- Introduction
- Section I: Object and scope of application
- Compliance levels and requirements
- Section III: Operational risk management
- Section IV: Operational risk factors
- Incident and problem management
- Section V: Business continuity management
- Section VI: Third-party services
- Section VIII: Responsibilities in operational risk management
- Challenges of implementing SEPS Resolución 116
- Benefits of implementing SEPS Resolución 116
- Best practices
- Conclusion
Introduction
If your institution takes deposits from members in Ecuador, the rules for handling operational risk changed in 2024. Resolution SEPS-IGT-IGS-INSESF-INR-INGINT-INSEPS-IGJ-0116 (referred to here as SEPS Resolución 116), issued by the Superintendencia de Economía Popular y Solidaria (SEPS) and published in the Registro Oficial in July 2024, sets out how savings and credit cooperatives, housing mutual associations, central funds, and the National Corporation of Popular and Solidarity Finance (CONAFIPS) identify, measure, and control operational risk. It treats that risk as the loss you take when something fails in one of four places: people, processes, IT, or external events.
The rule replaced a 2018 resolution, and it pushed hardest on the areas where members feel a failure fastest: technology governance, incident and problem management, business continuity, and the oversight of outsourced work. Obligations track your entity's segment, so a large cooperative and a small one are not held to the same list. In practice, SEPS Resolución 116 compliance comes down to one thing: a documented, repeatable way to keep services running and money reachable when something breaks.
Section I: Object and scope of application
Section I covers what the rule is for and who it reaches. It applies to your entity if you're a savings and credit cooperative, housing mutual association, or central fund. CONAFIPS is in scope too. If you're an auxiliary service organization, it covers the services you supply. None of it is one-size-fits-all. You're sorted into one of five segments, and the smallest carry a lighter load than the largest. That segmentation runs through the whole of the SEPS operational risk regulation and decides how much of what follows actually applies to you.
Compliance levels and requirements
SEPS Resolución 116 is made up of eight sections, and they stack from the groundwork up. The early ones set scope and the risk-management method; the middle ones dig into the four risk factors and the technology detail that dominates them; the later ones cover incidents, continuity, outsourced services, and who answers for what. Read in order, your entity moves from broad governance down to the specific controls it has to run every day.
Section III: Operational risk management
Section III is where the engine gets built. You manage operational risk through documented policies, a formal methodology, and a three-lines-of-defense model, and underneath sits a six-stage cycle that begins before a process runs and ends by telling member-owners what happened. You also keep a central record of risk events and a set of reports and key risk indicators, so exposure stays in front of the people who make the calls.
Section IV: Operational risk factors
Section IV asks you to handle each risk factor on its own terms, and in relation to the others. The technology factor is by far the heaviest, running from the technology committee through system operation, application development, change control, infrastructure, and cloud services. People and processes cover segregation of duties, the personnel life cycle, and documented processes; external events pull cyberattacks and fraud into the continuity plan.
Incident and problem management
This standard labels two sections as "IV," and this second one, incident and problem management, is about staying alert. You need response and recovery plans for incidents and problems, and you have to hold critical services at 99.99% availability across the year, scheduled maintenance aside. Every incident runs the full life cycle, from logging and triage through analysis, escalation, resolution, and reporting, with one named handler tracking it to the end.
Section V: Business continuity management
Section V is about continuity. You need a business continuity management system built on the ISO 22301 series and sized to what your entity does. The system names critical processes, works out what losing each one would cost, and sets a recovery time objective (RTO) and recovery point objective (RPO) for it. A disaster-recovery plan handles restoring IT services at a remote site, and the whole thing gets tested often enough to keep it reliable and working when needed.
Section VI: Third-party services
Almost nobody runs every service in-house, so Section VI deals with what you hand off. Before signing, you assess the provider, and for critical services you gather technical, security, and legal reports on the risk you're taking on. Cloud and foreign providers come with more: data centers built to ANSI/TIA-942 at TIER III or better, ISO 27017 and ISO 27018 where they apply, an independent audit each year, and a local representative who can take responsibility and answer for the service.
Section VIII: Responsibilities in operational risk management
Section VIII lays out who answers for what. The board or directorate approves policies and the operational-risk manual and sets tolerance; the comprehensive risk committee proposes methodologies and reviews the risk matrix; the risk unit does the daily work; and internal audit, the third line, checks that the first two are holding. If your entity falls in segments 4 or 5, you get a slimmer version of this, but ownership still has to be clear.
