2026-07-27
Added · Updated
The Central Bank of Cyprus mandates credit institutions to implement specific internal governance arrangements, including risk management frameworks, internal control systems, remuneration policies, and organizational structures, in alignment with EU Directives 2019/878/EU and 2013/36/EU. The directive applies to credit institutions resident in the Republic, as well as parent and subsidiary companies on a consolidated or sub-consolidated basis, while excluding third-country branches. It establishes detailed requirements for the administrative body, senior management, risk functions, and reporting to the competent authority, with provisions for exemptions where application is unconstitutional under third-country law.
Get CBC alerts — same-day email on every new publication.
CENTRAL BANK OF CYPRUS
UNOFFICIAL CONSOLIDATION OF THE DIRECTIVE TO LICENSED CREDIT INSTITUTIONS ON INTERNAL GOVERNANCE of 2021 to (No. 2) 2026 JUNE 2026
THE LAW ON CREDIT INSTITUTION OPERATIONS
LAWS OF 1997 TO 2026
Directive pursuant to Articles 19 and 41(1) and (2) 66(I) of 1997 74(I) of 1999 94(I) of 2000 119(I) of 2003 4(I) of 2004 151(I) of 2004 231(I) of 2004 235(I) of 2004 20(I) of 2005 The Central Bank, exercising the powers conferred upon it by Articles 19 and 41(1) & (2) of the Law on Credit Institution Operations of 1997 to 2026, and for the purpose of harmonization with Directive 2019/878/EU of the European Parliament and of the Council of 20 May 2019 on the amendment of Directive 2013/36/EU as regards exempted entities, financial holding companies, mixed financial holding companies, remuneration, supervisory measures and powers and capital conservation measures, and of re-harmonization with Directive 2013/36/EU on access to the activity of credit institutions and the prudential supervision of credit institutions and investment firms, amending Directive 2002/87/EC and repealing 80(I) of 2008 100(I) of 2009 123(I) of 2009 27(I) of 2011 141(I) of 2011 107(I) of 2012 14(I) of 2013 87(I) of 2013 102(I) of 2013 104(I) of 2013 5(I) of 2015 26(I) of 2015 35(I) of 2015 71(I) of 2015 93(I) of 2015 109(I) of 2015 152(I) of 2015 168(I) of 2015 21(I) of 2016 5(I) of 2017 38(I) of 2017 169(I) of 2017 28(I) of 2018 89(I) of 2018 153(I) of 2018 80(I) of 2019 149(I) of 2019 21(I) of 2020 73(I) of 2020 28(I) of 2021 94(I) of 2021 95(I) of 2021 162(I) of 2021 163(I) of 2021 61(I) of 2022 62(I) of 2022 162(I) of 2022 17(I) of 2023 59(I) of 2024 158(I) of 2024 14(I) of 2025 84(I) of 2026. Official Journal of the E.U.: L150, 7.6.2019, p. 253 Official Journal of the E.U.: L176, 27.6.2013, p. 338. EBA/GL/2021/05 02.07.2021 Directives 2006/48/EC and 2006/49/EC, and for the purpose of harmonization with the EBA Guidelines on internal governance, issues this Directive.
PART 1 – TITLE, PURPOSE, SCOPE AND INTERPRETATIONS
Short title.
Official Journal of the E.U.: Part III(I):
15.10.2021
(L.C.R. 426/2021)
Official Journal of the E.U.: Part III(I):
7.7.2023
(L.C.R. 213/2023)
Official Journal of the E.U.: Part III(I):
29.12.2023
(L.C.R. 428/2023)
Official Journal of the E.U.: Part III(I):
29.11.2024
(L.C.R. 395/2024)
Official Journal of the E.U.: Part III(I):
7.4.2025
1.- This Directive shall be known as the Directive on Internal Governance of Credit Institutions of 2021 to (No. 2) of 2026.
(L.C.R. 103/2025)
Official Journal of the E.U.: Part III(I):
28.4.2026
(L.C.R. 203/2026)
Official Journal of the E.U.: Part III(I):
2.6.2026
(L.C.R. 253/2026).
Purpose. 2.- This Directive specifies the arrangements, procedures and mechanisms of internal governance that credit institutions must implement, in accordance with Article 19 of the Law, to ensure the effective and prudent management of the credit institution.
Scope. 3.- (1) This Directive applies in relation to the governance arrangements of credit institutions, as specified in sub-paragraph (2), including their organizational structure and corresponding lines of responsibility, procedures for identifying, managing, monitoring and reporting the risks they undertake or may undertake, the internal control framework as well as remuneration policies and practices. (2) This Directive applies to credit institutions resident in the Republic, on an individual basis, unless the Central Bank makes use of the derogation provided for in Article 7 of Regulation (EU) No. 575/2013. Furthermore, parent companies and subsidiaries for which this Directive applies must – (a) comply with the obligations arising from this Directive on a consolidated or sub-consolidated basis to ensure that the arrangements, procedures and mechanisms maintained as provided for in this Directive are consistent and complete and that any data and information relevant for the purpose of supervision can be extracted, (b) apply such arrangements, procedures and mechanisms to their subsidiary companies that are not subject to this Directive, so as to ensure that these arrangements, procedures and mechanisms are consistent and complete and that these subsidiaries are able to produce any data and information relevant for the purpose of supervision, (3) Obligations arising from this Directive regarding subsidiary companies, which are not themselves subject to the provisions of this Directive, do not apply if the parent institution established in the EU or institutions controlled by a financial holding parent company established in the EU or by a mixed financial holding parent company established in the EU, can prove to the Central Bank that the application of this Directive is unconstitutional according to the legal framework of the third country where the subsidiary is established. (4) The provisions of Part 5 apply at group, parent and subsidiary level, including those established in offshore financial centres. (5) Branches of credit institutions of third countries in the Republic are excluded from the scope of this Directive. Interpretations. 4.- (1) For the purposes of this Directive, the interpretations provided for in the Law apply, unless a different interpretation emerges from the text. In addition, the following definitions apply:
6(I) of 2015
93(I) of 2021
“other systemically important institutions” or “O-SII” means the institutions as defined in Article 6 of the Macroprudential Supervision Law of 2015; “chief financial officer” means the person who is overall responsible for the management of all of the following activities: management of financial resources, financial planning and financial information; L.C.R. 179/2020 Official Journal of the E.U.: Part III(I) No. 5255 29.04.2020 No. 435 18.09.2020 “independent member of the administrative body” means a person appointed as an independent member following approval by the competent authority, having met the independence criteria set out in the Directive on the Assessment of the Fitness and Propriety of Members of the Administrative Body and Persons Holding Key Functions in Licensed Credit Institutions of 2020; “country exposure” means the totality of the credit institution’s assets, on and off balance sheet, linked to a foreign country. It includes, among others, exposures to counterparties established in that country, exposures whose performance depends essentially, in the assessment of the credit institution itself, on the economic or other conditions prevailing in that country, as well as exposures for which the ultimate risk arises from that country. The country exposure covers at least, credit exposures (including loans, advances and securities), interbank positions, derivatives and exposures to counterparties (including potential future exposure), guarantees, credit letters and other contingent liabilities, trade finance exposures, cross-border intra-group exposures as well as exposures arising from securities financing transactions, including repurchase/reverse repurchase agreements (repo/reverse repo), where the issuer of the provided collateral is established in a foreign country; Official Journal of the E.U.: L176 27.06.2013, p. 1. Official Journal of the E.U.: L287 29.10.2013, p. 63. “competent authority” means competent authority as defined in Article 4 paragraph 1 point (40) of Regulation (EU) No. 575/2013 and/or the European Central Bank for the purpose of exercising the tasks assigned to it under Regulation (EU) No. 1024/2013; “risk appetite” means the aggregate level and types of risks that a credit institution is willing to undertake within its risk-taking capacity, and in accordance with its business model, in order to achieve its strategic goals; “managing director” means the member of the administrative body who is responsible for the management and coordination of the overall business activities of a credit institution; “outsourcing” means an agreement of any form between a credit institution and a service provider, whereby the service provider performs a process, provides a service or exercises an activity that would otherwise have been performed, provided or exercised by the institution itself; 53(I) of 2017 171(I) of 2017 7(I) of 2018 69(I) of 2019 12(I) of 2020 “external auditor” means a third independent person, other than
the staff of the credit institution or the approved auditor, appointed for the purpose of auditing the credit institution and who is a legal auditor and/or legal audit office, within the meaning given to these terms by Article 2 of the Auditors Law; “head of the internal control system functions” means the persons at the highest hierarchical level, who are responsible for the effective management of the daily operation of the independent risk management, regulatory compliance, internal audit and ICT and security risk management functions; “supervisory consolidation” means the application of the prudential supervision rules provided for in Directive 2013/36/EU and Regulation (EU) No. 575/2013 on a consolidated or sub-consolidated basis, in accordance with Part 1 Title 2 Chapter 2 of Regulation (EU) No. 575/2013. Supervisory consolidation includes all subsidiaries that are institutions or financial institutions, as defined in Article 4(3) and (26) of Regulation (EU) No. 575/2013, respectively, and may also include ancillary service providers, as defined in Article 2(18) of the same Regulation, established within or outside the EU; “internal methods” means the method based on internal assessments referred to in Article 143 paragraph 1 of Regulation (EU) No. 575/2013, the internal models method referred to in Article 221 of Regulation (EU) No. 575/2013, the internal ratings method referred to in Article 225 of Regulation (EU) No. 575/2013, the advanced measurement methods referred to in Article 312 paragraph 2 of Regulation (EU) No. 575/2013, the internal models method referred to in Articles 283 and 363 of Regulation (EU) No. 575/2013 and the supervisory model method referred to in Article 259 paragraph 3 of Regulation (EU) No. 575/2013; “executive member of the administrative body position” means the position of member of the administrative body within the framework of which a person is responsible for actually directing the activities of the credit institution through an employment contract concluded with the said institution; “institution subject to consolidation” means a credit institution which is required to comply with the prudential supervision requirements based on the consolidated or sub-consolidated situation, in accordance with Part 1 Title 2 Chapter 2 of Regulation (EU) No. 575/2013; “risk-taking capacity” means the maximum level of risk that a credit institution is able to undertake given its capital base, its capabilities regarding risk management and control and its regulatory constraints; Official Journal of the E.U.: L158 27.05.2014, p. 77. Official Journal of the E.U.: L333/1 27.12.2022, p.1 “Regulation (EU) No. 537/2014” means Regulation (EU) No. 537/2014 of the European Parliament and of the Council on specific requirements regarding the statutory audit of public interest entities and repealing Commission Decision 2005/909/EC; “Regulation (EU) No. 2022/2254” means Regulation (EU) 2022/2554 of the European Parliament and of the
Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No. 1060/2009, (EU) No. 648/2012, (EU) No. 600/2014, (EU) No. 909/2014 and (EU) 2016/1011; Official Journal of the E.U.: L203 09.06.2021, p. 1. “Commission Delegated Regulation (EU) No. 2021/923” means Commission Delegated Regulation (EU) No. 2021/923 supplementing Directive 2013/36/EU of the European Parliament and of the Council as regards regulatory technical standards for the determination of the criteria on the basis of which management responsibilities, control functions, significant business units and significant impact on the risk characteristics of a significant business unit are defined, as well as the criteria for the determination of members or categories of staff, whose professional activities have an impact on the risk characteristics of the institution, both significantly and the impact of the members or categories of staff referred to in Article 92 paragraph 3 of the said Directive; “transmission risk” means the risk of loss, liquidity and/or financing that arises when adverse developments in one country are transmitted and lead to a deterioration of the economic conditions of another country of the same geographical area or with similar economic characteristics, in which the credit institution maintains exposures; “convertibility risk” means the risk of loss, liquidity and/or financing that arises when the counterparty is unable to convert the local currency into the currency of the obligation or to continue the uninterrupted provision of liquidity or financing to the credit institution, due to actions or restrictions imposed by public authorities, including restrictions on access to foreign exchange; “transfer risk” means the risk of loss, liquidity and/or financing that arises when the counterparty fails to pay in the currency of the obligation or to transfer funds in the currency of the obligation or to continue the uninterrupted provision of liquidity or financing to the credit institution, due to restrictions or controls imposed by public authorities or due to foreign exchange shortages; EBA/GL/2019/02 “ICT and security risk” means the risk of loss due to breach of confidentiality, failure of system and data integrity, unsuitability or unavailability of systems and data, or inability to change information technology within a reasonable time and at reasonable cost, when the requirements of the environment or business activities change. In this context, security risks arising from inadequacy or failure of internal processes or external events are included, including cyberattacks or inadequate physical security; “model risk” means the loss that an institution is threatened with as a result of decisions based primarily on the results of internal models, due to errors in the establishment, implementation or use of these models; “reputation risk” means the existing or future risk to the profits, own funds or
liquidity of the institution, arising from damage to the institution’s reputation; “country risk” means the risk of exposure to losses and/or the risk of liquidity and/or financing that arises for a credit institution due to adverse economic, political, social, legal or exchange rate developments in a specific country in which the credit institution maintains exposures; “risk culture” means the rules, attitudes and behaviors of a credit institution related to the awareness of risk, risk-taking and risk management, as well as the control systems that shape decisions regarding risks. The risk culture affects the decisions of management and employees in the exercise of daily activities and has an impact on the risks they undertake; “sovereign risk” means the risk of loss, liquidity and/or financing that arises when a government and/or organization or other public sector entity whose liabilities are fully and explicitly covered by the government of the relevant country, does not have
PART 2 – PROPORTIONALITY
5. Proportionality
PART 3 – ROLE AND COMPOSITION OF THE ADMINISTRATIVE BODY AND COMMITTEES
Section I – Administrative Body
6. General requirements
7. Role and responsibilities of the administrative body
8. Size and composition of the administrative body
9. Role of the chairman of the administrative body
10. Senior independent member of the administrative body
11. Meetings of the administrative body
12. Minutes of administrative body meetings
13. Role and responsibilities of the secretary
14. Access of the administrative body and committees to resources and information
15. Identification, selection and succession of members of the administrative body.
16. Evaluation of the administrative body
Section II – Administrative Body Committees
17. Establishment of administrative body committees
18. Composition of administrative body committees
19. Committee procedures
20. Role of the risk committee
21. Role of the audit committee
22. Role of the remuneration committee
23. Role of the nomination committee
24. Joint committees
PART 4 – SENIOR MANAGEMENT
25. Numerical adequacy and expertise of senior management
26. Selection, development and succession of senior management
27. Roles and responsibilities of senior management
28. Supervision of the institution’s operations and guidance on a daily basis
29. Providing advice to the administrative body
PART 5 – REMUNERATION FRAMEWORK
30. Remuneration policies
31. Variable remuneration components
32. Institutions benefiting from government intervention
PART 6 – GOVERNANCE FRAMEWORK
33. Organizational framework
34. Knowledge and understanding of the credit institution’s structure
35. Complex structures and non-standard or non-transparent activities
36. Organizational framework at group level
PART 7 – OUTSOURCING OF WORK TO THIRD PARTIES
37. Outsourcing policy
38. Outsourcing procedures
PART 8 – RISK APPETITE CULTURE AND CORPORATE BEHAVIOR
39. Risk culture
40. Corporate values and code of conduct
41. Conflict of interest policy at the credit institution level
42. Conflict of interest policy for staff
43. Internal alert procedures
44. Reports to the competent authority
PART 9 – RISK MANAGEMENT FRAMEWORK
Section I – Handling Specific Risks
45. Credit risk and counterparty risk
46. Residual risk
47. Concentration risk
48. Securitization risk
49. Market risk
50. Interest rate risk from trading book activities
51. Operational risk
51A. Reputation Risk
51B. Country Risk
52. Information and Communication Technology (ICT) and Security Risk
53. Liquidity risk
54. Excessive leverage risk
Section II – Internal Control Framework and Mechanisms
55. Internal control framework
56. Implementation of internal control framework
57. Risk management framework
58. New products and significant changes
Section III – Internal Control System Functions
59. Internal control system functions – General Requirements
60. Manual of internal control system functions
61. Head of the internal control system functions
62. Independence of the internal control system functions
63. Combination of the internal control system functions
64. Resources of the internal control system functions
Section IV – Risk Management Function
65. Risk management function – General requirements
66. The role of the risk management function in risk strategy and decisions regarding risk
67. The role of the risk management function in significant changes
68. The role of the risk management function in identifying, measuring, assessing, managing, mitigating, monitoring and reporting risks
69. The role of the risk management function in handling unapproved exposures
70. Head of the risk management function
71. Reporting requirements of the risk management function
Section V – Regulatory Compliance Function
72. Regulatory compliance function – General requirements
73. Reporting requirements of the regulatory compliance function
74. Role of the regulatory compliance function in preventing money laundering from illegal activities
Section VI – Information and Communication Technology (ICT) and Security Risk Management Function
75. ICT and security risk management function – General requirements
76. Reporting requirements of the ICT and security risk management function
Section VII – Internal Audit Function
77. Internal audit function – General requirements
78. Audit missions
79. Audit plans
80. Reporting requirements of the internal audit function
81. Cooperation of the internal audit function with the competent authority
82. External assessment of the adequacy of the internal control framework
PART 10 – BUSINESS CONTINUITY MANAGEMENT
83. Business continuity management
PART 11 – TRANSPARENCY
84. Transparency
85. Disclosures
PART 12 – REPORTING TO THE COMPETENT AUTHORITY
86. Reporting to the competent authority
PART 13 – MISCELLANEOUS PROVISIONS
87. Repeal
88. Entry into force
APPENDIX I Aspects to be taken into account when developing an internal governance policy
APPENDIX II Assessment of the adequacy of the internal control framework prepared by external auditors
ability or willingness to repay its direct or indirect (guaranteed) obligations;
"gender pay gap" means the difference between the average annual total gross earnings of men and women expressed as a percentage of the average annual total gross earnings of men;
"Law" means the Laws on the Operations of Credit Institutions of 1997 to (No. 3) 2021;
"service provider" means a third entity that undertakes an outsourced process, service, or activity, or part thereof, under an outsourcing agreement;
"credit institution" means a credit institution as defined in Article 4(1)(1) of Regulation (EU) 575/2013;
"persons holding key functions" means persons who exercise significant influence on the management of the CI, but are neither members of the administrative organ nor the managing director, and include the heads of the functions of the internal control system and the chief financial officer, if they are not members of the administrative organ, and, if determined by the CI according to a risk-based approach, other persons holding key functions, which may include the heads of significant business units, branches within the European Economic Area/European Free Trade Association, and subsidiaries in third countries;
Official Journal of the EU: L176 of 27.6.2013, p. 338.
"staff" means the total workforce of a credit institution and its subsidiaries within the scope of its consolidation, including subsidiaries not subject to Directive 2013/36/EU, and the total number of members of the administrative organ;
"significant institutions" means credit institutions referred to in Article 6 of the Law on Macroprudential Supervision of Institutions of 2015 [global systemically important institutions (G-SII) and other systemically important institutions (O-SII)] and, where applicable, other credit institutions determined by competent authorities, based on an assessment of the size and internal organization of credit institutions, as well as the nature, scope, and complexity of their activities;
"ICT" means information and communication technology.
"foreign currency funding exposure" means the total liabilities and funding sources of a credit institution that originate directly or indirectly from a foreign country. It includes, at a minimum, deposits taken from non-residents of Cyprus, funding through markets drawn from non-domestic counterparties, including debt issuances funded by non-domestic counterparties, funding provided by non-domestic public sector entities, funding and liquidity flows linked to derivative transactions with non-domestic counterparties, as well as cross-border intra-group funding;
The terms "critical function" and "essential function" have the same meaning for the purposes of this Directive.
(2) (a) In this Directive, any reference to a Directive, Regulation, Decision, or other legislative act of the European Union means that act as amended, modified, or replaced from time to time, unless a different meaning arises from the text.
(b) In this Directive, any reference to a law or regulatory administrative act of the Republic means that law or regulatory administrative act as amended, modified, or replaced from time to time, unless a different meaning arises from the text.
PART 2 – PROPORTIONALITY
Proportionality. 5.- (1) The framework, arrangements, procedures, and mechanisms of internal governance must be extensive and proportional to the nature, size, and complexity of the risks inherent in the institution's business model and activities.
(2) In developing and implementing internal governance arrangements, credit institutions take into account their size and internal organization, as well as the nature, scale, and complexity of their activities. Significant institutions should have more advanced governance arrangements, while small and less complex institutions may implement simpler governance arrangements. However, institutions must take into account that the size or systemic importance of an institution may not be indicative on its own of the degree of the institution's exposure to risk.
(3) For the purposes of applying the principle of proportionality as referred to in sub-paragraph (2), the following criteria are taken into account, both by credit institutions for the purpose of applying the requirements of the Directive and by the competent authority for the purpose of assessing the compliance of credit institutions with the requirements of this Directive:
(a) the size in terms of total assets on the balance sheet of the credit institution and its subsidiaries within the scope of supervisory consolidation; (b) the geographical presence of the credit institution and the size of its activities in each jurisdiction; (c) the legal form of the credit institution, including whether the credit institution belongs to a group and, if so, the proportionality assessment conducted for the group; (d) whether the credit institution's securities are listed on a regulated market; (e) whether the credit institution has received approval from the competent authority to use internal models for measuring capital requirements (e.g., internal ratings-based approach); (f) the type of activities and services for which the credit institution has received a license to operate, such as those provided in Annex IV of the Law; (g) the core business model and core business strategy, the nature and complexity of business activities, as well as the organizational structure of the credit institution; (h) the risk strategy, risk-taking appetite, and actual risk profile of the credit institution, also taking into account the outcome of the Supervisory Review and Evaluation Process (SREP) for capital adequacy and liquidity; (i) the ownership structure and financial structure of the credit institution; (j) the type of customers (e.g., retail customers, corporate customers, institutional customers, small businesses, public entities) and the complexity of products or contracts; (k) the activities subject to outsourcing and distribution channels; (l) existing ICT systems, including business continuity systems and outsourcing of activities in this specific sector; and (m) whether the institution falls under the definition of "small and non-complex credit institution" or "large institution" according to the definitions in points 145 and 146 of Article 4(1) of Regulation (EU) No 575/2013.
PART 3 – ROLE AND COMPOSITION OF THE ADMINISTRATIVE ORGAN AND COMMITTEES
Section I – Administrative Organ
General Requirements. 6.- (1) The administrative organ has the final and general responsibility for the credit institution and defines, oversees, and is accountable for the implementation of governance arrangements within the credit institution that ensure its effective and prudent management, including the segregation of duties and the prevention of conflicts of interest.
(2) Subject to the provisions of Article 19B of the Law, the arrangements referred to in sub-paragraph (1) comply with the following principles:
(a) the administrative organ has the general responsibility for the credit institution and approves and oversees the implementation of the strategic objectives, risk strategy, and internal governance of the credit institution; (b) the administrative organ ensures the integrity of accounting systems and financial reporting systems, including financial and operational controls and compliance with the relevant legislative framework and related standards; (c) the administrative organ oversees the disclosure process and announcements to external stakeholders and competent authorities; (d) the administrative organ is responsible for the effective oversight of senior management; (e) subject to the provisions of Article 19B(1) of the Law, the chairman of the administrative organ of the credit institution must not simultaneously serve as managing director in the same credit institution; (f) members of the administrative organ must meet the requirements set out in the Directive on the Assessment of the Suitability of Members of the Administrative Organ and Persons Holding Key Functions in Licensed Credit Institutions of 2020; (g) all members of the administrative organ devote sufficient time to the performance of their duties at the institution, including the preparation of administrative organ meetings.
(3) For the purposes of point (d) of sub-paragraph (2), the administrative organ establishes appropriate policies, practices, and procedures to ensure that senior management perform their roles and responsibilities in accordance with the provisions of paragraphs 25 to 29.
The practices and procedures include, inter alia, the following:
(a) regular meetings with senior management;
(b) questioning and critical examination of explanations and information provided by senior management; (c) setting formal performance objectives for senior management in line with the long-term objectives, strategy, and financial soundness of the institution, and monitoring the performance of senior management against these objectives.
(4) (a) Credit institutions ensure that data regarding financial exposures to members of the administrative organ and their connected parties are duly documented and made available to the competent authority upon request.
(b) For the purposes of this sub-paragraph, the term "connected party" means:
184(I)/2015
115(I)/2020
(i) spouse, partner as defined in the Law on Civil Partnership of 2015, child, or parent of a member of the administrative organ, (ii) a commercial entity in which a member of the administrative organ or a close relative as referred to in point (i) has an ownership interest of 5% or more of the capital or voting rights in that entity, or in which such persons can exercise significant influence, or in which such persons hold senior management positions or are members of the administrative organ, (iii) other natural or legal persons connected to the member of the administrative organ through a relationship of significant influence, exercised either by the member of the administrative organ or by the other natural or legal persons.
(c) Among the possible indicators of exercising significant influence as referred to in sub-points (ii) and (iii) of point (b), which institutions should take into account when conducting their assessment for the existence of a connection, include by analogy the provisions of Article 4(1)(39) of Regulation (EU) 575/2013, as well as the following:
(i) Regardless of any ownership percentage, each of the following powers of a person who happens to be a member of the administrative organ or a person connected to a member of the administrative organ provides an indication of the exercise of control by that member of the administrative organ over the respective entity, and consequently, the financial exposures of the institution to that entity are included in the financial exposures of that member of the administrative organ:
(A) power to direct the activities of the entity, (B) power to decide on significant transactions of the entity such as the transfer of profits or losses, (C) power to appoint or remove the majority of members of the administrative organ of the entity, (D) power of the casting vote in meetings of the board of directors, general assembly, or equivalent administrative organ of the entity, (E) power to coordinate the management of the entity with the management of other entities towards the achievement of a common goal, such as, without limitation, in cases where the same natural persons are involved in the management or administrative organ of two or more entities, (F) the right or possibility of exercising dominant influence over another entity based on a contract or according to the articles of association or statutory provisions.
(d) Financial exposures from the credit institution to third parties secured by the provision of either real security or personal guarantee by a member of the administrative organ constitute contingent liabilities of that member of the administrative organ and are therefore added to the financial exposures to that member of the administrative organ.
(e) When there is a financial exposure in underlying assets falling under the classes of securitization positions or claims in the form of Collective Investment Undertakings (CIUs), the institution must follow by analogy the provisions of Article 390(7) of Regulation (EU) 575/2013.
