Techno Time

Central Bank Sets Governance and Control Rules for Credit Guarantee Companies

Thursday 24 September 2026 16:44
Central Bank Sets Governance and Control Rules for Credit Guarantee Companies

The Central Bank of Egypt has introduced broad governance, internal control, risk management and information security requirements for credit guarantee companies, requiring independent control functions, defined board structures and committees, stronger disclosure rules, cybersecurity safeguards and compliance with anti-money laundering requirements.

Board and Governance Requirements

Credit guarantee companies must establish an effective governance framework defining the relationship between the board, senior management, shareholders and stakeholders, as well as their respective responsibilities. The framework must cover corporate strategy, employee appointment and performance policies, internal controls, internal audit, compliance, risk management, information and cybersecurity, succession planning and workforce development.

Board membership must be appropriate to the company’s size and activities, with due consideration for female representation. Executive directors may not exceed two, while the board must include at least two independent non-executive directors. Independence is restricted where a candidate worked for the company or related parties during the previous three years, holds relevant interests or relationships, has conflicts affecting impartiality, or has served on the board for more than six years.

The chairperson may not simultaneously serve as chief executive officer or managing director, and their responsibilities must be formally defined. The board is responsible for approving corporate strategy, risk management, internal controls, investment, guarantee issuance, disclosure, outsourcing, business continuity and disaster recovery policies, while avoiding interference in executive management.

The board must meet at least six times a year, with actual attendance at no fewer than four meetings. Participation by video or telephone is permitted under specified controls. The board must also conduct evaluations of its overall performance, its committees and individual members, and establish non-executive committees covering audit, risk, governance and nominations, and remuneration.

Committees and Internal Controls

The Audit Committee must have at least three non-executive members and meet at least quarterly. It oversees the annual internal audit plan, monitors internal audit and compliance functions, reviews financial statements and examines observations from the Central Bank and external auditors.

The Risk Committee must include at least three board members, most of whom should be non-executive. It monitors risk strategies, guarantee quality, liquidity and concentration risks and reviews risk assessments at least quarterly. The Governance and Nominations Committee evaluates the governance framework, proposes independent directors and reviews succession planning, while the Remuneration Committee oversees compensation policies and links performance-based rewards to actual results.

Companies must establish independent internal audit, compliance, risk and information security functions reporting to the relevant board committees. Internal audit assesses controls, governance, risk management, compliance and information security. Compliance manages compliance risks and anti-money laundering and counter-terrorist financing requirements, while the risk function sets acceptable risk limits and oversees stress testing and business continuity.

Cybersecurity and Disclosure

Information security functions must protect and classify data, preserve its confidentiality, integrity and availability, conduct periodic penetration tests and regularly update cybersecurity policies. Companies must notify the Central Bank’s Financial Sector Computer Emergency Response Center within six hours of detecting an actual or suspected data breach, hacking incident, fraud or technological failure.

Companies must disclose board members’ qualifications, ownership and organizational structures, as well as the number of board and committee meetings. They must publish information on headquarters and branches, working hours, services and contact details on their websites and disclose their Central Bank operating licence and its date.

Accounts must be audited by an auditor registered with the Central Bank, which must be notified of the appointment within 30 days. Companies must protect confidential information, revoke access rights when employment or roles change, and retain contracts with counterparties specifying services, responsibilities, fees, payment arrangements and dispute-resolution mechanisms.