Challenges of implementing SEPS Resolución 116
Getting to SEPS Resolución 116 compliance can be hard work, particularly if your entity grew faster than your controls did.
Scaling controls to your segment
Your segment decides how much you owe. Move up a tier and controls, committees, and plans that used to be optional suddenly are not, and the phased 2024 and 2025 deadlines gave little runway to catch up if you're a latecomer.
The 99.99% availability target
At 99.99% over a year, your entity gets roughly 53 minutes of unplanned downtime and no more. A lot of infrastructure, monitoring, and on-call cover was simply never designed to hold that line, and closing the gap means spending on redundancy and real-time visibility.
Depth of the technology controls
Article 14 by itself runs from data center access to segregated environments, change control, backups, and infrastructure monitoring. You need people who can put each control in place and then prove it, and for a small team, that skill set is hard to hire and harder to hold onto.
Third-party and cloud oversight
If you lean on cloud or foreign providers, they'll have to show TIER III data centers, the right ISO certifications, a yearly independent audit, and a local representative on file. Pulling that evidence together and refreshing it every year across several vendors turns into steady administrative work rather than a single sign-off.
Standing up the risk-event base and reporting
A central event base, key risk indicators, and a heat map all depend on data from systems that were never built to share it. The raw logs are usually there; turning them into the operational risk management reporting SEPS looks for takes both tooling and a methodology you apply consistently.
Benefits of implementing SEPS Resolución 116
Meeting these SEPS compliance requirements pays back well beyond the next supervisory review.
Services your members can rely on
The availability target and the continuity work push an entity toward infrastructure that stays up. Your members experience that as accounts, transfers, and payments that keep working, which is the plainest sign their money is being looked after.
Fewer and smaller incidents
Run incident and problem management properly and issues get caught earlier, with the same failure less likely to come back. The count of serious incidents falls over time, and the ones that slip through do less damage.
Calmer supervisory reviews
SEPS can ask for your matrices, reports, and plans whenever it likes. Keep them current, and a review turns into handing over documents instead of a late-night scramble to rebuild them.
A stronger grip on vendors
The third-party rules hand you a repeatable way to size up and watch your providers. That habit earns its keep outside compliance too, flagging a shaky vendor before it causes an outage and giving you firmer ground in negotiations.
A risk capability you keep
Once the six-stage cycle and the three lines of defense are running, you own a way of working that outlives any one audit. New products and systems go through the same steps, so risk gets weighed before launch rather than after.
Best practices
If you want more than the bare minimum, here are a few habits that make SEPS Resolución 116 compliance easier to hold onto.
Governance and methodology
- Write the operational risk manual to match how your entity really works, then review it on schedule instead of only before an audit.
- Keep the three lines of defense genuinely apart, so whoever owns a risk is not the one signing off on it.
- Put new products and processes through the six-stage cycle before launch, while changes are still cheap.
Technology, continuity, and incident readiness
- Feed the risk-event base from real system data and keep it live, so the indicators reflect today rather than last quarter.
- Test the disaster-recovery plan against scenarios you might actually face, and measure the result against your RTO and RPO.
- Rehearse incident response with tabletop exercises, so the handler and the escalation path are familiar before a real outage.
- Watch critical-service availability continuously; you cannot defend a number you are not measuring.
Vendor and evidence management
- Keep one register of provider certifications, audit reports, and renewal dates so nothing quietly lapses.
- Settle data-return and exit terms in the contract, not in the middle of a crisis.
- Collect audit and continuity evidence from critical vendors on the yearly rhythm SEPS expects.
Conclusion
SEPS Resolución 116 matters because of who sits behind it: the institutions holding the savings of millions of people across Ecuador's popular and solidarity financial sector. Operational risk can mean real-world consequences—a broken process, a compromised system, or an outage nobody planned for can put your members' funds out of reach.
Build the capability once and keep it running, and the picture changes. Stand up the six-stage cycle, the three lines of defense, the continuity plans, and the vendor controls as part of how you operate day to day, and SEPS Resolución 116 compliance stops being a project and becomes the by-product of running a resilient institution. It is one of the more demanding pieces of Ecuador's financial-sector regulation for the cooperative world, so start with the services your members depend on and the risks that would hurt them most, then let the rest of the framework grow out from there.
