2026-05-29
Added · Updated
The Directive establishes requirements for payment institutions to implement internal governance mechanisms, including the roles and responsibilities of the administrative organ, risk management frameworks, and internal control functions. It mandates specific organizational structures, defines key terms such as independent members and executive management, and sets out obligations for reporting to the Central Bank of Cyprus. The document also provides for potential exemptions from certain requirements for institutions offering only specific payment services, subject to prior approval.
Get CBC alerts — same-day email on every new publication.
E.E. Part III(1) C.D.P. 246/2026
No. 6026, 29.5.2026
Number 246
THE PROVISION AND USE OF PAYMENT SERVICES AND ACCESS TO PAYMENT SYSTEMS LAWS OF 2018 TO 2025 ____________________ Directive pursuant to Article 105 Directive pursuant to Articles 5(3)(e) and 105 of the Provision and Use of Payment Services and Access to Payment Systems Law of 2018 to 2025
CONTENTS
PART I - TITLE, PURPOSE, INTERPRETATIONS AND SCOPE
PART II - PROPORTIONALITY AND GENERAL REQUIREMENTS
5. Proportionality
6. General Requirements
PART III - ADMINISTRATIVE ORGAN
7. Role of the Administrative Organ
8. Responsibilities of the Administrative Organ and Executive Management
9. Size and Composition of the Administrative Organ
10. Role and Competences of the Chairman of the Administrative Organ
11. Meetings of the Administrative Organ and its Committees
12. Access of the Administrative Organ and Committees to Resources and Information
13. Evaluation of the Administrative Organ
14. Establishment of Administrative Organ Committees
15. Composition and Organization of Administrative Organ Committees
16. Role of the Risk Committee
17. Role of the Audit Committee
PART IV - GOVERNANCE AND RISK MANAGEMENT FRAMEWORK
18. Organizational Framework
19. Corporate Values and Code of Conduct
20. Customer Complaints Handling Procedure
21. Internal Whistleblowing/Reporting Procedures
22. Reporting Violations to the Central Bank
23. Internal Control Framework
24. Implementation of Internal Control System
25. Functions of the Internal Control System
26. Head of Internal Control System Functions
27. Risk Management Function
28. Regulatory Compliance Function
29. ICT Risk Management Function
30. Internal Audit Function
31. Audit Missions
32. Audit Plan
33. Outsourcing of Activities
34. ICT Risk
35. New Products and Significant Changes
PART V - REPORTS TO THE CENTRAL BANK
36. Submission of Reports to the Central Bank
PART VI - OTHER PROVISIONS
37. Transparency
38. Entry into Force
PART I - TITLE, PURPOSE, INTERPRETATIONS AND SCOPE
Short Title.
Purpose of the Directive.
2. The purpose of this Directive is to set requirements regarding the development, implementation and effective control of internal governance mechanisms, which payment institutions must put into effect, in order to ensure their effective and prudent management.
Interpretations.
3. (1) For the purposes of this Directive, the definitions in Article 2 of the Provision and Use of Payment Services and Access to Payment Systems Law of 2018 apply, unless a different interpretation arises from the text. In addition, the following terms and their definitions apply:
E.E. Part III(1)
13.6.2025
(C.D.P. 164/2025)
"independent member of the administrative organ" or "independent member" means a non-executive member of the administrative organ who meets all the criteria defined in Annex 1 of the Directive on the Assessment of the Suitability of Members of the Administrative Organ, Executive Management and Persons Responsible for the Management of Payment Institutions 2025;
N. 188(I) of 2007
E.E. Part I(1)
No. 4154
31/12/2007
58(I) of 2010
80(I) of 2012
192(I) of 2012
101(I) of 2013
184(I) of 2014
18(I) of 2016
13(I) of 2018
158(I) of 2019
81(I) of 2019
13(I) of 2021
22(I) of 2021
61(I) of 2021
40(I) of 2022
98(I) of 2023
118(I) of 2024
141(I) of 2024
172(I) of 2024
35(I) of 2025
96(I) of 2025
25(I) of 2026.
"executive management" means the natural persons exercising executive functions in a payment institution, including the executive members of the administrative organ, one of whom is the Chief Executive Officer, the Chief Financial Officer, the heads of the internal control functions, the compliance officer appointed pursuant to Article 69 of the Prevention and Combating of Money Laundering Proceeds of Illegal Activities Law of 2007 (in case he is different from the head of the regulatory compliance function) and any other persons at a senior level in the hierarchy for decision-making regarding the daily management of the institution;
"Chief Executive Officer" means the executive member of the administrative organ who is responsible for the management and coordination of the overall business activities of an institution;
"administrative organ" means the organ or organs of an institution, which are authorized to determine the strategy, objectives and general direction of the institution and oversee and monitor decision-making by the management and include the persons who actually direct the business activity of the institution;
"executive member of the administrative organ" means a member of the administrative organ of an institution who is responsible for actually directing the activities through an employment contract concluded with that institution;
"outsourcing" means an agreement of any form between an institution and a service provider, whereby the service provider performs a process, provides a service or exercises an activity which would otherwise have been performed, provided or exercised by the institution itself;
53(I) of 2017
171(I) of 2017
7(I) of 2018
69(I) of 2019
12(I) of 2020
153(I) of 2022
160(I) of 2025.
"external auditor" means a third independent person, other than the staff of the institution or the approved auditor, appointed for the purposes of auditing the institution and who is a legal auditor and/or legal audit firm, within the meaning given to these terms by Article 2 of the Auditors Laws of 2017 to 2025;
"head of the internal control system functions" means the persons at the highest hierarchical level, who are responsible for the effective management of the daily operation of the independent risk management, regulatory compliance, internal audit and ICT risk management functions;
"committee" means a sub-group of the administrative organ entrusted with the execution of specific functions or projects assigned to it;
"institution" means a payment institution as defined in Article 2 of the Provision and Use of Payment Services and Access to Payment Systems Law of 2018;
Official Journal of the
E.U.: L333/1
27.12.2022, p.1
"Regulation (EU) No. 2022/2554" means Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No. 1060/2009, (EU) No. 648/2012, (EU) No. 600/2014, (EU) No. 909/2014 and (EU) 2016/1011;
Official Journal of the
E.U.: L333/1,
27.12.2022.