(f) The competent authority may decide on a case-by-case basis that a specific person who does not fall under another provision of this Directive nevertheless constitutes part of the connected persons with a member of the administrative organ of the credit institution. In such a case, the competent authority notifies the credit institution in writing and sets a deadline for compliance with the provisions of this Directive. In cases where there is doubt as to whether two or more persons are connected, the credit institution appeals in writing to the competent authority providing all details. The competent authority decides on the matter and notifies the credit institution in writing, setting a deadline for compliance with this Directive, where applicable.
(g) If the financial interests of any member of the administrative organ are connected in such a way with the interests of another or other natural or legal persons, or if there are close ties between them or they are considered to belong to the same group of connected persons, such that the member of the administrative organ and those persons are considered to constitute one person, the financial exposures granted to that member of the administrative organ or to any person from among them are aggregated and treated as granted to that member of the administrative organ.
Role and responsibilities of the administrative organ.
7.- (1) The duties of the administrative organ should be clearly defined. The description of the responsibilities and duties of the administrative organ is documented and duly approved by the administrative organ.
(2) (a) All members of the administrative organ should have full awareness of the structure and responsibilities of the administrative organ, as well as the division of duties among the different functions of the administrative organ and its committees.
(b) The administrative organ ensures the existence of a clear and documented allocation of the roles, responsibilities, and powers of the administrative organ and its committees as bodies and the members of the administrative organ as persons, senior management, and the functions of the internal control system, in accordance with the provisions of the Law and this Directive, in such a way that:
(i) the allocation of roles, responsibilities, and powers promotes the substantive segregation of supervision and management functions; (ii) it is clear who holds which of these roles, responsibilities, and powers; (iii) in cases where responsibilities are allocated to more than one function of the credit institution, the manner in which these responsibilities are apportioned or distributed among the functions in question is appropriate and clearly documented; (iv) the operations and affairs of the institution can be adequately monitored and controlled by the administrative organ and senior management; (v) a record of the arrangements for the allocation of responsibilities and powers is kept for seven (7) years from the date it was replaced by a more up-to-date record.
(c) To ensure an appropriate system of checks and balances, a single member or a small subset of members should not hold a dominant position in the decision-making process of the organ.
(3) The responsibilities of the administrative organ should include the establishment, approval, and oversight of the implementation of the following elements:
(a) the overall business strategy and core policies of the credit institution consistent with the legal and regulatory framework within which it operates, taking into account the long-term financial interests and solvency of the credit institution, and evaluating at least once a year the degree of effectiveness of the credit institution's management of regulatory compliance risk. The administrative organ must know the regulatory environment in which the institution operates, ensure that the credit institution has an appropriate regulatory compliance framework, and maintain an effective and productive relationship with competent authorities; (b) the overall risk strategy, including the risk-taking appetite and risk management framework of the credit institution, as well as the measures taken to ensure that the administrative organ devotes sufficient time to risk issues; (c) an adequate and effective internal governance framework and internal control system, as defined in this Directive, which includes a clear organizational structure and smooth operation of independent risk management, regulatory compliance, internal control, and ICT risk and security management functions with sufficient powers, authority, and resources to perform their duties, and ensures compliance with regulatory requirements related to the prevention and combating of money laundering; (d) the amounts, categories, and allocation of both internal capital and supervisory capital to adequately cover the risks of the credit institution; (e) the objectives for the liquidity management of the institution; EBA/GL/2015/22 (f) the remuneration policy, which is consistent with the remuneration principles set out in paragraphs 30 and 31 of this Directive and the EBA guidelines on sound remuneration policies; (g) the arrangements aimed at ensuring the effective conduct of suitability assessments of members of the administrative organ at an individual and collective level, the suitability of the composition and succession planning of the administrative organ, as well as the effective exercise of the powers of the administrative organ;
(h) the process for selecting and assessing the suitability of persons holding key positions;
(i) the arrangements aimed at ensuring the internal functioning of each of the committees of the administrative organ, with a detailed description of the following:
(i) the role, composition and duties of each committee; (ii) the appropriate information flow, including documentation of recommendations and conclusions, and the reporting channels between each committee and the administrative organ, the competent authority and other parties;
(j) a risk-aware culture, in accordance with paragraph 39 of this Directive, which covers risk awareness and risk-taking behaviour by the institution;
(k) a corporate culture and corporate values, in accordance with paragraph 40 of this Directive, which promote responsible and ethical behaviour, including a code of conduct or similar instrument;
(l) a conflict of interest policy at the level of the credit institution, in accordance with paragraph 41, and for staff, in accordance with paragraph 42 of this Directive; and
(m) the arrangements aimed at ensuring the integrity of accounting and financial reporting systems, including financial and operational controls and compliance with the Law and relevant standards.
(4) In establishing, approving and overseeing the implementation of the elements listed in sub-paragraph (3), the administrative organ shall aim for a business model and governance arrangements, including a risk management framework, which take into account all risks, including environmental, social and governance (ESG) risks. Credit institutions should consider that the aforementioned risks may lead to supervisory risks, including credit risk, for example through transition factors related to the shift to a sustainable economy or external, physical, climate-related events affecting borrowers, the market, liquidity, but also operational risks and reputational risks, for example social factors and governance factors in the context of outsourcing. Such risks include, for example, legal risks in the context of contract and labour law, risks related to potential human rights violations, or factors related to environmental, social and governance (ESG) risks that can affect the country where the service provider is located and its ability to provide services at the agreed levels.
(5) All members of the administrative organ should be kept informed of the overall activity, financial position and risk profile of the credit institution, taking into account the economic environment, as well as the decisions taken and having a major impact on the business activity of the credit institution.
(6) The administrative organ ensures that the allocation of responsibilities to each member of the administrative organ duly takes into account whether the respective member has the expertise and the degree of independence and objectivity required to perform the duties assigned to them.
(7) The administrative organ monitors and ensures the ability of committee members to devote the necessary time to their participation in the committees. Where a member of a committee is unable to devote sufficient time to participate in committee meetings, the administrative organ shall replace them with another member who has the necessary time, experience and expertise.
(8) The administrative organ should monitor, periodically review and address any weaknesses identified regarding the implementation of the procedures, strategies and policies linked to the responsibilities provided for in paragraphs 6 and 7 of this Directive.
(9) The administrative organ monitors and periodically evaluates the effectiveness of the credit institution's governance arrangements and takes appropriate action to address any deficiencies. The internal governance framework is updated taking into account the principle of proportionality, in accordance with the provisions of paragraph 5 of this Directive. In the event of significant changes affecting the credit institution, a more thorough review should be conducted.
(10) The administrative organ actively participates in the business activity of the credit institution and makes decisions on a sound basis and after adequate information.
(11) The administrative organ is responsible for implementing the strategies defined and regularly discusses the implementation and appropriateness of such strategies. Operational implementation may be carried out by the management of the credit institution.
(12) (a) The administrative organ constructively reviews and critically evaluates the proposals, explanations and information received in exercising its judgment and making its decisions.
(b) The administrative organ receives detailed reports and updates on a regular basis and when required without undue delay regarding relevant information for assessing a situation, the risks and developments affecting or potentially affecting the credit institution, e.g. significant decisions concerning business activities and risks taken, the assessment of the economic and business environment of the credit institution, the liquidity and sound capital base of the credit institution, as well as the assessment of significant risk exposures taken.
188(I) of 2007
58(I) of 2010
80(I) of 2012
192(I) of 2012
101(I) of 2013
184(I) of 2014
18(I) of 2016
13(I) of 2018
158(I) of 2018
81(I) of 2019
13(I) of 2021
22(I) of 2021
61(I) of 2021.
(13) The administrative organ should appoint one of its members, in accordance with the requirements of Article 58D of the Prevention and Combating of Money Laundering Proceeds from Illegal Activities Law of 2007, who should be responsible at the level of the administrative organ for the implementation of the laws, regulations and administrative provisions required for compliance with the Prevention and Combating of Money Laundering Proceeds from Illegal Activities Law of 2007, and the directives and/or circulars and/or regulations issued thereunder, including any relevant acts of the European Union, including the corresponding arrangements and procedures of the credit institution for the prevention and combating of money laundering from illegal activities. Where there is an audit committee, the said responsible person should be the chairman of the audit committee.
(14) The role of members of the administrative organ should include monitoring and constructive critical review of the credit institution's strategy.
(15) (a) The administrative organ approves and periodically reviews the strategies and policies for the taking, management, monitoring and mitigation of risks to which the credit institution is or could be exposed, including those caused by the macroeconomic environment in which it operates its activities, taking into account the phase of the economic cycle.
(b) The administrative organ devotes sufficient time to the assessment of risk issues. The administrative organ actively participates and ensures that sufficient resources are available for the management of all significant risks examined in this Directive, in the harmonising legislative provisions with Directive 2013/36/EU and Regulation (EU) No 575/2013, as well as in the assessment of assets, the use of external credit ratings and internal models in relation to such risks. The credit institution establishes reporting channels to the administrative organ, covering all significant risks and risk management policies as well as changes thereto.
(16) (a) The administrative organ should ensure that the credit institution has an adequate internal governance framework and internal control system for the relevant ICT and security risks. The administrative organ should define clear roles and responsibilities for the department or departments responsible for ICT systems, information security risk management, as well as business continuity, including those concerning the administrative organ itself and its committees.
(b) The administrative organ should ensure that the number and skills of the credit institution's staff are sufficient to continuously support their operational needs in the field of ICT and their processes regarding ICT and security risk management, as well as to ensure the implementation of the relevant ICT strategy. The administrative organ should ensure that the available budget is appropriate to meet the aforementioned obligations.
(c) The administrative organ bears overall accountability for the definition, approval and oversight of the implementation of the ICT strategy of credit institutions within the framework of their overall business strategy, as well as for the creation of an effective risk management framework for ICT and security risks.
CH.113
46(I) of 1992
(17) Without prejudice to the duties under the Companies Law, the administrative organ should perform the following supervisory duties:
96(I) of 1992
41(I) of 1994
15(I) of 1995
21(I) of 1997
REV.2331
82(I) of 1999
149(I) of 1999
2(I) of 2000
135(I) of 2000
151(I) of 2000
76(I) of 2001
70(I) of 2003
167(I) of 2003
92(I) of 2004
24(I) of 2005
129(I) of 2005
130(I) of 2005
98(I) of 2006
124(I) of 2006
70(I) of 2007
71(I) of 2007
131(I) of 2007
186(I) of 2007
87(I) of 2008
41(I) of 2009
49(I) of 2009
99(I) of 2009
42(I) of 2010
60(I) of 2010
88(I) of 2010
53(I) of 2011
117(I) of 2011
145(I) of 2011
157(I) of 2011
198(I) of 2011
64(I) of 2012
98(I) of 2012
190(I) of 2012
203(I) of 2012
6(I) of 2013
90(I) of 2013
74(I) of 2014
75(I) of 2014
18(I) of 2015
62(I) of 2015
63(I) of 2015
89(I) of 2015
120(I) of 2015
40(I) of 2016
90(I) of 2016
97(I) of 2016
17(I) of 2017
33(I) of 2017
51(I) of 2017
37(I) of 2018
83(I) of 2018
149(I) of 2018
163(I) of 2019
38(I) of 2020
43(I) of 2020
191(I) of 2020
192(I) of 2020
32(I) of 2021
43(I) of 2021.
(a) to supervise and monitor decision-making and measures and ensure the effective functioning and evaluation of the administrative organ, including the monitoring and control of its performance at individual and collective level, as well as the implementation of the strategy and objectives of the credit institution;
(b) to constructively review and critically evaluate the proposals and information provided by senior management and their decisions, as well as their performance in meeting agreed targets and objectives;
(c) taking into account the principle of proportionality as defined in Part 2, to duly perform the duties and role of the risk committee, audit committee, remuneration committee and nomination committee, in the event that corresponding committees have not been established;
(d) to ensure and periodically evaluate the effectiveness of the credit institution's internal governance framework and take appropriate measures to address any deficiencies identified;
(e) to supervise and monitor the implementation of the strategic objectives, organisational structure and risk strategy of the credit institution, including risk appetite and the credit institution's risk management framework, as well as other policies, for example remuneration policy, and the disclosure framework;
(f) to monitor the consistent implementation of the credit institution's risk-aware culture;
(g) to supervise the implementation and maintenance of a code of conduct or similar and effective policies for the identification, management and mitigation of actual and potential conflicts of interest;
(h) to supervise the integrity of financial information and reporting, as well as the internal control framework, including an effective and sound risk management and regulatory compliance framework;
(i) to ensure that the heads of the internal control system functions are able to act independently and, regardless of the responsibility to report to other internal bodies, business units or units, to raise concerns and warn directly the administrative organ, if deemed necessary, in the event that the credit institution is affected or may be affected by adverse developments regarding risk;
(j) to monitor the implementation of the internal control system plan, after the preliminary participation of the risk and audit committees;
(k) to have a central role in the appointment, and where necessary, the removal of senior management, and in the succession planning of such staff; and
(l) to provide objective opinions on resources, appointments and behavioural standards.
(18) The administrative organ shall establish appropriate procedures for assessing whether the credit institution operates within its approved strategies and in this direction the administrative organ shall define clear and objective performance targets for senior management concerning both the credit institution and senior management.
(19) Independent members of the administrative organ shall, in any case, maintain independence of thought and opinion.
(20) Members of the administrative organ are responsible for their role and responsibilities as defined based on the prevailing legislation and instructions of the competent authority. Each member of the administrative organ does not cease to be responsible for their role and responsibilities for the duration of their term as a member of the administrative organ.
Size and composition of the administrative organ.
8.- (1) The size and composition of the administrative organ is determined taking into account the principle of proportionality, ensuring that the majority of members and the chairman of the administrative organ are independent, as defined in paragraph (1) of Article 19B of the Law. In particular, it should be ensured that–
(a) the administrative organ consists of at least seven (7) members and not more than thirteen (13) members;
(b) executive members are at least two (2) and not more than twenty-five percent (25%) of the members of the administrative organ rounded down, one of whom is the Managing Director;
(2) Members of the administrative organ may not appoint alternate members to represent them in their absence.
(3) The heads of the internal control system functions may not be appointed as members of the administrative organ.
(4) Regarding the organisational structure of the administrative organ:
(a) the position of the chairman of the administrative organ, in accordance with the provisions of Article 19B of the Law, is held by an independent member of the administrative organ;
(b) the position of the vice-chairman of the administrative organ is held by a non-executive member, and assumes the roles and responsibilities of the chairman in the latter's absence;
(c) an independent member of the administrative organ is appointed as senior independent member; It is understood that the senior independent member of the administrative organ cannot hold the position of chairman or vice-chairman;
(d) committees of appropriate size, composition, structure and responsibilities are established for the effective performance of the roles and responsibilities of the administrative organ, in accordance with the provisions of Section II of this Part.
Role of the chairman of the administrative organ.
9.- (1) The chairman of the administrative organ should guide the administrative organ, contribute to ensuring the efficient flow of information, both within the administrative organ and between the administrative organ and its committees, while should also be responsible for the effective overall functioning of the administrative organ.
(2) The chairman of the administrative organ should encourage and promote open debate with critical thinking and ensure that divergent views can be expressed and discussed within the decision-making process.
(3) The chairman of the administrative organ should define the agenda items of the meetings and ensure that issues of strategic importance are discussed as a priority.
(4) (a) The chairman of the administrative organ should ensure that the decisions of the administrative organ are taken on a sound basis and after adequate information and ensure the timely receipt of relevant documents and information before the meeting.
(b) The chairman of the administrative organ should ensure that sufficient time is provided to the members of the administrative organ to examine significant issues and obtain answers to any questions or concerns they may have, without facing unrealistic deadlines for decision-making.
(5) The chairman of the administrative organ should contribute to the clear allocation of duties among the members of the administrative organ and to ensuring efficient information flow among them, so as to enable members to contribute constructively to discussions and exercise their voting rights on a sound basis and after adequate information.
(6) The chairman of the administrative organ is responsible for ensuring compliance with paragraphs 11 and 12 of this Directive, through appropriate procedures and actions.
(7) Subject to the requirements of paragraph 42 of this Directive, the chairman of the administrative organ ensures, through an explicit procedure, the disclosure of conflicting interests to the administrative organ and the abstention of members from the discussion, decision-making or voting process on any matter for which they may have a conflict of interest.
(8) The chairman of the administrative organ maintains adequate contact with the competent authority and other supervisory authorities and ensures that the views and concerns of the supervisory authorities and any views and concerns of shareholders that come to his knowledge are communicated in full to the administrative organ.
(9) The chairman of the administrative organ:
(a) is responsible for ensuring that procedures (e.g. in the context of the proper functioning of the nomination committee) are followed so that members of the administrative organ have at all times sufficient knowledge and skills to perform their duties; the chairman must ensure compliance with procedures for the participation of new members of the administrative organ in an induction training programme, in accordance with paragraphs 16 and 17 of the 2020 Directive on the Assessment of Suitability of Members of the Administrative Organ and Persons Holding Key Positions in Licensed Credit Institutions;
(b) is responsible for ensuring compliance with procedures for identifying the training needs of members of the administrative organ on an individual basis as well as of the administrative organ as a whole, based on reports submitted at least annually by the nomination committee in accordance with paragraph 23(1) of this Directive, and to ensure that these needs are met;
(c) is responsible for ensuring that the evaluation of the administrative organ, its committees and each member of the administrative organ is conducted in accordance with the provisions of paragraph 16 and that the credit institution takes action commensurate with the results of these evaluations, recognising the capabilities and addressing the weaknesses of the administrative organ.
Senior independent member of the governing body.
10.- The duties of the senior independent member of the governing body, who is appointed in accordance with paragraph (c) of sub-paragraph (4) of paragraph 8 of this Directive, include, among others, the following:
(a) to act as a point of contact with shareholders and other stakeholders regarding concerns that could not be examined or resolved, or that could not be examined or resolved through the usual channels of communication with the chairman of the governing body or the senior management; (b) to ensure that the governing body has a balanced understanding of the most significant issues and concerns of the shareholders; (c) to chair the meetings with the non-executive members of the governing body, without the presence of the chairman, at least annually, in order to evaluate the performance of the chairman in accordance with paragraph 11 of this Directive; (d) to chair the governing body during the examination of the chairman's succession and to ensure a smooth succession process.
Meetings of the governing body.
11.- (1) Regarding the organization of the meetings of the governing body and its committees:
(a) the governing body and its committees hold regular meetings for the adequate and effective performance of their duties; (b) every effort is made to conduct at least one regular meeting of the governing body per year with the physical presence of all members; (c) the non-executive members of the governing body hold regular meetings without the presence of the executive members, which may include the external auditors and/or the heads of the internal control system functions, as appropriate, and at least on a semi-annual basis; (d) the non-executive members of the governing body meet without the presence of the chairman at least annually to evaluate the performance of the chairman; (e) the arrangement for participation in regular or extraordinary meetings via videoconference should not be used abusively but with caution at the level of the member or the governing body, ensuring that, as a rule and where there are no special circumstances justifying the contrary, at least the majority of the members are physically present at each regular or extraordinary meeting; (f) members of the governing body may not be absent from the regular and extraordinary meetings of the governing body, either physically or via videoconference, for more than two (2) consecutive meetings or twenty-five percent (25%) of the annual meetings; (g) the exercise of voting rights by proxy may be permitted to a member absent from a meeting, provided that the exercise of voting by proxy is limited to one (1) per year for each member participating in the meeting, and members voting by proxy are accountable for the vote of their proxy; (h) it is prohibited for persons proposed by the credit institution for the position of member of the governing body, for which a decision by the competent authority is pending, to attend as observers.
It is understood that the person acting as interim managing director may attend the meetings of the governing body, only upon relevant invitation by the governing body, for specific matters and for specific reasons related to their executive duties. Subject to the requirements of Article 18 of the Law, this person does not attend the part of the meetings concerning the discussions and decision-making of the governing body.
(2) Regarding the handling of interests or conflict of interests or potential conflict of interests of the members of the governing body:
(a) there is a recorded procedure for the examination or approval of participation of members of the governing body in specific activities, such as participation in the governing body of another entity, to ensure that such participation does not create a conflict of interests; (b) there is a requirement for members to disclose any conflicts of interests and to abstain from the decision-making process or voting on any matter where they may have a conflict of interests; specifically:
(i) before the start of each meeting, the chairman of the meeting must read all agenda items one by one, and ask each participant, including themselves, to clearly state for each item whether they have or do not have an interest or conflict of interests or potential conflict of interests or conflict of interests;
It is understood that a member acting as a proxy additionally states for each item whether the member who granted the proxy has or does not have an interest or conflict of interests or potential conflict of interests or conflict of interests; (ii) upon completion of the procedure referred to in sub-paragraph (i), the chairman calls all members participating in the meeting to submit their comments regarding the statements made; (iii) if a conflict of interests is identified for an agenda item, the involved member must abstain from the discussion and voting on that specific item, either in person or through a proxy; (iv) a similar procedure must be followed for any other/special matters discussed; (c) the manner in which the governing body addresses any non-compliance with policies, practices, and procedures regarding conflicts of interests is recorded; non-compliance must be reported directly to the Central Bank.
Minutes of meetings of the governing body.
12.- Regarding the keeping of minutes of the meetings of the governing body and its committees:
(a) detailed minutes are kept for each meeting, which are finalized no later than fifteen (15) working days after the meeting and officially approved at the next meeting; (b) the minutes of the meeting record – (i) the time of the meeting, the location of conduct, and those present, including guests, physically present and via electronic means; (ii) the reasons for inviting persons who are neither members of the governing body nor the persons referred to in paragraph (h) of paragraph 11, to attend the meeting, the relevant agenda item, and their positions and/or views; (iii) all agenda items and the respective discussions, decisions, voting results, opinions, and views of the minority, as well as unresolved concerns; (iv) the statements of the members of the governing body regarding conflict of interests separately under the title "recognition of interests or conflicts of interests or potential conflicts of interests or conflict of interests."
Role and responsibilities of the secretary.
13.- (1) Credit institutions appoint a person to perform the duties of secretary pursuant to Article 171 of the Companies Law.
(2) Taking into account the provisions of Articles 172 and 173 of the Companies Law, credit institutions must ensure the avoidance of any conflict of interests regarding the appointment of a secretary.
The secretary may delegate duties referred to in this paragraph to third parties provided no conflict of interests arises, and the secretary reviews and signs the relevant minutes and documents and remains responsible and accountable for the results of the delegation.
It is understood that the secretary cannot delegate their duties to the heads of the internal control system functions.
(3) The secretary monitors and ensures that the governing body and its committees are established and operate in accordance with the internal rules and regulations of the governing body, the provisions of this Directive, and other applicable legal and supervisory requirements.
(4) The secretary acts as a source of information and advice to the members of the governing body, ensures the existence of adequate information flow within the governing body and its committees, between the senior management and the non-executive members, and between the heads of the internal control system functions and the non-executive members.
(5) (a) The secretary organizes induction training programs for the non-executive members of the governing body, which provide an official, complete, and personalized introduction to the credit institution and their duties and responsibilities.
(b) The secretary assists the chairman of the governing body in evaluating and satisfying the training needs of the members of the governing body and ensures that there is an ongoing program for keeping members well-informed regarding developments in the credit institution and matters related to their responsibilities in general.
(6) The secretary ensures that if necessary, the non-executive members have access to independent professional advice at the expense of the Credit Institution.
(7) The secretary actively participates in the preparation of the schedule of all meetings of the governing body and its committees and must:
(a) prepare, in collaboration with the chairman, the agenda of these meetings, ensuring that matters requiring the attention or actions of the governing body or committee are included in the agenda; (b) ensure that relevant information is sent in a timely manner to all members of the governing body, so that they can adequately prepare for these meetings.
(8) The secretary ensures that minutes are kept, in accordance with the provisions of paragraph 12 of this Directive, and must – (a) explicitly express, in a separate paragraph, their assessment of whether the meeting was conducted in accordance with the internal rules and regulations of the governing body, the provisions of this Directive, and other applicable regulatory and supervisory requirements; (b) ensure the circulation, completion, and approval of the minutes in a timely manner by all members who were present at the meeting; (c) ensure the timely distribution of the final minutes to all recipients; (d) ensure the appropriate communication of decisions taken, pursue the implementation of subsequent actions, and report to the governing body any issues that arise.
(9) The secretary provides support to the governing body, the chairman of the governing body and/or the nomination committee for the determination of succession planning and the supervision of the succession and rotation of duties of the non-executive members of the governing body.
Access of governing body and committees to resources and information.
14.- (1) (a) The governing body, in exercising its supervisory responsibilities, and all its committees, must have adequate access to resources and information concerning their duties.
(b) The governing body must determine a framework and appropriate and transparent procedures for this access, and appropriate and transparent procedures in case it allows members to communicate individually and directly with the senior management and/or staff of the credit institution, in exercising their supervisory responsibilities as members of the governing body or its committees.
(c) The governing body and the risk committee, if such a committee has been established pursuant to the provisions of Section II of this Part, have adequate access to information regarding the risk status of the credit institution and, if required and deemed appropriate, to information concerning the operation of the risk management function and to specialized external advisors.
(2) The governing body and the risk committee, established pursuant to the provisions of Section II of this Part, determine the type, quantity, form, and frequency of information to be received regarding risk matters.
Nomination, selection, and succession of members of the governing body.
15.- (1) Credit institutions and their respective nomination committees ensure a wide range of qualifications and skills during the appointment of members and the reappointment of existing members to the governing body and apply a policy for this purpose that promotes the appropriate level of diversity of the governing body.
(2) Credit institutions apply an appropriate appointment policy for the nomination, selection, reappointment, and succession of members of the governing body, which includes, at least, the following:
(a) a description of the necessary abilities, skills, and academic or professional qualifications to ensure adequate expertise and compliance with the requirements of this Directive and the provisions of the 2020 Directive on the Assessment of Suitability of Members of the Governing Body and Persons Holding Key Positions in Licensed Credit Institutions; (b) the requirement that, before the appointment of new members, candidates are verified to have the knowledge, skills, experience, and time to contribute positively to the governing body; (c) the requirement that the nomination committee prepares a report for the governing body stating how it arrived at the nomination of candidates to fill vacant positions on the governing body; (d) the obligation to provide adequate information to shareholders for the selection of a person as a member of the governing body, including:
(i) a description of the person's qualifications, experiences, and abilities; (ii) a description of the roles and duties of the specific vacant position; (iii) the expected time commitment; (iv) an explanation of the reason why the appointment of the specific person was deemed appropriate; (e) the requirement that any reappointment is based on the performance of the member, as documented by evaluation reports; (f) an appropriate succession plan for the members of the governing body, which takes into account, among other things, the expiration date of each member's contract, aiming to prevent the simultaneous replacement of multiple members of the governing body.
