Commission Delegated Regulation (EU) 2017/392 of 11 November 2016 supplementing Regulation (EU) No 909/2014 of the European Parliament and of the Council with regard to regulatory technical standards on authorisation, supervisory and operational requirements for central securities depositories (Text with EEA relevance. )

Type Delegated Regulation
Publication 2016-11-11
Last updated 2026-04-15
State In force
Department European Commission, FISMA
Source EUR-Lex
articles 96
Reform history JSON API

COMMISSION DELEGATED REGULATION (EU) 2017/392 of 11 November 2016 supplementing Regulation (EU) No 909/2014 of the European Parliament and of the Council with regard to regulatory technical standards on authorisation, supervisory and operational requirements for central securities depositories (Text with EEA relevance)

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) No 909/2014 of the European Parliament and of the Council of 23 July 2014 on improving securities settlement in the European Union and on central securities depositories and amending Directives 98/26/EC and 2014/65/EU and Regulation (EU) No 236/2012 (1), and in particular Article 12(3), Article 17(9), Article 22(10), Article 25(12), Article 55(7), Article 18(4), Article 26(8), Article 29(3), Article 37(4), Article 45(7), Article 46(6), Article 33(5), Article 48(10), Article 49(5), Article 52(3), and Article 53(4) thereof,

Whereas:

(1) The provisions in this Regulation are closely linked, since they all deal with the supervisory requirements applicable to central securities depositories (CSDs). To ensure coherence between these provisions, which should enter into force at the same time, and to facilitate a comprehensive view and easy access by persons that are subject to these provisions, it is desirable to include all the regulatory technical standards concerning the supervisory requirements under Regulation (EU) No 909/2014 in a single Regulation.

(2) In view of the global nature of financial markets and given the commitments undertaken by the Union in this field, due regard should be had to the Principles for Financial Market Infrastructures issued by the Committee on Payment and Settlement Systems and the International Organisation of Securities Commissions (CPSS-IOSCO Principles) in April 2012.

(3) In order to ensure consistent application of rules concerning improving securities settlement in the Union, certain technical terms should be clearly defined.

(4) It is important to ensure appropriate authorisation and supervision of a CSD. As such, a list of the relevant authorities issuing the most relevant Union currencies in which settlement takes place to be involved in the process of authorisation and supervision of a CSD should be defined. This should be based on the share of the currencies that those authorities issue in the total value of settlement instructions against payment settled annually by a CSD and on the share of settlement instructions against payment settled by a CSD in a Union currency compared to the total value of settlement instructions against payment settled in that currency across all CSDs in the Union.

(5) In order to allow competent authorities to perform a thorough assessment, a CSD applying for authorisation should provide information on the structure of its internal controls and the independence of its governing bodies to enable the competent authority to assess whether the corporate governance structure ensures the independence of the CSD and whether that structure and its reporting lines, as well as the mechanisms adopted for managing possible conflicts of interest are adequate.

(6) To enable the competent authority to assess the good reputation and the experience and skills of the CSD's senior management and members of the management body, an applicant CSD should provide all relevant information to perform that assessment.

(7) Information on a CSD's branches and subsidiaries is necessary to enable the competent authority to clearly understand the CSD's organisational structure and evaluate any potential risk to the CSD due to the activity of those branches and subsidiaries.

(8) A CSD applying for authorisation should provide the competent authority with the relevant information to demonstrate that it has the necessary financial resources at its disposal and adequate business continuity arrangements for the performance of its functions on an ongoing basis.

(9) In addition to receiving information on the core activities, it is important for the competent authority to receive information on the ancillary services that the CSD applying for authorisation intends to offer to enable the competent authority to have a complete overview of the applicant CSD's services.

(10) In order for the competent authority to assess the continuity and orderly functioning of technological systems of an applicant CSD, that CSD should provide the competent authority with descriptions of the relevant technological systems and how they are managed, including if they are outsourced.

(11) Information concerning the fees associated with the core services provided by CSDs is important and should form part of the application for authorisation of a CSD in order to enable the competent authorities to verify whether those fees are proportionate, non-discriminatory and not bundled with the costs of other services.

(12) In order to ensure that the investors' rights are protected, and that conflict of laws issues are adequately managed, when assessing the measures that a CSD intends to take to allow its users to comply with the national laws referred to in Article 49(1) of Regulation (EU) No 909/2014, the CSD should take into account both issuers and participants, as appropriate, in accordance with the respective national laws.

(13) In order to secure fair and non-discriminatory access to the notary, central maintenance and securities settlement services within the financial market, issuers, other CSDs and other market infrastructures have been granted access to a CSD in accordance with Regulation (EU) No 909/2014. An applicant CSD should, therefore, provide the competent authority with information about its access policies and procedures.

(14) In order to carry out its authorisation duties effectively, the competent authority should receive all information from CSDs applying for authorisation and related third parties, including third parties to whom applicant CSDs have outsourced operational functions and activities.

(15) To ensure general transparency of governance rules of a CSD applying for authorisation, the competent authority should be provided with documents confirming that the applicant CSD has adopted the necessary arrangements for a non-discriminatory establishment of an independent user committee for each securities settlement system that it operates.

(16) To secure the orderly functioning of core infrastructure services within the financial market, a CSD applying for authorisation should provide the competent authority with all necessary information to demonstrate that it has adequate policies and procedures for ensuring reliable record-keeping systems as well as effective mechanisms for CSD services, including in particular the measures for preventing and addressing settlements fails, and the rules concerning the integrity of the issue, the protection of securities of participants and those of their clients, settlement finality, participant default and transfer of participants and clients' assets in case of a withdrawal of authorisation.

(17) The risk-management models associated with the services provided by an applicant CSD are a necessary item in its application for authorisation so as to enable the competent authority to evaluate the reliability and integrity of the adopted procedures and help market participants make an informed choice.

(18) In order to verify the safety of the link arrangements of the CSD applying for authorisation, to assess the rules applied in the linked systems and evaluate the risks stemming from those links, the competent authority should receive from an applicant CSD any relevant information for the analysis, together with the CSD assessment of the link arrangements.

(19) When granting the approval of a CSD's participation in the capital of another entity, the competent authority of the CSD should take into consideration the criteria that ensure that the participation does not increase significantly the CSD's risk profile. In order to ensure its safety and continuity of its services, a CSD should not assume unlimited financial liabilities as a result of its participation in the capital of legal persons other than those providing the services set out in Regulation (EU) No 909/2014. A CSD should fully capitalise the risks resulting from any participation in the capital of another entity.

(20) In order for a CSD not to be dependent on other shareholders of the entities in which it holds a participation, including with regard to the risk-management policies, it should have full control of those entities. This requirement should also facilitate the exercise of supervisory and oversight functions by competent authorities and relevant authorities by allowing easy access to relevant information.

(21) A CSD should have a clear strategic rationale for the participation beyond mere profit making, taking into account the interests of the issuers of securities issued with the CSD; its participants and its clients.

(22) In order to properly quantify and outline the risks stemming from its participation in the capital of another legal person, a CSD should provide independent risk analyses, approved by an internal or external auditor, for the financial risks and liabilities of the CSD resulting from that participation.

(23) Following the experience of the financial crisis, authorities should focus on ongoing rather than ex post supervision. It is, therefore, necessary to ensure that for each review and evaluation under Regulation (EU) No 909/2014, the competent authority has sufficient access to information on a continuous basis. In order to determine the scope of information to be delivered for each review and evaluation, the provisions of this Regulation should follow the requirements for authorisation with which a CSD has to comply under Regulation (EU) No 909/2014. This includes substantive changes to elements already submitted during the process of authorisation, information relating to periodic events and statistical data.

