PART 1239—RESPONSIBILITIES OF BOARDS OF DIRECTORS, CORPORATE PRACTICES, AND CORPORATE GOVERNANCE Authority: 12 U.S.C. 1426, 1427, 1432(a), 1436(a), 1440, 4511(b), 4513(a), 4513(b), 4526, and 15 U.S.C. 78 oo Source: 80 FR 72336, Nov. 19, 2015, unless otherwise noted. Subpart A—General § 1239.1 Purpose. FHFA is responsible for supervising and ensuring the safety and soundness of the regulated entities. In furtherance of those responsibilities, this part sets forth minimum standards with respect to responsibilities of boards of directors, corporate practices, and corporate governance matters of the regulated entities. § 1239.2 Definitions. As used in this part, (unless otherwise noted): Board member Board of directors Business risk Community financial institution Compensation Credit risk Employee Executive officer Immediate family member Internal auditor Liquidity risk Market risk NYSE Operational risk Risk appetite Significant deficiency Subpart B—Corporate Practices and Procedures Applicable to All Regulated Entities § 1239.3 Law applicable to corporate governance and indemnification practices. (a) General. (b) Election and designation of body of law. (i) The law of the jurisdiction in which the principal office of the regulated entity is located; (ii) The Delaware General Corporation Law (Del. Code Ann. Title 8); or (iii) The Revised Model Business Corporation Act. (2) Each regulated entity shall designate in its bylaws the body of law elected for its corporate governance and indemnification practices and procedures pursuant to this paragraph, and shall do so by no later than March 18, 2016. (c) Indemnification. (2) Each regulated entity shall have in place policies and procedures consistent with this section for indemnification of its directors, officers, and employees. Such policies and procedures shall address how the board of directors is to approve or deny requests for indemnification from current and former directors, officers, and employees, and shall include standards relating to indemnification, investigations by the board of directors, and review by independent counsel. (3) Nothing in this paragraph (c) shall affect any rights to indemnification (including the advancement of expenses) that a director or any other officer or employee had with respect to any actions, omissions, transactions, or facts occurring prior to the effective date of this paragraph. (4) FHFA has the authority under the Safety and Soundness Act to review a regulated entity's indemnification policies, procedures, and practices to ensure that they are conducted in a safe and sound manner, and that they are consistent with the body of law adopted by the board of directors under paragraph (b) of this section. (d) No rights created. § 1239.4 Duties and responsibilities of directors. (a) Management of a regulated entity. (b) Duties of directors. (1) Carry out his or her duties as director in good faith, in a manner such director believes to be in the best interests of the regulated entity, and with such care, including reasonable inquiry, as is required under the Revised Model Business Corporation Act or the other body of law that the entity's board of directors has chosen to follow for its corporate governance and indemnification practices and procedures in accordance with § 1239.3(b); (2) For Bank directors, administer the affairs of the regulated entity fairly and impartially and without discrimination in favor of or against any member institution; (3) At the time of election, or within a reasonable time thereafter, have a working familiarity with basic finance and accounting practices, including the ability to read and understand the regulated entity's balance sheet and income statement and to ask substantive questions of management and the internal and external auditors; (4) Direct the operations of the regulated entity in conformity with the requirements set forth in the authorizing statutes, the Safety and Soundness Act, and this chapter; and (5) Adopt and maintain in effect at all times bylaws governing the manner in which the regulated entity administers its affairs. Such bylaws shall be consistent with applicable laws and regulations administered by FHFA, and with the body of law designated for the entity's corporate governance practices and procedures in accordance with § 1239.3(b). (c) Director responsibilities. (1) The risk management and compensation programs of the regulated entity; (2) The processes for providing accurate financial reporting and other disclosures, and communications with stockholders; and (3) The responsiveness of executive officers in providing accurate and timely reports to FHFA and in addressing all supervisory concerns of FHFA in a timely and appropriate manner. (d) Authority regarding staff and outside consultants. (2) The board of directors and its committees may require that staff of the regulated entity that provides services to the board or any committee under paragraph (d)(1) of this section report directly to the board or such committee, as