"ICT risk" means ICT risk as defined by Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector;
"code of conduct and corporate values" means the set of principles, values, standards, or rules of conduct that guide the decisions, processes and systems of an institution in accordance with Part IV;
"Central Bank" means the Central Bank of Cyprus;
"non-executive member of the administrative organ" means a member of the administrative organ of an institution who is responsible for overseeing and monitoring decision-making by the management, without having executive functions within the institution;
"Law" means the Provision and Use of Payment Services and Access to Payment Systems Law of 2018;
"service provider" means a third entity undertaking outsourced processes, services or activities, or part thereof, within the framework of an outsourcing agreement;
"staff" means the entire workforce of an institution, including executive management and the entire membership of the administrative organ;
"ICT" means information and communication technology.
(2)(a) In this Directive, any reference to a law or regulatory administrative act of the Republic means that law or regulatory administrative act as amended, modified or replaced from time to time, unless a different meaning arises from the text. (b) In this Directive, any reference to a Directive, Regulation, Decision or other legislative act of the European Union means that act as amended, modified or replaced from time to time, unless a different meaning arises from the text.
Scope.
4. (1) This Directive applies to payment institutions licensed by the Central Bank.
(2) With prior approval from the Central Bank, institutions may be exempted from specific requirements of this Directive due to the smaller scope of payment services they offer:
i. Institutions that provide exclusively service 7 based on Annex I of the Law (payment initiation services)
ii. Institutions that are registered in the register of the Central Bank exclusively for the provision of service 8 based on Annex I of the Law (account information services)
iii. Institutions that provide exclusively services 7 and 8 based on Annex I of the Law.
For this purpose, institutions submit a documented application to the Central Bank.
PART II - PROPORTIONALITY AND GENERAL REQUIREMENTS
Proportionality.
5. (1) Institutions apply the provisions provided in this Directive in accordance with the principle of proportionality, taking into account their size, overall risk profile, nature, scale and complexity of their services, activities and functions.
(2) For the application of the principle of proportionality, the criteria referred to in sub-paragraph (1) are taken into account, both by the institutions for the purposes of applying the requirements of the Directive and by the Central Bank for the purposes of assessing the compliance of institutions with the requirements of this Directive.
General Requirements.
6. Each institution must have a sound governance framework, which is consistent with and promotes the principles of sound and effective management of the institution and includes at least the following:
(a) a clear organizational structure with clear, transparent and consistent lines of responsibility; (b) appropriate and effective procedures and safeguards for the identification, management, monitoring and reporting of the risks to which the institution is or may be exposed, including risks of non-compliance with the applicable regulatory framework; (c) network and information systems that have been created and are managed in accordance with Regulation (EU) 2022/2554; (d) adequate internal control mechanisms, including mechanisms for compliance with regulatory requirements related to the prevention and combating of money laundering and terrorist financing; (e) appropriate and effective procedures and safeguards for the monitoring and handling of complaints and/or reports, and (f) appropriate and effective administrative and accounting procedures.
PART III - ADMINISTRATIVE ORGAN
Role of the Administrative Organ.
7. (1) The administrative organ has the ultimate and general responsibility for the internal governance of the institution and defines, oversees and is accountable for the implementation of governance arrangements that ensure effective and prudent management of the institution, including regulatory compliance and effective management of the risks faced by the institution.
(2) The administrative organ is responsible for the effective oversight of executive management.
(3) Where the institution is a parent institution of a group of companies, the administrative organ of the institution has overall responsibility for adequate internal governance throughout the group.
Responsibilities of the Administrative Organ and Executive Management.
8. (1) The duties of the administrative organ and executive management are clearly defined. The description of these responsibilities and duties is recorded in a relevant document approved by the administrative organ.
(2) All members of the administrative organ and executive management have full awareness of their structure and responsibilities, as well as the division of duties among the members of the administrative organ, its committees and executive management. (3) To ensure an appropriate system of checks and balances, the decision-making process of the administrative organ should not be dominated by a single member or a small subset of its members. (4) The responsibilities of the administrative organ include the establishment, approval and oversight of the implementation of the following elements:
(a) the overall business strategy and key policies of the institution, which must be consistent with the legal and regulatory framework within which it operates, taking into account the long-term financial interests and solvency of the institution, and evaluating at least once a year the degree of effectiveness of the institution's management of regulatory compliance risk. The administrative organ must know the regulatory environment in which the institution operates, ensure that it has an appropriate regulatory compliance framework and maintain an effective and productive relationship with the competent authorities; (b) the overall risk strategy, including the risk appetite framework and the risk management framework of the institution, as well as the relevant arrangements that ensure that the administrative organ devotes sufficient time to risk issues; (c) an adequate and effective internal governance framework and internal control system, as defined in this Directive, which includes a clear organizational structure and smooth operation of the independent risk management, regulatory compliance, internal audit and ICT risk management functions, which, respecting the principle of proportionality, have sufficient powers, authority and resources to perform their duties; (d) adequate internal control mechanisms, including mechanisms for compliance with regulatory requirements related to the prevention and combating of money laundering and terrorist financing; (e) a procedure for the selection and assessment of the suitability of members of the administrative organ and executive management; (f) arrangements aimed at ensuring the internal operation of each of the administrative organ committees, if established, with a description of the role, composition and duties of each committee, appropriate information flow, including documentation of recommendations and conclusions, and reporting lines between the committees and the administrative organ, the Central Bank and other parties; (g) a corporate culture and corporate values that promote responsible and ethical behavior, including a code of conduct or similar instrument; (h) a conflict of interest policy at both the institution and group level, as well as for each member of the administrative organ, executive management and the rest of the staff; (i) a policy to ensure the funds received from payment service users or through other payment service providers for the execution of payment transactions, which includes at least the safeguarding measures applied by the institution and the methods applied to monitor and control the institution's compliance with the requirements of Article 10 of the Law; (j) arrangements aimed at ensuring the soundness of accounting and financial reporting systems, including financial and operational controls, compliance with the relevant legislative framework and relevant financial standards. (5) The administrative organ examines constructively and evaluates critically the