(24) To promote an effective bilateral and multilateral exchange of information between competent authorities, the results of the review and evaluation by one authority of the activities of a CSD should be shared with other competent authorities where this information is likely to facilitate their tasks, without prejudice to confidentiality and data protection requirements and in addition to any cooperation arrangements provided in Regulation (EU) No 909/2014. An additional exchange of information among competent authorities and relevant authorities or authorities in charge of markets in financial instruments should be organised allowing for a sharing of the findings of the competent authority in the course of the process of review and evaluation.

(25) Taking into account the possible burden of gathering and processing a vast amount of information related to the operation of a CSD, and in order to avoid duplications, only relevant modified documents should be provided in the context of the review and evaluation. Those documents should be delivered in a manner that enables the competent authority to identify all the relevant changes made to the arrangements, strategies, processes and mechanisms implemented by the CSD since authorisation or since the completion of the last review and evaluation.

(26) Another category of information that is useful for the competent authority to have in order to be able to perform the review and evaluation refers to events that by nature occur on a periodic basis and which are related to the operation of the CSD and the provision of its services.

(27) To carry out a comprehensive risk evaluation of a CSD, the competent authority will need to request statistical data on the scope of the CSD's business activities in order to evaluate the risks related to CSDs operation and to the smooth operation of securities markets. In addition, statistical data enable the competent authority to monitor the size and importance of securities transactions and settlements within the financial markets as well as to assess the ongoing and potential impact of a given CSD on the securities market as a whole.

(28) For the competent authority to monitor and evaluate the risks to which the CSD is or may be exposed to and which may arise for the smooth functioning of securities markets, it should be able to request additional information on the risks and activities of a CSD. The competent authority should therefore be able to define and request on its own initiative, or following a request submitted to it by another authority, any additional information which it considers necessary for each review and evaluation of the activities of a CSD.

(29) It is important to ensure that third-country CSDs that intend to provide the services pursuant to Regulation (EU) No 909/2014 do not disrupt the orderly functioning of Union markets.

(30) The ongoing assessment of the full compliance of a third-country CSD with the prudential requirements of a third country is the duty of the third country competent authority. The information to be provided to the European Securities and Markets Authority (ESMA) by an applicant CSD should not have the objective of replicating the assessment of the third country competent authority, but ensuring that the applicant is subject to effective supervision and enforcement in that third country, thus guaranteeing a high degree of investor protection.

(31) To allow ESMA to perform a complete assessment of the application for recognition, the information provided by the applicant should be complemented by the necessary information to assess the effectiveness of the ongoing supervision, enforcement powers and actions taken by the third country competent authority. That information should be provided under a cooperation arrangement established in accordance with Regulation (EU) No 909/2014. The cooperation arrangement should ensure that ESMA is informed in a timely manner of any supervisory or enforcement action against the third-country CSD applying for recognition and any change of the conditions under which authorisation was granted to the relevant CSD and on any relevant update of the information originally provided by the CSD under the recognition process.

(32) In order to ensure that investors' rights are protected, and that conflict of laws issues are adequately managed, when assessing the measures that a third-country CSD intends to take to allow its users to comply with the national laws referred to in Article 49(1) of Regulation (EU) No 909/2014, that third-country CSD should take into account both issuers and participants, as appropriate, in accordance with the respective national laws referred to in Article 49(1) of that Regulation.

(33) To establish a sound risk-management framework, a CSD should take an integrated and comprehensive view of all relevant risks. This should include the risks that the CSD bears from any other entities and the risks that it poses to third parties, including its users and to the extent practicable their clients, as well as linked CSDs, central counterparties, trading venues, payment systems, settlement banks, liquidity providers and investors.

(34) To ensure that CSDs operate with the necessary level of human resources to meet all of their obligations and to ensure that competent authorities have the relevant contact points within the CSDs that they supervise, CSDs should have key dedicated staff that should be accountable for the CSD and their own individual performance, particularly at the level of senior management and management body.

(35) To ensure an adequate control of the activities performed by CSDs, independent audits covering the operations of the CSD, risk-management processes, compliance and internal control mechanisms should be put in place and performed regularly. The independence of audits should not necessarily require the involvement of an external auditor, provided that the CSD demonstrates to the competent authority that the independence of its internal auditor is properly ensured. In order to ensure the independence of its internal audit function, the CSD should also establish an audit committee.

(36) A CSD should set up a risk committee in order to ensure that the management body of the CSD is advised at the highest technical level on its overall current and future risk tolerance and strategy. To ensure its independence from the CSD's executive management and a high degree of competence, the risk committee should be composed of a majority of non-executive members and it should be chaired by a person with an appropriate experience on risk management.

(37) When assessing potential conflicts of interest, a CSD should not only examine the members of the management body, senior management or staff of the CSD but also any person directly or indirectly linked to those individuals or to the CSD, whether it is a natural or legal person.

(38) A CSD should have a chief risk officer, a chief compliance officer, a chief technology officer, as well as a risk-management function, a technology function, a compliance and internal control function, and internal audit function. A CSD should in any case be able to organise the internal structure of those functions according to its needs. Different persons should fulfil the roles of chief risk officer, chief compliance officer and chief technology officer given that those functions are usually fulfilled by persons with different academic and professional profiles. In this respect, the provisions set out in this Regulation closely follow the system established by Regulation (EU) No 648/2012 of the European Parliament and the Council (2) for other market infrastructures.

(39) Records kept by a CSD should be structured and allow for easy access to the data stored by the competent authorities involved in the supervision of CSDs. A CSD should ensure that the data records it keeps, including the complete accounting of the securities it maintains, are accurate and up-to-date in order to serve as a reliable data source for supervision purposes.

(40) To facilitate the reporting and recording of a consistent set of information under different requirements, records kept by CSDs should cover each individual service provided by the CSD in accordance with Regulation (EU) No 909/2014, and should include at least all the details to be reported under the rules on settlement discipline provided in that Regulation.

(41) The preservation of the rights of issuers and investors is essential for the orderly functioning of a securities market. A CSD should therefore employ appropriate rules, procedures and controls to prevent the unauthorised creation or deletion of securities. It should also conduct at least daily reconciliation of the securities accounts that it maintains.

(42) A CSD should maintain robust accounting practices and perform audits to verify that its records of securities are accurate and that its measures ensuring the integrity of securities issues are adequate.

(43) In order to effectively ensure the integrity of the issue, the reconciliation measures provided in Regulation (EU) No 909/2014 should apply to all CSDs regardless of whether or not they provide the notary service or central maintenance service referred to in that Regulation in relation to a securities issue.

(44) With regard to other entities involved in the reconciliation process, several scenarios should be distinguished depending on the role of those entities. The reconciliation measures should reflect the specific roles of those entities. According to the registrar model, the registrar maintains records of securities which are also recorded in a CSD. According to the transfer agent model, the fund manager or transfer agent is responsible for an account that maintains a part of a securities issue recorded in a CSD. According to the common depository model, the common depository is used by CSDs that establish an interoperable link and the common depository should be responsible for the overall integrity of the securities issues initially recorded or centrally maintained by the CSDs that have established an interoperable link.

(45) In order to mitigate operational risks, which comprise the risks caused by deficiencies in information systems, internal processes, and personnel performance or disruptions caused by external events which result in the reduction, deterioration or breakdown of services provided by a CSD, CSDs should identify all risks and monitor their evolution, irrespective of their origin that may include, for instance, their users, providers of services to CSDs and other market infrastructures, including other CSDs. Operational risks should be managed in accordance to a well-documented and robust framework with clearly assigned roles and responsibilities. That framework should include operational targets, tracing features, assessment mechanisms and it should be integrated in the risk-management system of the CSD. In this context, a CSD chief risk officer should be responsible for the operational risk-management framework. CSDs should manage their risk internally. Where internal controls are insufficient or where eliminating certain risks is not a reasonably feasible option, a CSD should be able to take a financial coverage of those risks through insurance.

(46) CSDs should not enter into investments that may affect their risk profile. CSDs should only enter into derivatives contracts if they are required to hedge a risk that they cannot reduce otherwise. The hedging should be subject to certain strict conditions that ensure that the derivatives are not used for purposes other than for covering risks and are not used for a realisation of profits.

