Internal control functions
In assessing the institution’s internal control functions, competent authorities should assess institution’s compliance with the EBA Guidelines on Internal Governance and the relevant provisions of the Regulation (EU) 2022/2554 (DORA)(30). In this context, competent authorities should consider inter alia whether:
the institution has an appropriate internal control framework covering all areas, consistent with the ‘three lines of defence’ model, including well-functioning, effective and independent risk management, compliance and internal audit functions;
the heads of internal control functions (i) are established at an adequate hierarchical level that provides them with the appropriate authority and stature needed to fulfil their responsibilities, (ii) have direct access and can report directly to the management body in its supervisory function, and (iii) have all the resources necessary to perform their tasks;
the institution has adequate written internal control policies effectively implemented and a clear allocation of responsibilities for the implementation of the framework, segregation of duties, sound administrative and accounting procedures and robust reporting arrangements.
Competent authorities should assess whether the risk management function covers the whole institution, having a holistic view of all risks, is actively involved at an early stage in elaborating the institution’s risk strategy and monitors its effective implementation. Competent authorities should also determine whether the risk management function provides the management body with complete, updated and relevant risk-related information to enable setting the institution’s risk appetite level and related risk limits. Competent authorities should also consider the risk management function’s assessment of the robustness and sustainability of the risk strategy and appetite as well as its involvement in the evaluation of the impact of material changes or exceptional transactions on the institution’s and group’s (where applicable) overall risk.
Competent authorities should assess whether the compliance function effectively assesses and mitigates compliance risks arising from non-compliance with applicable legal and regulatory requirements, contractual obligations or internal rules and codes of conduct, including rules on ethics, and ensures that all material risk management decisions adequately take into account these risks.
Competent authorities should assess whether the internal audit function independently reviews and provides objective assurance, in accordance with the audit plan and detailed work programme, on the appropriateness and effectiveness of the institution’s policies, procedures and internal controls and on the compliance of all the institution’s activities, including activities provided by third-party service providers, with legal and regulatory requirements. Where applicable, competent authorities should assess whether the group-wide internal audit function is independent, has a group-wide risk-based audit plan, has appropriate resources and stature and has a direct reporting line to the management body of the consolidating institution.