proposals, explanations and information it receives, in exercising its judgment and making its decisions. (6) The administrative organ oversees the disclosure process and announcements to external stakeholders and competent authorities. (7) All members of the administrative organ are kept informed of the overall activity, financial position and risks undertaken by the institution, taking into account the economic environment, as well as the decisions made by each function or business unit and which have a major impact on the business activity of the institution. (8) The administrative organ monitors, periodically reviews and takes appropriate measures to address any weaknesses identified in the implementation of the institution's procedures, strategies, policies and internal control system and periodically evaluates the effectiveness of the institution's governance arrangements, in accordance with the provisions of this Directive. (9) The administrative organ ensures that instructions for settlement transactions concerning transfers of funds from customer accounts are co-signed either by two members of the administrative organ or by two persons duly authorized by the administrative organ for this purpose. (10) The administrative organ approves and periodically reviews, and in any case at least annually, the institution's policy on delegating work to third parties and oversees its implementation. (11) The administrative organ appoints one of its members, in accordance with the requirements of Article 58D of the Prevention and Combating of Money Laundering Proceeds of Illegal Activities Law of 2007, who will be responsible for the implementation of the laws, regulations and administrative provisions required for compliance with the Prevention and Combating of Money Laundering Proceeds of Illegal Activities Law of 2007, and the directives and/or circulars and/or regulations issued thereunder, including any relevant acts of the European Union, including the institution's corresponding arrangements and procedures for the prevention and combating of money laundering and terrorist financing. (12) Executive management is responsible for:
(a) guiding and overseeing the effective management of the institution within the powers assigned to them by the administrative organ and in compliance with applicable laws and regulations;
(β) the direction and supervision of the institution's daily operations, adhering to the business objectives, strategies, and policies approved by the governing body, and to legal and regulatory requirements; (γ) the provision of recommendations to the governing body for its examination and approval, regarding the business objectives, strategies, and business plans and policies governing the operation of the governing body; (δ) the provision of comprehensive, relevant, and timely information to the governing body that will enable it to review the business objectives, business strategy, and policies, and to hold executive management accountable for the execution of their duties.
Size and composition of governing body.
9. (1) The size and composition of the governing body is determined taking into account the principle of proportionality, ensuring at least that:
(a) the governing body consists of at least five (5) members; the executive members of the governing body must be at least two (2), one of whom must be the Managing Director, and the independent members of the governing body are at least three (3); (b) the independent members of the governing body must hold the majority of votes in the institution's governing body; (c) the chairperson of the governing body must be an independent non-executive member, and where the number of members of the governing body is even, in the event of a tie, he/she shall hold the casting vote; (d) the members of the governing body must possess sufficient knowledge, skills, and experience to be able to understand the activities and obligations of the institution, which arise from the legal and regulatory framework, as well as the risks associated with the institution's operations.
(2) Members of the governing body cannot appoint substitute members to represent them in the proceedings of the governing body in their absence.
(3) The executive members of the governing body should be employed on full-time terms. Institutions must ensure the adequate physical presence of the executive members of the governing body in the performance of their duties as defined in this Guideline and in compliance with applicable laws and regulations.
(4) The heads of the internal control system functions cannot be appointed as members of the governing body.
Role and responsibilities of the chairperson of the governing body.
10. (1) The chairperson of the governing body:
(a) guides the governing body, contributes to ensuring the efficient flow of information, both within the governing body and between the governing body and its committees, and is responsible for the effective overall operation of the governing body; (b) encourages and promotes the conduct of open, critical discussion and ensures that divergent views can be expressed and discussed within the decision-making process; (c) determines the agenda items of the meetings and ensures that items requiring the attention or actions of the governing body or its committee are included in the agenda, and that strategic issues are discussed as a priority; (d) contributes to the clear distribution of responsibilities among the members of the governing body and ensures that decisions of the governing body are taken on a sound basis and after sufficient information, and ensures the timely receipt of relevant documents and information before the meeting; (e) ensures that sufficient time is provided to the members of the governing body to examine significant issues and to obtain answers to any questions or concerns they may have, without facing unrealistic deadlines for decision-making; (f) ensures, in cooperation with the executive members of the governing body, the circulation, completion, and approval of meeting minutes in a timely manner by all members who were present at the meeting; (g) ensures, in cooperation with the executive members of the governing body, the distribution of final meeting minutes in a timely manner to all recipients; (h) ensures, in cooperation with the executive members of the governing body, the appropriate communication of decisions taken, the implementation of subsequent actions, and the updating of the governing body on any emerging issues;
(i) ensures, through an explicit procedure, the communication to the governing body of any conflicts of interest of the members of the governing body and the abstention of such members from the discussion, decision-making, or voting process on any matter for which they may have a conflict of interest; (j) ensures the smooth succession of members of the governing body; (k) maintains adequate contact with the competent authority and ensures that the views and concerns of the competent authority and any views and concerns of shareholders that come to his/her knowledge are communicated in full to the governing body.
(2) The chairperson of the governing body is responsible for ensuring that:
(a) paragraph 11 of this Guideline is observed, through appropriate procedures and actions; (b) procedures are observed so that members of the governing body have at all times sufficient knowledge and skills to perform their duties; (c) procedures are observed for the participation of new members of the governing body in an induction training program; (d) the evaluation of the governing body, its committees, and each member of the governing body is conducted in accordance with the provisions of paragraph 13; (e) the institution takes actions commensurate with the results of these evaluations, recognizing the capabilities and addressing the weaknesses of the governing body in a timely manner, including the training needs of the members of the governing body on an individual and/or collective basis.
Meetings of the governing body and its committees.
11. (1) The governing body and its committees:
(a) hold regular and/or extraordinary meetings, at least four times a year, for the adequate and effective performance of their duties; (b) ensure that their members participate in regular or extraordinary meetings either in person or via teleconference, if this is permitted by the institution's statutes.
(2) The governing body ensures that:
(a) at least once a year, a regular meeting of the governing body is held in person by all members, while during the conduct of other meetings, it ensures that at least four members of the governing body participate either in person or via teleconference, of whom at least fifty percent (50%) must be non-executive members; (b) no person who has not received the approval of the Central Bank may act as a member of the governing body of an institution, or may participate in a meeting, unless he/she has been officially invited to participate in view of the discussion of a specific agenda item on which he/she has been asked to express opinions; any such person participates only in the discussion of the specific matter and leaves the conference room or teleconference immediately thereafter, without any participation in the decision-making process; (c) minutes are kept at each meeting, which are finalized and approved within one month from the date of the relevant meeting and are made available to the Central Bank upon its request.