(47) The assets of CSDs should be held safely, be easily accessible and able to be liquidated promptly. A CSD should therefore ensure that its policies and procedures concerning prompt access to its own assets are based at least on the nature, size, quality, maturity and location of the assets. A CSD should also ensure that prompt access to its assets is not negatively affected by the outsourcing of custody or investment functions to a third party entity.

(48) To manage its liquidity needs, a CSD should be able to access its cash assets immediately and also be able to access any securities that it holds under its own name on the same business day when a decision to liquidate the assets is taken.

(49) To ensure a greater degree of protection of the assets of a CSD from the default of the intermediary, a CSD that accesses another CSD through a CSD link should maintain those assets in a segregated account at the linked CSD. This level of segregation should ensure that the assets of a CSD are segregated from those of other entities and protected appropriately. It is however necessary to allow the establishment of links with third-country CSDs even where individually segregated accounts are not available at the third-country CSD provided that assets of the requesting CSD are in any case adequately protected and competent authorities are informed of the risks resulting from the unavailability of individually segregated accounts and the adequate mitigation of such risks.

(50) In order to ensure that a CSD invests its financial resources in highly liquid instruments with minimal market and credit risks and for these investments to be liquidated rapidly with minimal price effect, it should diversify its portfolio and establish appropriate concentration limits with respect to the issuers of the instruments in which it invests its resources.

(51) In order to ensure the safety and efficiency of the link arrangement of a CSD with another CSD, a CSD should identify, monitor, and manage all potential sources of risk arising from the link arrangement. A CSD link should have a well-founded legal basis, in all relevant jurisdictions, that supports its design and provides adequate protection to the CSDs involved in the link. Linked CSDs should measure, monitor, and manage the credit and liquidity risks arising from each other.

(52) A requesting CSD that uses an indirect CSD link or an intermediary to operate a CSD link with a receiving CSD should measure, monitor, and manage the additional risks, including custody, credit, legal, and operational risks, arising from the use of the intermediary in order to ensure the safety and the efficiency of the link arrangement.

(53) In order to ensure the integrity of the issue, where securities are maintained in several CSDs through CSD links, CSDs should apply specific reconciliation measures and coordinate their actions.

(54) CSDs should provide fair and open access to their services with due regard to the risks to financial stability and the orderliness of the market. They should control the risks arising from their participants and other users by setting risk-related criteria for the provision of their services. CSDs should ensure that their users, such as participants, any other CSDs, central counterparties (CCPs), trading venues or issuers that are granted access to their services meet the criteria and have the required operational capacity, financial resources, legal powers, and risk-management expertise in order to prevent the occurrence of risks for CSDs and other users.

(55) In order to ensure the safety and efficiency of its securities settlement system, a CSD should monitor compliance with its access requirements on an ongoing basis and have clearly defined and publicly disclosed procedures for facilitating the suspension and orderly exit of a requesting party that breaches, or no longer meets, the access requirements.

(56) For the purpose of the authorisation to provide banking-type ancillary services, a CSD should submit an application to the competent authority including all necessary elements to ensure that the provision of the banking-type ancillary services do not affect the smooth provision of core services of a CSD. Entities already authorised as CSDs should not be required to submit again any elements that were already submitted in the course of the process of application for being authorised as a CSD under Regulation (EU) No 909/2014.

(57) With a view to ensuring legal certainty and a consistent application of the law, certain requirements provided for in this Regulation concerning settlement discipline measures should start to apply from the date of entry into force of those measures.

(58) This Regulation is based on the draft regulatory technical standards submitted by ESMA to the Commission.

(59) In drawing up the technical standards contained in this Regulation, ESMA has worked in close cooperation with the members of the European System of Central Banks and the European Banking Authority.

(60) ESMA has conducted open public consultations on the draft regulatory technical standards on which this Regulation is based, analysed the potential related costs and benefits and requested the opinion of the Securities and Markets Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1095/2010 of the European Parliament and of the Council (3),

HAS ADOPTED THIS REGULATION:

CHAPTER I

GENERAL PROVISIONS

Article 1
Definitions

For the purposes of this Regulation, the following definitions apply:

(a) ‘review period’ means the period under review beginning on the day following the end of the previous review and evaluation period;

(b) ‘settlement instruction’ means a transfer order as defined in point (i) of Article 2 of Directive 98/26/EC of the European Parliament and of the Council (4);

(c) ‘settlement restriction’ means the blocking, reservation or earmarking of securities that make them unavailable for settlement, or the blocking or reservation of cash that make it unavailable for settlement;

(d) ‘exchange-traded fund’ (ETF) means a fund as defined in point (46) of Article 4(1) of Directive 2014/65/EU of the European Parliament and of the Council (5);

(e) ‘issuer CSD’ means a CSD which provides the core service referred to in point 1 or 2 of Section A of the Annex to Regulation (EU) No 909/2014 in relation to a securities issue;

(f) ‘investor CSD’ means a CSD that either is a participant in the securities settlement system operated by another CSD or that uses a third party or an intermediary that is a participant in the securities settlement system operated by another CSD in relation to a securities issue;

(g) ‘durable medium’ means any instrument which enables the storage of information in a way that is accessible for future reference for a period of time adequate for the purposes of the information, and allows the unchanged reproduction of the information stored.

CHAPTER II

DETERMINATION OF THE MOST RELEVANT CURRENCIES AND PRACTICAL ARRANGEMENTS FOR THE CONSULTATION OF THE RELEVANT COMPETENT AUTHORITIES

(Article 12(1)(b) and (c) of Regulation (EU) No 909/2014)

Article 2
Determination of most relevant currencies
1.

The most relevant currencies referred to in point (b) of Article 12(1) of Regulation (EU) No 909/2014 shall be identified according to either of the following calculations:

(a) the relative share of each Union currency in the total value of the settlement by a CSD of settlement instructions against payment, calculated over a period of one year, provided that each individual share exceeds 1 %;

(b) the relative share of settlement instructions against payment settled by a CSD in a Union currency compared to the total value of settlement instructions against payment settled in that currency across all CSDs in the Union, calculated over a period of one year, provided that each individual share exceeds 10 %.

2.

The calculations referred to in paragraph 1 shall be done on an annual basis by the competent authority of each CSD.

Article 3
Practical arrangements for the consultation of the relevant authorities referred to in Article 12(1)(b) and (c) of Regulation (EU) No 909/2014
1.

Where one of the most relevant currencies determined in accordance with Article 2 of this Regulation is issued by more than one central bank, those central banks shall determine a single representative as the relevant authority for that currency referred to in point (b) of Article 12(1) of Regulation (EU) No 909/2014.

2.

Where the cash leg of securities transactions is settled in accordance with Article 40(1) of Regulation (EU) No 909/2014 through accounts opened with several central banks that issue the same currency, those central banks shall determine a single representative as a relevant authority referred to in point (c) of Article 12(1) of that Regulation.

CHAPTER III

AUTHORISATION OF CSDs

(Article 17 of Regulation (EU) No 909/2014)

SECTION 1

General information on applicant CSDs

Article 4
1.

An application for authorisation shall clearly identify the applicant CSD and the activities and services that it intends to carry out.

2.