(3) Credit institutions must determine a maximum number of terms that a member may serve as a non-executive member of the governing body, subject to the provisions of the 2020 Directive on the Assessment of Suitability of Members of the Governing Body and Persons Holding Key Positions in Licensed Credit Institutions.
(4) Credit institutions must determine a maximum number of terms that a person may serve as chairman of the governing body or a committee of the governing body, subject to the overall term limit as a member of the governing body applicable for the purposes of independence of members of the governing body, in accordance with the 2020 Directive on the Assessment of Suitability of Members of the Governing Body and Persons Holding Key Positions in Licensed Credit Institutions, as amended subsequently.
(5) Appointed members of the governing body are subject to re-election at the Annual General Meeting, every 3 years from the date of their appointment:
It is understood that, in case of a change in the ownership regime of a credit institution, non-executive members are subject to re-election at a General Meeting before the expiration of three years from the date of their appointment.
It is further understood that a change in the ownership regime for the purposes of this sub-paragraph means the acquisition of a significant participation (at least 10%) in the share capital of the credit institution and any further increase of such significant participation such that the percentage of participation in the share capital of the credit institution reaches or exceeds 20%, 30%, or 50% of its share capital, based on the provisions of paragraph 1 of Article 17 of the Law.
(6) Credit institutions allocate adequate personnel and financial resources for the reception and training of the members of the governing body.
Evaluation of the governing body.
16.- (1) Credit institutions must have an appropriate methodology and procedure for the in-depth and rule-based evaluation of the performance of their governing body at least on an annual basis. The evaluation procedure must cover, at least, the following:
(a) the performance of the governing body as a whole, the committees, and individual members; (b) the contribution of the governing body as a whole, the committees, and individual members – (i) to the development of business objectives, risk-taking allocation, and strategies; (ii) to the determination and supervision of risk management and regulatory compliance frameworks; (iii) to the creation and maintenance of appropriate organizational and operational arrangements and internal control mechanisms; (c) the composition of the governing body and its committees; (d) communication with management, shareholders, and the competent authority; (e) the role of the chairman of the governing body, the company secretary, and the senior independent member of the governing body; (f) the time commitment of the non-executive members and the ability to critically examine information; (g) the assessment of the suitability of each member of the governing body based on the criteria of the 2020 Directive on the Assessment of Suitability of Members of the Governing Body and Persons Holding Key Positions;
It is understood that, if at any time, persons holding the position of independent member, due to developments, do not meet or appear not to meet any of the independence criteria, then the governing body addresses the matter immediately in accordance with paragraphs 25 and 27 of the 2020 Directive on the Assessment of Suitability of Members of the Governing Body and Persons Holding Key Positions in Licensed Credit Institutions, proceeding to take the necessary corrective measures, including the removal of the said member from the governing body or the redefinition of their role in the governing body and/or the appointment of a new independent member; the time period for the implementation of all necessary remedial measures should not exceed one (1) month.
It is further understood that the said member must be relieved of the duties they perform as an independent member of the governing body from the date the non-compliance of the member with the independence criteria is identified.
(2) Credit institutions must entrust the conduct of the examination and evaluation of the composition, efficiency, and effectiveness of the governing body and its committees to an independent external consultant at least every three (3) years, taking into account the requirements of this Directive and to gain an objective opinion, as well as to be informed about industry best practices.
Section II – Committees of the governing body
53(I) of 2017
171(I) of 2017
7(I) of 2018.
17.- (1) Credit institutions establish a risk committee, a nomination committee, and a remuneration committee, with the aim of advising the governing body and preparing the decisions that the specific body must take.
It is understood that credit institutions also establish an audit committee in accordance with the provisions of Article 78 of the Auditors Law.
(2) The competent authority may permit an institution that is not considered significant in terms of size, internal organization, nature, scope, and complexity of its activities, not to establish one or more of these committees, upon relevant application by the institution, provided that:
(a) in the case where the credit institution is a subsidiary of a group, the relevant duties are performed by the respective committees of the parent company, which submit their recommendations and decisions to the governing body of the credit institution; or (b) the relevant duties are performed by joint committees pursuant to the provisions of paragraph 24 of this Directive.
(3) In case the competent authority has permitted a credit institution not to establish one or more of the risk, nomination, or remuneration committees, based on sub-paragraph (2) of paragraph 17 of this Directive, the references to these committees contained in this Directive should be interpreted as applying to the governing body of the credit institution or the joint committees, respectively.
(4) Credit institutions may form other committees, such as, for example, ethics, conduct, regulatory compliance committees, and/or a committee for matters of prevention and combating money laundering from illegal activities, taking into account the criteria specified in Part 2 of this Directive.
(5) Credit institutions should ensure the clear distribution and allocation of duties and tasks among the specialized committees of the governing body.
(6) Each committee should have its mandate recorded, including the scope of its authority from the governing body, and should have established appropriate working procedures.
(7) Committees should support the supervisory function in specific areas and facilitate the development and implementation of a framework of sound internal governance.
The delegation of responsibilities to committees does not in any case exempt the governing body from the collective exercise of its duties and responsibilities.
Composition of committees of the governing body.
18.- (1) Independent members of the governing body should have active participation in the committees. For the mandatory committees referred to in paragraph 17 of this Directive, in addition to fifty percent (50%) of the members of each committee must be independent members.
(2) The committees of the governing body should consist of at least three members.
(3) Taking into account the size of the governing body and the number of independent members of the governing body, credit institutions should ensure that participation in more than one committee ensures that no person exercises excessive influence or control in them; in any case, a member of the governing body cannot be a member of more than two (2) committees referred to in paragraph 17(1) of this Directive.
(4) Credit institutions should consider the possibility of periodic rotation of the chairs and members of the committees, taking into account the specific experience and specialized knowledge and skills required for these committees at an individual or collective level.
(5) All committees of the governing body should consist of non-executive members of the governing body.
(6) Subject to the requirements of Article 78 of the Auditors Law regarding the composition of the audit committee, the chairman of the governing body cannot be a member of the audit committee.
(7) (a) With regard to the requirements of sub-paragraph (1) concerning the remuneration committee, where there is an insufficient number of specialized independent members, credit institutions should implement other measures within the remuneration policy in order to limit conflicts of interest in decisions regarding remuneration matters. (b) Members of the remuneration committee should collectively possess appropriate knowledge, expertise, and professional experience regarding remuneration policies and practices, risk management, and control activities, particularly with regard to the mechanism aligning the remuneration structure with the institution's risk and capital profile.
(8) (a) The nomination committee should be chaired by an independent member where the credit institution is a Global Systemically Important Institution (G-SII) or another Systemically Important Institution (O-SII). Subject to the principle of proportionality, other credit institutions may also consider it good practice to appoint an independent member as chair of the nomination committee. (b) Members of the nomination committee should possess, at both individual and collective levels, appropriate knowledge, skills, and expertise regarding the candidate selection process and their fitness requirements.
(9) (a) The risk committee should be chaired by an independent member where the credit institution is a Global Systemically Important Institution (G-SII) or another Systemically Important Institution (O-SII). For other institutions, the risk committee should, wherever possible, be chaired by an independent member. In all institutions, the chairmanship of the risk committee must not be held by the chair of the administrative body nor by the chair of any other committee. (b) Members of the risk committee should possess, at both individual and collective levels, appropriate knowledge, skills, and specialization to fully understand and monitor the credit institution's risk strategy and risk-taking policy, as well as its risk management and control practices.
(10) Members of a committee do not hold any other positions or conduct transactions that could be considered to conflict with the terms of the committee's mandate.
Procedures of committees.
19.-(1) Committees should report on a regular basis and communicate their minutes to the administrative body prior to the administrative body's meetings.
(2) Committees should interact with each other in an appropriate manner. Subject to sub-paragraph (4) of paragraph 18 of this Directive, this interaction could take the form of multiple participation such that the chair or a member of one committee may also be a member of another committee.
(3) Committee members should participate in open, critical discussions at committee meetings, within which divergent views are discussed constructively.
(4) Committees should record the agenda items of their meetings, as well as their main results and conclusions.
(5) The risk and nomination committees should at least:
(a) have access to all relevant information and data required for the exercise of their role, including information and data from relevant corporate and audit departments (e.g., legal department, finance department, human resources department, technology and information departments, audit, risk, IT risk and security, regulatory compliance, including information related to regulatory compliance regarding the prevention and combating of money laundering, including access to consolidated information related to suspicious transaction reports, and risk factors regarding the prevention and combating of money laundering); (b) receive regular reports, ad hoc information, announcements, and opinions from the heads of the internal control system functions regarding the credit institution's current risk profile, risk culture, and risk limits, as well as any significant breaches that may have occurred, with detailed information and recommendations for corrective measures that have been taken, need to be taken, or are proposed to address them; (c) periodically review and decide on the content, form, and frequency of information to be provided to them regarding risk; and (d) where deemed necessary, ensure the appropriate participation of the internal control system functions and other relevant functions (human resources department, legal department, finance department) within their respective fields of expertise and/or seek advice from external experts.
(6) Taking into account the provisions of paragraphs 20, 21, 22, and 23 of this Directive, the duties, tasks, and obligations of the risk, audit, remuneration, and nomination committees must not be delegated to another committee, except in the case where a joint committee has been established in accordance with the provisions of paragraph 24 of this Directive.
(7) (a) The provisions of paragraph 9 of this Directive apply mutatis mutandis to the chairs of each committee of the administrative body.
(b) The provisions of paragraphs 11 and 12 of this Directive apply mutatis mutandis to the committees of the administrative body.
(8) (a) All committees of the administrative body conduct annual self-assessments and report to the administrative body with conclusions and recommendations for improvements and changes.
(b) Subject to sub-paragraph (8) of paragraph 7 of this Directive, all committees conduct an annual review of their terms of reference and report to the administrative body with conclusions and recommendations for improvements.
(9) The chair of each committee ensures that no person, other than the committee members, is present at a committee meeting, including other members of the administrative body, unless formally invited to attend for a specific agenda item; any such person is present only for the presentation of the specific item and leaves the meeting room immediately thereafter, without participating in the decision-making process.
Role of the risk committee.
20.-(1) The risk committee should at least:
(a) advise and support the administrative body regarding the credit institution's current and future overall risk-taking appetite and risk strategy, taking into account all types of risks, so as to ensure they are consistent with the credit institution's business strategy, objectives, corporate culture, and corporate values; (b) assist the administrative body in overseeing the implementation, by senior management, of the risk strategy and the application of the corresponding limits; the administrative body bears full responsibility for the proper and adequate handling of risks; (c) oversee the implementation of strategies for capital and liquidity management, as well as for all other relevant risks of an institution, such as market risk, credit risk, operational risks (including legal risk and IT risk), country risk, and reputational risk, and, relying on the work of the audit committee, the risk management function, and external auditors, assess their adequacy against the approved risk-taking appetite and risk strategy, and assess the adequacy of provisions and the effectiveness of strategies regarding the continuous maintenance of sufficient amounts, types, and distribution of internal capital and own funds to cover the credit institution's risks; (d) address recommendations to the administrative body regarding necessary adjustments to the risk strategy arising, inter alia, from changes in the credit institution's business model, market developments, or recommendations made by the risk management function; (e) provide advice regarding the appointment of external advisors, who may be decided to be engaged in the supervisory function to provide advice or support; (f) examine various possible scenarios, including stress testing scenarios, in order to evaluate the potential reaction of the credit institution's risk profile to external and internal events; (g) oversee the alignment between, on the one hand, all significant financial products and services offered to customers, and, on the other hand, the credit institution's business model and risk strategy, taking into account the EBA Guidelines on supervision and governance of retail banking products. The risk committee should assess the risks associated with the offered financial products and services and take into account the correspondence between the prices set for such products and services and the profits derived from them. The risk committee checks whether the prices of liability and asset items offered to customers fully take into account the credit institution's business model and risk strategy. When prices do not accurately reflect risks according to the business model and risk strategy, the risk committee submits a corrective plan to the administrative body; (h) assess the recommendations of internal or external auditors regarding its subject matter and monitor the proper implementation of measures taken.
(2) The risk committee should cooperate with other committees of the administrative body whose activities may impact the risk strategy (e.g., audit and remuneration committees) and maintain regular communication with the credit institution's internal control system functions, and specifically with the risk management and IT security functions.
(3) The risk committee submits recommendations to the administrative body regarding the appointment or removal of the heads of the risk management function and the IT risk and security management function.
(4) The risk committee conducts an annual assessment of the heads of the risk management function and the IT risk and security management function and submits it to the administrative body.
(5) The risk committee assesses and monitors the independence, adequacy, and effectiveness of the risk management function and the IT risk and security management function, and advises the administrative body on these matters, as well as on the adequacy and effectiveness of the information security framework, which among other things, ensures the adequate protection of the AFI's confidential and proprietary information.
(6) The risk committee conducts an examination and approval of the budgets of the risk management function and the IT risk and security management function, ensuring that they are sufficiently flexible to adapt to changes according to developments.
(7) The risk committee, subject to the duties of the remuneration committee, and in order to contribute to the formulation of proper remuneration policies and practices, is required to examine whether the incentives provided by the remuneration system, policies, and practices take into account risk, capital, liquidity, as well as the probability and timing of the credit institution's profits.
(8) The risk committee monitors and assesses country risk by preparing periodic reports to the administrative body and submitting recommendations for taking measures to mitigate country risk. Any significant changes in the conditions of a country in which the credit institution maintains material exposures through country opening or financial exposure are reported immediately to the administrative body.
Role of the audit committee.
21.-(1) Subject to the provisions of the Auditors Law, the audit committee should, inter alia:
(a) monitor the effectiveness of the credit institution's systems for internal quality control and risk management, and, where applicable, its internal audit function, regarding the financial information of the audited credit institution, without compromising its independence; (b) assess and monitor the independence and adequacy of the internal audit function; (c) oversee the establishment of accounting policies by the credit institution; (d) monitor the financial information process and submit recommendations aimed at ensuring its integrity; (e) review and monitor the independence of statutory auditors or audit firms in accordance with Articles 58, 59, 60, 63, and 64 of the Auditors Law and Article 6 of Regulation (EU) No 537/2014, and specifically the suitability of providing supplementary services to the audited institution in accordance with Article 5 of Regulation (EU) No 537/2014; (f) monitor the mandatory audit of annual and consolidated financial statements, and specifically its performance, taking into account any findings and conclusions of the competent authority in accordance with Article 26(6) of Regulation (EU) No 537/2014; (g) be responsible for the selection process of external/statutory auditors or audit firms and propose to the competent body of the credit institution for approval, in accordance with Article 16 of Regulation (EU) No 537/2014, their appointment, remuneration, and termination; (h) review the scope and frequency of the mandatory audit of annual or consolidated accounts; (i) inform the administrative body of the audited entity in accordance with paragraph (a) of paragraph 5 of Article 78 of the Auditors Law regarding the result of the mandatory audit and explain how the mandatory audit contributed to the integrity of the financial information and what was the role of the audit committee in this process; and (j) receive and take into account audit reports.
(2) The audit committee should assist the administrative body regarding the supervision of the independence, adequacy, and effectiveness of the regulatory compliance function, or in the case where the regulatory compliance function's duties are conducted in combination with another control function in accordance with paragraph 55 of this Directive, the audit committee assesses and monitors the independence, adequacy, and effectiveness of the compliance function within the combined control function. Specifically, the audit committee ensures the following:
(a) advising the administrative body, based on the work of the regulatory compliance function, regarding the adequacy and effectiveness of the business ethics framework; (b) advising the administrative body, based on the work of the regulatory compliance function and external auditors, regarding the adequacy and effectiveness of the compliance framework;
(3) The audit committee ensures the examination and assistance of the administrative body regarding the approval of the annual audit program of the internal audit function and the compliance program of the regulatory compliance function;
(4) The audit committee submits recommendations to the administrative body regarding the appointment or removal of the heads of the internal audit and regulatory compliance functions;
(5) The audit committee conducts an annual assessment of the heads of the internal audit and regulatory compliance functions and subsequently submits it to the administrative body;
(6) The audit committee ensures the assistance of the administrative body regarding the examination and approval of the budgets of the internal audit and regulatory compliance functions, ensuring that they are sufficiently flexible to adapt to changes according to developments;
(7) The audit committee supervises the timely taking of necessary corrective measures by senior management to address control weaknesses, non-compliance with the credit institution's policies, laws, and regulations, and other weaknesses identified by external auditors, internal audit and regulatory compliance functions, and supervisory authorities;
(8) The audit committee assists the administrative body regarding the examination, monitoring, and approval of the credit institution's official announcements concerning financial performance and other disclosures.
Role of the remuneration committee.
22.-(1) The remuneration committee is established to duly and independently express an opinion on remuneration policies and practices and on the incentives created for the management of risks, capital, and liquidity. It supports and advises the administrative body regarding the design and/or updating and monitoring of the implementation of remuneration policies and practices and compliance with them.
(2) The remuneration committee is responsible for preparing decisions regarding remuneration, including those that have implications for the credit institution's risks and risk management, which are taken by the administrative body.
(3) In preparing the decisions referred to in sub-paragraph (2), the remuneration committee is obliged to take into account the long-term interests of the shareholders, investors, and other stakeholders of the credit institution and the public interest, and to ensure that:
(a) they are closely linked to the credit institution's business objectives and strategies; (b) they are in accordance with the requirements specified in Part 4 of this Directive; (c) non-executive members are not included among the beneficiaries of remuneration linked to performance.
(4) The remuneration committee ensures that internal audit functions are involved in the design, review, and implementation of the remuneration policy.
(5) The remuneration committee ensures that staff members involved in the design, review, and implementation of remuneration policies and practices have relevant experience and are capable of forming an independent opinion on the suitability of remuneration policies and practices, including their suitability for risk management.
Role of the nomination committee.
23.-(1) The nomination committee, as part of its core duties and responsibilities:
(a) identifies and proposes, for approval by the administrative body or for approval at the general meeting, candidates for vacant positions of the administrative body, senior management, and key position holders, assessing the combination of knowledge, skills, diversity, and experience of the administrative body, and drafts a description of roles and competencies for
specific appointment position and calculates the time expected to be devoted to this position; (b) periodically and at least annually, assesses the structure, size, composition and performance of the administrative body and makes recommendations to the administrative body regarding any changes; (c) periodically and at least annually, assesses the knowledge, skills and experience of individual members of the administrative body and of the administrative body as a whole and submits relevant reports to the administrative body; (d) periodically, reviews the succession plans of the administrative body to ensure, on the one hand, the existence of smooth succession and maintenance of appropriate balance, diversity, skills and experience and, on the other hand, the gradual renewal of the administrative body, and submits relevant reports to the administrative body; (e) periodically reviews the policy applied by the administrative body for the selection, development and appointment of senior management and heads of the internal control functions and makes recommendations to the administrative body. (f) periodically reviews the credit institution's policy regarding the recruitment, job rotation and promotion of staff and submits relevant reports to the administrative body; (g) periodically, in cooperation with the control and risk committees, reviews the composition, powers and independence of the internal control functions and submits relevant reports to the administrative body; (2) For the purposes of sub-paragraph (1)(a), the nomination committee decides on the determination of a target for the representation of the underrepresented gender in the administrative body and prepares a policy on how to increase the number of persons of the underrepresented gender in the administrative body, in order to achieve this target; the target, the policy and their implementation are disclosed in accordance with the provisions of Article 435 paragraph (2) point c) of Regulation (EU) No. 575/2013. (3) The nomination committee, in performing its duties, takes into account, to the extent possible and on an ongoing basis, the need to ensure that decision-making by the administrative body is not dominated by one person or a small group of persons in a manner that prejudices the interests of the credit institution as a whole. (4) The nomination committee uses any kind of resources it deems appropriate, including external advisors, and receives adequate funding for this purpose. Joint Committees. 24.- (1) The competent authority may permit a credit institution which is not considered significant in terms of size, internal organization and nature, scope and complexity of its activities to establish:
(a) a joint committee consisting of the risk committee and the control committee or/and (b) a joint committee consisting of the nomination committee and the remuneration committee.
(2) Credit institutions intending to establish a joint committee should submit a request to the competent authority and justify the reasons for which they have chosen to establish a joint committee, as well as the manner in which this specific approach achieves the objectives of the committees. (3) In any case, credit institutions should ensure that the members of a joint committee as referred to in sub-paragraph (1) possess, at individual and collective level, the required knowledge, skills and expertise, which are required to fully understand the duties that the joint committee must perform.
PART 4 - SENIOR MANAGEMENT
Numerical adequacy and technical know-how of senior management.
25.- (1) Senior management must be sufficient in number and possess the necessary know-how for the effective management of the credit institution's activities.
(2) Credit institutions ensure that senior management assume the roles of heads of the internal control functions, in accordance with the provisions of this Directive and that these persons do not have direct responsibilities in the business units and support units which the internal control functions, within the framework of their duties, monitor and control. Selection, development and succession of senior management. 26.- (1) Credit institutions have appropriate policies and procedures for the selection, development and, when necessary, replacement of the Managing Director or other senior management and appropriate succession plans, duly taking into account the importance and criticality of their obligations towards the internal control work and operation of the credit institution and its group. These policies, plans and procedures ensure:
(a) the recognition and regular updating of the necessary qualifications, skills and academic or professional qualifications for ensuring – (i) the effectiveness of the Managing Director and other senior management and heads of the internal control functions, in performing their duties and responsibilities; (ii) compliance with regulatory requirements; (b) the monitoring of the development and evolution of potential internal candidates and the periodic assessment of their suitability for a senior management position in relation to the required abilities, skills and qualifications; (c) that in the design of the succession of the Managing Director and other senior management, the expiry date of the term, assignment or employment contract of each person is taken into account, so that – (i) the need for simultaneous replacement of many senior management is avoided; (ii) it is ensured that these transitions are made smoothly with the minimum possible impact on the work of the credit institution; (d) that emergency succession plans have been established for unforeseen events, such as the departure, death or disability of the Managing Director or other senior management, to facilitate the filling of both temporary and long-term basis, a senior management position vacated prematurely. Roles and responsibilities of senior management. 27.- (1) The Managing Director and other senior management are responsible for guiding and overseeing the effective management of the credit institution within the powers assigned to them by the administrative body and in compliance with applicable laws and regulations. (2) Senior management are responsible for:
(a) directing and overseeing the daily operations of the credit institution, observing the business objectives, strategies and policies approved by the administrative body, and legal and regulatory requirements; (b) providing recommendations to the administrative body, for its examination and approval, regarding business objectives, strategies and business plans and the major policies governing the operation of the administrative body; (c) providing complete, relevant and timely information to the administrative body that will allow it to review business objectives, business strategy and policies, and to hold senior management accountable for the performance of their duties. Oversight of institution's operations and guidance on daily basis. 28.- (1) Senior management are responsible for implementing an effective and transparent functional structure in the credit institution or group, in accordance with the business objectives, strategies and policies approved by the administrative body. Where the credit institution operates outside the Republic or operates through special purpose companies or similar structures or in jurisdictions that hinder transparency, senior management exercise adequate supervision of the credit institution's operations at group level, including these activities, and ensure the existence of appropriate reporting structures and the accessibility of the administrative body and supervisory authorities to significant information concerning non-transparent or non-standardized structures, branches and subsidiary companies outside the Republic. (2) Senior management are responsible for assigning tasks to staff and establishing such administrative structure and hierarchy that promote accountability and transparency, without gaps in reporting channels, and to supervise the exercise of the aforementioned assigned responsibilities. (3) Senior management implement effective capital and liquidity funding planning and budgeting process in a manner consistent with the direction given by the administrative body. Senior management oversee the implementation of the budget and capital and liquidity funding process, identify weaknesses and potential constraints and assess their significance, and develop recovery plans in case weaknesses affect the adequacy of liquidity and own funds. (4) Senior management set a good example for the implementation of the code of business ethics and corporate values and promote a corporate culture where staff members are encouraged to identify themselves issues of ethics, regulatory compliance or risk, and do not rely on internal control functions for the identification of values, in a manner consistent with the direction given by the administrative body and in accordance with the provisions of this Directive. (5) Senior management implement an appropriate compliance framework in accordance with the direction given by the administrative body and in accordance with the provisions of Part 9 of this Directive. (6)
Senior management implement an appropriate risk management framework in accordance with the risk strategy and the disposition and direction given by the administrative body and the provisions of Part 9 of this Directive; senior management ensure that effective procedures for the approval of new products have been developed and implemented, in accordance with the provisions of paragraph 58 of this Directive. (7) Senior management implement an appropriate internal control framework, in accordance with the direction given by the administrative body and the provisions of Part 9 of this Directive. Senior management ensure that adequate resources with appropriate authority and know-how are available to the internal control functions. (8) Senior management ensure that the credit institution develops appropriate information systems and communication systems to assist the administrative body in conducting effective supervision of the credit institution in accordance with the direction given by the administrative body and the provisions of Part 11 of this Directive. Senior management are responsible for ensuring the maintenance of appropriate records. (9) Senior management define appropriate human resources policies, including the development of management and their succession planning. (10) Credit institutions must ensure the adequate physical presence of senior management in the performance of their duties as defined in this Directive and in compliance with applicable laws and regulations. Providing recommendations to the administrative body. 29.- (1) Senior management provide detailed recommendations to the administrative body regarding business objectives, strategy and risk appetite, capital and funding plans, distribution decisions and remuneration policy. (2) Senior management ensure that the proposed recommendations are adequately analyzed and reflect the expectations of significant stakeholders, including creditors, counterparties, investors and supervisory authorities. (3) Senior management report to the administrative body weaknesses and constraints identified in strategies and design, simultaneously submitting recommendations for remediation.
PART 5 - REMUNERATION FRAMEWORK
Remuneration policies.
EBA/GL/2015/22
21.12.2015.
30.- (1) Credit institutions comply with the EBA guidelines on sound remuneration policies pursuant to Article 74 paragraph 3 and Article 75 paragraph 2 of Directive 2013/36/EU and disclosures pursuant to Article 450 of Regulation (EU) No. 575/2013.