(3) Members of the governing body cannot be absent from the regular and extraordinary meetings of the governing body and its committees, either in person or via teleconference, for more than two (2) consecutive meetings, provided that their total absences do not exceed twenty-five percent (25%) of the annual meetings.
Access of governing body and committees to resources and information.
12. The governing body and its committees have adequate access to all information and data necessary for the performance of their duties.
Evaluation of the governing body.
13. (1) The institution has an appropriate methodology and procedure for the in-depth evaluation of the performance of the governing body as a whole, each committee, and each member. This evaluation is conducted at least on an annual basis.
(2) The evaluation procedure referred to in sub-paragraph (1) covers, at least, the following:
(a) the performance of the governing body as a whole, the committees, and individual members; (b) the contribution of the governing body as a whole, the committees, and individual members:
(i) in formulating the business objectives and strategies of the institution; (ii) in defining and supervising risk management and regulatory compliance frameworks; (iii) in creating and maintaining strong organizational and operational arrangements and internal control mechanisms; (c) the composition of the governing body and its committees; (d) communication with executive management, shareholders, and the Central Bank; (e) the role of the chairperson of the governing body; (f) the time spent by non-executive members in performing their duties;
Official Gazette of the Republic, Part III, Issue I 13.6.2025 C.P. 164/2025
(g) the assessment of the suitability of each member of the governing body based on the applicable criteria of the 2025 Guideline on the Assessment of the Suitability of Members of the Governing Body and Executive Management of Payment Institutions.
Establishment of governing body committees.
14. The institution:
(a) establishes a risk committee and an audit committee with the aim of providing advice and assisting the governing body in decision-making; (b) may request the Central Bank to establish a joint risk and audit committee; in any case, the institution must ensure that the members of a joint committee possess, at an individual and collective level, the required knowledge, skills, and expertise to fully understand the duties and responsibilities of the joint committee; (c) ensures that the chairperson of the risk committee and the chairperson of the audit committee have the appropriate qualifications to act as chairs of these committees; (d) may establish other committees beyond those referred to in sub-paragraph (a).
Composition and organization of governing body committees.
15. For the committees of the governing body referred to in paragraph 14 of this Guideline:
(1) The number of members of each committee of the governing body must be sufficient to handle the volume and complexity of the committee's duties, and in any case not less than three (3) members.
(2) The audit committee should consist exclusively of independent non-executive members of the governing body, while the risk committee should consist of a majority of independent non-executive members of the governing body. In the case of a joint committee, it should consist of independent non-executive members of the governing body.
(3) Subject to the principle of proportionality, the institution should consider the possibility of rotating members of the committees, taking into account the specific experience, specialized knowledge, and skills required for these committees at an individual or collective level.
(4) Members of a committee should not hold any other positions or conduct transactions that could be considered to conflict with the terms of the committee's mandate.
(5) Committees should report on a regular basis and communicate their minutes to the governing body before the governing body's meetings.
Role of the risk committee.
16. (1) Without prejudice to the full responsibility of the governing body for the proper and adequate handling of risks, the risk committee should at least:
(a) advise and support the governing body regarding the monitoring of the institution's overall current and future risk strategy and risk-taking capacity, taking into account all types of risks, so as to ensure that they are consistent with the business strategy, objectives, corporate culture, and corporate values of the institution; (b) advise and support the governing body in identifying risks arising in the context of the implementation of the institution's decisions, policies, and strategy, as well as in the context of any changes in the business model, the institution's operations, and the products and services it offers; (c) submit proposals to the governing body for any necessary adjustments to the strategy that arise, inter alia, from market developments, and for addressing related risks;
(d) provide advice regarding the appointment of external consultants, who may be decided to be hired by the governing body to provide advice or support to the institution; (e) evaluate and monitor the implementation of the recommendations of internal and external auditors; (f) evaluate and monitor the independence and adequacy of the risk management function and the IT risk management function; (g) supervise that executive management takes the necessary corrective measures in a timely manner to address the risks and weaknesses identified by the risk management and IT risk management functions; (h) submit recommendations to the governing body regarding the appointment or removal of the heads of the risk management function and the IT risk management function; (i) conduct an annual evaluation of the heads of the risk management function and the IT risk management function and submit it to the governing body; (j) assist the governing body in examining and approving the budgets of the risk management function and the IT risk management function, ensuring that they are sufficiently flexible to adapt to changes according to developments.
(2) The risk committee maintains regular communication with the institution's internal control system functions, and specifically with the risk management function and the IT risk management function, including cases of their outsourcing.
Role of the audit committee.
17. The audit committee should at least:
(a) monitor the financial information process and the effectiveness of the institution's systems for controlling the quality of financial information, and submit recommendations aimed at ensuring its integrity.
(b) supervise the establishment of accounting policies by the institution; (c) supervise the process of selecting external auditors and submit proposals to the governing body regarding their appointment, remuneration, terms of engagement, and replacement, and maintain contact with external auditors, particularly regarding the findings of their audit; (d) evaluate and monitor the independence, adequacy, and effectiveness of the internal control function and the regulatory compliance function; (e) provide advice to the governing body, based on the work of the regulatory compliance function, regarding the adequacy and effectiveness of the corporate ethics framework; (f) provide advice to the governing body, based on the work of the regulatory compliance function and external auditors, regarding the adequacy and effectiveness of the compliance framework; (g) submit recommendations to the governing body regarding the appointment or removal of the heads of the internal control and regulatory compliance functions; (h) conduct an annual evaluation of the heads of the internal control and regulatory compliance functions and subsequently submit it to the governing body; (i) assist the governing body in examining and approving the annual audit program and the budgets of the internal control and regulatory compliance functions, ensuring that they are sufficiently flexible to adapt to changes according to developments; (j) supervise executive management to take the necessary corrective measures in a timely manner to address control weaknesses, non-compliance with the institution's policies, laws and regulations, and other weaknesses identified by external auditors, internal control functions, and supervisory authorities.
PART IV - GOVERNANCE AND RISK MANAGEMENT FRAMEWORK
Organizational framework.