The application for authorisation shall include the following information:

(a) contact details of the person responsible for the application;

(b) contact details of the person or persons in charge of the applicant CSD's compliance and internal control function;

(c) the corporate name of the applicant CSD, its Legal Entity Identifier (LEI) and registered address in the Union;

(d) the memorandum and articles of association or other constitutional and statutory documentation of the applicant CSD;

(e) an excerpt from the relevant commercial or court register, or other forms of certified evidence of the registered address and business activity of the applicant CSD that is valid at the date of the application;

(f) the identification of the securities settlement systems that the applicant CSD operates or intends to operate;

(g) a copy of the decision of the management body regarding the application and the minutes of the meeting in which the management body approved the application file and its submission;

(h) a chart showing the ownership links between the parent undertaking, subsidiaries and any other associated entities or branches, wherein the entities shown in the chart are identified by their full corporate name, legal status, registered address, and tax numbers or company registration numbers;

(i) a description of the business activities of the applicant CSD's subsidiaries and other legal persons in which the applicant CSD holds a participation, including information on the level of participation;

(l) a list of core services listed in Section A of the Annex to Regulation (EU) No 909/2014 that the applicant CSD is providing or intends to provide;

(m) a list of ancillary services explicitly specified in Section B of the Annex to Regulation (EU) No 909/2014 that the applicant CSD is providing or intends to provide;

(n) a list of any other ancillary services permitted under, but not explicitly specified under Section B of the Annex to Regulation (EU) No 909/2014 that the applicant CSD is providing or intends to provide;

(o) a list of the investment services subject to Directive 2014/65/EU referred to in point (n);

(p) a list of services and activities that the applicant CSD outsources or intends to outsource to a third party in accordance with Article 30 of Regulation (EU) No 909/2014;

(q) the currency or currencies that the applicant CSD processes, or intends to process in connection with services that the applicant CSD provides, irrespective of whether cash is settled on a central bank account, a CSD account, or an account at a designated credit institution;

(r) information on any pending and final judicial, administrative, arbitration or any other legal proceedings to which the applicant CSD is a party and which may cause it financial or other costs.

3.

Where the applicant CSD intends to provide core services or to set up a branch in accordance with Article 23(2) of Regulation (EU) No 909/2014, the application for authorisation shall also include the following information:

(a) the Member State or Member States in which the applicant CSD intends to operate;

(b) a programme of operations stating in particular the services which the applicant CSD provides or intends to provide in the host Member State;

(c) the currency or currencies that the applicant CSD processes or intends to process in the host Member State;

(d) where the services are provided or intended to be provided through a branch, the organisational structure of the branch and the names of the persons responsible for its management;

(e) where relevant, an assessment of the measures that the applicant CSD intends to take to allow its users to comply with the national laws referred to in Article 49(1) of Regulation (EU) No 909/2014.

Article 5
General information concerning policies and procedures
1.

An application for authorisation shall specify the following information on the policies and procedures of the applicant CSD referred to in this Chapter:

(a) the job titles of the persons responsible for the approval and implementation of the policies and procedures;

(b) a description of the measures implementing and monitoring the compliance with the policies and procedures.

2.

An application for authorisation shall include a description of the procedures put in place by the applicant CSD pursuant to Article 65(3) of Regulation (EU) No 909/2014.

Article 6
Information concerning services and activities of the CSD

The applicant CSD shall include the following in the application for authorisation:

(a) a detailed description of the services referred to in points (l) to (p) of Article 4(2);

(b) the procedures to be applied in the provision of the services referred to in point (a).

Article 7
Information concerning groups
1.

Where the applicant CSD is part of a group of undertakings that includes other CSDs or credit institutions referred to in point (b) of Article 54(2) of Regulation (EU) No 909/2014, the application for authorisation shall include the following:

(a) the policies and procedures referred to in Article 26(7) of Regulation (EU) No 909/2014;

(b) information on the composition of the senior management, the management body, and the shareholders structure of the parent undertaking and of the other undertakings in the group;

(c) the services and key individuals other than senior management that the applicant CSD shares with other undertakings in the group.

2.

Where the applicant CSD has a parent undertaking, the application for authorisation shall provide the following information:

(a) the registered address of the parent undertaking of the applicant CSD;

(b) where the parent undertaking is an entity authorised or registered and subject to supervision under Union or third country legislation, any relevant authorisation or registration number and the name of the authority or authorities competent for the supervision of the parent undertaking.

3.

Where the applicant CSD has outsourced services or activities to an undertaking within the group in accordance with Article 30 of Regulation (EU) No 909/2014, the application shall include a summary and a copy of the outsourcing agreement.

SECTION 2

Financial resources for the provision of services by the applicant CSD

Article 8
Financial reports, business plan, and recovery plan
1.

An application for authorisation shall include the following financial and business information to enable the competent authority to assess compliance of the applicant CSD with Articles 44, 46 and 47 of Regulation (EU) No 909/2014:

(a) financial reports including a complete set of financial statements for the preceding three years, and the statutory audit report on the annual and consolidated financial statements within the meaning of Directive 2006/43/EC of the European Parliament and of the Council (6), for the preceding three years;

(b) where the applicant CSD is audited by an external auditor, the name and the national registration number of the external auditor;

(c) a business plan, including a financial plan and an estimated budget that foresees various business scenarios for the services provided by the applicant CSD, over a reference period of at least three years;

(d) any plan for the establishment of subsidiaries and branches and their location;

(e) a description of the business activities that the applicant CSD plans to carry out, including the business activities of any subsidiaries or branches of the applicant CSD.

2.

Where historical financial information referred to in point (a) of paragraph 1 is not available, an application for authorisation shall include the following information about the applicant CSD:

(a) evidence that demonstrates sufficient financial resources during six months after the granting of an authorisation;

(b) an interim financial report;

(c) statements concerning the financial situation of the applicant CSD, including a balance sheet, income statement, changes in equity and in cash flows and a summary of accounting policies and other relevant explanatory notes;

(d) audited annual financial statements of any parent undertaking for the three financial years preceding the date of the application.

3.

The application shall include a description of an adequate recovery plan to ensure continuity of the applicant CSD's critical operations referred to in Article 22(2) of Regulation (EU) No 909/2014 including:

(a) a summary that provides an overview of the plan and its implementation;

(b) the identification of the critical operations of the applicant CSD, stress scenarios and events triggering recovery, and a description of recovery tools to be used by the applicant CSD;

(c) an assessment of any impact of the recovery plan on stakeholders that are likely to be affected by its implementation;

(d) an assessment of the legal enforceability of the recovery plan that takes account of any legal constraints imposed by Union, national or third country legislation.

SECTION 3

Organisational requirements

Article 9
Organisational chart

An application for authorisation shall include an organisational chart that describes the organisational structure of the applicant CSD. The chart shall include the following:

(b) the number of staff members in each division and operational unit.

Article 10
Staffing policies and procedures

An application for authorisation shall include the following information on the applicant CSD's policies and procedures related to staff:

(a) a description of the remuneration policy including information about the fixed and variable elements of the remuneration of the senior management, the members of the management body and the staff employed in the risk-management, compliance and internal control, internal audit and technology functions of the applicant CSD;

(b) the measures put in place by the applicant CSD to mitigate the risk of over-reliance on the responsibilities entrusted to any individual person.

Article 11
Risk monitoring tools and governance arrangements
1.

An application for authorisation shall include the following information on the governance arrangements and risk monitoring tools of the applicant CSD:

(a) a description of the governance arrangements of the applicant CSD established in accordance with paragraph 2 of Article 47;

(b) the policies, procedures and systems established in accordance with paragraph 1 of Article 47;

(c) a description of the composition, role and responsibilities of the members of the management body and senior management and the committees established in accordance with Article 48.

2.

The information referred to in paragraph 1 shall include a description of the processes concerning the selection, appointment, performance evaluation and removal of senior management and members of the management body.

3.

The applicant CSD shall describe its procedure to make its governance arrangements and the rules governing its activity available to the public.

4.

Where the applicant CSD adheres to a recognised corporate governance code of conduct, the application shall identify any code, include a copy of that code and justify any situations where the applicant CSD deviates from the code.

Article 12
Compliance, internal control and internal audit functions
1.

An application for authorisation shall include a description of the procedures for the applicant CSD's internal reporting of infringements referred to in Article 26(5) of Regulation (EU) No 909/2014.

2.

