Corporate Governance - 2020 ANNUAL REPORT
Corporate Governance
Banco Nacional de Comercio Exterior, S. N. C. relies on an Internal Control System that is based on its corporate governance structure, which is comprised of the Board of Directors, and of several committees that make decisions on the various aspects of the institution’s operation, such as integral risk management, credit activities, investment services, human resources and institutional development, IT systems, audit, and internal control; it also relies on a periodic assessment performed by different levels of supervision which aid in the management of the Institution.
The implementation and continuity of internal control measures are the responsibility of the Office of the Director General of the Institution, as well as of its governing body, and of the executives and employees of the Institution, as a whole. Compliance, supervision, and updating of internal control measures is an ongoing, periodic practice in processes and areas of the Institution.
On the other hand, the Audit Committee is a body reporting to the Board of Directors that is in charge of evaluating and monitoring institutional activity within the framework of the Internal Control System (ICS). It is comprised of independent directors and is assisted by the statutory auditors.
As per the foregoing and pursuant to the General Provisions set forth by the Mexican National Banking and Securities Commission (CNBV) which apply to Credit Institutions (Provisions), BANCOMEXT has an Institutional Internal Control Model (MICI), which was updated and approved by the Board of Directors in December of 2020, and includes goals and guidelines with the purpose of establishing a general framework for the personnel of the Institution to implement the ICS in areas and processes under their responsibility.
The components of the model are outlined in the following graph.

The purpose of the MICI model is to assist in the generation of an environment that fosters a reasonable fulfillment of institutional goals, an orderly operational performance, an adequate risk management, observance of the law, and the evolution of processes by using resources efficiently, reliable institutional information, and resource loss prevention.
A Three Line model was designed to support the MICI model. It is to be implemented on three workgroups, with specific activities and responsibilities, with the purpose of reasonably mitigating risk by establishing and performing internal controls.
The first line refers to the participation of senior-level officials, as well as all staff, to manage their risks and establish their own controls.
The second line refers to the functions of risk supervision, controls, and compliance with policies, as well as standards set forth by the Institution, addressing cross-sectional, general, and specific risks. The third line is undertaken by the Internal Audit Department (IAD), which provides supervision that is independent of the two prior lines, evaluates the ICS, and identifies weaknesses and recommends improvements. Similarly, the DAI reports directly to the Audit Committee.
It is worth mentioning that the effectiveness of the internal control system is evaluated every year, and as a result, the institutional internal control annual status report is prepared and submitted to the Board of Directors and the Audit Committee of the BANCOMEXT, as well as to several levels of supervision. In this sense, the areas of opportunity detected as a result of the assessment are addressed by one of several administrative units, depending on their areas of responsibility.
Moreover, control routines involving the implementation of a standardized assessment methodology are in place, which consist of periodically applying self-control mechanisms in critical processes of banking operations through questionnaires that allow for verification at reasonably applied checkpoints and, if necessary, have the capacity to identify possible incidents that justify making reasonable adjustments to said processes.
Additionally, procedures are in place for evaluating and monitoring compliance with the Institutional Security Master Plan, and assessments of different critical processes, in terms of information and communication technologies, are performed periodically.