18. (1) The governing body of an institution ensures and records an appropriate and transparent organizational and functional structure to promote and assist the effective and prudent management of the institution.
(2) The governing body ensures that the institution's internal control system functions are independent from the business areas they control, ensuring, inter alia, the separation of duties of these functions and that they have adequate financial and human resources, as well as powers for the effective exercise of their role.
(3) The governing body ensures that reporting lines and the distribution of responsibilities, inter alia, among executive management, must be clear, fully defined, consistent, and binding. The distribution should be adequately documented and recorded in a relevant document which is updated appropriately.
Corporate values and code of conduct.
19. (1) The governing body develops, approves, maintains, and promotes high ethical and professional standards, taking into account the specific needs and characteristics of the institution, and ensures the implementation of these standards, based on a code of conduct or similar instrument. Where appropriate, the governing body may approve and implement the institution's standards established at the group level or common standards issued by associations (e.g., professional bodies) or other relevant organizations.
(2) The governing body, and executive management, supervise the compliance of personnel with the standards referred to in sub-paragraph (1).
(3) The institution ensures that there is no discrimination based on gender, race, color, ethnic or social origin, genetic characteristics, language, religion or beliefs, political or other opinion, membership of a national minority, property, birth, disability, age, or sexual orientation.
(4) The institution's policies are gender-neutral, and the institution implements measures that ensure equal opportunities for all genders.
(5) The applied standards should aim to strengthen the institution's governance arrangements and reduce the risks to which the institution is exposed, particularly operational risks and reputational risks, which may have significant adverse effects on its profitability and viability through fines, legal costs, restrictions imposed by the competent authority, other financial and criminal sanctions, as well as the loss of the value of its commercial identity and customer confidence.
(6) The governing body and executive management should have clear and documented policies regarding how the institution complies with the applied standards. These policies should:
(a) remind personnel that all activities of the institution should be conducted in accordance with applicable law and in compliance with the institution's corporate values; (b) promote risk awareness through a strong risk-aware culture; (c) define principles and provide examples of acceptable and unacceptable behaviors specifically related to the commission of offenses, economic and financial crime, including, but not limited to, fraud, money laundering, and terrorist financing, mis-selling, and other violations of consumer protection legislation; (d) clarify that, in addition to compliance with legislative and regulatory requirements and internal policies, personnel are expected to behave with honesty and integrity and to perform their duties with due skill, care, and diligence; and (e) ensure that personnel are informed about internal disciplinary measures, any external measures, legal actions, and sanctions that may arise from the commission of offenses and unacceptable behavior.
(7) The institution monitors personnel's compliance with the respective standards and ensures personnel awareness, for example, by providing necessary training.
(8) The institution identifies the function responsible for monitoring compliance and for evaluating violations of the code of conduct or similar instrument, as well as the procedure for addressing non-compliance issues. The results should be communicated to the governing body on a periodic basis.
Customer complaint handling procedure.
JC 2018 35
04/10/2018.
20. (1) The institution establishes and maintains effective and transparent procedures for handling complaints received from customers.
(2) In relation to sub-paragraph (1), the institution follows the guidelines contained in the document "Guidelines on the handling of complaints for the securities and banking sectors" issued by the Joint Committee of the European Securities and Markets Authority and the European Banking Authority.
Internal Whistleblowing/Reporting Procedures.
(2) Staff members who report breaches should not be required to provide relevant evidence; however, they should possess a sufficient level of certainty that adequately justifies the initiation of a related investigation.
6(I) of 2022
13(I) of 2024
148(I) of 2025
216(I) of 2025.
(3) The institution shall apply appropriate procedures to ensure its compliance with the Protection of Persons Who Report Violations of the Union and National Law of 2022.
(4) To avoid conflicts of interest, staff should be able to report breaches by bypassing regular reporting channels, such as through the regulatory compliance function, the internal audit function, or an independent internal malfunction reporting (whistleblowing) procedure within the institution.
Official Journal of the EU: L 119,
4.5.2016, p. 1
L 127
23.5.2018, p. 2
L 074, p. 35
125(I) of 2018
26(I) of 2022.
(5) Internal whistleblowing procedures should ensure the protection of personal data, both of the person reporting the breach and of the natural person alleged to have committed the breach, in accordance with Regulation (EU) 2016/679 and the Law on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data of 2018.
(6) Internal whistleblowing procedures should be available to all staff of the institution.
(7) (a) Information provided by staff through internal whistleblowing procedures should be transmitted, where appropriate, to the administrative organ, senior management, and other relevant functions identified in the internal whistleblowing policy. Upon request of the staff member reporting a breach, the information should be transmitted anonymously.
(b) The institution may also provide a malfunction reporting (whistleblowing) procedure, which allows for the submission of information anonymously.
(8) The institution shall ensure the appropriate protection of the person reporting the breach from any negative consequences, such as reprisals, discrimination, or other forms of unfair treatment. The institution shall ensure that no person under the control of the institution is involved in the victimization of a person who has reported a breach, and shall also take appropriate measures against those responsible for such victimization.
(9) In cases where no evidence emerges justifying measures against the aforementioned persons from the investigation, the institution shall protect the reported persons from potential negative consequences. In the event of measures being taken, the institution shall ensure the protection of the involved person from unintended negative consequences that go beyond the purpose of the measure taken.
(10) Internal whistleblowing procedures should:
(a) be documented, for example in staff handbooks;
(b) provide clear rules ensuring that information regarding the reports, the reported persons, and the breach are treated as confidential information, in accordance with Regulation (EU) 2016/679 and the Law on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data of 2018, unless disclosure of their identity is required under national legislation in the context of further investigations or subsequent judicial proceedings;
(c) protect staff members who raise concerns from any victimization due to the fact that they reported breaches that must be declared;
(d) ensure that potential or actual reported breaches are assessed and referred to higher levels of the hierarchy, including, where appropriate, to the competent authority or law enforcement authorities;
(e) ensure, where feasible, that acknowledgment of receipt of information is provided to staff members who have reported potential or actual breaches;
(f) ensure monitoring of the outcome of the investigation regarding the reported breach; and
(g) ensure appropriate record-keeping.
Reporting Violations to the Central Bank.