appropriate. § 1239.5 Board committees. (a) General. (b) Required committees. (c) Charter. (d) Frequency of meetings. Subpart C—Other Requirements Applicable to All Regulated Entities § 1239.10 Code of conduct and ethics. (a) General. (b) Review. § 1239.11 Risk management. (a) Risk management program Adoption. (2) Risk appetite. (3) Risk management program requirements. (i) Risk limitations appropriate to each business line of the regulated entity; (ii) Appropriate policies and procedures relating to risk management governance, risk oversight infrastructure, and processes and systems for identifying and reporting risks, including emerging risks; (iii) Provisions for monitoring compliance with the regulated entity's risk limit structure and policies relating to risk management governance, risk oversight, and effective and timely implementation of corrective actions; and (iv) Provisions specifying management's authority and independence to carry out risk management responsibilities, and the integration of risk management with management's goals and compensation structure. (b) Risk committee. (1) Committee structure. (i) Be chaired by a director not serving in a management capacity of the regulated entity; (ii) Have at least one member with risk management experience that is commensurate with the regulated entity's capital structure, risk appetite, complexity, activities, size, and other appropriate risk-related factors; (iii) Have committee members that have, or that will acquire within a reasonable time after being elected to the committee, a practical understanding of risk management principles and practices relevant to the regulated entity; (iv) Fully document and maintain records of its meetings, including its risk management decisions and recommendations; and (v) Report directly to the board and not as part of, or combined with, another committee. (2) Committee responsibilities. (i) Periodically review and recommend for board approval an appropriate enterprise-wide risk management program that is commensurate with the regulated entity's capital structure, risk appetite, complexity, activities, size, and other appropriate risk-related factors; (ii) Receive and review regular reports from the regulated entity's chief risk officer, as required under paragraph (c)(5) of this section ; and (iii) Periodically review the capabilities for, and adequacy of resources allocated to, enterprise-wide risk management. (c) Chief Risk Officer. Appointment of a chief risk officer (CRO). (2) Organizational structure of the risk management function. (3) Responsibilities of the CRO. (i) Allocating risk limits and monitoring compliance with such limits; (ii) Establishing appropriate policies and procedures relating to risk management governance, practices, and risk controls, and developing appropriate processes and systems for identifying and reporting risks, including emerging risks; (iii) Monitoring risk exposures, including testing risk controls and verifying risk measures; and (iv) Communicating within the organization about any risk management issues and/or emerging risks, and ensuring that risk management issues are effectively resolved in a timely manner. (4) The CRO should have risk management expertise that is commensurate with the regulated entity's capital structure, risk appetite, complexity, activities, size, and other appropriate risk related factors. (5) The CRO shall report regularly to the risk committee and to the chief executive officer on significant risk exposures and related controls, changes to risk appetite, risk management strategies, results of risk management reviews, and emerging risks. The CRO shall also report regularly on the regulated entity's compliance with, and the adequacy of, its current risk management policies and procedures, and shall recommend any adjustments to such policies and procedures that he or she considers necessary or appropriate. (6) The compensation of a regulated entity's CRO shall be appropriately structured to provide for an objective and independent assessment of the risks taken by the regulated entity. § 1239.12 Compliance program. A regulated entity shall establish and maintain a compliance program that is reasonably designed to assure that the regulated entity complies with applicable laws, rules, regulations, and internal controls. The compliance program shall be headed by a compliance officer, however styled, who reports directly to the chief executive officer. The compliance officer also shall report regularly to the board of directors, or an appropriate committee thereof, on the adequacy of the entity's compliance policies and procedures, including the entity's compliance with them, and shall recommend any revisions to such policies and procedures that he or she considers necessary or appropriate. § 1239.13 Regulatory reports. (a) Reports. (b) Definition. Regulatory Report (1) Provision in the Bank Act, Safety and Soundness Act, or other law, order, rule, or regulation; (2) Condition imposed in writing by FHFA in connection