(2) When determining and applying the entire set of remuneration policies, including salaries and optional pension benefits, for categories of employees whose professional activities have a significant impact on the risk characteristics of the credit institution, credit institutions comply with the following requirements in a manner appropriate to their size, internal organization and nature, scope and complexity of their activities:
(a) the remuneration policy is consistent with and promotes prudent and effective risk management and does not encourage risk-taking by the credit institution; (b) the remuneration policy is a gender-neutral remuneration policy; (c) the remuneration policy is consistent with the business strategy, objectives, values and long-term interests of the credit institution, and incorporates measures to avoid conflicts of interest; (d) the administrative body of the credit institution, in exercising its supervisory responsibility, adopts and periodically reviews the general principles of the remuneration policy and is responsible for overseeing its implementation; (e) the implementation of the remuneration policy is subject, at least annually, to central and independent internal control regarding compliance with the remuneration policies and procedures approved by the administrative body in exercising its supervisory powers; (f) staff members entrusted with control duties are independent from the business units they supervise, have the appropriate powers and are remunerated according to the achievement of objectives related to their duties, regardless of the performance of the business sectors they control; (g) the remuneration of senior management in risk management and regulatory compliance functions is directly supervised by the remuneration committee or by the joint nomination and remuneration committee if its establishment has been permitted by the competent authority pursuant to sub-paragraph (1) of paragraph 24 of this Directive; (h) in the remuneration policy, taking into account national wage setting criteria, a clear distinction is made between the criteria regarding the determination:
(i) of fixed basic remuneration, which should primarily reflect relevant professional experience and management responsibility, as defined in the employee's job description as part of employment terms; and (ii) of variable remuneration, which should reflect sustainable and risk-adjusted performance, as well as performance exceeding that required for the fulfillment of the employee's duties as defined in the employee's job description as part of employment terms. (3) For the purposes of sub-paragraph 2, categories of employees whose professional activities have a significant impact on the risk characteristics of credit institutions include at least:
(a) all members of the administrative body and senior management, (b) staff members with managerial responsibilities for control functions or significant business units of the credit institution, (c) staff members who were entitled to significant remuneration in the previous financial year, provided the following conditions are met:
(i) the annual remuneration of the staff member is equal to or higher than five hundred thousand (500,000) euros and equal to or higher than the average remuneration provided to members of the administrative body and senior management of the credit institution referred to in point (a), (ii) the staff member performs the professional activity within a significant business unit and this activity belongs to a type that has significant implications for the risk characteristics of the relevant business unit. (4) Credit institutions ensure that shareholders are informed about the total remuneration of senior management. Variable elements of remuneration. 31.- (1) For the variable elements of remuneration, the following principles apply additionally to, and under the same conditions as those defined in paragraph 30 of this Directive:
(a) in the case where remuneration is linked to performance, the total amount of remuneration is based on a combination of assessment of the individual's performance, the relevant business unit and the overall results of the credit institution, and, when assessing individual performance, financial and non-financial criteria are taken into account; (b) the performance assessment is integrated into a multi-year framework, to ensure that the assessment process is based on longer-term performance and that the payment of the parts of the remuneration linked to performance is distributed over a period that takes into account the underlying cycle of the credit institution's economic activity and its business risks; (c) the total variable remuneration does not restrict the credit institution's ability to strengthen its capital base; (d) guaranteed variable remuneration is not consistent with sound risk management or the principle of performance-based pay and is not included in future remuneration plans; (e) guaranteed variable remuneration constitutes an exception and may be provided only when hiring new staff, provided that the credit institution has a healthy and strong capital base and is limited only to the first year of employment; (f) the fixed and variable components of total remuneration are appropriately balanced and the fixed component represents a sufficiently high percentage of total remuneration, in order to make it possible to apply a fully flexible policy regarding the variable elements of remuneration, including the possibility of not paying the variable element of remuneration; (g) credit institutions define the appropriate ratio between fixed and variable components of total remuneration, where the following principles apply:
(i) the variable component does not exceed fifty percent (50%) of the fixed component of total remuneration for each person; (ii) shareholders or owners or members of the credit institution may approve a higher maximum ratio between fixed and variable components of remuneration provided that the total amount of the variable component does not exceed one hundred percent (100%) of the fixed component of total remuneration for each person. Any approval of a higher ratio, according to point (i) is carried out in accordance with the following procedure:
(A) the shareholders or owners or members of the credit institution act on the basis of a detailed recommendation of the credit institution, which sets out the reasons and scope of the sought approval, including the number of staff affected, their duties, and the expected impact on the requirement to maintain a sound capital base;
(B) the shareholders or owners or members of the credit institution decide by a majority of at least sixty-six percent (66%), provided that at least fifty percent (50%) of the shares or equivalent ownership rights are represented, or, in the absence thereof, decide by a majority of seventy-five percent (75%) of the represented ownership rights;
(C) the credit institution notifies all shareholders or owners or members of the credit institution, providing a reasonable prior period of notice, that approval under sub-paragraph (A) above will be sought;
(D) the credit institution informs the competent authority without delay regarding the recommendation to the shareholders or owners or members, including the proposed higher maximum ratio of the relevant rationale, and is able to demonstrate to the competent authority that the proposed higher ratio does not conflict with the obligations of the credit institution under this Directive and under Regulation (EU) No 575/2013, primarily regarding the capital requirements of the credit institution;
(E) the credit institution informs the competent authority without delay regarding the decisions of the shareholders or owners or members, including any approval of a higher ratio under point (A) above, and the competent authority uses the information received for the comparative assessment of the relevant practices of credit institutions.
(F) the staff members directly concerned by the higher maximum levels of variable remuneration referred to in this point are not allowed, where applicable, to exercise, directly or indirectly, any voting rights they may have as shareholders or owners or members of the credit institution;
EBA/GL/2014/01
27.03.2014.
(iii) credit institutions may apply an adjustment factor for an amount of up to twenty-five percent (25%) of total variable remuneration, provided that this is paid in instruments deferred for a period of not less than five (5) years. Credit institutions that choose to apply the provisions of this point must comply with the EBA Guidelines on the Applicable Hypothetical Adjustment Factor for Variable Remuneration of 2014;
(h) remuneration payments linked to the early termination of an employment contract reflect long-term performance and do not reward failure or the commission of misconduct;
(i) remuneration packages concerning compensation or buy-out from previous employment contracts must be aligned with the long-term interest of the credit institution, including provisions on withholding, suspension, performance, and recovery;
(j) the measurement of performance used for the calculation of components for variable remuneration or grouped components for variable remuneration includes an adjustment for all kinds of current and future risks and takes into account the cost of capital and the required liquidity;
(k) the allocation of components for variable remuneration within the credit institution also takes into account the full spectrum of current and future risks;
(l) a significant part, and in any case at least fifty percent (50%) of any variable remuneration, consists of a proportion of the following:
(i) shares or, depending on the legal structure of the relevant credit institution, equivalent ownership rights; or instruments linked to shares or, depending on the legal structure of the relevant credit institution, equivalent non-easily liquid instruments;
(ii) where possible, other instruments, within the meaning of Article 52 or 63 of Regulation (EU) No 575/2013, or other instruments fully convertible into Common Equity Tier 1 instruments or which have been revalued, which in any case duly reflect the creditworthiness of the credit institution under normal economic conditions and are suitable for use for the purposes of variable remuneration.
The instruments referred to in this point are subject to an appropriate holding policy, with the aim of aligning incentives with the long-term interests of the credit institution. The competent authority may impose restrictions on the type and design of these instruments or prohibit certain instruments as appropriate in each case. This point applies both to the deferred part of the variable component of remuneration according to point (m) and to the part of the variable component of remuneration that is not deferred;
(m) (i) the payment of a significant part and in any case at a rate of at least forty percent (40%) of the variable component of remuneration is deferred for a period of not less than four to five years and is properly aligned with the nature of the business activity, its risks, and the activities of the staff member concerned. For members of the administrative body and senior management of credit institutions that are significant in terms of size, internal organization, and nature, scope, and complexity of their activities, the deferral period should not be less than five (5) years.
(ii) Payable remuneration subject to deferral arrangements does not become payable faster than provided on a pro-rata basis. In the case of a particularly high amount of variable remuneration, payment is deferred by at least sixty percent (60%). The duration of the deferral period is determined according to the business cycle, the nature of the business activity, the risks involved, and the activities of the staff members concerned;
(n) the variable remuneration, including the deferred part, is paid or vested only if it is sustainable based on the overall financial situation of the credit institution and justified based on the performance of the credit institution, the relevant business unit, and the individual concerned.
Subject to the general principles of national labor law, including provisions on employment contracts, the total variable remuneration should generally shrink significantly when the credit institution shows weak or negative financial performance, taking into account both current remuneration and reductions in remuneration previously received, including through malus arrangements or remuneration recovery arrangements.
Up to one hundred percent (100%) of the total variable remuneration is subject to malus arrangements or remuneration recovery arrangements. Credit institutions establish specific criteria for the application of malus or remuneration recovery. These criteria cover in particular situations where the staff member:
(i) participated in or was responsible for behavior that caused significant losses to the institution;
(ii) did not meet the appropriate standards of competence and propriety;
(o) the pension policy is consistent with the business strategy, objectives, values, and long-term interests of the credit institution.
If the employee leaves the credit institution before retirement, the optional pension benefits are retained by the credit institution for a period of five years, in the form of the instruments referred to in point (l). In the case of an employee reaching retirement, the optional pension benefits are paid to the employee in the form of the instruments referred to in point (l), subject to a five-year holding period;
(p) staff members are required not to use personal risk hedging strategies or insurance linked to remuneration or liability to circumvent the risk alignment mechanisms included in the remuneration arrangements;
(q) variable remuneration is not paid through mechanisms or methods that facilitate non-compliance with legislative provisions harmonized with Directive 2013/36/EU or Regulation (EU) No 575/2013.
(2) By way of derogation from sub-paragraph 1, the requirements provided for in points (l) and (m) and in the second paragraph of point (o) of that sub-paragraph do not apply to:
(a) a credit institution that is not a large institution as defined in Article 4(1)(146) of Regulation (EU) No 575/2013 and the value of its assets is on average and on an individual basis in accordance with this Directive and Regulation (EU) No 575/2013 equal to or less than five (5) billion euros during the four-year period immediately preceding the current financial year,
(b) a staff member whose annual variable remuneration does not exceed fifty thousand (50,000) euros and does not represent more than one third of the total annual remuneration of the staff member.
(3) By way of derogation from sub-paragraph 2(a) of this paragraph, the competent authority may reduce or increase the maximum limit referred to in that provision, provided that:
(a) the credit institution in question is not a large institution as defined in Article 4(1)(146) of Regulation (EU) 575/2013 and, in the event that the maximum limit is increased:
(i) the credit institution meets the criteria defined in points (c), (d), and (e) of Article 4(1)(145) of Regulation (EU) 575/2013, and
(ii) the maximum limit does not exceed fifteen billion (15,000,000,000) euros,
(b) it is appropriate to modify the maximum limit, in accordance with this paragraph, taking into account the nature, scope, and complexity of the activities of the credit institution, its internal organization, or, where applicable, the characteristics of the group to which it belongs.
(4) By way of derogation from sub-paragraph 2(b) of this paragraph, the competent authority may decide that staff members entitled to annual variable remuneration below the limit and share referred to in that point are not subject to the exemption defined in that provision due to the specifics of the national market regarding remuneration practices or due to the nature of the responsibilities and job descriptions of the staff members concerned.
Institutions benefiting from government intervention.
32.- In the case of institutions benefiting from exceptional government intervention, the following principles apply in addition to those provided for in sub-paragraph (2) of paragraph 30 of this Directive:
(a) variable remuneration is strictly limited as a percentage of net revenues, when it does not align with the maintenance of a sound capital base and early exit from state support;
(b) remuneration is restructured by credit institutions in a manner that aligns with sound risk management and long-term development, including, where appropriate, the establishment of limits on the remuneration of members of the administrative body of the credit institution;
(c) no variable remuneration is paid to members of the administrative body of the credit institution, unless justified.
PART 6 – GOVERNANCE FRAMEWORK
Organizational framework.
33.- (1) The administrative body of an institution should ensure an organizational and operational structure that is appropriate and transparent for the credit institution in question, and have a written description of it.
(2) The structure should promote and demonstrate effective and prudent management of the credit institution on an individual, sub-consolidated, and consolidated level.
(3) The administrative body should ensure that the functions of the internal control system are independent from the business areas they monitor, including, among other things, regarding the appropriate segregation of duties, and that they have the appropriate financial and human resources, as well as powers for the effective exercise of their role.
(4) Reporting lines and the distribution of responsibilities, especially among persons holding key positions, within the credit institution should be clear, fully defined, consistent, mandatory, and duly documented. The documentation should be updated appropriately.
(5) The structure of the credit institution should not hinder the ability of the administrative body to effectively supervise and manage the risks to which the credit institution or the group is exposed, nor the ability of the competent authority to effectively exercise its supervision over the credit institution.
(6) The administrative body should assess the possible consequences resulting from significant changes in the group structure (e.g., establishment of new subsidiaries, mergers and acquisitions, sale or liquidation of parts of the group, or external developments) regarding the robustness of the organizational framework of the credit institution. In the event that weaknesses are identified, the administrative body should immediately make all necessary adjustments.
Knowledge and understanding of the structure of the credit institution.
34.- (1) The administrative body should know and fully understand the legal, organizational, and operational structure of the credit institution (“Know your structure”) and ensure that it complies with the approved business strategy, risk strategy, and risk appetite of the credit institution.
(2) The administrative body should be responsible for approving sound strategies and policies regarding the establishment of new structures.
(3) When a credit institution establishes many legal entities within its group, the number of them, and in particular the interconnections and transactions between them, should not hinder the design of its internal governance, as well as the effective management and supervision of the risks faced by the group as a whole.
(4) The administrative body should ensure that the structure of the institution and, where deemed necessary, the structures within the group, taking into account the criteria defined in paragraph 36 of this Directive, are clear, efficient, and transparent to the staff, shareholders, and other interested parties of the institution, as well as to the competent authority.
(5) The administrative body should guide the structure of the credit institution, its evolution, and its limitations, ensure that the structure is duly justified and efficient, and does not involve unnecessary or inappropriate complexity.
(6) (a) The administrative body of a credit institution with consolidation obligations should understand both the legal, organizational, and operational structure of the group as well as the purpose and activities of the various entities of the group, as well as the links and relationships between them. This includes understanding the operational risks of the group and intra-group exposures, as well as the way the funding, capital profile, liquidity, and risk profile of the group could be affected under normal and adverse conditions.
(b) The administrative body should ensure that the credit institution is able to produce timely information for the group regarding the type, characteristics, organizational chart, ownership structure, and business activities of each legal entity of the group and that the credit institutions of the group comply with all supervisory reporting requirements on an individual, sub-consolidated, and consolidated basis.
(7) (a) The administrative body of a credit institution with consolidation obligations should ensure that the various entities of the group (including the credit institution itself that performs the consolidation) receive sufficient information in order to form a clear understanding of the general objectives, strategies, and risk profile of the group, as well as the way the respective entity of the group is integrated into the structure and operational functioning of the group. The relevant information and their reviews should be documented and made available to the respective competent functions, including the administrative body, the business areas, and the internal control system functions.
(b) Members of the administrative body of a credit institution with consolidation obligations should ensure that they are informed about the risks entailed by the structure of the group, taking into account the criteria defined in paragraph 36 of this Directive.
(c) The information referred to in points (a) and (b) includes the receipt of:
(i) updates on main risk drivers;
(ii) regular reports on the assessment of the overall structure of the credit institution and the relevant compliance activities with the approved strategy of each entity at the group level; and
(iii) regular reports on issues for which compliance is required, based on the regulatory framework, on an individual, sub-consolidated, and consolidated level.
Complex structures and non-standard or non-transparent activities.
35.- (1) Credit institutions should avoid creating complex and potentially non-transparent structures.
(2) In the context of their decision-making process, credit institutions should take into account the results of the risk assessment they conduct to investigate whether such structures could be used for a purpose related to money laundering from illegal activities or other economic crimes, as well as the corresponding controls and the legal framework applied.
(3) For the purposes of sub-paragraph (2), credit institutions should take into account at least the following:
(a) the extent to which the jurisdiction in which the structure will be established actually complies with European and international standards regarding tax transparency, the fight against money laundering from illegal activities, and the fight against terrorist financing;
(b) the extent to which the structure serves an apparent economic and legal purpose;
(c) the extent to which the structure could be used to hide the identity of the ultimate beneficial owner;
(d) the extent to which the customer’s request leading to the possible establishment of a structure raises concerns;
(e) whether the structure may hinder the due supervision by the administrative body of the credit institution or the ability of the credit institution to manage the relevant risk; and
(f) whether the structure poses obstacles to effective supervision by the competent authority.
(4) In any case, credit institutions should not create non-transparent or unnecessarily complex structures, which lack a clear economic rationale or legal purpose, or if credit institutions are concerned that such structures may be used for a purpose related to economic crime.
(5) In the establishment of the credit institution’s structures, the administrative body should understand both the structures and their purpose, as well as the specific risks associated with them, and ensure the appropriate participation of the internal control system functions.
(6) The structures of the credit institution should be approved and maintained only if their purpose is clearly formulated and understood, and provided that the administrative body is convinced that all significant risks have been identified, including the
reputational risks, that it is possible to effectively manage and appropriately report all risks and that effective supervision has been ensured. The more complex and opaque the organizational and operational structure is, and the greater the risks, the more intensive the supervision of the structure by the administrative body should be.
(7) Credit institutions should document their decisions and be able to justify their decisions to the competent authority.
(8) The administrative body should ensure the adoption of appropriate measures to avoid or reduce the risks of activities conducted within the structures of the credit institution. In this context, it should ensure, among other things, that:
(a) the credit institution has adequate policies and procedures and documented processes (e.g., applicable limits, information requirements) for the assessment, regulatory compliance, approval and risk management of such activities, taking into account the consequences for the organizational and operational structure of the group, its risk profile and reputational risk;
(b) the credit institution with consolidation obligations, as well as internal and external auditors, have access to information regarding these activities and their risks, and such information is submitted to the administrative body under its supervision and to the competent authority that issued the operating license; and
(c) the credit institution periodically assesses the ongoing need to maintain its structures.
(9) The structures and activities of the credit institution, including its compliance with legislation and professional standards, should be subject to regular review by the internal control function, using a risk-based approach.
(10) Credit institutions should take the same risk management measures that are taken within the framework of their own operational activities when conducting non-standard or opaque activities on behalf of clients (e.g., assisting clients in establishing companies in offshore jurisdictions, developing complex structures and financial transactions on their behalf, or providing custodial services) that raise similar internal governance challenges and pose serious operational and reputational risks. In particular, institutions should analyze the reason why a client wishes to create a specific structure.
Organizational framework at group level.
36.- (1) For the purposes of paragraph 2 of this Directive, and subject to the provisions of Articles 4 and 5 of Article 19ST of the Law, parent undertakings and subsidiaries falling within the scope of supervisory consolidation should ensure the implementation of the governance arrangements, procedures and mechanisms referred to in their subsidiaries that are not subject to the provisions of the Law and the Directive, including those established in third countries and in offshore financial centers, in order to ensure a sound governance framework on a consolidated and sub-consolidated basis.
(2) The competent functions of the credit institution with consolidation obligations and its subsidiaries should interact and exchange data and information appropriately. The governance arrangements, procedures and mechanisms should ensure that the credit institution with consolidation obligations has adequate data and information and is able to assess the risk profile at group level, as described in detail in paragraph 34 of this Directive.
(3) The administrative body of a subsidiary subject to the provisions of the Law, this Directive, or Directive 2013/36/EU should approve and implement at the individual level the governance policies established at the group level on a consolidated or sub-consolidated basis, in a manner consistent with all specific requirements of Union and national law.
(4) At consolidated and sub-consolidated level, the credit institution with consolidation obligations should ensure compliance with group-level governance policies by all credit institutions and other entities falling within the scope of supervisory consolidation, including their subsidiaries that are not themselves subject to the provisions of the Law and this Directive.
(5) When implementing governance policies, the credit institution with consolidation obligations should ensure that sound governance arrangements are in place for each subsidiary and explore the possibility of establishing specific arrangements, procedures and mechanisms, within the framework of which business activities are not conducted under the individual organization of separate legal entities, but under the sum of business sectors of different legal entities.
(6) The credit institution with consolidation obligations should take into account the interests of all its subsidiaries, as well as the way in which strategies and policies contribute to the interests of each individual subsidiary and the interests of the group as a whole in the long term.
(7) Parent undertakings and their subsidiaries should ensure that credit institutions and group entities comply with all specific requirements of each relevant jurisdiction.
(8) The credit institution with consolidation obligations should ensure that subsidiaries established in third countries, which are included in the scope of supervisory consolidation, have governance arrangements, procedures and mechanisms consistent with group-level governance policies and comply with the requirements of paragraphs (2), (3) and (5) of Article 19, Article 19B, Article 19C, Article 19D, Article 22E, Article 24A, Article 24B, paragraphs 13 and 14 of Article 26, paragraphs (1) and (2) of Article 26G, Article 26D, and paragraph (1) of Article 30B of the Law, with the provisions of the Directive on the Assessment of the Fitness of Members of the Administrative Body and Persons Holding Key Functions in Licensed Credit Institutions of 2020, as well as with the provisions of this Directive, to the extent that this is not prohibited by the legislation of the relevant third country.
(9) (a) The governance requirements provided for in the Law and this Directive apply to credit institutions under paragraph 3 of this Directive, regardless of whether they are subsidiaries of a parent undertaking in a third country.
(b) In the event that a credit institution is a subsidiary of a parent undertaking established in a third country and the credit institution is an institution with consolidation obligations, the scope of supervisory consolidation does not include the level of the parent undertaking established in a third country and other direct subsidiaries of that parent undertaking.
(c) The credit institution with consolidation obligations should ensure that the governance policy of the parent institution established in a third country is taken into account within its own governance policy, to the extent that this does not conflict with the requirements provided under relevant Union law, including Directive 2013/36/EU, the Law and this Directive.
Annex I
(10) In the establishment of policies and documentation of governance arrangements, credit institutions should take into account the aspects listed in Annex I of this Directive. Although policies and documentation may be included in separate documents, credit institutions should consider combining or referencing them in a single document for the governance framework.
PART 7 – DELEGATION OF WORK TO THIRD PARTIES
Outsourcing policy.
37.- (1) The administrative body should approve, as well as review and update at regular intervals, and in any case at least every three years, the written outsourcing policy of the credit institution, ensuring the timely implementation of appropriate changes.
(2) (a) In the outsourcing policy of activities, the impact of outsourcing on the business activities of the credit institution and the risks it faces, such as operational risks, including legal risk and ICT and security risks, reputational risks, and concentration risks, should be taken into account.
(b) The policy should include reporting and monitoring of the arrangements to be implemented from the initial conception until the termination of the outsourcing agreement, including the preparation of the business feasibility report for outsourcing, the conclusion of an outsourcing contract, the execution of the contract until its termination, contingency plans, and exit strategies.
(c) The credit institution remains fully responsible for all services that are the subject of outsourcing, as well as for the activities and management decisions arising from them. The activity outsourcing policy should make it clear that outsourcing does not exempt the credit institution from its regulatory obligations and its responsibilities towards its clients.
(3) This specific policy should state that activity outsourcing arrangements should not hinder the exercise of effective on-site and off-site supervision of the credit institution and should not conflict with supervisory restrictions regarding services or activities. The policy should also cover internal outsourcing of activities, i.e., services provided by a separate legal entity within the group of the credit institution, and should take into account any specific conditions present at the group level.
Outsourcing procedures.
EBA/GL/2019/02
25.02.2019.
38.- (1) Credit institutions apply, in relation to the outsourcing policy and procedures, the EBA Guidelines on outsourcing of activities.
(2) Credit institutions clearly assign responsibilities for the documentation, management, and control of outsourcing agreements and have adequate resources to ensure compliance with all legislative and regulatory requirements, including the EBA guidelines referred to in sub-paragraph (1) and the documentation and monitoring of all outsourcing agreements.
(3) Subject to the principle of proportionality, credit institutions establish an outsourcing function and in any case appoint one of their staff members (Outsourcing Officer) as head for the management and supervision of the risks of outsourcing agreements as part of the institution's internal control framework, as well as for the supervision of the documentation of outsourcing agreements. This appointment, in the case where it does not concern a member of the administrative body or an existing holder of a key function, falls under the persons holding key functions and consequently under the requirements set by the Directive on the Assessment of the Fitness of Members of the Administrative Body and Persons Holding Key Functions in Licensed Credit Institutions of 2020.
(4) The Outsourcing Officer is, within the framework of his duties, the contact person with the competent authority for outsourcing matters and provides all necessary information required by the competent authority.
(5) Credit institutions maintain an updated register of information for all outsourcing agreements in accordance with the provisions of the Guidelines referred to in sub-paragraph (1) and make available to the competent authority, whenever requested, either the full register or parts thereof concerning the outsourcing of specific activities.
(6) Credit institutions submit to the competent authority, on an annual basis, a report which includes the following, in relation to outsourcing of activities that are not considered essential or significant:
(a) a list of outsourcings made during the reporting period with a brief description of the relevant activity, the duration of the outsourcing, and the relevant department/unit that owns the activity.
(b) the full name and country of establishment of the service provider and, in the case of a supervised entity, the competent supervisory authority.
(c) confirmation that the outsourcing risks have been duly assessed.
(d) confirmation that the outsourcing was approved by a competent approving body.
(e) confirmation that a legal opinion was obtained regarding the fact that the outsourcing does not concern an essential or significant activity.
The annual report is submitted by January 31 of each year, with the reporting period being the preceding year. The submission date and reporting period may vary as appropriate, in consultation with the competent authority.
(7) (a) Credit institutions should consider an activity to be essential or significant, among other cases, in the cases listed in the relevant provisions of the EBA Guidelines on outsourcing of activities.
(b) In addition to the cases in point (a), the management of the main information systems of the credit institution by third parties, including systems that store customer data and bank accounts, as well as systems that are the source of information for supervisory and accounting reports, are considered "essential or significant activities". It is understood that the use of "cloud" service providers for the aforementioned tasks is also considered an essential or significant activity.
(8) Credit institutions obtain, for each case of outsourcing of activities, a legal opinion regarding whether the activity in question can be considered essential or significant, in accordance with the provisions of this Directive and the criteria set for this purpose in the EBA Guidelines referred to in sub-paragraph (1). The legal opinion is additional to the institution's obligations for risk assessment and other factors that must be taken into account when assessing any outsourcing, but may take into account the conclusions arising from the assessment of these factors.
(9) Credit institutions inform the competent authority in writing regarding each case of outsourcing of an activity that has been deemed essential or significant, at least two months before the finalization of the outsourcing, submitting, at a minimum, the following information:
(a) the department/unit of the credit institution that owns the work to be outsourced;
(b) a description of the service or activity to be outsourced;
(c) information about the service provider. In the event that the service provider is supervised by another competent supervisory authority, relevant information should be provided;
(d) confirmation that the outsourcing process complies with the provisions of this Directive and the EBA Guidelines on outsourcing of activities, which includes confirmation that a risk assessment was conducted by the Risk Management Function and that a legal opinion has been obtained;
(e) confirmation that official approval for the outsourcing has been obtained from the competent approving body;
(f) confirmation that an official agreement will be prepared and signed between the credit institution and the service provider, which will comply with the provisions of this Directive and the Guidelines referred to in sub-paragraph (1).