An application for authorisation shall include information regarding an applicant CSD's internal audit policies and procedures referred to in Article 51, including:

(a) a description of the monitoring and evaluation tools for the adequacy and effectiveness of the applicant CSD's internal audit systems;

(b) a description of the control and safeguard tools for the applicant CSD's information processing systems;

(c) a description of the development and application of the applicant CSD's internal audit methodology;

(d) a work plan of the internal audit function for three years following the date of application;

(e) a description of the roles and qualifications of each individual who is responsible for internal audit referred to in Article 47(3)(d) under the oversight of the audit committee referred to in Article 48(1)(b).

3.

An application for authorisation shall include the following information concerning the compliance and internal control function of the applicant CSD's referred to in Article 47(3)(c):

(a) a description of the roles and qualifications of individuals who are responsible for the compliance and internal control function and of any other staff involved in the assessments of compliance, including a description of the means to ensure the independence of the compliance and internal control function from the rest of the business units;

(b) the policies and procedures of the compliance and internal control function, including a description of the compliance role of the management body and senior management;

(c) where available, the most recent internal report prepared by the persons responsible for the compliance and internal control function or by any other staff involved in the assessments of compliance within the applicant CSD.

Article 13
Senior management, management body and shareholders
1.

An application for authorisation shall include, for each member of the senior management and each member of the management body of the applicant CSD, the following information to enable the competent authority to assess compliance of the applicant CSD with Article 27(1) and (4) of Regulation (EU) No 909/2014:

(a) a copy of a curriculum vitae which sets out the experience and knowledge of each member;

(b) details regarding any criminal and administrative sanctions imposed on a member in connection with the provision of financial or data services or in relation to acts of fraud or misappropriation of funds, in the form of an appropriate official certificate where available in the relevant Member State;

For the purposes of point (c)(i) of this paragraph, the self-declaration shall not be required where an official certificate is submitted under point (b) of this paragraph.

2.

The application for authorisation shall include the following information regarding the management body of the applicant CSD:

(a) evidence of compliance with Article 27(2) of Regulation (EU) No 909/2014;

(b) a description of the roles and responsibilities of the members of the management body;

(c) the target for the representation of the underrepresented gender in the management body, the relevant policy on how to meet that target and the method used by the applicant CSD to make public the target, policy and its implementation.

3.

The application for authorisation shall include the following information concerning the ownership structure and shareholders of the applicant CSD:

(a) a description of the ownership structure of the applicant CSD referred to in point (i) of Article 4(2), including a description of the identity and size of interests of any entity in a position to exercise control over the operation of the applicant CSD;

(b) a list of the shareholders and persons who are in a position to exercise, directly or indirectly, control over the management of the applicant CSD.

Article 14
Management of conflicts of interest
1.

An application for authorisation shall include the following information on the policies and procedures put in place to identify and manage potential conflicts of interest by the applicant CSD in accordance with Article 50:

(a) a description of the policies and procedures concerning the identification, management and disclosure to the competent authority of potential conflicts of interest and of the process used to ensure that the staff of the applicant CSD is informed of those policies and procedures;

(b) a description of the controls and measures put in place to ensure that the requirements referred to in point (a) on the management of conflicts of interest are met;

2.

Where the applicant CSD is part of a group, the register referred to in point (c)(iii) of paragraph 1 shall include a description of the conflicts of interest arising from other undertakings within the group in relation to any service provided by the applicant CSD, and the arrangements put in place to manage those conflicts of interest.

Article 15
Confidentiality
1.

An application for authorisation shall include the applicant CSD's policies and procedures put in place for preventing the unauthorised use or disclosure of confidential information. Confidential information shall include the following information:

(a) information relating to participants, clients, issuers or other users of the applicant CSD services;

(b) other information held by the applicant CSD as a result of its business activity not permitted to be used for commercial purposes.

2.

An application for authorisation shall include the following information concerning the access of staff to information held by the applicant CSD:

(a) the internal procedures concerning permissions of access to information that ensure secured access to data;

(b) a description of any restrictions on the use of data for reasons of confidentiality.

Article 16
User committee

An application for authorisation shall include the following information on each user committee:

(a) the mandate of the user committee;

(b) the governance arrangements of the user committee;

(c) the operating procedures of the user committee;

(d) the admission criteria and the election mechanism for the members of the user committee;

(e) a list of the proposed members of the user committee and the indication of interests that they represent.

Article 17
Record-keeping
1.

An application for authorisation shall include a description of the record-keeping systems, policies and procedures of the applicant CSD, established and maintained in accordance with Chapter VIII of this Regulation.

2.

Where an applicant CSD applies for authorisation before the date of application of Article 54, the application for authorisation shall contain the following information:

(a) an analysis of the extent to which the applicant CSD's existing record-keeping systems, policies and procedures are compliant with the requirements under Article 54;

(b) an implementation plan detailing how the applicant CSD will comply with the requirements referred to in Article 54 by the date on which it becomes applicable.

SECTION 4

Conduct of business rules

Article 18
Goals and objectives

An application for authorisation shall include a description of the goals and objectives of the applicant CSD referred to in Article 32(1) of Regulation (EU) No 909/2014.

Article 19
Handling of complaints

An application for authorisation shall include the procedures the applicant CSD has established for the handling of complaints.

Article 20
Requirements for participation

An application for authorisation shall include all necessary information concerning the participation in the securities settlement systems operated by the applicant CSD in accordance with Article 33 of Regulation (EU) No 909/2014 and Articles 88-90 of this Regulation. That information shall include the following:

(a) the criteria for participation that allow fair and open access for all legal persons that intend to become participants in the securities settlement systems operated by the applicant CSD;

(b) the procedures for the application of disciplinary measures against existing participants that do not comply with the criteria for participation.

Article 21
Transparency
1.

An application for authorisation shall include the documents and information on the pricing policy of the applicant CSD concerning services referred to in Article 34 of Regulation (EU) No 909/2014. That information shall include in particular the prices and fees for each core service provided by the applicant CSD and any existing discounts and rebates, as well as the conditions for the reductions.

2.

The applicant CSD shall provide the competent authority with a description of methods used to disclose the relevant information in accordance with paragraphs (1), (2), (4) and (5) of Article 34 of Regulation (EU) No 909/2014.

3.

An application for authorisation shall include information allowing the competent authority to assess how the applicant CSD intends to comply with the requirements to account separately for costs and revenues in accordance with Article 34(6) and (7) of Regulation (EU) No 909/2014.

Article 22
Communication procedures with participants and other market infrastructures

An application for authorisation shall include the relevant information concerning the use by the applicant CSD of international open communication procedures and standards for messaging and reference data in its communication procedures with participants and other market infrastructures.

SECTION 5

Requirements for services provided by CSDs

Article 23
Book-entry form

An application for authorisation shall include information on the processes concerning book entries that ensure the compliance of the applicant CSD with Article 3 of Regulation (EU) No 909/2014.

Article 24
Intended settlement dates and measures for preventing and addressing settlement fails
1.

An application for authorisation shall include the following information in respect of the applicant CSD:

(a) the procedures and measures to prevent settlement fails in accordance with Article 6 of Regulation (EU) No 909/2014;

(b) the measures to address settlement fails in accordance with Articles 7 of Regulation (EU) No 909/2014.

2.

Where an applicant CSD applies for authorisation before Articles 6 and 7 of Regulation (EU) No 909/2014 are applicable in accordance with paragraphs (4) and (5) of Article 76 of that Regulation, the application for authorisation shall contain an implementation plan detailing how the applicant CSD will comply with the requirements under Articles 6 and 7 of Regulation (EU) No 909/2014.

Institutions referred to in Article 69(1) of Regulation (EU) No 909/2014 shall include in the implementation plan referred to in the first subparagraph an analysis of the extent to which their existing rules, procedures, mechanisms and measures comply with the requirements under Articles 6 and 7 of Regulation (EU) No 909/2014.