with the granting of any application or other request by a regulated entity; or (3) Written agreement entered into between FHFA and a regulated entity. § 1239.14 Strategic business plan. (a) Adoption of strategic business plan. (1)(i) In the case of a Bank, articulate measurable goals and objectives for each significant business activity and for all authorized new business activities, which must include plans for maximizing activities that further the Bank's housing finance and community lending mission, consistent with part 1265 of this chapter; (ii) In the case of an Enterprise, articulate measurable goals and objectives for each significant existing activity and for significant authorized new activities; (2) Discuss how the regulated entity will address credit needs and market opportunities identified through ongoing market research and stakeholder consultations; (3) Describe any significant activities in which the regulated entity is planning to be engaged, including any significant changes to business strategy or approach that the regulated entity is planning to undertake, and discuss how such activities would further the regulated entity's mission and public purposes; (4)(i) In the case of a Bank, be supported by appropriate and timely research and analysis of relevant market developments and member and housing associate demand for Bank products and services; (ii) In the case of an Enterprise, be supported by appropriate and timely research and analysis of relevant market developments; and (5) Identify current and emerging risks associated with the regulated entity's significant existing activities or new activities, and discuss how the regulated entity plans to address such risks while furthering its public purposes and mission in a safe and sound manner. (b) Review and monitoring. (1) Review the regulated entity's strategic business plan at least annually; (2) Re-adopt the strategic business plan for the regulated entity at least every three years; and (3) Establish management reporting requirements and monitor implementation of the strategic business plan and the goals and objectives contained therein. [83 FR 52954, Oct. 19, 2018] Subpart D—Enterprise Specific Requirements § 1239.20 Board of directors of the Enterprises. (a) Membership Limits on service of board members. General requirement. (ii) Waiver. (2) Independence of board members. (3) Segregation of duties. (b) Meetings, quorum and proxies, information, and annual review Frequency of meetings. (2) Non-management board member meetings. (3) Quorum of board of directors; proxies not permissible. (4) Information. (5) Annual review. § 1239.21 Compensation of Enterprise board members. Each Enterprise may pay its directors reasonable and appropriate compensation for the time required of them, and their necessary and reasonable expenses, in the performance of their duties. Subpart E—Bank Specific Requirements § 1239.30 Bank member products policy. (a) Adoption and review of member products policy Adoption. (2) Review and compliance. (i) Review the Bank's member products policy annually; (ii) Amend the member products policy as appropriate; and (iii) Re-adopt the member products policy, including interim amendments, not less often than every three years. (b) Member products policy requirements. (1) Address credit underwriting criteria to be applied in evaluating applications for advances, standby letters of credit, and renewals; (2) Address appropriate levels of collateralization, valuation of collateral and discounts applied to collateral values for advances and standby letters of credit; (3) Address advances-related fees to be charged by each Bank, including any schedules or formulas pertaining to such fees; (4) Address standards and criteria for pricing member products, including differential pricing of advances pursuant to § 1266.5(b)(2) of this chapter, and criteria regarding the pricing of standby letters of credit, including any special pricing provisions for standby letters of credit that facilitate the financing of projects that are eligible for any of the Banks' CICA programs under part 1292 of this chapter; (5) Provide that, for any draw made by a beneficiary under a standby letter of credit, the member will be charged a processing fee calculated in accordance with the requirements of § 1271.6(b) of this chapter; (6) Address the maintenance of appropriate systems, procedures, and internal controls; and (7) Address the maintenance of appropriate operational and personnel capacity. § 1239.31 [Reserved] § 1239.32 Audit committee. (a) Establishment. (b) Composition. (2) The audit committee shall include, to the extent practicable, a balance of representatives of: (i) Community financial institutions and other members; and (ii) Independent directors and member directors of the Bank, both as defined in the Bank Act. (3) The terms of audit committee members shall be appropriately staggered so as to provide for continuity of service. (4) At least one member of the audit committee shall have extensive