Assessment of internal governance arrangements and controls
Competent authorities should assess the adequacy of the TCB’s governance arrangements using Title 5 and section 7 of the EBA Guidelines on Internal Governance in accordance with Directive 2013/36/EU(61) as a guide as well as the TCB-specific considerations below. The assessment should include the overall framework, risk culture and risk conduct, remuneration policies and practices, and the internal control and risk management framework including the management of ICT risks and third-party risks.
In conducting the assessment of internal governance, competent authorities should consider whether the TCB maintains sufficient substance in the Member State in accordance with the requirements in paragraph 90(g) of the EBA Guidelines on internal governance.
Organisational framework
Competent authorities should assess whether the persons directing the TCB:
have sufficient understanding of the activities and risks of the branch and knowledge of the local market, as well as of EU and national regulations of the Member State;
have sufficient authority, stature, and independence, taking into account the extent they are empowered to contribute to decisions by the head undertaking affecting the branch;
spend sufficient time within its Member State and in the premises of the branch to effectively fulfil their role.
Where the TCB branch has established a management committee, competent authorities should review its role in ensuring adequate governance. In the absence of such body, competent authorities should review whether an appropriate and proportionate alternative framework for senior management oversight of the TCB’s activities and risks has been implemented.
Relation with the head undertaking
Competent authorities should assess the TCB’s relation with the head undertaking, including whether the branch is integrated into the group governance and risk management framework effectively. They should take into account whether:
the branch’s reporting to the head undertaking provides sufficient visibility of the branch’s material risks;
d. the risk framework applied to the TCB adequately addresses EU financial services regulations.
Where the TCB engages in back-to-back or intragroup operations, competent authorities should verify that the branch has an appropriate framework for managing its counterparty credit risk.
Internal control framework and third-party risk management
Competent authorities should assess whether the TCB has robust internal control functions. For class 1 TCBs (and class 2 TCBs where applicable in accordance with Article 48g(3) of Directive 2013/36/EU), competent authorities should assess whether suitable heads of internal control functions have been appointed who are independent and have sufficient capacity to fulfil the function as provided for in Article 76(6) of Directive 2013/36/EU.
Competent authorities should assess whether the TCB conducts appropriate due diligence and ongoing oversight of functions provided by third-party service providers. They should verify that third-party arrangements, including intragroup arrangements, are governed by documented agreements and that the TCB has access to all information required to exercise its monitoring obligations, including when subcontractors are used. Competent authorities should review the TCB’s management of its ICT risks, including whether the TCB maintains an appropriate register of its third-party service providers including when subcontractors performing critical or important function are used.