Article 25
Integrity of the issue

An application for authorisation shall include information concerning the applicant CSD's rules and procedures for ensuring the integrity of securities issues referred to in Article 37 of Regulation (EU) No 909/2014 and Chapter IX of this Regulation.

Article 26
Protection of participants' and their clients' securities

An application for authorisation shall include the following information concerning the measures put in place to protect the securities of the applicant CSD's participants and those of their clients in accordance with Article 38 of Regulation (EU) No 909/2014:

(a) the rules and procedures to reduce and manage the risks associated with the safekeeping of securities;

(b) a detailed description of the different levels of segregation offered by the applicant CSD, a description of the costs associated with each level, the commercial terms on which they are offered, their main legal implications and the applicable insolvency law;

(c) the rules and procedures for obtaining the consents referred to in Article 38(7) of Regulation (EU) No 909/2014.

Article 27
Settlement finality

An application for authorisation shall contain information concerning the rules on settlement finality put in place by the applicant CSD in accordance with Article 39 of Regulation (EU) No 909/2014.

Article 28
Cash settlement
1.

An application for authorisation shall include the procedures for the settlement of the cash payments for each securities settlement system that the applicant CSD operates in accordance with Article 40 of Regulation (EU) No 909/2014.

2.

The applicant CSD shall provide information about whether the settlement of the cash payments is provided in accordance with Article 40(1) or (2) of Regulation (EU) No 909/2014.

If the settlement of the cash payments is intended to take place in accordance with Article 40(2) of Regulation (EU) No 909/2014, the applicant CSD shall explain why settlement in accordance with Article 40(1) of Regulation (EU) No 909/2014 is not practical and available.

Article 29
Participant default rules and procedures

An application for authorisation shall include the rules and procedures put in place by the applicant CSD to manage the default of a participant.

Article 30
Transfer of participants and clients' assets in case of a withdrawal of authorisation

An application for authorisation shall include information concerning the procedures put in place by the applicant CSD to ensure the timely and orderly settlement and transfer of the assets of clients and participants to another CSD in the event of a withdrawal of its authorisation.

SECTION 6

Prudential requirements

Article 31
1.

An application for authorisation shall include all information necessary to enable the competent authority to assess that the rules, procedures, and contracts of the applicant CSD are clear, understandable and enforceable in all relevant jurisdictions in accordance with Article 43(1) and (2) of Regulation (EU) No 909/2014.

2.

Where the applicant CSD intends to conduct business in different jurisdictions, the applicant CSD shall provide the competent authority with information concerning the measures put in place to identify and mitigate the risks arising from potential conflicts of laws across jurisdictions in accordance with Article 43(3) of Regulation (EU) No 909/2014. That information shall include any legal assessment on which those measures are based.

Article 32
General business risks
1.

The applicant CSD shall provide the competent authority with a description of the risk-management and control systems as well as the IT tools put in place by the applicant CSD to manage business risks in accordance with Article 44 of Regulation (EU) No 909/2014.

2.

Where the applicant CSD has obtained a risk rating from a third party, it shall provide it to the competent authority including any relevant information supporting that risk rating.

Article 33
Operational risks
1.

An application for authorisation shall include information that demonstrates the applicant CSD is compliant with the requirements for the management of operational risks in accordance with Article 45 of Regulation (EU) No 909/2014 and Chapter X of this Regulation.

2.

An application for authorisation shall also contain the following information concerning the list of services referred to in point (p) of Article 4(2) of this Regulation:

(a) a copy of the outsourcing agreements;

(b) the methods used to monitor the service level of the outsourced services and activities.

Article 34
Investment policy

An application for authorisation shall include evidence demonstrating that:

(a) the applicant CSD holds its financial assets in accordance with Article 46(1), (2) and (5) of Regulation (EU) No 909/2014 and Chapter XI of this Regulation.

(b) the investments of the applicant CSD are compliant with Article 46(3) of Regulation (EU) No 909/2014 and Chapter XI of this Regulation.

Article 35
Capital requirements

An application for authorisation shall include the following information concerning the capital requirements:

(a) information demonstrating that the capital of the applicant CSD, including retained earnings and reserves of the applicant CSD, meets the requirements of Article 47 of Regulation (EU) No 909/2014;

(b) the plan referred to in Article 47(2) of Regulation (EU) No 909/2014 and any updates to that plan, and evidence of its approval by the management body or an appropriate committee of the management body of the applicant CSD.

SECTION 7

Article 36

Where the applicant CSD has established or intends to establish CSD links, the application for authorisation shall contain the following information:

(a) a description of the CSD links accompanied by assessments of potential sources of risks arising from those link arrangements by the applicant CSD;

(b) the expected or actual settlement volumes and values of the settlement performed within the CSD links;

(c) the procedures concerning the identification, assessment, monitoring and management of all potential sources of risk for the applicant CSD and for its participants arising from the link arrangement and the appropriate measures put in place to mitigate them;

(d) an assessment of the applicability of insolvency laws applicable to the operation of a CSD link and their implications for the applicant CSD;

(e) other relevant information requested by the competent authority for assessing the compliance of CSD links with the requirements provided in Article 48 of Regulation (EU) No 909/2014 and Chapter XII of this Regulation.

SECTION 8

Access to CSDs

Article 37
Access rules

An application for authorisation shall include a description of the procedures for dealing with the following requests for access:

(a) from legal persons intending to become participants in accordance with Article 33 of Regulation (EU) No 909/2014 and Chapter XIII of this Regulation;

(b) from issuers in accordance with Article 49 of Regulation (EU) No 909/2014 and Chapter XIII of this Regulation;

(c) from other CSDs in accordance with Article 52 of Regulation (EU) No 909/2014 and Chapter XIII of this Regulation;

(d) from other market infrastructures in accordance with Article 53 of Regulation (EU) No 909/2014 and Chapter XIII of this Regulation.

SECTION 9

Additional information

Article 38
Request for additional information

The competent authority may request from the applicant CSD any additional information necessary for assessing whether, at the time of granting the authorisation, the applicant CSD complies with the requirements of Regulation (EU) No 909/2014.

CHAPTER IV

PARTICIPATION OF CSDs IN CERTAIN ENTITIES

(Article 18(3) of Regulation (EU) No 909/2014)

Article 39
Criteria for participation of a CSD

In granting the approval for a CSD's participation in a legal person which does not provide the services set out in Sections A and B of the Annex to Regulation (EU) No 909/2014, the competent authority shall take into account the following criteria:

(a) the extent of the financial liabilities assumed by the CSD as a result of that participation;

(d) whether the participation of the CSD results in the control by the CSD over the legal person as defined in point (21) of Article 2(1) of Regulation (EU) No 909/2014;

CHAPTER V

REVIEW AND EVALUATION

(Article 22 of Regulation (EU) No 909/2014)

Article 40
Information to be provided to the competent authority
1.

For the purposes of this Chapter, a ‘review period’ as defined in point (a) of Article 1 shall include the period between the first authorisation granted to a CSD in accordance with Article 17(1) of Regulation (EU) No 909/2014 and the first review and evaluation referred to in Article 22(1) of that Regulation

2.

For the purposes of the review and evaluation referred to in Article 22(1) of Regulation (EU) No 909/2014, a CSD shall provide the following information to its competent authority:

(a) the information referred to in Articles 41 and 42;

(b) a report on the CSD's activities and the substantive changes referred to in Article 16(4) of Regulation (EU) No 909/2014 made during the review period and all related documents;

(c) any additional information requested by the competent authority that is necessary for assessing the compliance of the CSD and its activities with Regulation (EU) No 909/2014 during the review period.

3.

The report referred to under point (b) of paragraph 2 shall include a declaration by a CSD of an overall compliance with the provisions of Regulation (EU) No 909/2014 during the review period.

