; and (5) Making recommendations on adjustments to the risk management policies, procedures, and risk controls of the Corporation. § 653.4 Internal controls. (a) The Corporation's board of directors must adopt an internal controls policy that provides adequate directions for, and identifies expectations in, establishing effective safety and soundness control over, and accountability for, the Corporation's operations, programs, and resources. (b) The internal controls system must address: (1) The efficiency and effectiveness of the Corporation's activities; (2) Safeguarding the assets of the Corporation; (3) Evaluating the reliability, completeness, and timely reporting of financial and management information; (4) Compliance with applicable laws, regulations, regulatory directives, and the policies of the Corporation's board of directors and senior management; (5) The appropriate segregation of duties among the Corporation personnel so that personnel are not assigned conflicting responsibilities; and (6) The completeness and quality of information provided to the Corporation's board of directors. (c) The Corporation is responsible for establishing and implementing an effective system to identify internal controls weaknesses and taking action to correct detected weaknesses. The Corporation must document: (1) The process used to identify weaknesses, (2) Any found weaknesses, and (3) How identified weaknesses were addressed.