Staff members of the institution may approach the Central Bank in cases where such staff members:
(a) have reason to believe that the use of their institution's internal whistleblowing procedures may not be effective, or
(b) consider that despite the provisions of paragraph 21 of this Directive, any internal reporting would create a risk of negative consequences for them, or
(c) consider it appropriate to submit the report directly to the Central Bank due to the severity of the potential or actual breach, and/or the potential involvement of senior management of the institution, or
(d) consider it appropriate to submit the report directly to the Central Bank for any other reason they explain to the Central Bank in the context of submitting their report.
Internal Control Framework.
(2) The institution shall apply appropriate measures and procedures to ensure compliance with its obligations to prevent and combat money laundering from illegal activities and terrorist financing. The institution shall assess its exposure to the risk of being used for money laundering from illegal activities and terrorist financing purposes and take measures to mitigate such risks, as well as operational and reputational risks related to them. The institution shall take measures to ensure that its staff is informed about these risks and their consequences for the institution and the integrity of the financial system.
(3) The internal control framework should cover the entire organization, including the responsibilities and duties of the administrative organ, as well as the activities of all functions of the institution, including the functions of the internal control system and activities that are outsourced and distribution channels.
(4) The institution's internal control framework should ensure:
(a) the effective and efficient operation of the institution;
(b) the prudent conduct of the institution's business activities;
(c) adequate identification, measurement, and reduction of risks;
(d) the reliability of financial and non-financial reports, which should be submitted internally and externally;
(e) the correctness of administrative and accounting procedures;
(f) compliance with the institution's internal policies, procedures, rules, and decisions;
(g) compliance with applicable laws, regulations, directives issued thereunder, circulars, and resulting supervisory requirements.
(5) The institution shall commission, at least once every three years, an assessment of the adequacy and effectiveness of the internal control framework to an external auditor who possesses the necessary expertise, other than the institution's external and internal auditor.
Implementation of Internal Control System.
(2) The institution shall establish, maintain, and periodically update appropriate and documented internal control policies, mechanisms, and procedures, which should be approved by the administrative organ.
(3) The institution shall have a clear, transparent, and documented decision-making process, as well as a clear allocation of responsibilities and powers within the internal control system, including business sectors, internal units, and functions of the internal control system.
Functions of the Internal Control System.
(a) establish separate units or appoint separate individuals responsible for each of the risk management, regulatory compliance, IT risk management, and internal control functions.
(b) except for medium-sized and larger enterprises as defined in Article 3 of Regulation (EU) 2022/2554, with the approval of the Central Bank, may combine the risk management, regulatory compliance, and IT risk management functions. In any case, any combination should not contain more than two of these functions.
Provided that the internal control function is not combined with any other function of the internal control system.
(2) The risk management, regulatory compliance, and IT risk management functions are subject to assessment and control by the internal control function.
(3) The functions of the internal control system are independent from the operational units they monitor and control.
(4) The activities of the internal control system functions, with the exception of the regulatory compliance function, may be outsourced in part or in whole, subject to the provisions of paragraph 33. In the case of partial outsourcing, the head of the respective internal control system function retains responsibility for the entire activities of the function. In the event that the operational duties of the internal control system function are outsourced in whole, the administrative organ and its relevant committee are responsible for this activity, and the chairman of the administrative organ or the relevant committee serves as the communication link with the Central Bank.
Heads of Internal Control System Functions.
(2) Subject to the overall responsibility of the administrative organ, the heads of the internal control system functions should be independent from the business sectors or units they control. To ensure their independence, these heads report and are accountable directly to the administrative organ, and their performance is evaluated by the administrative organ.
(3) (a) The heads of the internal control system functions are appointed by the institution and approved by the Central Bank before the commencement of operations of a licensed institution.
(b) In the event of the departure from the institution of a head of an internal control system function, the institution shall submit to the Central Bank a fully completed Individual Questionnaire for a successor within three (3) months from the vacancy of the position.
Provided that in any case, the provisions of the Directive on the Assessment of Fitness and Propriety of Members of the Administrative Organ, Senior Management, and Persons Responsible for the Management of Payment Institutions of 2025 are observed.
Risk Management Function.
(2) The risk management function shall have sufficient powers, authority, and resources, appropriate to the size and complexity of the institution, to be able to implement the institution's risk policies and risk management framework.
(3) The head of the risk management function reports to the administrative organ through the Risk Committee and, where applicable, to its committees, including specifically the risk committee, to convey any concerns and to warn, when deemed appropriate, of developments related to a risk that affect or may affect the institution.
(4) The staff of the risk management function possesses a sufficient level of knowledge, skills, and experience in risk management technical and procedural matters.
(5) The risk management function is actively involved in the processing and development of the institution's strategy and risk appetite allocation and in all significant risk management decisions.
(6) The risk management function ensures the identification, assessment, measurement, monitoring, and management of all risks to which the institution is exposed and informs the administrative organ, or, where applicable, the risk committee, accordingly.
(7) The risk management function:
(a) ensures that all identified risks are effectively monitored by operational units,
(b) analyzes market trends and identifies any new or emerging risks as well as cases of increased risks arising from changing circumstances and conditions,
(c) regularly compares actual risk losses with previous estimates (back-testing) to assess and improve the accuracy and effectiveness of the risk management process,
(d) evaluates possible ways to reduce risks.
(e) regularly monitors the institution's actual risk profile and examines it in detail in relation to the institution's strategic objectives and risk appetite allocation, to facilitate decision-making and critical review by the administrative organ.
(8) The head of the risk management function submits an annual report and ad hoc reports when deemed necessary to the administrative organ, through the risk committee, with a copy to the Chief Executive Officer. The reporting period of the report covers the respective calendar year, unless the period is differentiated in consultation with the Central Bank. The report includes at least a summary of risks related to the institution's activities, their internal assessment, the results and assumptions of the analyses performed, proposed risk reduction measures, and information on the external environment, to determine market conditions and trends that may affect the institution's existing risk profile and thus be taken into account for shaping a new risk profile, if the institution deems it necessary.
Regulatory Compliance Function.
(2) The administrative organ of the institution is responsible for establishing and overseeing the implementation of a well-designed and comprehensive regulatory compliance policy, which is documented in a relevant document and communicated to all staff members.