(10) Within the two-month period referred to in sub-paragraph (9):
(a) the competent authority may request further information regarding the outsourcing of an essential or significant activity and/or, in the event of finding deficiencies, require the adoption of relevant corrective measures. In such a case, the credit institution does not proceed with the outsourcing until the competent authority is satisfied regarding the aforementioned and informs the credit institution in writing.
(b) the competent authority may object to the outsourcing, justifying its decision. In such a case, the credit institution does not proceed with the said outsourcing.
PART 8 - RISK APPETITE CULTURE AND BUSINESS CONDUCT
Risk appetite culture.
39.- (1) A sound, diligent, and consistent risk appetite culture should constitute a key element of effective risk management of credit institutions and should enable credit institutions to make sound and documented decisions.
(2) Credit institutions should develop a comprehensive risk appetite culture for the entire group, based on a full understanding and holistic view of the risks they face and their management methods, and taking into account the risk appetite of the credit institution.
(3) Credit institutions should develop a risk appetite culture through policies, communication, and staff training regarding the activities, strategy, and risk profile of credit institutions, while also adapting staff communication and training to take into account staff responsibilities regarding risk taking and management.
(4) Staff members should be fully informed of their responsibilities regarding risk management. Risk management should not be limited to specialized risk management staff or the internal control system functions. Business units, under the supervision of the administrative body, should be the main responsible parties for daily risk management, in accordance with the policies, procedures, and control systems of the credit institution, taking into account the risk appetite and capacity of the credit institution.
(5) A strong risk appetite culture should include, among other things, the following elements:
(a) Top-down coordination (“tone from the top”): The administrative body should be responsible for defining and communicating the core values and expectations of the credit institution. The behavior of administrative body members should reflect the values espoused by the credit institution. The management of the credit institution, including persons holding key functions, should contribute to the internal communication of core values and expectations to staff. Staff should act in accordance with all applicable legislative and regulatory provisions and directly refer any observed non-compliance to higher levels of the hierarchy. The administrative body should promote, monitor, and evaluate, on a regular basis, the risk appetite culture of the credit institution, take into account the impact of the risk appetite culture on financial stability, the risk profile, and the sound governance of the credit institution, and make changes where deemed necessary.
(β) Accountability: members of the relevant staff at all levels should know and understand the core values of the credit institution and, to the extent required for their role, the risk appetite and risk-taking capacity of the credit institution. They should be able to perform their roles and be aware of the fact that they should be accountable for their actions in relation to the behavior of the credit institution regarding risk-taking.
(γ) Effective communication and critical review: a well-developed risk culture should promote an environment of open communication and effective critical review, within which decision-making processes encourage the expression of a wide range of views, allow existing practices to be tested, encourage staff members to adopt a constructive critical stance, and promote an environment of open and constructive participation throughout the organization.
(δ) Incentives: the provision of appropriate incentives should play a key role in aligning risk-taking behavior with the risk profile of the credit institution and its long-term interests.
Corporate values and code of ethics.
40.- (1) The administrative body should develop, approve, maintain and promote high ethical and professional standards, taking into account the specific needs and characteristics of the credit institution, and ensure the implementation of these standards based on a code of ethics or similar instrument.
(2) The administrative body should also supervise the compliance of staff with the standards referred to in sub-paragraph (1). Where appropriate, the administrative body may approve and apply the credit institution's standards established at group level or common standards issued by associations or other relevant bodies.
(3) Credit institutions should ensure that there is no discrimination on the grounds of sex, race, colour, ethnic or social origin, genetic features, language, religion or belief, political or other opinion, membership of a national minority, property, birth, disability, age or sexual orientation.
(4) The policies of credit institutions must be gender-neutral and credit institutions must implement measures that ensure equal opportunities for all sexes, including those concerning career prospects and aimed at improving the representation of the underrepresented sex in managerial positions and among staff holding managerial responsibilities, as defined in Commission Delegated Regulation (EU) 2019/923. Credit institutions should monitor the development of the gender pay gap separately for the defined staff (excluding members of the administrative body). Credit institutions should have policies that facilitate the reintegration of staff after maternity, paternity, or parental leave.
(5) The applied standards should aim to strengthen the governance arrangements of the credit institution and reduce the risks to which the credit institution is exposed, particularly operational risks and reputational risks, and may have significant adverse effects on the profitability and sustainability of an institution through fines, legal costs, restrictions imposed by the competent authority, other financial and criminal sanctions, as well as the loss of the value of its commercial identity and consumer confidence.
(6) The administrative body should have clear and documented policies regarding the manner of compliance with these standards. These policies should:
(a) remind staff that all activities of the credit institution should be conducted in accordance with applicable law and the corporate values of the credit institution;
(b) promote risk awareness through a strong risk culture in accordance with paragraph 39 of this Directive, expressing the expectation of the administrative body that activities do not exceed the defined risk appetite nor the limits set by the credit institution and the respective competencies of the staff;
(c) define the principles and provide examples of acceptable and unacceptable behaviors specifically related to incorrect financial reporting and the commission of misdemeanors, economic and financial crimes, including but not limited to fraud, money laundering from illegal activities and terrorist financing, anti-competitive practices, economic sanctions, bribery and corruption, market manipulation, abusive sales and other violations of consumer protection legislation, tax offenses committed indirectly or directly, and which include illegal or prohibited dividend schemes or dividend schemes aimed at abusive selection of the most favorable regulatory framework;
(d) clarify that, in addition to compliance with legislative and regulatory requirements and internal policies, staff are expected to behave with honesty and integrity and to perform their duties with due skill, care and diligence; and
(e) ensure that staff are informed about internal and external disciplinary measures, legal actions and sanctions that may result from the commission of misdemeanors and unacceptable behavior.
(7) Credit institutions should monitor compliance with the respective standards and ensure staff awareness, for example by providing training.
(8) Credit institutions should identify the function responsible for monitoring compliance and for assessing violations of the code of ethics or similar instrument, as well as a procedure for addressing non-compliance issues. The results should be reported periodically to the administrative body.
Conflict of interest policy at credit institution level.
41.- (1) The administrative body should be responsible for establishing, approving and supervising the implementation and maintenance of effective policies aimed at identifying, assessing, managing and limiting or preventing actual and potential conflicts of interest at credit institution level, such as those that may arise, for example, due to the different activities and roles of the credit institution, due to the different institutions falling within the scope of supervisory consolidation or due to the different business sectors or units within the credit institution or regarding external stakeholders.
(2) Within their organizational and administrative arrangements, credit institutions should take adequate measures to avoid the possibility that conflicts of interest have negative effects on the interests of their customers.
(3) The measures of credit institutions for the management or, where appropriate, limitation of conflicts of interest should be documented and include, among others, the following:
(a) appropriate segregation of duties, e.g. the assignment of conflicting activities in the context of transaction execution or when providing services to different persons or the assignment of supervisory competencies and reporting competencies on conflicting activities to different persons;
(b) imposition of information barriers, e.g. through the physical separation of certain business sectors or units.
Conflict of interest policy for staff.
42.- (1) The administrative body should be responsible for establishing, approving and supervising the implementation and maintenance of effective policies aimed at identifying, assessing, managing and limiting or preventing actual and potential conflicts between the interests of the credit institution and the private interests of staff members, including members of the administrative body, which could adversely affect the exercise of their duties and responsibilities. A credit institution subject to consolidation should take into account interests within a conflict of interest policy at group level, on a consolidated or sub-consolidated basis.
(2) (a) The specific policy referred to in sub-paragraph (1) should aim to identify conflicts of interest of staff members, including the interests of their closest relatives.
(b) Credit institutions should take into account that conflicts of interest may arise not only from existing but also from previous personal or professional relationships.
(c) In the event that conflicts of interest arise, credit institutions should assess their seriousness, decide on the adoption of appropriate measures to limit them and implement these measures.
(3) Regarding conflicts of interest likely to arise from previous relationships, credit institutions should define an appropriate timeframe within which they wish staff to report such conflicts of interest, based on the reasoning that these conflicts may continue to affect staff behavior and their participation in decision-making.
(4) The policy should cover at least the following situations or relationships within which conflicts of interest may arise:
(a) financial interests, such as shares, other ownership and participation rights, financial portfolio companies and other financial interests in commercial clients, intellectual property rights, loans granted by the credit institution to a company owned by staff members, participation in or ownership of an entity or entity with conflicting interests;
(b) personal or professional relationships with holders of major holdings in the credit institution;
(c) personal or professional relationships with staff members of the credit institution or with entities included in the scope of supervisory consolidation, for example family relationships;
(d) other employment positions and previous employment positions in the recent past, for example over a five-year period;
(e) personal or professional relationships with relevant external stakeholders, for example connection with significant suppliers, consultants or other service providers; and
(f) political influence or political relationships.
(5) Without prejudice to the above, credit institutions should take into account that the status of a shareholder in a credit institution or maintaining private accounts or loans in a credit institution or using other services of the credit institution should not result in the formation of a situation in which it is considered that the specific staff member is involved in a conflict of interest, if it remains within an appropriate minimum limit to be established by credit institutions as part of their policy.
(6) The policy should define the reporting and disclosure procedures to the function responsible in accordance with this policy. Staff should have the duty to notify at credit institution level any issue that may lead or has already led to a conflict of interest.
(7) Within the policy, there should be a distinction between conflicts of interest that persist and require management on a permanent basis and conflicts of interest that arise suddenly in relation to an individual event - such as for example a transaction or the selection of a service provider - and their management is usually possible by taking one-off measures. In any case, the interest of the credit institution should be at the center of decisions taken.
(8) The policy should define the procedures, measures, documentation requirements and responsibilities for identifying and preventing conflicts of interest, for assessing their seriousness and for taking measures to limit them. Within the context of these procedures, requirements, responsibilities and measures, the following should be included:
(a) the assignment of conflicting activities or transactions to different persons;
(b) the prevention of staff members active outside the credit institution from acquiring undue influence within the credit institution regarding these other activities;
(c) the attribution of responsibility to members of the administrative body to abstain from discussion and/or voting on any issue regarding which a member is or may be in a conflict of interest or in cases where the objectivity of the member or their ability to properly perform their duties to the credit institution may be jeopardized in another way;
(d) the establishment of appropriate procedures for transactions with related parties (credit institutions may consider, among others, the possibility to require the execution of transactions under normal commercial terms, the full application of all relevant procedures of the internal control system to these transactions, the provision of binding advice by independent members of the administrative body, the approval of the most significant transactions by shareholders and the limitation of exposure to these transactions); and
(e) the prevention of members of the administrative body from holding positions on the boards of directors of competing credit institutions, unless these are credit institutions falling within the same institutional protection scheme, as referred to in Article 113(7) of Regulation (EU) No 575/2013, credit institutions permanently linked to a central body, as referred to in Article 10 of Regulation (EU) No 575/2013, or credit institutions falling within the scope of supervisory consolidation.
(9) The policy should specifically cover the risk of conflict of interest at the administrative body level and provide adequate guidance regarding the identification and management of conflicts of interest that may hinder the ability of members of the administrative body to make objective and impartial decisions aimed at serving the interests of the credit institution. Credit institutions should take into account that conflicts of interest can affect the independent judgment of members of the administrative body.
(10) When mitigating conflicts of interest identified for members of the administrative body, the institution should document the measures taken, including the reasoning for how they are effective to ensure objective decision-making.
(11) Actual or potential conflicts of interest reported to the competent function of the credit institution should be subject to appropriate assessment and management. In the event of identification of a conflict of interest regarding a staff member, the credit institution should document the decision taken, especially if the conflict of interest and related risks have been accepted, and if so, the manner in which such conflict of interest has been limited or addressed to a satisfactory degree.
(12) All actual and potential conflicts of interest at the administrative body level, on an individual and collective basis, should be adequately documented, reported to the administrative body and subject to discussion, decision-making and due management by the administrative body.
(13) The existence of non-performing loans of a person holding a key function, including their related parties, may create doubts about the independent and impartial judgment of the key function holder in the performance of their duties and may constitute a conflict of interest situation. For the purpose of avoidance and rapid management of such situations:
(a) credit institutions should ensure that persons appointed to key positions do not present, upon their appointment, loans belonging to the category of non-performing loans.
(b) credit institutions establish appropriate policies and procedures for the handling and rapid clearance of situations where loans granted by the credit institution to a person holding a key function, including their related parties, have become, after their appointment, non-performing loans. For example, such policies and procedures may include regular reporting of these cases to the audit committee and their relevant monitoring by said committee, the definition of a clear timeline for normalization, etc.
Internal whistleblowing procedures.
Official Journal of the EU: L305, 26.11.2019, p.17.
43.- (1) Credit institutions must establish and maintain appropriate whistleblowing policies and procedures for the reporting of potential or actual violations of regulatory or internal requirements by staff, including in particular the requirements of Regulation (EU) No 575/2013, legislative provisions harmonized with Directive 2013/36/EU and this Directive, through a specific, independent and autonomous channel for this purpose.
(2) Staff members reporting violations should not be required to provide relevant evidence; however, they should have a sufficient level of certainty, which adequately justifies the initiation of a related investigation.
(3) Credit institutions should implement appropriate procedures to ensure their compliance with national legislation that will harmonize national law with Directive 2019/1937/EU on the protection of persons reporting breaches of Union law.
125(I) of 2018.
(4) To avoid conflicts of interest, staff should be given the opportunity to report violations by bypassing regular reporting channels, such as through the regulatory compliance function, the internal audit function or an independent malfunction reporting (whistleblowing) procedure within the credit institution.
(5) Whistleblowing procedures should ensure the protection of personal data of both the person reporting the violation and the natural person alleged to have committed the violation, in accordance with Regulation (EU) 2016/679 and the Law on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data.
(6) Whistleblowing procedures should be available to all staff of the credit institution.
(7) (a) Information provided by staff through whistleblowing procedures should be transmitted, where appropriate, to the administrative body and to other competent functions identified within the whistleblowing policy. Upon request of the staff member reporting a violation, the information should be transmitted to the administrative body and to other competent functions anonymously.
(b) Credit institutions may also provide a whistleblowing procedure, which allows the submission of information anonymously.
(8) Credit institutions should ensure the appropriate protection of the person reporting the violation from any negative effects, such as retaliation, discrimination or other forms of unfair treatment. The credit institution should ensure that no person subject to the control of the credit institution is involved in the
victimization of a person who has reported a violation, while it should also take appropriate measures against those responsible for such victimization.
(9) Credit institutions should also protect reported persons from possible negative consequences, in case the investigation does not reveal evidence justifying measures against said persons. In case of taking measures, the credit institution should ensure the protection of the involved person from unintended negative consequences that go beyond the purpose of the measure taken.
(10) Internal whistleblowing procedures should:
(a) be documented, for example in staff manuals; (b) provide clear rules ensuring that information regarding complaints, reported persons, and violations is treated as confidential information, in accordance with Regulation (EU) 2016/679 and the Law on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data, unless the disclosure of their identity is required under applicable national legislation in the context of further investigations or subsequent judicial proceedings; (c) protect staff members who raise concerns from any victimization resulting from reporting violations that must be declared; (d) ensure that potential or actual violations reported are evaluated and referred to higher levels of the hierarchy, including, where applicable, to the competent authority or authorities responsible for law enforcement; (e) ensure, where feasible, that confirmation of receipt of information is provided to staff members who have reported potential or actual violations; (f) ensure the monitoring of the outcome of an investigation regarding a reported violation; and (g) ensure the proper maintenance of records.
Reporting to the competent authority.
44.- Staff members of credit institutions may report to the competent authority relevant potential or actual violations of regulatory requirements, including, among others, the requirements of Regulation (EU) No. 575/2013, and EU harmonized legislative provisions with Directive 2013/36/EU, the Law, and this Directive, in case such staff members:
(a) have reason to believe that the use of the credit institution's internal whistleblowing procedures may not be effective, or (b) consider that, despite the provisions of paragraph 43 of this Directive, any submission of an internal complaint would create a risk of negative consequences for themselves, or (c) consider it appropriate to submit the complaint directly to the competent authority due to the severity of the potential or actual violation, and/or possible involvement of senior management of the credit institution, or (d) consider it appropriate to submit the complaint directly to the competent authority for any other reason which they will explain to the competent authority in the context of submitting their complaint.
PART 9 - RISK MANAGEMENT FRAMEWORK
Section I - Addressing Specific Risks
Credit Risk and Counterparty Risk.
R.C.O. 74/2016
O.O. Part III(I)
No. 4933
18.03.2016
R.C.O. 259/2016
O.O. Part III(I)
No. 4964
16.09.2016
R.C.O. 41/2017,
O.O. Part III(I)
No. 4994
03.02.2017
R.C.O. 274/2019
O.O. Part III(I)
No. 5177
45.- (1) Credit institutions establish healthy and clearly defined criteria, in connection with their risk-taking framework, for the granting of credits and clearly define the approval, modification, renewal, and refinancing procedures for credits in accordance with the provisions of the Directive on Procedures for Granting New and Reviewing Existing Credit Facilities of 2016 to 2020, the Directive on the Management of Delinquencies of 2015 to 2020, the guidelines of the Central Bank or the European Central Bank for the management of credit risk, and the respective Guidelines of the EBA adopted by the Central Bank, which it calls upon credit institutions to apply.
09.08.2019
R.C.O. 106/2020
O.O. Part III(I)
No. 5221
19.03.2020.
R.C.O. 07/2015,
O.O. Part III(I)
No. 4862
03.04.2015
EBA/GL/2017/06
20.09.2017.
(2) Credit institutions ensure that:
(a) the granting of credit is based on sound and clearly defined criteria and that the approval, modification, renewal, and refinancing procedures for credits are clearly defined; (b) they have internal methods enabling them to assess the credit risk of exposures to individual borrowers, securities, or securitization positions, and the credit risk at the portfolio level. Specifically, internal methods do not rely exclusively or mechanically on external credit assessments. Where capital requirements are based on an assessment by an External Credit Assessment Institution (ECAI) or the fact that an exposure is unrated, this does not exempt institutions from additional examination of other relevant information for the assessment of internal capital allocation; (c) the ongoing management and monitoring of various portfolios and exposures of credit institutions involving credit risk, including the identification and management of problematic credits, the making of adequate adjustments and value provisions, is carried out through effective systems; (d) the diversification of credit portfolios is sufficient, in accordance with target markets and the overall credit strategy of the credit institution.
Residual Risk.
46.- Credit institutions ensure that the risk of recognized credit risk mitigation techniques proving less effective than expected is addressed and controlled through documented policies and procedures.
Concentration Risk.
47.- Credit institutions ensure that concentration risk from exposures to each counterparty, including central counterparties, groups of connected counterparties, and counterparties in the same economic sector or geographic area, or from the same activity or key commodity, or from the application of credit risk mitigation techniques, and particularly the risk associated with large indirect credit exposures, such as a single issuer of collateral, is addressed and controlled through documented policies and procedures.
Securitization Risk.
48.- (1) Credit institutions evaluate and address through appropriate policies and procedures, the risks arising from securitization transactions in which the institution is an investor, transferor, or funder, including reputation risks arising in relation to complex structures or products, ensuring that the economic significance of the transaction is fully taken into account in risk assessment and management decisions. (2) A credit institution that is the transferor institution of revolving securitization transactions with an early repayment clause must have a liquidity plan to address the consequences of both scheduled and early repayments.
Market Risk. 49.- (1) Credit institutions apply policies and procedures for the identification, measurement, and management of all significant sources and impacts of market risks, in accordance with the Central Bank's guidelines for the management of market risk.
(2) Credit institutions take measures against the risk of insufficient liquidity, in case the negative position (short position) becomes due before the positive position (long position).
(3) Credit institutions apply policies and procedures to ensure that internal capital is sufficient for significant market risks not subject to capital requirements.
(4) Credit institutions that, in calculating capital requirements for position risk, according to Part Three, Title IV Chapter 2 of Regulation (EU) No.
575/2013, have netted positions they hold in one or more of the shares constituting a stock index with a position or positions in a stock index futures contract or another product linked to a stock index, must have sufficient internal capital to cover the basis risk arising from the possibility that the price of the futures contract or other product does not fully follow the prices of the constituent shares. Credit institutions also have such sufficient internal capital when credit institutions hold opposite positions in a stock index futures contract whose expiration date, composition, or both are not identical. (5) Credit institutions ensure that, when using the treatment of Article 345 of Regulation (EU) No. 575/2013, they have sufficient internal capital to cover the loss risk existing between the time of initial commitment and the next working day.
Interest Rate Risk from Trading Book
Activities.
50.- (1) Credit institutions apply internal systems and use the standardized methodology or the simplified standardized methodology for the identification, assessment, management, and mitigation of risks arising from potential interest rate changes affecting both the economic value of equities and net interest income from the trading book activities of the credit institution. (2) Credit institutions apply systems for the assessment and monitoring of risks arising from potential changes in credit margins affecting both the economic value of equities and net interest income from the trading book activities of the institution. (3) The competent authority may require a credit institution to use the standardized methodology referred to in sub-paragraph (1), when the internal systems applied by this credit institution for the purpose of assessing the risks referred to in said sub-paragraph are not satisfactory. (4) The competent authority may require a small and non-complex credit institution, as defined in Article 4 paragraph 1 point 145) of Regulation (EU) No. 575/2013, to use the standardized methodology, if it deems that the simplified standardized methodology is insufficient to reflect the interest rate risk arising from trading book activities of said credit institution.
Operational Risk.
51.- (1) Credit institutions apply policies and procedures for the assessment and management of exposures to operational risk, including model risk and risks arising from outsourcing, and for covering the risk arising from low-frequency, high-severity events. Credit institutions clearly define what constitutes operational risk for the purposes of these policies and procedures. Reputation Risk. (2) Credit institutions develop policies and emergency response and business continuity plans, including IT policies and IT business continuity plans and IT recovery and response plans regarding the technology used for information disclosure, and that these plans are developed, managed, and tested in accordance with Article 11 of Regulation (EU) No. 2022/2554, so that credit institutions have the ability to continue their operations in case of serious disruption of their activities and to limit the damages caused as a result of such disruption.
51A. (1) Credit institutions must apply adequate procedures for the assessment of both internal and external factors or events that may raise concerns about the institution's reputation, taking into account, among others, the following factors:
(a) ongoing known investigations by official bodies regarding the institution or its representatives, and imposed sanctions; (b) media campaigns and initiatives contributing to the deterioration of public opinion and the institution's reputation; (c) the number and changes in customer complaints or sudden loss of customers or investors; (d) negative events affecting the entire financial sector or similar institutions, in case the public links them to the entire financial sector or a group of institutions. (2) Credit institutions must assess the significance of the institution's exposure to reputation risk and how it connects with other risks (i.e., credit risk, market risk, operational risk, and liquidity risk), utilizing other risk assessments to identify any secondary effects in any direction (from reputation risk to other risks and vice versa). (3) Credit institutions must apply adequate rules, strategies, procedures, and mechanisms for the management of reputation risk. Among others, credit institutions:
(a) have standardized policies and procedures for the identification, management, and monitoring of reputation risk; (b) address reputation risk in a proactive manner; (c) conduct extreme scenario simulations or scenario analyses to assess any secondary effects of reputation risk (e.g., liquidity, funding cost, access to services via correspondents, etc.); (d) protect their brand through direct communication campaigns in case of specific events that may endanger their reputation; (e) examine the impact of their strategy and business plans, and generally their behavior, on their reputation, and make necessary revisions.
Country Risk. 51B.- (1) The credit institution must ensure that adequate policies, procedures, and mechanisms are applied for the effective management of country risk, including sovereign risk, transfer risk, convertibility risk, and contagion risk, providing at least for the following:
(a) the identification, assessment, measurement, and monitoring of country risk, including the identification and documentation of key country risk drivers (country risk drivers), such as macroeconomic developments, political stability, geopolitical factors, legal/regulatory changes, capital flow restrictions, liquidity conditions, and access to foreign exchange; (b) the development and/or application of appropriate assessment, grading, and documentation methodologies for country risk taking, which include both tools for detecting potential future risks taking into account expected developments and possible future risks, and tools for analyzing historical risk profiles. These methodologies must allow for the cumulative calculation and consistent categorization of the credit institution's relevant exposures and financial statements, and facilitate the early identification of risk concentrations; (c) the determination, application, and documented review of maximum exposure limits per country and per economic activity sector (e.g., transportation and storage, construction, real estate management) regarding country exposures, in accordance with the risk-taking appetite and risk absorbing capacity (risk absorbing capacity) of the credit institution, as well as the determination of an appropriate limit-setting approach, including any sub-limits where deemed necessary (e.g., per counterparty category, products); (d) the continuous and uninterrupted monitoring of developments that may affect country risk and the credit institution's exposure profile, utilizing appropriate early warning indicators. These indicators are documented based on policy and reviewed periodically, and may include, among others, changes in credit assessments, exchange rate volatility, evolution of foreign exchange reserves, changes in funding costs/government yields, capital control measures, developments in capital markets, as well as macroeconomic, geopolitical, and regulatory developments; (e) the conduct of scenario analyses and/or stress tests, as part of the overall country risk assessment, to estimate possible impacts and support the decision-making process and limit setting; (f) the determination and application of clear escalation procedures in cases of increased risk and/or violation/exceedance of established limits, including predefined risk restriction actions, approval procedures for any deviations, and timely notification of competent administrative bodies/committees; (g) the establishment and periodic updating of reduction, disengagement, or exit strategies for countries where significant deterioration in risk is observed and/or where the credit institution has significant exposures or financial statements. These strategies are documented, operationally applicable, and consistent with the risk profile, risk-taking appetite, and risk absorbing capacity (risk absorbing capacity) of the credit institution; (h) the creation and maintenance of a watchlist of countries
subject to enhanced monitoring and more frequent reporting. The credit institution must define clear and documented entry/exit criteria for this list, which may be linked, among others, to early warning indicators and/or significant differentiation of internal country risk grading and/or macroeconomic conditions and/or events increasing transfer or convertibility risk, and (i) the determination of minimum capabilities of management information systems, to ensure timely and effective measurement, monitoring, and reporting of country risk. These systems must allow, at a minimum, the analysis and aggregation of relevant data as follows:
(i) per country,
(ii) per counterparty sector (e.g., sovereign, financial, corporate), (iii) per currency, (iv) per maturity/duration (maturity), (v) per product/exposure type and funding channel, (vi) per risk level/country rating, and facilitate the monitoring of concentrations, trends, and limit violations where applicable. (j) ensuring that it has adequate and appropriate resources, specialized personnel, expertise, and appropriate infrastructure for the continuous and systematic monitoring and assessment of economic, political, institutional, legal, and operational conditions in countries where it maintains or may create country exposures. This monitoring covers, among others, developments in the macroeconomic environment, changes in the regulatory and legal framework, the operation and effectiveness of institutions and the judicial system, possible restrictions on cross-border capital transfers or the enforcement of rights, as well as other factors that may affect the creditworthiness of counterparties and/or the effective management and recovery of claims. The credit institution also ensures that it has the necessary expertise, procedures, and mechanisms to prospectively assess and effectively manage the legal and practical aspects related to the holding and liquidation of collateral in foreign jurisdictions, taking into account peculiarities such as local practices, the operation of enforcement mechanisms, and the effectiveness of the legal and institutional framework. For this purpose, the credit institution ensures that it has adequate and reliable information regarding the peculiarities of each jurisdiction, as well as, where required, access to appropriate local or external expertise, to support the correct assessment, monitoring, and management of relevant exposures. The resources, tools, and procedures used are reviewed periodically to remain adequate and appropriate in relation to the risk-taking appetite and risk absorbing capacity (risk absorbing capacity), as well as the scope and geographic diversification of the credit institution's activities.