Article 41
Periodic information relevant for the reviews

For each review period, the CSD shall provide the competent authority with the following information:

(a) a complete set of the latest audited financial statements of the CSD, including those consolidated at group level;

(b) a summarised version of the most recent interim financial statements of the CSD;

(c) any decisions of the management body following the advice of the user committee, as well as any decisions where the management body has decided not to follow the advice of the user committee;

(d) information on any pending civil, administrative or any other judicial or extrajudicial proceedings involving the CSD, in particular in relation to matters concerning tax and insolvency, or matters that may cause financial or reputational costs for the CSD;

(e) information on any pending civil, administrative or any other judicial or extrajudicial, proceedings involving a member of the management body or a member of the senior management that may have an negative impact on the CSD;

(f) any final decisions resulting from the proceedings referred to in points (d) and (e);

(g) a copy of the results of business continuity stress tests or similar exercises performed during the review period;

(h) a report on the operational incidents that occurred during the review period and affected the smooth provision of any core services, the measures taken to address them and the results thereof;

(i) a report on the performance of the securities settlement system, including an assessment of the system's availability during the review period, measured on a daily basis as the percentage of time the system is operational and functioning according to the agreed parameters;

(j) a summary of the types of manual intervention performed by the CSD;

(k) information concerning the identification of the CSD's critical operations, any substantive changes to its recovery plan, the results of stress scenarios, the recovery triggers and the recovery tools of the CSD;

(m) information concerning the cases where the CSD denied access to its services to any existing or potential participant, any issuer, another CSD or another market infrastructure in accordance with Articles 33(3), 49(3), 52(2) and 53(3) of Regulation (EU) No 909/2014;

(n) a report on changes affecting any CSD links established by the CSD, including changes to the mechanisms and procedures used for the settlement in those CSD links;

(o) information concerning all cases of identified conflicts of interests that materialised during the review period, including the description of how they were managed;

(p) information concerning internal controls and audits performed by the CSD during the review period;

(q) information concerning any identified infringement of Regulation (EU) No 909/2014, including those identified through the reporting channel referred to in Article 26(5) of Regulation (EU) No 909/2014;

(r) detailed information concerning any disciplinary actions taken by the CSD, including any cases of suspension of participants in accordance with Article 7(9) of Regulation (EU) No 909/2014 with a specification of the period of suspension and the reason for suspension;

(s) the general business strategy of the CSD covering a period of at least three years after the last review and evaluation and a detailed business plan for the services provided by the CSD covering at least a period of one year after the last review and evaluation.

Article 42
Statistical data to be delivered for each review and evaluation
1.

For each review period, the CSD shall provide the competent authority with the following statistical data:

(a) a list of the participants of each securities settlement system operated by the CSD, specifying their country of incorporation;

(b) a list of issuers and a list of securities issues recorded in securities accounts centrally and not centrally maintained in each securities settlement system operated by the CSD, specifying the country of incorporation of the issuers and the identification of the issuers to whom the CSD provides the services referred to in points (1) and (2) of Section A of the Annex to Regulation (EU) No 909/2014;

(c) the total market value and nominal value of the securities recorded in securities accounts centrally and not centrally maintained in each securities settlement system operated by the CSD;

(e) the nominal and market value of the securities initially recorded in each securities settlement system operated by the CSD;

(g) the total number and the values of the settlement instructions against payment and the total number and the values of the free of payment (FOP) settlement instructions settled in each securities settlement system operated by the CSD;

(i) the number and value of buy-in transactions referred to in Article 7(3) of Regulation (EU) No 909/2014;

(j) the number and amount of penalties referred to in Article 7(2) of Regulation (EU) No 909/2014 per participant;

(k) the total value of securities borrowing and lending operations processed by the CSD acting as an agent or as principal for each type of financial instruments referred to in point (d)(i);

(l) the total value of settlement instructions settled via each CSD link, specifying whether the CSD is the requesting CSD or the receiving CSD;

(m) the value of guarantees and commitments received or provided by the CSD related to securities borrowing and lending operations;

(n) the value of treasury activities involving foreign exchange and transferable securities related to managing participants' long balances including categories of institutions whose long balances are managed by the CSD;

(o) the number of reconciliation processes revealing undue creations or deletions of securities as referred to in Article 65(2) where those processes concern securities issues recorded in securities accounts centrally and not centrally maintained by the CSD;

(p) the mean, median, and mode for the length of time taken to remedy the error identified according to Article 65(2).

The values referred to in points (g), (h) and (l) of subparagraph 1 shall be calculated as follows:

(a) in the case of settlement instructions against payment, the settlement amount of the cash leg;

(b) in the case of FOP settlement instructions, the market value of the financial instruments or, where not available, the nominal value of the financial instruments.

2.

The market value referred to in paragraph 1 shall be calculated on the last day of the review period as follows:

(a) for financial instruments referred to in Article 3(1) of Regulation (EU) No 600/2014 of the European Parliament and of the Council (7) admitted to trading on a trading venue within the Union, the market value shall be the closing price of the most relevant market in terms of liquidity referred to in Article 4(6)(b) of that Regulation;

(b) for financial instruments admitted to trading on a trading venue within the Union other than those referred to in point (a), the market value shall be the closing price derived from the trading venue within the Union with the highest turnover;

(c) for financial instruments other than those referred to in points (a) and (b) the market value shall be determined on the basis of a price calculated using a pre-determined methodology that refers to criteria related to market data, such as market prices available across trading venues or investment firms.

3.

The CSD shall provide the values referred to in paragraph 1 in the currency in which the securities are denominated, settled or in which credit is extended. The competent authority may request the CSD to provide these values in the currency of the home Member State of the CSD or in euro.

4.

For the purposes of statistical reporting by a CSD, the competent authority may determine algorithms or principles for data aggregation.

Article 43
Other information

Documents provided by the CSD to the competent authority pursuant to Article 41 shall indicate the following:

(a) whether a document is provided for the first time or is a document that has already been provided and has been updated during the review period;

(b) the unique reference number of the document assigned by the CSD;

(c) the title of the document;

(d) the chapter, section or page of the document where changes have been introduced during the review period and any additional explanation in relation to the changes introduced during the review period.

Article 44
Information to be supplied to the authorities referred to in Article 22(7) of Regulation (EU) No 909/2014

For each review period, the competent authority shall supply the following information to the authorities referred to in Article 22(7) of Regulation (EU) No 909/2014:

(a) a report on the evaluation by the competent authority of the risks to which the CSD is or might be exposed or which it creates for the smooth functioning of securities markets;

(b) any envisaged or final remedial actions or penalties against the CSD as a result of the review and evaluation.

Where applicable, the report referred to in point (a) shall include the results of the competent authority's analysis of how the CSD complies with the requirements referred to in Article 24(2), and the relevant documents and information referred to in Article 24(2) submitted by the CSD.

Article 45
Exchange of information between the competent authorities referred to in Article 22(8) of Regulation (EU) No 909/2014
1.

During the review and evaluation, the competent authority shall send to the competent authorities referred to in Article 22(8) of Regulation (EU) No 909/2014 any relevant information provided by the CSD in connection to staff, key individuals, functions, services or systems shared between that CSD and other CSDs with which it maintains the types of relations referred to in points (a), (b) and (c) of Article 17(6) of Regulation (EU) No 909/2014 within 10 working days from the receipt of that information.

2.

After performing the review and evaluation, the competent authority shall send the following information to the competent authorities referred to in Article 22(8) of Regulation (EU) No 909/2014:

(a) a report on the evaluation by the competent authority of the risks to which the CSD is or might be exposed or which it creates for the smooth functioning of securities markets;

(b) any envisaged or final remedial actions or penalties against the CSD as a result of the review and evaluation.

CHAPTER VI

RECOGNITION OF A THIRD-COUNTRY CSD

(Article 25(6) of Regulation (EU) No 909/2014)

Article 46
Content of the application
1.

An application for recognition shall include the information set out in Annex I.

2.

An application for recognition shall:

(a) be provided in a durable medium;

(b) be submitted in both paper form and electronic form, the latter using open source formats that may be read easily;

(c) be submitted in a language customary in the sphere of international finance, including translations therein where the original documents are not drawn up in a language customary in the sphere of international finance;

(d) be provided with a unique reference number for each document included.