(3) The institution ensures that the regulatory compliance policy identifies the business and legal environment applicable to the institution and defines the objectives, principles, and allocation of regulatory compliance responsibilities.
(4) The institution establishes a procedure for the regular assessment of changes in legislative and regulatory provisions governing its activities.
(5) The head of the institution's regulatory compliance function:
(a) contributes to the formulation of the institution's regulatory compliance policy;
(b) reports to the administrative organ and provides recommendations on measures to be taken and organizational and procedural changes to ensure compliance with the current regulatory framework;
(c) assesses the impact that changes in the legislative or regulatory framework will have and submits proposals and recommendations to the administrative organ for adjusting the institution's regulatory compliance framework;
(d) ensures that monitoring of compliance with the regulatory framework is carried out through a structured and clearly defined compliance monitoring program and that the regulatory compliance policy is maintained;
(e) maintains adequate contact with the Central Bank and other authorities, and ensures that the views and concerns of supervisory authorities and any views and concerns of shareholders that come to his knowledge are fully communicated to the administrative organ;
(f) issues written instructions and circulars to staff, business units, and relevant departments of the institution for their timely and adequate information on regulatory compliance matters and/or adaptation of internal procedures and regulations to changes in the regulatory framework;
(g) provides advice and responds to inquiries regarding compliance matters from staff.
(6) The regulatory compliance function and the risk management function cooperate and exchange information appropriately to be able to perform their duties. The findings of the regulatory compliance function are taken into account by the administrative organ for decision-making and by the risk management function for monitoring, assessing, and measuring risks.
(7) The head of the regulatory compliance function submits a report, on an annual basis and exceptionally when deemed necessary, to the administrative body, through the audit committee, with a copy to the chief executive officer, which includes at least:
(i) information on the main regulatory compliance risk indicators monitored by the regulatory compliance function, (ii) updated information on the operational and regulatory framework, (iii) significant penalties or other disciplinary measures imposed during the previous year by supervisory authorities concerning the institution or any of its staff. The reporting period of the report covers the respective calendar year, unless the period is differentiated in consultation with the Central Bank.
(8)(a) The regulatory compliance function ensures the institution's compliance with the Law on the Prevention and Combating of Money Laundering from Illegal Activities of 2007 and the Central Bank's Directives on the prevention of money laundering from illegal activities and terrorist financing, as well as the relevant Circulars of the Central Bank.
(b) The institution appoints a compliance officer in accordance with the requirements of Article 69 of the Law on the Prevention and Combating of Money Laundering from Illegal Activities of 2007 and in compliance with the provisions of the relevant sub-paragraphs of the Directive on the Prevention of Money Laundering from Illegal Activities and Terrorist Financing of 2025, which define, among other things, the role and duties of the compliance officer.
(c) The institution may establish a separate compliance function regarding the prevention of money laundering from illegal activities and terrorist financing, as an independent control function.
ICT Risk Management Function.
(2) The institution ensures that the head and staff of the ICT risk management function possess a sufficient level of knowledge, skills, and experience to perform their duties.
(3) The head of the ICT risk management function submits reports on an annual basis and exceptionally when deemed necessary, to the administrative body, through the risk committee, with a copy to the chief executive officer, as listed in point (c) of sub-paragraph (2) of paragraph 36 of the Directive.
Internal Audit Function.
(2) The institution appoints a person as head of the internal audit function and ensures that the head and staff of the internal audit function possess a sufficient level of knowledge, skills, and experience in matters of internal audit techniques and procedures.
(3) The internal audit function evaluates both the effectiveness and efficiency of the institution's internal audit framework and evaluates:
(a) the suitability of the institution's governance framework; (b) whether existing policies and procedures governing the institution's operations, including those subject to outsourcing, are applied correctly and effectively, are adequate, and comply with legislative and regulatory requirements, as well as address risks in the institution's operations; (c) compliance with decisions of the administrative body and senior management; (d) the adequacy, quality, and effectiveness of audits conducted and reports submitted by supporting operational units, as well as by the internal audit system functions; (e) the accuracy of reports submitted to the Central Bank, by conducting sample checks; (f) other matters that may be requested by the administrative body, senior management, or the Central Bank.
(4) The internal audit function should not be involved in the design, selection, establishment, and implementation of specific policies, mechanisms, and procedures of the internal audit system, nor of risk limits.
(5) The internal audit function has unrestricted access to all files, documents, information, and building infrastructure of the institution. This access includes access to information management systems and the minutes of all committees and decision-making bodies.
(6) The internal audit function prepares an internal audit plan at least once a year based on annual internal audit objectives. The internal audit plan is approved by the administrative body to ensure its effective and timely implementation.
(7) The head of the internal audit function submits a report on an annual basis, to the administrative body and exceptionally when deemed necessary, through the audit committee and with a copy to the chief executive officer. The reporting period of the report covers the respective calendar year, unless the period is differentiated in consultation with the Central Bank. The report includes at least the most significant findings arising from audits conducted since the last report to the administrative body, as well as recommendations for addressing any identified weaknesses.
Audit Missions.
(2) At least the following audit activities are included in the scope of internal audit missions:
(a) assessment of the degree of compliance of operational units and internal audit system functions with officially defined instructions and procedures.
(b) assessment of the degree of integration into all processes and transactions conducted of appropriate risk prevention and control mechanisms; (c) assessment of the completeness and adequacy of the institution's information security policy, including information system security; (d) assessment of the degree of implementation of procedures for the approval of new products in accordance with new product approval procedures and whether these procedures are adequate and effective; (e) assessment of systems and procedures governing the extraction of reliable, complete, and updated financial, administrative, and regulatory information; (f) assessment of the completeness and adequacy of the institution's business continuity plans and information system disaster recovery plans; (g) assessment of the completeness and effectiveness of the outsourcing policy; (h) assessment of the adequacy and effectiveness of the means and resources available to operational units and control functions, as well as the collective bodies of the institution.
Audit Plan.
Outsourcing of Activities.
EBA/GL/2019/02
25.02.2019.
Official Journal of the E.U.:
L2024/1773
25.6.2024
(2) The institution, respecting the principle of proportionality, establishes an outsourcing function and in any case appoints a senior staff member, as the Outsourcing Officer, who reports directly to the administrative body. The Outsourcing Officer is responsible, as head for the management and supervision of the risks of outsourcing agreements as part of the institution's internal audit framework, as well as responsible for the supervision of the documentation of outsourcing agreements. They prepare an annual report submitted to the administrative body regarding the outsourcing of activities.