ICT and Security Risk.
52.- (1) Credit institutions, in accordance with the provisions of paragraph 7 of this Directive and Section VI, have mature strategies, policies, and procedures for the management of ICT and security risk, and for this purpose have effective and reliable ICT systems covering all their significant activities and ensuring that they extract timely, accurate, consistent, complete, and relevant information, so that it becomes possible:
(a) the preparation of annual or periodic financial or non-financial statements for the financial profile and risk profile of the credit institution, for internal purposes, or external purposes as required by the regulatory framework; (b) the effective management of decision-making and supervision by the credit institution; (c) effective information for purposes of internal control of the credit institution and/or supervision; and (d) the creation of well-founded opinions regarding the effectiveness of risk management, compliance, and internal control frameworks.
(2) Information systems, including those storing and processing data in electronic form, must be secure and supported by appropriate emergency arrangements.
(3) Credit institutions ensure that transaction records are maintained in a systematic and secure manner for a period of not less than ten (10) years, in a manner that facilitates the production of audit trail records and the reconstruction of all transactions in chronological order, the verification of each recorded transaction against original invoices, and the validation of any changes to account balances against supporting documents covering all transactions leading to the aforementioned changes.
EBA/GL/2019/04
29.11.2019.
(4) Credit institutions should comply with the provisions set out in the EBA Guidelines on IT Risk Management and Security, taking into account the proportionality criteria defined in Part 2 of this Directive and applying the general requirements of Part II of this Section.
Liquidity Risk.
53.- (1) Credit institutions possess adequate strategies, policies, procedures, and systems for the identification, measurement, management, and monitoring of liquidity risk within an appropriate set of time horizons, including within the same day, in order to ensure that adequate levels of liquidity reserves are maintained. These strategies, policies, procedures, and systems shall be designed based on the business lines, currencies, sectors, and legal entities of the group, and shall include adequate mechanisms for the allocation of liquidity costs, benefits, and risks.
(2) The strategies, policies, procedures, and systems referred to in paragraph (1) are proportional to the complexity, risk profile, scope of operations of the credit institutions, and the level of risk tolerance defined by the administrative body, and reflect the importance of the credit institution in the Republic and in any other Member State where it operates commercially. Credit institutions communicate the risk tolerance to all relevant business lines.
(3) Credit institutions develop methods for the determination, measurement, management, and monitoring of funding positions. These methods include current and projected significant cash flows arising from assets, liabilities, off-balance sheet items, including potential liabilities and possible effects of reputational risk.
(4) Credit institutions distinguish between encumbered and unencumbered assets which are always available, particularly in emergency situations. Credit institutions take into account the legal entity to which the assets belong, the country where the assets are registered in a register or account, and their eligibility, and monitor how the assets can be mobilized in a timely manner.
(5) Credit institutions take into account existing legal, regulatory, and operational restrictions on potential transfers of liquidity and unencumbered assets between legal entities, within and outside the European Economic Area.
(6) Credit institutions examine various liquidity risk mitigation instruments, including a system of liquidity limits and reserves, in order to be able to withstand various stress scenarios, as well as a sufficiently diversified funding structure and access to funding sources. Credit institutions ensure that these arrangements are reviewed regularly.
(7) Credit institutions examine alternative scenarios regarding liquidity positions and risk mitigation factors, and review at least annually the assumptions on which decisions regarding the funding position are based. For these purposes, the alternative scenarios address in particular off-balance sheet items and other potential liabilities, including those of special purpose securitization entities (SPSE) or other special purpose entities, as defined in Regulation (EU) No 575/2013, in relation to which the credit institution acts as sponsor or provides significant liquidity support.
(8) Credit institutions examine the possible effects of combined alternative scenarios related to the credit institution, scenarios covering the entire range of the market, and combined alternative scenarios. Different time periods and various degrees of stress conditions are examined.
(9) Institutions adapt their strategies, internal policies, and liquidity risk limits and develop effective emergency plans, taking into account the results of the alternative scenarios referred to in paragraph (8).
(10) (a) Credit institutions establish liquidity recovery plans, which define adequate strategies and appropriate implementation measures, in order to address potential liquidity shortages, including shortages affecting branches in other Member States.
(b) Liquidity recovery plans are reviewed by credit institutions at least annually, updated based on the results of the alternative scenarios defined in paragraph 8 of this section, submitted in the form of a report to senior management, and receive their approval, so that internal policies and procedures can be adjusted accordingly.
(c) Credit institutions take the necessary operational actions in advance to ensure that liquidity recovery plans can be implemented immediately. For credit institutions, these operational actions include maintaining collateral that is immediately available for financing by the competent authority. This includes maintaining collateral, where required, in the currency of another Member State or in the currency of a third country to which the credit institutions are exposed, and, where required for operational reasons, within the territory of a host Member State or third country in the currency to which they are exposed.
Excessive Leverage Risk.
54.- (1) Credit institutions establish policies and procedures for the identification, management, and monitoring of excessive leverage risk. Leverage risk indicators include the leverage ratio defined in accordance with Article 429 of Regulation (EU) No 575/2013 and discrepancies between assets and liabilities.
(2) Credit institutions address excessive leverage risk in a proactive manner, taking into account potential increases in excessive leverage risk due to reductions in the credit institution's own funds resulting from expected or realized losses, according to applicable accounting rules. For this purpose, credit institutions must be able to withstand a series of different stress scenarios regarding excessive leverage risk.
Part II – Internal Control Framework and Mechanisms
Internal Control Framework.
55.- (1) Credit institutions develop and maintain a culture that encourages the adoption of a positive attitude towards risk control and regulatory compliance within the credit institution, as well as a sound and comprehensive internal control framework.
(2) In this context, the business lines of credit institutions should be responsible for managing the risks arising from the exercise of their activities and should have control systems aimed at ensuring compliance with internal and external requirements.
(3) Within this framework, credit institutions should have separate internal control system functions, with appropriate and sufficient authority, status, and access to the administrative body, in order to carry out their mission, as well as a risk management framework.
(4) The internal control framework of a credit institution should be adapted on an individual basis to the specifics of its business activity, its complexity, and the associated risks, taking into account the group's framework.
(5) The relevant credit institutions must organize the exchange of required information in such a way as to ensure that every administrative body, business line, and internal unit, including each separate function of the internal control system, is able to perform its respective duties. The relevant credit institutions ensure the exchange of sufficient information, for example, between business lines and the regulatory compliance function at the group level, as well as between the heads of the internal control system functions at the group level and the administrative body of the credit institution.
(6) Credit institutions should implement appropriate procedures to ensure compliance with obligations to prevent and combat money laundering from illegal activities. Credit institutions should assess their exposure to the risk of being used for money laundering purposes, and, where necessary, take mitigation measures to reduce such risks, as well as operational and reputational risks associated with them. Credit institutions should take measures to ensure that their staff are informed about these risks and their consequences for the credit institution and the integrity of the financial system.
(7) The internal control framework should cover the entire organization, including the responsibilities and duties of the administrative body, as well as the activities of all business lines and internal units, including the internal control system functions, activities subject to outsourcing, and distribution channels.
(8) The credit institution's internal control framework should ensure:
(a) effective and efficient operation;
(b) prudent exercise of business activity;
(c) adequate identification, measurement, and reduction of risks;
(d) reliability of financial and non-financial reporting submitted internally and externally;
(e) sound administrative and accounting procedures; and
(f) compliance with laws, regulations, supervisory requirements, and internal policies, procedures, rules, and decisions of the institution.
(9) The internal control system functions should participate, in an advisory role, in the establishment/design of new procedures.
Implementation of Internal Control Framework.
56.- (1) The administrative body should be responsible for establishing and monitoring the adequacy and effectiveness of the framework, procedures, and mechanisms of the internal control system, as well as for overseeing all business lines and internal units, including the separate functions of the internal control system, such as risk management, regulatory compliance, internal audit, and IT risk and security management functions.
(2) Credit institutions should establish, maintain, and update at regular intervals appropriate and writtenly documented policies, mechanisms, and procedures of the internal control system, which should be approved by the administrative body.
(3) A credit institution should have a clear, transparent, and documented decision-making process, as well as a clear allocation of responsibilities and powers within its internal control system, including its business lines, internal units, and internal control system functions.
(4) Credit institutions should ensure the communication of these policies, mechanisms, and procedures to all staff and whenever significant changes occur.
(5) When implementing the internal control framework, credit institutions should provide for the appropriate separation of duties, such as assigning conflicting activities within the execution of transactions or when providing services to different persons, or assigning supervisory and reporting responsibilities regarding conflicting activities to different persons, as well as the imposition of information barriers, for example through the physical separation of certain departments.
(6) The internal control system functions should verify the correct implementation of the policies, mechanisms, and procedures defined within the internal control framework in their respective areas of competence.
(7) Credit institutions ensure that internal control systems include training regarding internal control mechanisms, particularly for employees in positions of high responsibility or conducting high-risk work.
(8) The internal control system functions should regularly submit written reports to the administrative body regarding identified deficiencies that have been deemed significant. These reports should include, for each newly identified significant deficiency, the relevant risks involved, impact assessment, recommendations, and corrective measures to be taken.
(9) The administrative body should follow up on the findings of the internal control system functions in a timely and effective manner, and require adequate corrective actions. An official monitoring procedure regarding the findings and corrective measures taken should be established.
Risk Management Framework.
57.- (1) Within the overall internal control system, credit institutions should possess a holistic risk management framework at the credit institution level, which extends to all its business lines and internal units, including the internal control system functions, fully recognizing the economic substance that all risk exposures undertaken may have.
(a) The risk management framework should enhance the credit institution's ability to make fully documented decisions regarding the undertaking of risks.
(b) The risk management framework should include on-balance sheet and off-balance sheet risks, as well as existing and future risks to which the credit institution may be exposed.
(c) Risks should be evaluated from "bottom-up" and "top-down", within and outside business lines, using consistent terminology and compatible methodologies throughout the credit institution and at consolidated or sub-consolidated levels.
(d) All relevant risks should be included in the risk management framework, taking due account of both financial and non-financial risks, including credit risk, market risk, liquidity risk, concentration risk, operational risks, IT risk, reputational risk, legal risk, conduct risk, compliance risk, and strategic risks.
(2) The credit institution's risk management framework should include policies, procedures, risk limits, and internal control systems that ensure adequate, timely, and continuous identification, measurement or assessment, monitoring, reduction, and reporting of risks, at the business line level, at the credit institution level, and at consolidated or sub-consolidated levels.
(3) Credit institutions ensure that each significant risk is linked to a policy, procedure, or measure, as well as a relevant control that ensures that each such policy, procedure, or other measure is applied and functions as intended.
(4) An effective risk management framework requires at least:
(a) assessment of the credit institution's risk-taking capacity;
(b) determination of the credit institution's risk-taking appetite, through the formulation of a written statement of risk-taking appetite;
(c) derivation of the credit institution's risk-taking appetite statement to business lines, business units, specific risk categories, concentrations, and other relevant levels in the form of risk limits;
(d) assessment of the credit institution's risk profile in relation to its risk-taking capacity;
(e) description of the roles and responsibilities of personnel overseeing the implementation and monitoring of the risk-taking capacity framework.
(5) Credit institutions ensure that the risk-taking appetite statement:
(a) is linked to strategic planning and funding and liquidity planning, as well as remuneration programs;
(b) defines the level of risk the institution is willing to accept to achieve its strategic objectives and business plan, taking into account the interests of stakeholders, as well as capital and other regulatory requirements;
(c) defines for each significant activity the maximum level of risk within which the institution is willing to operate, based on its risk-taking capacity, risk-taking ability, and risk profile;
(d) ensures that the strategy and risk limits for each business line of the credit institution and legal entity are aligned with the institution's risk-taking appetite statement as appropriate; and
(e) is forward-looking and subject to scenarios and stress testing to ensure that the institution understands the type of events that could place it outside its risk-taking capacity and risk-taking ability.
(6) Credit institutions ensure that risk limits:
(a) are defined at a level that limits risk-taking within the risk-taking capacity based on the assessment of the impact on stakeholders' interests, as well as compliance with capital and other regulatory requirements, in the event of a risk limit breach and the likelihood of realization of any significant risk;
(b) cover concentrations of significant risks and all business lines and units of the credit institution, such as counterparty risk, sector, region, type of collateral, currency, and product risk;
(c) are monitored regularly.
(7) Credit institutions ensure that they have the necessary mechanisms to adjust the risk-taking capacity framework to changing business conditions and market conditions.
(8) Credit institutions ensure that risk limit breaches are referred to the appropriate reporting level and addressed with due monitoring.
(9) The credit institution's risk management framework should provide specific guidance regarding the implementation of its strategies. As appropriate, this guidance should establish and maintain specific internal limits that are consistent with the credit institution's risk-taking capacity and proportional to sound operation, financial strength, capital base, and strategic objectives. The profile
risk of the credit institution should be maintained within these established limits.
The risk management framework should ensure that, in the event of breaches of risk limits, a defined procedure is implemented to refer them to higher levels of the hierarchical scale and address them through an appropriate monitoring process.
(10) The risk management framework should be subject to independent internal assessment, conducted by the internal control function, and external assessment, and should be regularly re-evaluated in relation to the credit institution's risk-taking appetite, taking into account information derived from the risk management function and the risk committee. (11) The factors that should be taken into account for the assessment of the risk management framework include internal and external developments, including changes in the balance sheet and income, the increase in the complexity of business activities, the risk profile or the operational structure of the credit institution, geographical expansion, any mergers and acquisitions, as well as the introduction of new products or business lines. (12) (a) When identifying and measuring or assessing risks, the credit institution should develop appropriate methodologies, including both forward-looking tools for detecting potential future risks and backward-looking tools for analyzing historical risk profiles. These methodologies should allow for the aggregate calculation of risk exposures across all business lines and facilitate the identification of risk concentrations. (b) The tools provided for in point (a) of this sub-paragraph should include the assessment of the actual risk profile against the credit institution's risk-taking appetite, as well as the identification and assessment of potential risk exposures and risk exposures in stress testing scenarios under a wide range of hypothetical adverse conditions against the credit institution's risk-taking capacity. (c) The tools provided for in point (a) of this sub-paragraph should provide information regarding any adjustments to the risk profile that may be necessary. Credit institutions should rely on appropriately conservative assumptions when developing stress testing scenarios. (13) Credit institutions should take into account that the results of quantitative assessment methodologies, including stress testing, depend to a large extent on the limitations and assumptions of the models used, including the severity and duration of the test, as well as the underlying risks. For example, models that show particularly high returns on economic capital may be due to model failure, for example because they do not take into account certain relevant risks, and not to superior strategy or best implementation of a strategy by the credit institution. (14) (a) The risk management framework includes quantitative measurements that can be translated into risk limits applicable to business lines and units, which in turn can be aggregated and disaggregated to allow for the measurement of the risk profile in relation to the credit institution's risk-taking capacity and risk-bearing capacity; (b) Subject to the provisions of sub-paragraph (1) of this paragraph, the determination of the level of risk taken should not be based solely on quantitative information or data
derived from the use of models, but should also include a qualitative approach, including expert advice and critical analysis. Relevant trends and macroeconomic environment data should be explicitly examined to recognize their potential impact on exposures and portfolios. (15) The ultimate responsibility for risk assessment rests exclusively with the credit institution, which, consequently, should assess risks with critical thinking and should not rely solely on external assessments. The credit institution should review and approve an external risk model (purchased risk model) and adapt it to its specific conditions, in order to ensure accurate and comprehensive depiction and analysis of risk by the model. (16) Credit institutions should be fully aware of the limitations of models and measurement systems and should use tools for both quantitative and qualitative assessment of risks, including expert advice and critical analysis.
(17) (a) In addition to assessments conducted by themselves, credit institutions may additionally use external risk assessments, including external creditworthiness assessments or external risk models.
(b) Credit institutions should be fully aware of the exact scope of such assessments as well as their limitations.
(18) (a) Regular and transparent reporting mechanisms should be established, so that the administrative body, its risk committee, and all relevant units of the credit institution receive reports in a timely, accurate, comprehensive, understandable, and constructive manner and are able to exchange relevant information regarding the identification, measurement, or assessment, monitoring, and management of risks. (b) The framework for reporting should be clearly defined and documented. (19) Credit institutions make written records on an individual and consolidated basis of:
(a) main sources of risk identified;
(b) assessments conducted for these risks as well as details of stress testing scenarios and scenario analysis performed; (c) how they intend to address these risks; and (d) final financial resources estimated to be required as part of the internal capital adequacy process.
(20) (a) Effective communication of information and awareness regarding risks and risk strategy is a vital aspect of the entire risk management process, including review and decision-making processes, and contributes to preventing decisions that may lead to unintentional increases in risks. (b) Effective reporting on risks presupposes proper internal assessment and communication of the risk strategy and relevant risk data (e.g., exposures and significant risk indicators), both horizontally and throughout the entire hierarchy of the credit institution. New products and significant changes. EBA/GL/2015/18 15.07.2015. 58.- (1) Subject to the EBA Guidelines on retail banking product oversight and governance arrangements, the credit institution should have a sufficiently documented new product approval policy, which is approved by the administrative body and covers the development of new markets, products, services, and significant changes to existing markets, products, and services, as well as exceptional transactions. (2) The new product approval policy should include the significant changes that occur in the relevant processes, for example, new outsourcing arrangements, and in the corresponding systems, for example, technology system change processes. (3) The new product approval policy should ensure that approved products and changes are consistent with the credit institution's risk strategy and risk-taking appetite, as well as with the respective limits, or that the required reviews are conducted. (4) The significant changes or exceptional transactions referred to in sub-paragraph (1) as components of the new product approval policy may include mergers and acquisitions, including the potential impact of conducting inadequate due diligence that fails to identify post-merger risks and obligations; the establishment of structures, for example, new subsidiaries or single purpose vehicles; new products; changes either in systems or in the risk management framework or processes; and changes in the organization of the credit institution. (5) The credit institution must have specific procedures for assessing compliance with new product approval policies, taking into account data derived from the risk management function. These procedures should include systematic ex-ante assessment and documented advice from the regulatory compliance function for new products or significant changes to existing products. (6) The credit institution's policy for new product approval should cover every parameter that must be taken into account before making a decision to enter new markets, trade new products, start providing new services, or make significant changes to existing products or services. (7) The new product approval policy should also include the definitions of the concepts 'new product / new market / new business activity' and 'significant changes' that will be used in the credit institution, as well as the internal functions that will be involved in the
decision-making process. Official Journal of the EU: L141, 05.06.2015, p.73. (8) The new product approval policy should define the main issues to be addressed before making the relevant decisions. These issues should include the following: regulatory compliance, accounting, pricing models, impact on the risk profile, capital adequacy, and profitability, availability of resources for adequate front office services, back office organizational support services, and middle office operational support and risk management services, availability of appropriate internal tools, and expertise for understanding and monitoring relevant risks. (9) Credit institutions should identify and assess the money laundering risk associated with a new product or practice and put measures in place to mitigate the risk, in accordance with the Law on the Prevention and Combating of Money Laundering of 2007. (10) The decision to start a new activity should clearly define the competent unit of the enterprise and the competent persons. New activities should not be undertaken if adequate resources for understanding and managing the relevant risks have not been secured. (11) The risk management function, the IT risk and security management function, and the regulatory compliance function should participate in the approval of new products or significant changes to existing products, processes, and systems. Their contribution should include a full and objective assessment of the risks arising from the new activities under various scenarios, potential deficiencies in the credit institution's risk management and internal control systems, and the credit institution's ability to effectively manage new risks. (12) The risk management function should also have a clear overall picture of the introduction of new products, or significant changes to existing products, processes, and systems, for all business lines and portfolios, as well as the authority to require that changes to existing products be submitted to the formal new product approval process.
Part III - Internal Control System Functions
Internal Control System
Functions – General
Requirements.
59.- (1) The internal control system should include the following four separate functions: risk management function, regulatory compliance function, internal audit function, and IT risk and security management function.
(2) The risk management, regulatory compliance, and IT risk and security management functions should be subject to assessment by the internal audit function.
(3) The obligations of the internal control system functions also include ensuring the institution's compliance with the requirements of the Law on the Prevention and Combating of Money Laundering of 2007.
(4) The operational duties of the internal control system functions may be outsourced, taking into account the proportionality criteria listed in Part 2 of this Directive, to the credit institution with consolidation obligations or to another entity within or outside the group, with the consent of the administrative bodies of the credit institution and the other entity. (5) Even when the operational duties of the internal control system functions are partially or fully outsourced, the head of the corresponding internal control system function and the administrative body continue to be responsible for these activities, as well as for maintaining the relevant internal control system function within the credit institution. (6) The internal control system functions have the right, on their own initiative, to communicate with any staff member and to access any records, files, or any other form of information as necessary for the performance of their duties. (7) Due to the close relationship between the activities of the internal control system functions, the credit institution ensures that there is a clearly defined distribution and separation of responsibilities, particularly regarding the responsibility for measuring risks, as well as the identification, verification, and assessment of the adequacy of the relevant internal control procedures and regulations. (8) A function of the internal control system must communicate to other functions of the internal control system any findings concerning them; these findings serve as a feedback mechanism for assessing areas under the responsibility of functions in the relevant control policies and procedures. (9) Subject to the provisions of the Law on the Prevention and Combating of Money Laundering of 2007, credit institutions should assign the responsibility for ensuring the credit institution's compliance with the requirements of the Law on the Prevention and Combating of Money Laundering of 2007, as well as the credit institution's policies and procedures, to a staff member who is responsible for implementing the laws, regulations, and administrative provisions necessary for compliance with the Law on the Prevention and Combating of Money Laundering of 2007 (e.g., compliance head). Credit institutions may establish a separate compliance function regarding the prevention and combating of money laundering and terrorist financing, as an independent control function. The person responsible for the money laundering prevention and combating function should, where required, be able to report directly to the administrative body. (10) Credit institutions should, whenever feasible and without compromising the capability and expertise of the internal control system functions, periodically rotate the staff of each internal control function or transfer staff from one internal control function to another function of the credit institution, in order to ensure that the discretion of employees of an internal control
function is not called into question due to possible loss of objectivity from the continuous performance of similar or routine tasks. (11) The rotation of roles and positions of staff within an internal control function and the transfer of staff to and from an internal control function should be governed and conducted in accordance with a sound and documented policy; this policy should be designed in a way that avoids conflicts of interest and ensures that:
(a) a sufficient period of time adapted to the size and complexity of the credit institution has passed before assigning oversight responsibilities related to the internal control function in which the transferred staff previously worked to staff who have moved to an internal control function from other operational areas of the credit institution; (b) the minimum possible disruption of the internal control function's operations is created by the transfer process. (12) The administrative body should ensure that there are appropriate controls for each significant business process and policy and for the relevant risks and obligations. (13) The internal control system functions ensure that communication with senior management, the administrative body, and relevant committees is sufficiently documented. Internal Control System Manual. 60.- (1) The purpose, nature, and powers of each function of the internal control system should be governed by a relevant manual that is periodically reviewed by the head of the respective function and approved by the administrative body. (2) The manual defines, at a minimum, the following:
(a) the nature of the internal control system function within the credit institution, its powers, purpose, and scope, its main characteristics and responsibilities, its communication channels, and its relationships with other functions of the internal control system, in a manner that promotes its effectiveness; (b) measures to ensure its independence; (c) its right to initiate communication with any staff member, to obtain full and unconditional access to all records and files of the credit institution, as well as any other information required for the performance of its duties; (d) its right to freely express and report its findings to the administrative body and relevant committees without the presence of executive members of the administrative body; (e) the terms and conditions under which the internal control system function may be called upon to provide support or advisory services or to perform other special duties; (f) its role in the approval of new products and services, the development of new markets, and significant changes to existing ones; (g) the responsibility and accountability of the head of the internal control system function; (h) requirement for compliance with relevant professional standards. Heads of the Internal Control System Functions 61.- (1) The heads of the internal control system functions should be appointed at an appropriate hierarchical level that provides the head of the respective function with the appropriate powers and authority required to exercise their responsibilities.
internal control.
