Overall internal governance framework
In line with the EBA Guidelines on internal governance, the Joint ESMA and EBA Guidelines on the assessment of the suitability of members of the management body and key function holders(19), the EBA Guidelines on disclosure requirements(20), the EBA Guidelines on outsourcing arrangements(21) and the EBA Guidelines on sound remuneration policies(22), the assessment of the internal governance framework by competent authorities should include an assessment of whether the institution demonstrates at least that:
the duties of the management body are clearly defined, distinguishing between the duties of the management (executive) function and of the supervisory (non-executive) function and that appropriate governance arrangements have been implemented;
a suitable and transparent organisational and operational structure with well-defined, transparent and consistent lines of responsibility, including those of the management body and its committees has been set up;
the management body has set and ensured the implementation of the overall business and risk strategies, including the setting of the institution’s risk appetite, on an individual and a consolidated basis with the appropriate involvement of the management body;
risk culture through policies and their implementation, including communication and training, are appropriate;
a selection and suitability assessment process for the members of the management body and key function holders has been implemented;
an adequate and effective internal governance and internal control framework is in place with independent risk management, compliance and internal audit functions that have sufficient authority, stature and resources to perform their functions;
a remuneration policy and remuneration practices that are in line with the remuneration principles set out in Articles 92 to 95 of Directive 2013/36/EU and the EBA Guidelines on sound remuneration policies have been implemented;
arrangements aimed at ensuring the integrity of the accounting and financial reporting systems, including financial and operational controls and compliance with the law and relevant standards have been implemented;
an outsourcing policy and strategy that consider the impact of outsourcing on the institution’s business and the risks it faces have been implemented;
the internal governance framework is set, overseen and regularly assessed by the management body; and
that the internal governance framework is transparent to stakeholders, including shareholders.