(3) The Outsourcing Officer is, within the framework of their duties, the contact person with the Central Bank for outsourcing matters and provides all information required.
(4) The institution maintains an updated register of information for all outsourcing agreements in accordance with the provisions of the Guidelines referred to in sub-paragraph (1) and makes available to the Central Bank, whenever requested, either the full register or parts thereof concerning the outsourcing of specific activities.
(5) The institution clearly assigns responsibilities for the documentation, management, and control of outsourcing agreements and has sufficient resources to ensure compliance with all legislative and regulatory requirements, including the EBA guidelines and Regulation (EU) 2022/2554 referred to in sub-paragraph (1) and the documentation and monitoring of all outsourcing agreements.
(6) The institution remains fully responsible for all services subject to outsourcing, as well as for the activities and management decisions arising from them. The outsourcing policy of activities should make it clear that outsourcing does not exempt the institution from its regulatory obligations and its responsibilities towards its customers.
(7) The institution includes in the outsourcing contract a provision according to which the person to whom significant operational activities are outsourced must, in relation to the reported activities, submit to the Central Bank any information that the Central Bank may require.
ICT Risk.
EBA/GL/2019/04
29.11.2019.
New Products and Significant Changes.
EBA/GL/2015/18
15.07.2015.
(2) The new product approval policy includes significant changes that occur in relevant processes, for example, new outsourcing arrangements, and in corresponding systems, for example, technology system change procedures.
(3) The new product approval policy ensures that approved products and changes are consistent with the risk strategy or that the required reviews are conducted.
(4) The significant changes or exceptional transactions referred to in sub-paragraph (1) as components of the new product approval policy may include mergers and acquisitions, including the potential impacts of conducting insufficient due diligence that fails to identify risks and liabilities post-merger; the establishment of structures (for example, new subsidiaries or single purpose vehicles); new products; changes either to systems or to the risk management framework or procedures, and changes in the organization of the institution.
(5) The institution has specific procedures for assessing compliance with new product approval policies, taking into account data originating from the risk management function. These procedures include the systematic prior assessment and documented opinion of the regulatory compliance function for new products or significant changes to existing products.
(6) The institution's policy for new product approval covers every parameter that must be taken into account before making a decision to enter new markets, buy/sell new products, start providing a new service, or make significant changes to existing products or services.
(7) The new product approval policy also includes the definitions of the concepts "new product/new market/new business activity" and "significant changes" to be used in the institution, as well as the internal functions that will be involved in the decision-making process.
(8) The new product approval policy defines the main issues to be addressed before making the relevant decisions. These issues include the following: regulatory compliance, accounting, pricing models, impact on the risk profile, profitability, availability of resources for adequate front office services, organizational support services (back office), availability of appropriate internal tools, and expertise for understanding and monitoring relevant risks.
(9) The institution identifies and assesses the money laundering and terrorist financing risk associated with the development of new products and new business practices, including new delivery mechanisms, as well as regarding the use of new or emerging technologies for both new and pre-existing products, before promoting or using these products, practices, and technologies, and takes measures to mitigate the risk, in accordance with the Law on the Prevention and Combating of Money Laundering from Illegal Activities of 2007 as amended or replaced from time to time.
(10) In the decision to start a new activity, the responsible business unit and responsible persons should be clearly defined. New activities should not be undertaken if adequate resources for understanding and managing relevant risks have not been secured.
(11) The risk management function, the ICT risk management function, and the regulatory compliance function participate in the approval of new products or significant changes to existing products, processes, and systems. Their contribution includes a full and objective assessment of the risks arising from new activities under various scenarios, potential deficiencies in the institution's risk management and internal audit systems, as well as the institution's ability to effectively manage new risks.
(12) The risk management function also has a clear overall picture of the introduction of new products, or significant changes to existing products, processes, and systems, for all business sectors and portfolios, as well as the authority to require that changes to existing products be submitted to the official new product approval process.
PART V - REPORTS TO THE CENTRAL BANK
Submission of Reports to the Central Bank.
(1) Within six (6) months from the end of each year, excluding point (c) where submission within two (2) months is required, the following reports and information, accompanied by the respective assessments of the relevant committees of the administrative body and relevant excerpts from the minutes of the administrative body meetings:
(a) the annual report of the head of the internal audit function, which is prepared based on the provisions of sub-paragraph (7) of paragraph 30, in accordance with the provisions of paragraphs 31 and 32; (b) the annual report of the outsourcing officer, which is prepared based on the actions taken in accordance with the provisions of sub-paragraph (2) of paragraph 33; (c) the two annual reports of the head of the ICT risk management function, which are prepared:
(i) as required in accordance with the provisions of sub-paragraph (5) of Article 6 of Regulation (EU) 2022/2554 and in accordance with Delegated Regulation (EU) 2024/1774 regarding the regulatory technical standards for determining the tools, methods, procedures, and policies for ICT risk management, as well as the simplified ICT risk management framework and (ii) as required in accordance with the provisions of paragraph (2) of Article 95 of the Law and the provisions of Article (8) of Regulation (EU) 2022/2554
(d) the annual report of the head of the risk management function, which is prepared based on the actions taken in accordance with the provisions of sub-paragraph (8) of paragraph 27; (e) the annual report of the head of the regulatory compliance function, which is prepared based on the actions taken in accordance with the provisions of sub-paragraph (8) of paragraph 28;
(2) The assessment reports regarding the adequacy and effectiveness of the internal audit framework which are drawn up by an external auditor, in accordance with the provisions of sub-paragraph (5) of paragraph 23, within six (6) months from the end of the assessment period.
PART VI - OTHER PROVISIONS
Transparency.
Entry into Force.
(2) By way of derogation from sub-paragraph (1), the institution submits to the Central Bank within three (3) months from the date of entry into force of the Directive a draft action plan for its full compliance with the provisions of this Directive.
(3) In any case, the institution must have fully complied within nine (9) months from the date of entry into force of the Directive.
Read the rest free
Source: Central Bank of Cyprus — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CBC
We email you every new CBC publication the day it's published.