(2) Subject to the overall responsibility of the governing body, the heads of the internal control system functions should be independent from the business areas or units they monitor. For this purpose, the heads of risk management, regulatory compliance, internal control, and IT risk and security functions should report and be accountable directly to the governing body, and their performance should be evaluated by the governing body. (3) Where deemed necessary, the heads of the internal control system functions should be able to access and report directly to the governing body or its committees, in order to express concerns, raise issues, and warn, whenever deemed appropriate, when the credit institution is affected or may be affected by specific developments and/or in the event of specific risk developments that affect or may affect the credit institution, subject to the responsibilities of the governing body under the legislative provisions harmonized with Directive 2013/36/EU and Regulation (EU) No 575/2013. This ability should not prevent the heads of the internal control system functions from submitting reports through regular reporting channels. (4) The heads of the internal control function are responsible for:
(a) ensuring the objectivity and independence of control functions; (b) staffing the control functions with personnel possessing sufficient qualifications and skills to ensure the ability of such functions to perform their duties and responsibilities; (c) continuous evaluation and monitoring of the skills necessary to perform the duties of control functions at the required level; (d) ensuring adequate continuous training of the personnel of such control function, in order to conduct the full range of activities resulting from the introduction of new products and processes within the credit institution, changes in regulations or professional standards, and other developments in the financial sector; (e) immediate notification to the heads of other functions regarding any findings affecting them; (f) submitting reports to the governing body and relevant committees and presenting such reports at the meetings of the Governing Body and providing additional information and/or clarification or support for the management of arising issues; (g) preparing and delivering to newly appointed members of the governing body, in coordination with the secretary of the governing body, an introductory seminar covering the relevant areas of responsibility of each control function, with references to the responsibilities of the governing body and regulatory requirements; (h) expressing an opinion, in the case where the credit institution is the parent company, on the selection and suitability of persons responsible for the respective control functions of subsidiary companies in Cyprus and abroad, as well as those employed in foreign branches; (i) notifying the competent authority regarding significant findings or developments that have a significant impact on the risk profile of the credit institution and any significant changes in the structure and operations of such control function; (j) holding meetings with the competent authority at any time requested by the competent authority, in order to discuss the scope and extent of the work of control functions, as well as risk analysis, findings, and recommendations. (5) The credit institution should have documented procedures regarding the appointment and removal of a head of an internal control system function. (6) In any case, the heads of the internal control system functions are not relieved of their duties without the prior approval of the governing body. (7) Subject to the provisions of the 2020 Directive on the Assessment of the Suitability of Members of the Governing Body and Persons Holding Key Positions in Licensed Credit Institutions, credit institutions immediately notify the competent authority regarding the approval and main reasons for the removal of a head of an internal control system function. (8) The heads of the internal control system functions should receive any report, information, or communication sent by the competent supervisory authorities to the credit institution containing findings and
comments regarding their responsibilities as defined in this Directive. Independence of the functions of the internal control system. 62.- The functions of the internal control system are considered independent, provided the following conditions are met:
internal control.
(a) their personnel do not perform operational duties falling within the scope of activities for which they are responsible for monitoring and control; (b) they are organizationally separated from the activities for which they are responsible for monitoring and control; (c) subject to the overall responsibility of the members of the governing body of a credit institution, the head of the internal control system function should not report to a person who has managerial authority over the activities monitored and controlled by the internal control system function; and (d) the remuneration of the personnel of the internal control system functions should not be linked to the performance of the activities monitored and controlled by the internal control system function, nor should it otherwise jeopardize their objectivity. Combination of the functions of the internal control system. 63.- (1) Taking into account the proportionality criteria specified in Part 2, the possibility is provided, provided that prior approval of the competent authority has been obtained, to combine the functions of risk management, regulatory compliance, and IT risk and security management. In any case, any such combination should not contain more than two of these functions. (2) The internal control function should not be combined with any other function of the internal control system. Resources of the functions of the internal control system. 64.- (1) The functions of the internal control system should have sufficient resources at their disposal. They should have a sufficient number of personnel with appropriate qualifications, both at the level of the parent company and at the level of subsidiaries. Personnel should possess appropriate qualifications on an ongoing basis and receive appropriate training according to needs. (2) The functions of the internal control system should have appropriate information systems and support at their disposal, with access to the required internal and external information to exercise their responsibilities. Furthermore, they should have access to all necessary information regarding all business areas and related subsidiaries undertaking risks, particularly regarding subsidiaries likely to cause significant risks to credit institutions.
Part IV - Risk Management Function
Risk Management
Function – General
Requirements.
65.- (1) Institutions should establish a risk management function covering the entire credit institution. Taking into account the proportionality criteria listed in Part 2, the risk management function is independent of operational functions and has sufficient authority, prestige, and resources, so that it is able to implement risk policies and the risk management framework as specified in paragraph 57 of this Directive. The risk management function reports to the governing body through the risk committee. (2) The risk management function should have, whenever required and independently of senior management, direct access to the governing body and its committees, including specifically the risk committee, to raise concerns and warn the governing body, when deemed appropriate, in the event of specific risk developments affecting or potentially affecting the institution, regardless of the responsibilities of the governing body in exercising its supervisory and/or managerial authority under the legislative provisions harmonized with Directive 2013/36/EU and Regulation (EU) No 575/2013. (3) The risk management function should have access to all business areas and other internal units with risk-creating capabilities, as well as related subsidiaries and affiliated enterprises. (4) The personnel of the risk management function should possess a sufficient level of knowledge, skills, and experience in technical and procedural risk management matters. (5) The risk management function should be independent of the business areas and units whose risks it monitors but not isolated, i.e., its interaction with such areas and units should not be hindered. (6) The interaction between the operational functions of the credit institution and the risk management function should contribute to achieving the goal of the sense of responsibility of all personnel of the credit institution regarding risk management. (7) The risk management function:
(a) is a central organizational element of the credit institution, structured in such a way as to be able to implement risk management policies and control the risk management framework.
(b) plays a key role in ensuring the implementation of effective risk management processes by the credit institution.
(c) actively participates in all significant decisions regarding risk management.
(8) Significant institutions may consider establishing specialized risk management functions for each significant business area. However, there should be a central risk management function, including a risk management function at the group level in the credit institution with consolidation obligations, so as to provide a holistic view of all risks at the credit institution and group level, and to ensure compliance with the risk strategy. (9) The risk management function should provide relevant independent information, analyses, and expert opinions on risk exposures, advise the governing body on proposals and decisions taken by business areas or internal units regarding risk, and inform the governing body on whether these are consistent with the risk appetite and risk strategy of the credit institution. (10) The risk management function may propose improvements to the risk management framework, as well as corrective measures in cases of violations of policies, procedures, and limits regarding risks. The role of the risk management function in the risk strategy and decisions regarding risk. 66.- (1) The risk management function should be actively involved, at an early stage, in both the formulation of the credit institution's risk strategy and ensuring the implementation of effective risk management processes. (2) The risk management function is actively involved in the detailed processing and development of the credit institution's risk strategy and in all significant risk management decisions and should be able to provide a comprehensive picture of the entire range of risks facing the credit institution. (3) The risk management function should provide the governing body with all relevant information related to risks, in order to facilitate its determination of the credit institution's risk appetite level. (4) The risk management function should evaluate the adequacy and viability of the risk strategy and risk appetite. It should ensure that the risk appetite is appropriately translated into specific risk limits. (5) The risk management function should evaluate the risk strategies of operational units, including the objectives proposed by operational units, while it should additionally participate in the process before the decision is taken by the governing body regarding risk strategies. The objectives should be reasonable, consistent with the risk strategy of credit institutions, and include reliable creditworthiness assessments and equity performance indicators. (6) The risk management function adequately participates in any changes to the credit institution's strategy, risk appetite framework, and risk limits. (7) The risk management function plays a primary role in ensuring that the decision regarding its recommendations is taken at the appropriate level, is complied with by the relevant operational units, and is appropriately reported to the governing body, the risk committee, and the support unit. (8) The participation of the risk
management function in decision-making processes should ensure that risk assessments remain objective and independent and are duly taken into account. However, accountability for decisions taken should rest with the operational and internal units of the credit institution and primarily the governing body. The role of the risk management function in significant changes. 67.- (1) In accordance with the provisions of paragraph 58 of this Directive, before taking decisions on significant changes or unusual transactions, the risk management function should participate in assessing the impact of such changes and unusual transactions on the overall risk undertaken by the credit institution and the group, while it should also report its findings directly to the governing body before a decision is taken. (2) The risk management function should evaluate how the identified risks could affect the credit institution's ability to manage its risk profile, liquidity, and robust capital base under normal or adverse conditions. The role of the risk management function in the identification, measurement, evaluation, management, mitigation, monitoring, and reporting of risks. 68.- (1) The risk management function should ensure the identification, evaluation, measurement, monitoring, management, and adequate reporting of all significant risks by the respective units of the credit institution. (2) The risk management function should ensure that risk identification and evaluation are not based solely on quantitative information or data resulting from the use of models, but also that qualitative approaches are taken into account. (3) The risk management function should inform the governing body about the assumptions used and the potential deficiencies of risk models and corresponding analysis. (4) The risk management function actively participates at an early stage in assessing the impact of significant changes in the structure of the credit institution and unusual transactions on the overall risk of the credit institution and the group, before any decision is taken regarding such changes and transactions. (5) The risk management function should ensure that transactions with related parties are examined, and that the risks they pose to the credit institution are adequately identified and evaluated. (6) The risk management function should ensure that all identified risks are effectively monitored by operational units. (7) The risk management function should regularly monitor the actual risk profile of the credit institution and examine it in detail in relation to the strategic objectives and risk appetite of the credit institution, in order to facilitate decision-making and critical review by the governing body. (8) The risk management function should analyze trends and identify any new or emerging risks and cases of increasing risks arising from changing circumstances and conditions. Furthermore, it should regularly evaluate the results of risks compared to previous
assessments (i.e., conducting back-testing), in order to assess and improve the accuracy and effectiveness of the risk management process. (9) The risk management function should evaluate possible ways to mitigate risks. The report submitted to the governing body should include proposed appropriate measures for risk mitigation. The role of the risk management function in handling unapproved exposures. 69.- (1) The risk management function should independently evaluate violations of risk appetite or exceedance of risk limits, including verifying the cause and preparing a legal and economic analysis of the actual cost of closing, reducing, or hedging the exposure versus the potential cost of maintaining it. (2) In relation to the evaluation provided in sub-paragraph (1) of this paragraph, the risk management function should keep involved operational units and the governing body informed and formulate recommendations regarding possible corrective actions. In the event of a significant breach, the risk management function should report directly to the governing body, subject to the obligation of the risk management function to report to other internal functions and committees. (3) The risk management function should play a key role in ensuring that decisions based on its recommendations are made at the appropriate hierarchical level, and that such decisions are implemented by the relevant operational units and appropriately reported to the governing body and the risk committee. Head of the Risk Management Function. 70.- (1) Subject to the provisions of paragraph 60 of this Directive, the head of the risk management function of the credit institution, and where applicable, the parent institution regarding the consolidated situation, should be responsible for providing the governing body with comprehensive and understandable information regarding risks, as well as relevant advice, facilitating the governing body's understanding of the overall risk profile of the credit institution.
(2) The Head of the Risk Management Function should possess sufficient expertise, independence, and level of seniority to critically review decisions that affect the risk exposure of the credit institution.
(3) Subject to sub-paragraph (4) of this paragraph, credit institutions should appoint an independent Head of the Risk Management Function, who has no responsibility for other functions of the credit institution and reports directly to the administrative organ.
(4) In cases where the appointment of a person exclusively responsible for the role of Head of the Risk Management Function is not proportionate, taking into account the principle of proportionality as defined in Part 2 of this Directive, this function may, provided that prior approval is obtained from the competent authority, be combined with the Head of the Regulatory Compliance Function or may be performed by another senior executive, provided that there is no conflict of interest between the combined functions. In any case, such person should possess sufficient authority, status, and independence.
(5) The Head of the Risk Management Function should be able to critically review decisions taken by the senior management and the administrative organ of the credit institution, while the reasons for any objections raised should be officially documented.
(6) If the credit institution wishes to grant the Head of the Risk Management Function veto rights in decision-making, for example, credit or investment decisions or limit setting, at levels below the administrative organ, it should define the scope of such veto rights, the referral procedures to higher levels of the hierarchy or appeal procedures, as well as the manner in which the administrative organ will be involved.
(7) Credit institutions should establish enhanced procedures for the approval of decisions on which the Head of the Risk Management Function has expressed a negative opinion.
(8) The administrative organ should be able to communicate directly with the Head of the Risk Management Function on key risk matters, including developments that may not align with the risk appetite and risk strategy of the credit institution.
Reporting Requirements of the Risk Management Function
71.- (1) Subject to the provisions of this Section, the Head of the Risk Management Function submits a quarterly report to the Risk Committee, a copy of which is communicated to the Chief Executive Officer. The report should cover, at least, the following:
(a) internal assessment and measurement of the risks faced by the credit institution; (b) results and assumptions of stress tests or scenario analyses; (c) calculation of capital requirements and the capital adequacy ratio; and (d) information on the external environment for the purpose of determining market conditions and trends that may relate to the current and future risk profile of the credit institution.
(2) The Head of the Risk Management Function submits an annual report to the administrative organ within two months from the end of each year, via the Risk Committee, a copy of which is communicated to the Chief Executive Officer, which includes, at least, the following information:
(a) an overview of key financial developments during the year that had a significant impact on the operations of the credit institution and its risk profile; (b) description of the risk management framework, including the organization and operation of the Risk Management Function activities, and the existing risk management procedure; (c) the assumptions and results of stress tests and scenario analyses conducted during the reviewed year; (d) detailed information on the institution's risk profile and the capital allocation process; (e) summary of the results of the risk self-assessment and audit conducted during the reviewed year, along with recommendations for minimizing any identified increased operational risks; (f) information on operational losses during the reviewed year; (g) information on significant risk indicators and significant non-performing loan performance indicators monitored by the credit institution; (h) calculation of the credit institution's capital requirements and the capital adequacy ratio; (i) recommendations and specific measures to be taken to address any weaknesses identified in the credit institution's risk management framework; and (j) a comprehensive gap analysis, where the Risk Management Function will comment on the recommendations made in the previous year's report, including the assessment of progress achieved and the current situation.
Part V - Regulatory Compliance Function
Regulatory Compliance Function – General Requirements.
72.- (1) Credit institutions should establish a permanent and effective Regulatory Compliance Function for the management of compliance risk, and should also appoint a person as Head for this function throughout the credit institution.
(2) In cases where the appointment of a person exclusively responsible for the role of Head of the Regulatory Compliance Function is not proportionate, taking into account the principle of proportionality as defined in Part 2 of this Directive, this function may be combined with the Head of the Risk Management Function or another senior executive, for example, the Head of the Legal Department, provided that there is no conflict of interest between the combined functions.
(3) The Regulatory Compliance Function, including its Head, should be independent from the business sectors and internal units it monitors and should possess sufficient authority, status, and resources. The Regulatory Compliance Function reports to the administrative organ via the Audit Committee and informs senior management of its findings, in accordance with the provisions of this Directive.
(4) Taking into account the proportionality criteria defined in Part 2, the Regulatory Compliance Function may either be assisted in its work by the Risk Management Function or be combined with the Risk Management Function or other suitable functions, for example, the Legal Department or the Human Resources Department.
(5) The staff of the Regulatory Compliance Function should possess a sufficient level of knowledge, skills, and experience in compliance matters and related procedures, and should also have guidance, support, and access to regular training to assist them in fulfilling their obligations.
(6) The administrative organ should oversee the implementation of a well-documented regulatory compliance policy, which should be communicated to all staff members.
(7) Credit institutions should establish a procedure for the regular assessment of changes in the legislative and regulatory provisions governing their activities.
(8) Credit institutions design, develop, and implement a comprehensive regulatory compliance framework based on the regulatory compliance policy and supported by regulatory compliance plans, procedures, and safeguards.
(9) Credit institutions ensure that their regulatory compliance framework includes at least a regulatory compliance policy, which identifies the business and legal environment applicable to the institution and defines the objectives, principles, and allocation of regulatory compliance responsibilities; in the case of a group, the regulatory compliance policy states how compliance responsibilities are allocated and handled at group and credit institution levels.
(10) Credit institutions ensure that the process for identifying compliance requirements covers at least the following areas of regulatory, business, and internal requirements:
(a) the credit institution's code of operational ethics and corporate values; (b) laws and regulations on prudential supervision; (c) arrangements for the prevention of money laundering from illegal activities and terrorist financing; (d) arrangements concerning the provision of investment services and activities; (e) tax laws concerning the structure of banking products or advice to customers; (f) other regulations applicable to credit institutions such as regulations concerning consumer rights, data protection, and competition; (g) accounting and audit requirements; (h) business standards and best practices such as – (i) market conduct; (ii) management of conflicts of interest; (iii) fair treatment of customers and ensuring the suitability of advice provided to customers; (iv) information technology and electronic banking.
(11) Credit institutions ensure that their processes and procedures for monitoring regulatory compliance are regularly submitted to staff appointed as Regulatory Compliance Officers in major business units, branches, and subsidiaries in the Republic and abroad for the execution of regulatory compliance duties, thereby assisting such staff in fulfilling their duties related to the Regulatory Compliance Function.
(12) The regulatory compliance framework should include methods and procedures for creating and maintaining an updated register of legal, internal, regulatory, and operational requirements. There should be mechanisms and procedures for appropriate and effective staff access to it and appropriate notification mechanisms for staff changes in the framework and the relevant register, so that each staff member is kept informed of the requirements affecting their work and duties.
(13) Credit institutions establish an official and well-documented mechanism for providing guidance and assigning responsibilities for:
(i) the assessment of causes of non-compliance; (ii) the requirement, initiation, implementation, and monitoring of the effectiveness of corrective measures; and (iii) the documentation of the entire process and the outcome of the process.
(14) The Regulatory Compliance Function should provide the administrative organ with advice on measures to be taken to ensure compliance with applicable laws, rules, regulations, and standards, and should also assess the potential impacts of upcoming changes in the legislative or regulatory environment on the activities and regulatory compliance framework of the credit institution.
(15) The Regulatory Compliance Function should ensure that compliance monitoring is carried out through a structured and clearly defined compliance monitoring program and that the regulatory compliance policy is maintained.
(16) The Regulatory Compliance Function should report to the administrative organ and communicate appropriately with the Risk Management Function on matters related to the credit institution's regulatory compliance risk and its management.
(17) The Regulatory Compliance Function and the Risk Management Function should cooperate and exchange appropriate information, in order to be able to perform their respective duties. The findings of the Regulatory Compliance Function should be taken into account by the administrative organ and the Risk Management Function in the decision-making process.
(18) In accordance with paragraph 58 of this Directive, the Regulatory Compliance Function should also confirm, in close cooperation with the Risk Management Function and the Legal Department, that new products and new processes are consistent with the existing legal framework and, where applicable, with any known upcoming changes in legislative, regulatory, and supervisory requirements.
(19) Credit institutions should take appropriate measures against internal or external behavior that could facilitate fraud, or activities related to money laundering from illegal activities and terrorist financing, and other cases of economic crime and disciplinary offenses, such as, for example, violation of internal procedures or exceeding limits.
(20) Credit institutions should ensure that their subsidiaries and branches abroad take measures to ensure the compliance of their activities with local legislative and regulatory provisions. In cases where local legislative and regulatory provisions prevent the implementation of stricter compliance procedures and systems applied by the group, especially if they do not allow the communication and exchange of necessary information between group entities, subsidiaries and branches should inform the Regulatory Compliance Officer or the Head of the Regulatory Compliance Function of the institution with consolidation responsibility.
(21) Credit institutions develop a comprehensive regulatory compliance culture,
(a) which is based on –
(i) a full understanding of the regulations, national and international standards, and best practices concerning them; and (ii) the compliance risks they face and the manner of managing these risks; and (b) is consistent with their code of business ethics and corporate values; credit institutions develop their regulatory compliance culture through policies, communication examples, and staff training regarding their responsibilities for regulatory compliance.
(22) Credit institutions ensure that the regulatory compliance culture permeates all levels of hierarchy, aiming to raise awareness and ensure that each staff member –
(a) understands the regulations, standards, and best practices related to the fulfillment of their operational or supervisory duties; (b) understands the relevant regulatory compliance risks and the need and responsibility for managing these risks; and (c) understands the importance of control departments in managing regulatory compliance risks and facilitates their work.
(23) The Regulatory Compliance Function establishes, implements, and maintains appropriate mechanisms and activities for –
(a) promoting and maintaining a corporate culture of regulatory compliance and integrity within the credit institution; (b) assisting senior management in the design, development, and implementation of an appropriate and effective regulatory compliance framework for:
(i) the early and continuous compliance of the credit institution and its subsidiaries in Cyprus and abroad with their legal, regulatory, and operational obligations; (ii) the effective management of non-compliance risks with these obligations.
(24) Regulatory compliance activities are defined in a regulatory compliance program prepared and monitored by the Head of the Regulatory Compliance Function, who ensures that all relevant areas of the credit institution and its subsidiaries in Cyprus and abroad are appropriately covered, taking into account their sensitivity to compliance risk; regulatory compliance activities include at least the following:
(a) continuous identification, with the assistance of the Legal Services Unit and other relevant units of the credit institution, of the legal, regulatory, and operational requirements governing and/or affecting the institution's activities; (b) updates to business units and subsidiaries regarding applicable legal, regulatory, and operational requirements for – (i) the identification of compliance obligations arising from these requirements; (ii) the measurement and assessment of the impact of these obligations on the processes, procedures, and activities of the credit institution; (iii) the assessment of the suitability of the credit institution's regulatory compliance policies and procedures, monitoring of deficiencies, and, where necessary, formulation of recommendations for modifications; (c) proactive identification and recording of regulatory compliance risks related to the credit institution's business activities;
(d) development of appropriate practices and methodologies for measuring regulatory compliance risk, such as risk indicators, with the assistance, if necessary, of experts from the Risk Management Department, and the use of such measures to improve the ability to assess regulatory compliance risk; the Regulatory Compliance Department ensures that these methodologies allow for the aggregation or filtering of data that may indicate potential regulatory compliance problems; (e) formulation of proposals for organizational and procedural changes to ensure the appropriate management of identified regulatory compliance risks; (f) ensuring the use of appropriate tools and methodologies for monitoring activities, which among other things include:
(i) assessment of periodic reports submitted by compliance officers; (ii) the use of aggregate risk measures, such as risk indicators; (iii) the use of management alerts, recording significant deviations between actual events and expectations (exception reporting) or situations requiring remediation (issue recording); (iv) targeted business monitoring of the transaction portfolio, observation of processes, document checks and/or interviews with involved staff; (v) verification of the practical implementation of regulatory compliance policies and procedures through on-site inspections; and (vi) investigation of potential violations of compliance policy and the regulatory framework with the assistance, if necessary, of experts within the credit institution such as experts from the Internal Audit Inspection Department or the Legal Services Unit; (g) ensuring the existence of an internal early warning mechanism to facilitate confidential reporting by employees regarding concerns, deficiencies, or potential violations of the credit institution's policies, legal, regulatory, or operational obligations, or ethical issues; (h) oversight of the complaints process and utilization of customer complaints as a source of useful information within the general monitoring responsibilities; (i) periodic re-evaluation and review of the scope of regulatory compliance controls to be conducted; (j) cooperation and information exchange with other control and risk management functions on compliance matters; (k) early reporting to senior management and the administrative organ regarding significant deficiencies and weaknesses in regulatory compliance policy and internal control procedures, as well as violations of the regulatory framework revealed by the credit institution's compliance monitoring activities, on-site inspections, and investigations; (l) organization of regular training and education programs for management and staff on regulatory compliance and regulation matters; (m) provision of advice and response to inquiries regarding compliance matters from staff; (n) issuance of written instructions and circulars to staff, business units, and relevant departments of the credit institution and group for the early adaptation of internal procedures and regulations to changes in the regulatory framework; (o) verification that new products and processes are consistent with the existing legal framework and professional standards and with any known changes in legislation, regulations, supervisory requirements, and professional standards.
Reporting Requirements of the Regulatory Compliance Function.
73.- (1) The Head of the Regulatory Compliance Function submits a quarterly report to the Audit Committee, a copy of which is communicated to the Chief Executive Officer, which covers, at least, the following:
(a) information on the main compliance risk indicators monitored by the credit institution; (b) significant compliance areas and the progress of related investigations that have been conducted or other actions taken; (c) updated information on the operational and regulatory framework of the credit institution for the determination of developments that may affect the current and future compliance obligations of the institution;
(d) a brief update regarding the above for each subsidiary in Cyprus and abroad, as well as for branches; (e) penalties or other disciplinary measures taken by the supervisory authorities concerning the credit institution or any of its senior management.
(2) The Head of the Regulatory Compliance Function shall submit an annual report to the administrative organ within two months from the end of each year, through the audit committee, a copy of which shall be communicated to the Chief Executive Officer, containing the following minimum information:
(a) a description of the regulatory compliance framework, including the organization and operation of the Regulatory Compliance Function’s activities, and the existing regulatory compliance management process; (b) the regulatory compliance program for the year under review; (c) the regulatory compliance work carried out during the year under review; (d) a summary description, accompanied by extensive comments, of the most significant findings and weaknesses identified from the examination of the regulatory compliance policy and procedures conducted during the year under review, and the submission of recommendations for taking corrective measures; (e) an updated summary of the progress achieved and the implementation of corrective measures taken to address any compliance weaknesses and findings identified in the findings of various control functions, external auditors and consultants, as well as the reports of the supervisory authorities; (f) an assessment of the most significant compliance risks faced by the credit institution based on risk indicators and the measures taken to address them; (g) an updated summary of the changes and developments in legal, regulatory, and operational requirements that were made during the year under review and are expected to be made in the near future, and the measures taken or to be taken to ensure compliance with the modified requirements; (h) details regarding the above for each subsidiary in Cyprus and abroad, as well as for branches; (i) an updated summary of the most significant correspondence with the competent authority; (j) the regulatory compliance program and the action plan of the Regulatory Compliance Function for the following year.
(3) Regarding the procedures for monitoring cases of non-compliance with the Law and this Directive, the following shall be communicated to the competent authority:
(a) within one (1) month from the date of their identification, cases of non-compliance together with information regarding the nature of the violation, the procedure followed or being followed, and the persons involved in the handling and resolution of such cases, and (b) within two (2) months from the date of identification of a case of non-compliance, the corrective measures taken to address these cases.
Role of the Regulatory Compliance Function in preventing money laundering from illegal activities.
74.- The Regulatory Compliance Function ensures the credit institution's compliance with the Law on the Prevention and Suppression of Money Laundering from Illegal Activities of 2007 and the Central Bank’s Directives concerning the prevention of money laundering from illegal activities and terrorist financing issued under paragraph (4) of Article 59 of said Law, as well as relevant Circulars of the Central Bank. As Compliance Officer under Article 69 of said Law, either the Head of the Regulatory Compliance Function or another member of said function holding a key position is appointed, subject to the requirements of said Law.
Section VI - IT Risk and Security Management Function
IT Risk and Security Management Function – General Requirements.
75.- (1) Subject to the provisions of sub-paragraph (3) of paragraph 5, credit institutions shall establish an IT Risk and Security Management Function covering the entire institution. Institutions shall ensure the independence and objectivity of this control function, properly separating it from IT operations. This control function shall report directly to the administrative organ and shall be responsible for monitoring and controlling the adherence to the IT Risk and Security Management framework, including information security policy, as specified in paragraph 52. It shall ensure the identification, measurement, assessment, management, monitoring, and reporting of IT and security risks. The IT Risk and Security Management Function reports to the administrative organ through the risk committee.