accounting or related financial management experience. (c) Independence. (1) Being employed by the Bank in the current year or any of the past five years; (2) Accepting any compensation from the Bank other than compensation for service as a board director; (3) Serving or having served in any of the past five years as a consultant, advisor, promoter, underwriter, or legal counsel of or to the Bank; or (4) Being an immediate family member of an individual who is, or has been in any of the past five years, employed by the Bank as an executive officer. (d) Charter. (2) The board of directors of each Bank shall review and assess the adequacy of the audit committee charter on an annual basis, shall amend the audit committee charter whenever it deems it appropriate to do so, and shall reapprove the audit committee charter not less often than every three years; and (3) Each Bank's audit committee charter shall: (i) Provide that the audit committee has the responsibility to select, evaluate and, where appropriate, replace the internal auditor and that the internal auditor may be removed only with the approval of the audit committee; (ii) Provide that the internal auditor shall report directly to the audit committee on substantive matters and that the internal auditor is ultimately accountable to the audit committee and board of directors; (iii) Provide that the audit committee shall be directly responsible for the appointment, compensation, retention, and oversight of the work of the external auditor; (iv) Provide that the external auditor shall report directly to the audit committee; (v) Provide that both the internal auditor and the external auditor shall have unrestricted access to the audit committee without the need for any prior management knowledge or approval; and (vi) Provide that the Bank shall make available appropriate funding, as determined by the audit committee, for payment of compensation to the external auditor, to any independent advisors or counsel engaged by the audit committee, and ordinary administrative expenses that are necessary or appropriate for the audit committee to carry out its duties. (e) Duties. (1) Direct senior management to maintain the reliability and integrity of the accounting policies and financial reporting and disclosure practices of the Bank; (2) Review the basis for the Bank's financial statements and the external auditor's opinion rendered with respect to such financial statements (including the nature and extent of any significant changes in accounting principles or the application thereof) and ensure that policies are in place that are reasonably designed to achieve disclosure and transparency regarding the Bank's true financial performance and governance practices; (3) Oversee the internal audit function by: (i) Reviewing the scope of audit services required, significant accounting policies, significant risks and exposures, audit activities, and audit findings; (ii) Assessing the performance and determining the compensation of the internal auditor; and (iii) Reviewing and approving the internal auditor's work plan. (4) Oversee the external audit function by: (i) Approving the external auditor's annual engagement letter; and (ii) Reviewing the performance of the external auditor. (5) Provide an independent, direct channel of communication between the Bank's board of directors and the internal and external auditors; (6) Conduct or authorize investigations into any matters within the audit committee's scope of responsibilities; (7) Ensure that senior management has established and is maintaining an adequate internal control system within the Bank by: (i) Reviewing the Bank's internal control system and the resolution of identified material weaknesses and significant deficiencies in the internal control system, including the prevention or detection of management override or compromise of the internal control system; and (ii) Reviewing the programs and policies of the Bank designed to ensure compliance with applicable laws, regulations and policies, and monitoring the results of these compliance efforts; (8) Review the policies established by senior management to assess and monitor implementation of the Bank's strategic business plan and the operating goals and objectives contained therein; (9) Report periodically its findings to the Bank's board of directors; and (10) Establish procedures for the receipt, retention, and treatment of complaints received by the Bank regarding accounting, internal accounting controls, or auditing matters, and for the confidential, anonymous submission by employees of the Bank of concerns regarding questionable accounting or auditing matters. (f) Meetings. [80 FR 72336, Nov. 19, 2015, as amended at 81 FR 76295, Nov. 2, 2016] § 1239.33 Dividends. A Bank's board of directors may not declare or pay a dividend based on projected or anticipated earnings and may not declare or pay a dividend if the par value of the Bank's stock is impaired or is projected to become impaired after paying such dividend.