3.

The applicant CSD shall provide evidence certifying the information included in Annex I.

CHAPTER VII

RISK MONITORING TOOLS

(Article 26(1) to (7) of Regulation (EU) No 909/2014)

Article 47
Risk monitoring tools of CSDs
1.

A CSD shall establish, as part of its governance arrangements, documented policies, procedures and systems that identify, measure, monitor, manage and enable reporting on the risks that the CSD may be exposed to and the risks that the CSD poses to any other entities including its participants and their clients, as well as linked CSDs, CCPs, trading venues, payment systems, settlement banks, liquidity providers and investors.

The CSD shall structure the policies, procedures and systems referred to in the first subparagraph so as to ensure that users and, where relevant, their clients properly manage and address the risks they pose to the CSD.

2.

For the purposes of paragraph 1, the governance arrangements of the CSD shall include the following:

(a) the composition, role, responsibilities, procedures for appointment, performance assessment and accountability of the management body and of its risk monitoring committees;

(b) the structure, role, responsibilities, procedures for appointment and performance assessment of the senior management;

(c) the reporting lines between the senior management and the management body;

The governance arrangements referred to in the first subparagraph shall be clearly specified and well documented.

3.

A CSD shall establish and specify the tasks of the following functions:

(a) a risk-management function;

(b) a technology function;

(c) a compliance and internal control function;

(d) an internal audit function.

Each function shall have a well-documented description of its tasks, the necessary authority, resources, expertise and access to all relevant information to carry out those tasks.

Each function shall operate independently from the other functions of the CSD.

Article 48
Risk monitoring committees
1.

A CSD shall establish the following committees:

(a) a risk committee responsible for advising the management body on the CSD's overall current and future risk tolerance and strategy;

(b) an audit committee responsible for advising the management body on the performance of the CSD's internal audit function, which it shall oversee;

(c) a remuneration committee responsible for advising the management body on the CSD's remuneration policy, which it shall oversee.

2.

Each committee shall be chaired by a person who has appropriate experience in the field of competence of that committee and is independent from the CSD's executive members of the management body.

The majority of members of each committee shall not be executive members of the management board.

The CSD shall establish a clear and publicly available mandate and procedures for each committee, and shall ensure their access to external expert advice where necessary.

Article 49
Responsibilities of key personnel in respect to the risks
1.

A CSD shall have adequate staff to meet its obligations. A CSD shall not share staff with other group entities, unless it does so under the terms of a written outsourcing arrangement in accordance with Article 30 of Regulation (EU) No 909/2014.

2.

The management body shall assume at least the following responsibilities:

(a) establish well-documented policies, procedures and processes by which the management body, senior management and committees shall operate;

(b) establish clear objectives and strategies for the CSD;

(c) effectively monitor senior management;

(d) establish adequate remuneration policies;

(e) ensure the surveillance of the risk-management function and take the decisions related to risk management;

(f) ensure the independence and adequate resources of the functions referred to in Article 47(3);

(g) monitor outsourcing arrangements;

(h) monitor and ensure compliance with all relevant regulatory and supervisory requirements;

(i) be accountable to shareholders or other owners, employees, users and other relevant stakeholders;

(j) approve internal audit planning and review;

(k) review and update regularly the governance arrangements of the CSD.

Where the management body or its members delegate tasks, they shall retain the responsibility for decisions that may affect the smooth provision of services by the CSD.

The CSD's management body shall hold the final responsibility for managing the CSD's risks. The management body shall define, determine and document an appropriate level of risk tolerance and risk bearing capacity for the CSD and for all the services that the CSD provides. The management body and senior management shall ensure that the CSD's policies, procedures and controls are consistent with the CSD's risk tolerance and risk bearing capacity and that these policies, procedures and controls address how the CSD identifies, reports, monitors and manages risks.

3.

The senior management shall have at least the following responsibilities:

(a) ensure consistency of the activities of the CSD with the objectives and strategy of the CSD as determined by the management body;

(b) design and establish risk-management, technology, compliance and internal control procedures that promote the objectives of the CSD;

(c) subject the risk-management, technology, compliance and internal control procedures to regular review and testing;

(d) ensure that sufficient resources are devoted to risk management, technology, compliance and internal control, and internal audit.

4.

A CSD shall establish lines of responsibility that are clear, consistent and well-documented. A CSD shall have clear and direct reporting lines between the members of its management body and the senior management in order to ensure that the senior management is accountable for its performance. The reporting lines for the risk-management function, compliance and internal control function and internal audit function shall be clear and separate from those for the operations of the CSD.

5.

A CSD shall have a chief risk officer who shall implement the risk-management framework including the policies and procedures established by the management body.

6.

A CSD shall have a chief technology officer who shall implement the technology framework including the policies and procedures established by the management body.

7.

A CSD shall have a chief compliance officer who shall implement the compliance and internal control framework including the policies and procedures established by the management body.

8.

A CSD shall ensure that the functions of the chief risk officer, chief compliance officer and chief technology officer are carried out by different individuals, who shall be employees of the CSD or of an entity from the same group as the CSD. A single individual shall have the responsibility for each of these functions.

9.

The CSD shall establish procedures ensuring that the chief risk officer, the chief technology officer and the chief compliance officer have direct access to the management body.

10.

Persons appointed as chief risk officer, chief compliance officer or chief technology officer may undertake other duties within the CSD provided that specific procedures are put in place in the governance arrangements to identify and manage any conflict of interest that may arise from those duties.

Article 50
Conflicts of interest
1.

A CSD shall put in place a policy in relation to conflicts of interest arising or affecting the CSD or its activities, including with respect to outsourcing arrangements.

2.

Where a CSD is part of a group of undertakings, its organisational administrative arrangements shall take into account any circumstances, of which the CSD is or should be aware, which may give rise to a conflict of interest arising as a result of the structure and business activities of other undertakings of the same group.

3.

Where a CSD shares the functions of chief risk officer, chief compliance officer, chief technology officer, or internal audit with other entities of the group, the governance arrangements shall ensure that related conflicts of interest at group level are appropriately managed.

4.

The organisational and administrative arrangements referred to in Article 26(3) of Regulation (EU) No 909/2014 shall include a description of the circumstances which may give rise to a conflict of interest entailing a material risk of damage to the interests of one or more users of the CSD, or their clients, as well as the procedures to be followed and the measures to be adopted in order to manage those conflicts of interest.

5.

The description of circumstances referred to in paragraph 4 shall take into account whether a member of the management body, senior management or staff of the CSD, or any person directly or indirectly linked to those individuals or to the CSD:

(a) has a personal interest in the use of the services, materials and equipment of the CSD for the purposes of another commercial activity;

(b) holds a personal or financial interest in another entity that enters into contracts with the CSD;

(c) holds a participation or a personal interest in another entity that provides services used by the CSD, including any entity to which the CSD outsources services or activities;

(d) has a personal interest in an entity that uses the service of the CSD;

(e) is related to any legal or natural person that has influence on the operations of any entity that provides the services used by the CSD or uses the services provided by the CSD;

(f) is member of the management body or any other bodies or committees of any entity that provides the services which are used by the CSD or uses the services provided for the CSD.

Reading this document does not replace reading the official text published in the Official Journal of the European Union. We assume no responsibility for any inaccuracies arising from the conversion of the original to this format.

This text is published under EUR-Lex's own terms of reuse, not a Legalize or public-domain licence. EUR-Lex
Creative Commons Attribution 4.0 International (CC BY 4.0)
© European Union, https://eur-lex.europa.eu — Source: EUR-Lex (Publications Office of the European Union). Reused under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence. Only EU legislation published in the printed Official Journal of the European Union is deemed authentic; consolidated texts are reproduced here for documentation purposes and have been reformatted to Markdown.