(2) Subject to sub-paragraph (16) of paragraph 7 of this Directive, credit institutions shall ensure that all staff members, including those holding key positions, receive appropriate training regarding IT and security risks, including information security, on an annual basis or more frequently if required.
Reporting Requirements for the IT Risk and Security Management Function.
76.- The Head of the IT Risk and Security Management Function shall submit an annual report to the administrative organ, through the risk committee, a copy of which shall be communicated to the Chief Executive Officer. The reporting period of the report concerns the respective calendar year unless the period is differentiated in agreement with the competent authority. The annual report shall be submitted to the administrative organ within one month from the end of the reporting period. The report covers, at least, the following:
(a) a summary of the most significant IT and security risks faced by the credit institution during the year under review; (b) a list of all significant information security incidents that occurred during the year under review and the corrective measures taken to prevent the recurrence of similar incidents; (c) a summary of activities during the reporting year regarding staff training on IT and security risks; (d) any significant actions taken during the year under review to improve weaknesses in the information security environment; and (e) any pending issues that jeopardize the credit institution's information security.
Section VII – Internal Audit Function
Internal Audit Function – General Requirements.
77.- (1) Credit institutions must establish an independent and effective internal audit function, taking into account the proportionality criteria specified in Part 2, and shall appoint a person as responsible/head for this function throughout the institution.
(2) The internal audit function shall be independent and possess sufficient authority, status, and resources. The internal audit function reports to the administrative organ through the audit committee and informs senior management of its findings, in accordance with the provisions of this Directive.
(3) The credit institution shall ensure that both the qualifications of the staff of the internal audit function and its resources, particularly regarding audit tools, risk analysis methods used, and methods for examining and evaluating audit documentation, are sufficient for the size and countries where the institution operates, as well as for the nature, scale, and complexity of risks associated with the business model, activities, risk culture, and risk appetite of the credit institution.
(4) The internal audit function shall be independent from the audited activities. Consequently, the internal audit function shall not be combined with other functions of the institution.
(5) The internal audit function, applying a risk-based approach, shall conduct independent assessments and provide objective assurance regarding the compliance of all activities and units of the institution, including activities subject to outsourcing, with the institution's policies and procedures, as well as external requirements. Every entity of the group shall fall within the scope of the internal audit function.
(6) The internal audit function shall not be involved in the design, selection, establishment, and implementation of specific policies, mechanisms, and procedures of the internal control system, nor of risk limits.
The internal audit function may provide evidence on matters related to risks and internal controls upon request of senior management, provided that the independence of the function's mission is not called into question.
(7) The internal audit function shall evaluate both the effectiveness and efficiency of the credit institution's internal control framework, as specified in paragraph 55 of this Directive.
Specifically, the internal audit function performs audit assignments according to paragraph 78 on its own initiative in all areas and functions of the credit institution, according to the audit plan prepared by the head of the function and approved by the administrative organ, to provide independent assurance to the administrative organ on matters such as:
(a) the suitability of the credit institution's governance framework; (b) whether existing policies and procedures remain adequate and consistent with legislative and regulatory requirements, as well as with the credit institution's risk appetite and risk strategy; (c) the compliance of procedures with current legislative and regulatory provisions and with decisions of the administrative organ; (d) whether procedures are applied in a correct and effective manner, for example, regarding regulatory compliance or the level of risk actually arising; (e) the adequacy, quality, and effectiveness of controls conducted and reports submitted by supporting operational units, as well as by risk management and regulatory compliance functions; (f) the accuracy of reports submitted to the competent authority; (g) the overall means by which the institution manages and mitigates risks to preserve its assets, and seeks to prevent fraud, misappropriation, or misuse of such assets; (h) the design and operational effectiveness of individual controls and functions of the credit institution's internal control system regarding the aforementioned matters, as well as regarding the totality of such controls; (i) other matters that may be requested by the administrative organ, senior management, or the competent authority; and (j) other matters that the internal audit function requires for review to fulfill its mission.
(8) The internal audit function shall verify, in particular, the integrity of procedures ensuring the reliability of the credit institution's methods and techniques, as well as the assumptions and information sources used in its internal models, for example, risk models and accounting valuations. Furthermore, it shall evaluate the quality and use of tools for qualitative identification and assessment of risk, as well as the measures taken to reduce risk.
(9) The internal audit function shall have unimpeded access, at the level of the credit institution, to all records, documents, information, and physical infrastructure of the credit institution. Such access shall also include access to information management systems and the minutes of all committees and decision-making bodies.
(10) The internal audit function shall adhere to relevant national and international professional standards. Examples of professional standards referred to herein include the standards established by the International Institute of Internal Auditors.
(11) The staff of the internal audit function shall – (a) act with integrity, perform their duties in a sincere and professional manner, and inform the head of the internal audit function if their ability to conduct an audit assignment is called into question; (b) exercise diligence regarding the protection of information obtained during the performance of their duties; (c) ensure that their professional opinion is not influenced by any personal or professional interests.
(12) Internal audit work shall be performed based on an internal audit plan and a detailed audit program, according to a risk-based approach.
(13) An internal audit plan shall be prepared at least once a year, based on annual internal audit objectives. The internal audit plan shall be approved by the administrative organ.
(14) All recommendations within the audit shall be subject to a formal monitoring process by the appropriate levels of management, to ensure their effective and timely implementation and to submit relevant reports.
Audit Assignments. 78.- (1) The internal audit function conducts the assignments required to fulfill its duties to provide assurance according to paragraph 76, through regular and special audits, both announced and unannounced.
(2) At least the following audit activities are included in the scope of internal audit assignments:
(a) assessment of the suitability and adequacy of the organizational structure and human resource management, and the extent to which the institution has established appropriate corporate governance policies and procedures;
(b) assessment of the extent of effective utilization by the credit institution's collective organs, as well as by operational units and control functions, of the means and resources available, compliance with officially defined guidelines and procedures, whether due attention was given to ensuring the completeness and accuracy of information, and whether appropriate risk prevention and control mechanisms are integrated into all processes and transactions conducted; (c) assessment of the effectiveness, adequacy, and adherence of risk and compliance management procedures; (d) assessment of the integrity of information systems, including risk management and accounting information systems, as well as the accuracy, reliability, and completeness of information used or extracted; (e) assessment of systems and procedures governing the extraction of reliable, complete, and updated financial, administrative, and regulatory information; (f) assessment of information security of any kind, located in any medium, including information in printed form; (g) assessment of procurement/bidding procedures and bids conducted; (h) assessment of the completeness and effectiveness of the outsourcing policy; (i) assessment of the completeness and adequacy of the credit institution's business continuity and information system disaster recovery plans; (j) assessment of the completeness and adequacy of the credit institution's information security policy, including information system security; (k) assessment of the Internal Capital Adequacy Assessment Process (ICAAP) of the credit institution in relation to its risk profile, the parameters on which the credit institution has based its calculations regarding capital adequacy, and the examination of the stress testing process regarding the credit institution's capital base, taking into account the frequency of such tests, their purpose, the logic of scenarios, underlying assumptions, and the reliability of procedures used; (l) assessment of the extent to which procedures for approving new products are applied according to new product approval procedures, and whether these procedures are adequate and effective; (m) assessment of the suitability of the remuneration policy in relation to predetermined goals set by the legal and regulatory framework, as well as the possible consequences of the policy on risk taking and management; (n) assessment of the adequacy and applicability of clawback arrangements, as well as the structure of additional incentives in relation to the deferred payment component and its link to future returns within a reasonable time horizon; (o) assessment of the adequacy and effectiveness of regulatory compliance, risk management, and information security functions.
Audit Plan. 79.- (1) The audit program shall be based on risk assessment, be dynamic and targeted, and ensure that all entities and all activities of the credit institution are audited at least once within a suitably defined time period. The audit program shall be a means to assess the adequacy and effectiveness of the internal control framework.
(2) The audit program ensures at least:
(a) the conduct of audits regarding the creditworthiness assessment process on an appropriate scale on an annual basis as a means to assess:
(i) the adequacy and effectiveness, and adherence of procedures and credit granting policy, including assessment procedures for credit applications and approval of credit facilities, as well as the management and monitoring of the collateral mechanism and ensuring compliance with credit clauses, and in accordance with the Central Bank’s Directive on Procedures for Granting New Credit Facilities and Procedures for Reviewing Existing Credit Facilities; (ii) the correct application of the internal creditworthiness assessment system developed by the credit institution in accordance with Central Bank guidelines regarding credit risk management; (iii) the suitability, adequacy, and correct application of the policy for creating provisions for impaired assets, as well as the adequacy of provisions and completeness
of the methodology and procedure for calculating loan impairments, including the criteria for selecting loans for impairment control purposes; (iv) the completeness of the methodology and procedure for calculating the impairment of other assets, as well as the adequacy of related provisions for doubtful requirements and impairment write-offs; (v) the adequacy of monitoring and handling procedures for non-performing and problematic loans; (vi) the adequacy and effectiveness of internal audits in relation to the subject; (b) annual assessment of the adequacy and adherence to credit granting procedures for members of the governing body and persons associated with them, for major shareholders and persons associated with them; (c) the conduct of annual special audits of appropriate scope, as a means of assessing the adequacy and effectiveness of information systems and information security; (d) annual assessment of the effectiveness and adequacy of the policy, procedures and controls for preventing money laundering and terrorist financing, as well as the level of compliance with the provisions of the Law on the Prevention and Combating of Money Laundering from Illegal Activities of 2007 and the Directive on the Prevention of Money Laundering and Terrorist Financing of 2013; (e) the assessment at least every three years of the adequacy and completeness of the policy on outsourcing activities and the taking of corrective monitoring measures on an annual basis; furthermore, the internal audit department conducts assessments of outsourcing activities, at a frequency determined based on the results of the internal audit department's annual risk assessment, as provided for in sub-paragraph (1) of this paragraph, and at least every two years. These assessments are conducted at an appropriate scale, as a means of assessing compliance with the policy on outsourcing activities, prioritizing the outsourcing of significant activities to third parties; (f) the assessment at least on an annual basis of the implementation of the remuneration policy by senior management and its compliance with the relevant policies and procedures adopted by the governing body. Reporting requirements of the internal audit function. 80.- (1) The head of the internal audit function submits to the governing body through the audit committee, at least on a quarterly basis, a report of the most significant observations arising from the audits conducted since the last report to the governing body, as well as recommendations for addressing any weaknesses that were identified. When significant weaknesses are identified, the head of the internal audit function is responsible for notifying the governing body as soon as practically possible. (2) The head of the internal audit function submits an annual report to the governing body, within two months from the end of each year, through the audit committee, a copy of which is communicated to the managing director, with the following minimum
information:
(a) audit program approved by the governing body for the year under review and the rationale for any deviations in its implementation; (b) summary, combined with extensive observations, of the most significant findings and weaknesses identified by the audits conducted during the year under review for each area audited; (c) updated summary of the progress achieved in the execution and implementation of corrective measures taken to address any weaknesses and findings identified in various reports of internal and external auditors, as well as supervisory authorities; (d) verification, on a sample basis, of the accuracy of reports submitted to the competent authority; (e) audit and action plan for the following year. Cooperation of the internal audit function with the competent authority. 81.- The cooperation of the head of the internal audit function with the competent authority must cover the following, based on the results of the assessments conducted:
(a) adequacy and effectiveness of the credit institution's processes for setting goals and strategic decisions; (b) quality and significance of governance and management structures and procedures; (c) the capital base and liquidity position of the credit institution and its processes and methods for identifying, monitoring, controlling and reporting on significant risks, including the risks referred to in paragraphs 45 to 54;
(d) the credit institution's business model, including risks in the credit institution's business activities, processes and functions and the adequacy of monitoring and supervision of these risks, such as:
(i) execution and implementation of risk management and risk assessment methods as applied to significant risks, including the risks referred to in paragraphs 63 to 71; (ii) appropriateness and adequacy of the provision policy for doubtful requirements as well as the adequacy of provisions; (iii) completeness of the impairment/write-off methodology; (iv) adequate management of significant transactions; (v) handling of non-performing and problematic loans; (vi) fraud management / fraud risk management; (vii) management of outsourcing arrangements; (e) ethical issues, such as:
(i) conflict of interest management;
(ii) compliance with rules in the provision of services to customers; (iii) money laundering prevention procedures and controls; (f) issues related to the internal audit function and the adequacy and effectiveness of other functions of the internal audit system.
External assessment of the adequacy of the internal audit framework.
82.- (1) Credit institutions entrust at least once every three years, the assessment of the adequacy and effectiveness of the internal audit framework to an external auditor, other than the approved auditor of the credit institution, who possesses the necessary technical expertise to conduct the required assessment in accordance with the provisions of
Appendix II.
(2) The assessment referred to in sub-paragraph (1) of this paragraph is conducted on a consolidated basis and on an individual basis. Before the start of the assessment work, the audit committee of the credit institution must define the units and subsidiaries that will be included in the scope of the assessment. This should be based on the principle of proportionality, as well as other qualitative criteria. The scope of the assessment, should be submitted in advance to the competent authority. (3) Credit institutions change the external auditors referred to in sub-paragraph (1) of this paragraph, after two consecutive assessments.
PART 10 – BUSINESS CONTINUITY MANAGEMENT
Business continuity management.
83.- (1) Credit institutions should prepare a sound business continuity management plan, in order to ensure their uninterrupted operation and to limit losses in the event of a significant disruption of business operations.
(2) Credit institutions may establish a special independent business continuity function, for example within the risk management function.
(3) The credit institution's business activity is based on various critical resources, such as information systems, communication systems, key personnel and building infrastructure. The purpose of business continuity management is to mitigate operational, financial and legal impacts, as well as reputational impacts on the credit institution and other significant impacts arising from a disaster or prolonged deprivation of these resources and the subsequent disruption of the credit institution's usual business processes. Other risk management measures may aim to reduce the likelihood of such events or transfer their financial impact to third parties, such as through insurance (e.g. insurance policies). (4) To prepare a sound business continuity management plan, the credit institution should carefully analyze risk factors and its exposure to significant disruptions of its business operations and assess (quantitatively and qualitatively) their potential impact using internal and/or external data and scenario analysis. The analysis should cover all business areas and internal units of the credit institution, including the risk management function, while also taking into account their interdependence. The results of the analysis should contribute to determining the credit institution's recovery priorities and goals. (5) Based on the above analysis, the credit institution should implement:
(a) emergency and business continuity plans, which ensure that the credit institution responds adequately to emergencies and maintains the ability to conduct its most significant business activities in the event of disruption of its usual business processes; and (b) critical resource recovery plans, which allow the credit institution to return to usual business practices within a reasonable time frame. Any residual risk from potential business disruptions should be consistent with the credit institution's risk appetite. (6) Emergency, business continuity and recovery plans should be documented and implemented with particular care. The relevant documentation should be available to business areas, internal units and the risk management function and stored in systems located in separate spaces and easily accessible in case of emergency. Appropriate training should be provided. The plans should be subject to testing and updating at regular intervals. Any challenges or failures identified during simulation tests should be documented and analyzed, and the plans should be revised accordingly.
PART 11 – TRANSPARENCY
Transparency. 84.- (1) Strategies, policies and procedures should be communicated to all members of the relevant staff of the credit institution. The credit institution's staff should understand and comply with the credit institution's policies and procedures regarding their duties and responsibilities. (2) The governing body should inform and provide relevant staff with up-to-date information regarding the credit institution's strategies and policies clearly and consistently, at least at the hierarchical level required for the performance of their specific duties. This information may be provided through written guidelines, manuals or other means. Disclosures. 85.- (1) Credit institutions that are parent companies disclose annually in accordance with paragraph (c) of paragraph (3A) of Article 24 of the Law, a description of the legal structure and governance and the organizational structure of the group. This information should include all entities within the group structure. It is understood that for the purposes of this paragraph, "group" is defined as in Article 4 paragraph 1 point 138) of Regulation (EU) 575/2013. (2) The disclosure should include at least:
(a) an overview of the internal organization of the institutions and the group structure, and changes thereto, including the main reporting lines and responsibilities; (b) any significant changes that have occurred since the last disclosure and the date of each significant change; (c) new legal structures, governance structures or organizational structures; (d) information regarding the structure, organization and members of the governing body, including the number of members and the number of members characterized as independent, specifying the gender and the term of office of each member of the governing body; (e) the main responsibilities of the governing body; (f) a list of the governing body's committees under its supervision, as well as their composition; (g) an overview of the conflict of interest policy applied to the institutions and the governing body; (h) an overview of the internal audit framework; (i) an overview of the business continuity management framework; and (j) when a credit institution is state-owned, the general objectives of state ownership, including any specific obligations of the credit institution regarding the state's social policy, how these obligations are funded, as well as the state's policy and role in the internal governance of the credit institution. (3) In cases where a high degree of accuracy might delay the notification of time-sensitive information, the institution should make a decision regarding finding the appropriate balance between timeline and accuracy, taking into account the requirement to present a true and fair view of its situation and providing a satisfactory explanation for any delay; this explanation should not be used to delay the submission of regular required reports.
(4) Credit institutions explain on their website how they comply with the requirements of the harmonized legislative provisions of Articles 88 to 95 of Directive 2013/36/EU:
(a) regarding Article 88, in sub-paragraph (1) of paragraph 6 and points (a) to (d) of sub-paragraph (2) of paragraph 6, in sub-paragraph (10) of paragraph 7 and paragraph 23 of this Directive, as well as in Article 19B(2) of the Law; (b) regarding Article 89, in Article 24A of the Law; (c) regarding Article 90, in Article 24B of the Law; (d) regarding Article 91, in points (e) and (f) of sub-paragraph (2) of paragraph 6 and sub-paragraphs (1) and (5) of paragraph 15, in point (d) of sub-paragraph (1) of paragraph 26 and point (c) of sub-paragraph (5) of paragraph 83 of this Directive, in sub-paragraph (3) of paragraph 12 of the Directive on the Assessment of the Suitability of Members of the Governing Body and Persons Holding Key Positions in Licensed Credit Institutions of 2020 and in paragraph (1) of Article 26 of the Law; (e) regarding Article 92, in sub-paragraph (2) of paragraph 30 of this Directive; (f) regarding Article 93, in paragraph 32 of this Directive; (g) regarding Article 94, in paragraph 31 of this Directive; (h) regarding Article 95, in sub-paragraph (1) of paragraph 17, sub-paragraph (5) of paragraph 18 and sub-paragraphs (1) to (3) of paragraph 22 of this Directive.
PART 12 – REPORTING TO THE COMPETENT AUTHORITY
Reporting to the competent authority.
86.- (1) Credit institutions submit to the competent authority the final minutes of the governing body, audit committee and risk committee meetings, as provided for in paragraphs 12 and 19 of this Directive, within one (1) month from the date of the meeting. In the event that no meeting of the governing body is held within the one (1) month period, the minutes are approved via a written procedure by all members attending the meeting and submitted within the specified deadline to the competent authority. (2) Credit institutions submit to the competent authority, within three (3) months from the end of each year, the following reports and information, accompanied by the respective assessments of the competent committees of the governing body and the relevant excerpts from the minutes of the governing body meetings:
(a) annual report on the internal audit framework prepared by the head of the internal audit function; (b) annual report on risk management, prepared by the head of the risk management function; (c) annual report on regulatory compliance, prepared by the head of the regulatory compliance function; (d) performance assessment report of the governing body as a whole, the committees and individual members, prepared by the governing body in accordance with the provisions of paragraph 16 of this Directive, including the assessment of the chairman of the governing body as referred to in paragraph 11 of this Directive; 31(I) of 2018 32(I) of 2019. (3) Credit institutions submit to the competent authority the annual report on information security, referred to in paragraph 75. The annual report is submitted within two months from the end of the reporting period. This report takes into account and covers the requirements of paragraph (2) of Article 95 of the Law on the Provision and Use of Payment Services and Access to Payment Systems of 2018. (4) Credit institutions submit to the competent authority the annual report of the outsourcing officer, in accordance with the provisions of sub-paragraph (6) of paragraph 38 of this Directive. (5) Credit institutions submit to the competent authority on an annual basis by June 30 of each year:
EBA/GL/2014/08
16.07.2014
(a) for the purposes of Article 26D of the Law, the standards provided for in Appendices 1-3 of the EBA Guidelines on Comparative Remuneration Assessment of 2014, in accordance with the requirements specified in Titles III and IV of the aforementioned EBA Guidelines; EBA/GL/2014/07 16.07.2014 (b) for the purposes of Article 26C(2) of the Law, the standards provided for in Appendix 1 of the EBA Guidelines on Data Collection regarding Highly Remunerated Persons of 2014, in accordance with the requirements specified in Titles II and III of the aforementioned guidelines.
(6) Credit institutions submit to the competent authority, within a reasonable time frame and in collaboration with the competent authority, assessment reports regarding the adequacy and effectiveness of the internal audit framework on an individual and consolidated basis, which are prepared by external auditors in accordance with the provisions of paragraph 82 of this Directive. (7) Credit institutions submit to the competent authority, within a reasonable time frame and in collaboration with the competent authority, assessment reports regarding the composition, efficiency and effectiveness of the governing body and its committees, which are prepared by an external consultant in accordance with the provisions of sub-paragraph (2) of paragraph 16 of this Directive.
PART 13 - MISCELLANEOUS PROVISIONS
Repeal. 87. - The Directive on Governance and Management Regulations of 2014 issued by the Central Bank to credit institutions is repealed.
Entry into force. 88.- The provisions of this Directive enter into force from the date of its publication in the Official Gazette of the Republic.
Appendix I
ASPECTS TO BE CONSIDERED WHEN DEVELOPING AN INTERNAL GOVERNANCE POLICY According to Part 6, when documenting internal governance policies and arrangements, institutions should take into account the following aspects:
Appendix II
CONTENT OF THE ASSESSMENT REPORT ON THE ADEQUACY OF THE INTERNAL CONTROL FRAMEWORK PREPARED BY EXTERNAL AUDITORS
PART I - INTRODUCTION
(2) The assessment of the adequacy of the internal control framework must cover an inspection of:
(a) the control environment;
(b) the risk assessment process;
(c) control mechanisms and safeguards;
(d) communication networks and information systems; (e) the role, duties, and responsibilities of the governing body and internal control functions; and (f) the operation and staffing of the credit institution's key functions/departments/units, their terms of reference, procedures, and information systems used.
PART II - MINIMUM ASPECTS OF THE ASSESSMENT
(a) Organizational Structure
(i) Organizational structure (organizational chart and reporting lines, composition, terms of reference, and operation of the governing body and its committees); (ii) Assessment of whether the general corporate governance framework complies with the provisions of this Directive and ensures timely and accurate communication of all significant matters concerning the credit institution; (iii) Adequacy of systems used to generate information, in accordance with the relevant legal/regulatory framework; (iv) The role of the governing body in ensuring the adequacy of the internal control system framework; (v) Conflict of interest, the four-eyes principle, and segregation of duties; and (vi) Procedure for preparing the annual budget, in accordance with the credit institution's strategy and procedures, which must be followed in cases of deviation from such strategy.
(b) Accounting System
When examining the accounting system, the adequacy of the internal control system regarding the preparation of reliable financial statements must be evaluated. The assessment should cover the system's ability to manage information, facilitating the timely and reliable flow of required information to each relevant employee or administrative unit, to fulfill their duties.
(c) Information Systems
(i) organization and governance of information systems; (ii) development and commissioning of systems; (iii) operation and support of systems; (iv) physical and logical security; (v) electronic and mobile banking; and (vi) business continuity plans and recovery plans.
(d) Audit Committee and Internal Control Function
(i) Assessment of the audit committee regarding its members, duties, participation in the audit process, the annual report on the internal control system prepared by the head of the internal control function, and the update of the governing body.
(ii) Regarding the head of the internal control function, their independence, position in the organizational chart, and connection with the governing body and audit committee should be examined; (iii) internal control practices and methodology, which must be compared with best practices; (iv) internal inspection system (for storing audit programs, plans, findings, recommendations, and generating management reports) and computer-assisted inspection techniques, if any, used by the credit institution; (v) on a sample basis, the adequacy of audit reports for the credit institution and its subsidiaries, prepared by the internal control function; (vi) procedure for monitoring the compliance of inspected units with the recommendations of the head of the internal control function; and (vii) external quality assessment of the internal control function.
(e) Risk Committee and Risk Management Function
(i) composition and role of the risk committee; (ii) framework for risk management, and specifically, whether there are adequate mechanisms for identifying, monitoring, and managing all types of risks undertaken by the credit institution; (iii) measures to be taken when emergency liquidity problems arise; (iv) independence, roles, responsibilities, and work performed by the risk management function and the head of such function; (v) adequacy and effectiveness of risk management policies and procedures (including the methodology for provisioning for impaired exposures); (vi) possibility of different risk management procedures in other countries where the credit institution has a presence; (vii) risk assessment procedure related to the design of new products/promotion of new services; (viii) objectivity of risk assessment procedures for credit applications and credit facility approvals, tools used for internal credit rating of grants, management and monitoring of the collateral mechanism, compliance with contractual clauses, measures taken to address non-performing loans, and the ability to monitor risks across the credit institution's entire loan portfolio; and (ix) adequacy and adherence to procedures for granting credit facilities to members of the governing body and related parties, as well as other persons holding a qualifying holding in the credit institution, and ensuring non-preferential treatment.
(f) Regulatory Compliance Function
(i) Assessment of the regulatory compliance function regarding its independence, roles, and responsibilities, its access to all information sources, the direct and reliable communication of its findings, and the effective adoption of changes in the regulatory framework; (ii) adequacy and effectiveness of policies and procedures, as well as the responsibilities of senior management and the governing body for managing regulatory compliance risk; and (iii) adequacy of procedures existing to prevent and combat money laundering from illegal activities and terrorist financing, and the procedure for classifying transactions and counterparties into various risk categories.
(g) IT Risk and Security Management Function
(i) Assessment of the IT risk and security management function regarding its independence, roles, and responsibilities, its access to all information sources, the direct and reliable communication of its findings, and the effective adoption of changes in the information security framework;
(ii) adequacy and effectiveness of the information security framework, as well as the responsibility of the governing body and senior management for overseeing information risk; (iii) adequacy of policies and procedures for effective IT risk and security management, as well as effective mitigation thereof; (iv) existence of adequate monitoring and inspection of procedures for the continuous improvement of information security in the credit institution.
Read the rest free
Source: Central Bank of Cyprus — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CBC
We email you every new CBC publication the day it's published.