FactBox.

La Gaceta — Diario Oficial · 22 Sep 2026 · 5 vistas

ICE reforms the Audit and Risk Committee to strengthen control

Por FactBox Admin

ICE reforma el Comité de Auditoría y Riesgos para fortalecer el control

The Board of Directors of the Costa Rican Electricity Institute (ICE) approved the reform of the Internal Regulations of the Audit and Risk Committee, through an administrative act issued in Article 1 of Chapter II of the final minutes of Session No. 6750 on July 28, 2026. The modification was published in La Gaceta No. 178 on Tuesday, September 22, 2026, pages 27 to 30, under official reference IN202601123794. The text was submitted by Marlen Venegas Oviedo, head of the Strategy and Corporate Management Division of ICE.

The reform redefines the Audit and Risk Committee as a technical body with independent judgment that provides non-binding technical and strategic advice to the Board of Directors, in order to support decision-making regarding the strengthening of the Internal Control System, comprehensive risk management, and the analysis of internal audit results, external audits, and other control instances. The regulation is based on the General Internal Control Law No. 8292 and specifies that the committee has no operational or direct supervision functions, nor does it replace the Internal Audit.

The reform modifies articles 1, 5, 8, 9, 18, 19, 31, 32, 33, 34, and 35 of the regulation, which cover everything from the purpose and applicable documents to the duties of the members, reports, the participation of the General Management, and institutional and corporate functions in auditing and risks.

A normative reference framework

Article 5 lists the internal documentation that must be considered to execute the regulation:

  • 89.00.002.2024, Corporate Policy for the prevention of corruption and management of conflicts of interest.
  • C.10.01.2025, Transparency and Access to Information Policy of the ICE Group.
  • SE.6613.2024, Corporate Code of Ethics and Conduct.
  • SE.6566.1.2.2023, Corporate Governance Code of the ICE Group.
  • 38.00.002.2013, Corporate Information Confidentiality Policy.
  • SE.6567.2.4.2023, Corporate Framework for the Comprehensive Risk Management of the ICE Group.
  • 28.00.005.2011, Corporate Policy for Financial Risk Management and Financial Hedging.
  • 38.00.003.2028, Corporate Organization Regulation, and 38.00.001.2023, Autonomous Organization Regulation.
  • 51.00.001.2013, Internal Regulations of the Board of Directors, and PRO-PCL-SCD-001, Procedure for the delivery of documents and presentation before the Board of Directors.
  • 38.00.002.2024, Methodological Framework for the Assessment and Management of risks of ICE.

Duties of members and session rules

Article 8 establishes the duties of the committee members:

  • Attend ordinary and extraordinary sessions in person or virtually, and justify any absences.
  • Maintain secrecy and confidentiality regarding the strategic information of the ICE and the companies owned by the ICE.
  • Sign an annual sworn statement of independence and absence of conflicts of interest, as well as adherence to the Corporate Code of Ethics and Conduct.
  • Verify that the sessions are recorded in audio and video.
  • Comply with the Corporate Policy for the Prevention of Corruption and Management of Conflicts of Interest.

Article 18 establishes that the heads of General Management and Internal Audit participate in the sessions when convened, with a voice but without a vote; Internal Audit acts as a technical advisor and may abstain to preserve its functional and judgmental independence. The committee may rely on external advisors, subject to prior authorization from the Board of Directors, with ad honorem participation.

Functions in auditing and risks

Articles 31 to 34 detail the institutional and corporate functions of the committee:

  • Advise the Board of Directors on the operation and strengthening of the Internal Control System and Corporate Governance.
  • Follow up on compliance with recommendations, provisions, and findings from Internal Audit, external audits, the Comptroller General of the Republic, and other supervisory bodies.
  • Alert the Board of Directors to risks or situations requiring immediate attention that could compromise legality, service continuity, strategic objectives, or institutional assets.
  • Review the audited annual financial statements of the ICE and the ICE Group, the quarterly corporate financial report, the Management Letter, and communications from the External Auditor.
  • Assess and recommend the risk appetite and the limits that the institution is willing to assume, at least once a year.
  • Communicate to the competent external authorities the results of inaction, undue delay, or significant urgency in addressing critical alerts not attended to by the Board of Directors.

Annual evaluation and accountability

Article 35 requires committee members to conduct an annual self-evaluation of their management and present the results to the Board of Directors in the month of March. The Board of Directors must evaluate the effectiveness, independence, and strategic contribution of the committee at least annually. Article 9 provides that the committee submit an annual report of its actions, documented in digital minutes that ensure integrity, traceability, and preservation, and that the reports be published on the official website, safeguarding sensitive information.

The strengthening of internal control and risk management of the ICE Group directly affects the governance and oversight of the country’s main public company: the reform expands the duties of its members, mandates the follow-up of findings from control bodies, and empowers the committee to alert the Board of Directors and external agencies about critical risks, meaning that supervision no longer depends solely on Internal Audit.


Source: La Gaceta No. 178, Tuesday, September 22, 2026, pages 27-30 (official reference: IN202601123794).