Commission Delegated Regulation (EU) 2017/392 of 11 November 2016 supplementing Regulation (EU) No 909/2014 of the European Parliament and of the Council with regard to regulatory technical standards on authorisation, supervisory and operational requirements for central securities depositories (Text with EEA relevance. )

Type Delegated Regulation
Publication 2016-11-11
Last updated 2026-04-15
State In force
Department European Commission, FISMA
Source EUR-Lex
articles 96
Reform history JSON API

For the purposes of this paragraph, a direct or indirect link to a natural person shall comprise the spouse or legal partner, family members in direct ascending or descending line up to the second degree and their spouses or legal partners, the siblings and their spouse or legal partners, and any person having the same domicile or habitual residence as the employees, managers or members of the management body.

6.

A CSD shall take all reasonable steps to prevent any misuse of the information held in its systems and shall prevent the use of that information for other business activities. A natural person who has access to information recorded in a CSD or a legal person that belongs to the same group as the CSD shall not use information recorded in that CSD for any commercial purposes without prior written consent of the person to whom the information refers.

Article 51
Audit methods
1.

The internal audit function of a CSD shall ensure the following:

(a) establish, implement and maintain an all-encompassing audit plan to examine and evaluate the adequacy and effectiveness of the CSD's systems, risk-management processes, internal control mechanisms, remuneration policies, governance arrangements, activities and operations, including outsourced activities;

(b) review and report the audit plan to the competent authority at least annually;

(c) establish a comprehensive risk-based audit;

(d) issue recommendations based on the result of work carried out in accordance with point (a) and verify compliance with those recommendations;

(e) report internal audit matters to the management body;

(f) be independent from the senior management and report directly to the management body;

(g) ensure that special audits may be performed at short notice on an event-driven basis.

2.

Where the CSD belongs to a group, the internal audit function may be carried out at group level provided that the following requirements are complied with:

(a) it is separate and independent from other functions and activities of the group;

(b) it has a direct reporting line to the management body of the CSD;

(c) the arrangement concerning the operation of the internal audit function does not prevent the exercise of supervisory and oversight functions, including on-site access to acquire any relevant information needed to fulfil those functions.

3.

The CSD shall assess the internal audit function.

Internal audit assessments shall include an on-going monitoring of the performance of the internal audit activity and periodic reviews performed through self-assessment carried out by the audit committee or by other persons within the CSD or the group with sufficient knowledge of internal audit practices.

An external assessment of the internal audit function shall be conducted by a qualified and independent assessor from outside the CSD and its group structure at least once every five years.

4.

A CSD's operations, risk-management processes, internal control mechanisms and records shall be subject to regular internal or external audits.

The frequency of the audits shall be determined on the basis of a documented risk assessment. Audits referred to in the first subparagraph shall be carried out at least every two years.

5.

A CSD's financial statement shall be prepared on an annual basis and be audited by statutory auditors or audit firms approved in accordance with Directive 2006/43/EC.

Article 52
Sharing audit findings with the user committee
1.

A CSD shall share audit findings with the user committee in any of the following cases:

(a) where the findings relate to the criteria for accepting issuers or users to their respective securities settlement systems operated by the CSDs;

(b) where the findings relate to any other aspect of the user committee's mandate;

(c) where the findings may impact the level of provision of services by a CSD, including ensuring business continuity.

2.

Members of the user committee shall not be provided with information that may place those members at a competitive advantage.

CHAPTER VIII

RECORD-KEEPING

(Article 29(3) of Regulation (EU) No 909/2014)

Article 53
General requirements
1.

A CSD shall maintain full and accurate records of all its activities as specified in this Regulation at all times, including during disruption events when the business continuity policy and disaster recovery plans are activated. Those records shall be readily accessible.

2.

The records kept by a CSD shall cover separately each individual service provided by the CSD in accordance with Regulation (EU) No 909/2014.

3.

A CSD shall keep records in a durable medium that allows information to be provided to the authorities referred to in Article 29(2) of Regulation (EU) No 909/2014. The record-keeping system shall ensure that all of the following conditions are met:

(a) each key stage of the processing of records by the CSD may be reconstituted;

(b) the original content of a record before any corrections or other amendments may be recorded, traced and retrieved;

(c) measures are put in place to prevent unauthorised alteration of records;

(d) measures are put in place to ensure the security and confidentiality of the data recorded;

(e) a mechanism for identifying and correcting errors is incorporated in the record-keeping system;

(f) the timely recovery of the records in the case of a system failure is ensured within the record-keeping system.

Article 54
Transaction/settlement instruction (Flow) records
1.

A CSD shall maintain records of all transactions, settlement instructions and orders concerning settlement restrictions that it processes and it shall ensure that its records include all necessary information to accurately identify them.

2.

In relation to every settlement instruction and order concerning settlement restrictions received, a CSD shall, immediately upon receiving the relevant information, make and keep updated a record of the following details, depending on whether the settlement instruction or settlement restrictions covers securities or cash only, or both securities and cash:

(a) type of settlement instruction as referred to in point (h)(v) of Article 42(1);

(c) unique instruction reference of the participant;

(d) trade date;

(e) intended settlement date;

(f) settlement timestamp;

(g) timestamp of the moment of entry of the settlement instruction into the securities settlement system;

(h) timestamp of the moment of irrevocability of the settlement instruction;

(i) matching timestamp in case of matched settlement instructions;

(j) securities account identifier;

(k) cash account identifier;

(l) settlement bank identifier;

(m) identifier of the instructing participant;

(n) identifier of the instructing participant's counterpart;

(o) identifier of the instructing participant's client, where known to the CSD;

(p) identifier of the client of the instructing participant's counterpart, where known to the CSD;

(q) securities identifier;

(r) settlement currency;

(s) settlement cash amount;

(t) quantity or nominal amount of securities;

For each of the categories of settlement instructions referred to in the first subparagraph, the following information shall be recorded:

(a) whether an instruction is matched or not matched;

(b) whether an instruction can settle partially;

(c) whether an instruction is on hold;

(d) where relevant, what the reasons are for instruction being pending or failing

(e) place of trading;

(f) if applicable, place of clearing;

where a buy-in process is initiated in accordance with Article 7(3) of Regulation (EU) No 909/2014, details regarding:

(i) the final results of the buy-in process on the last business day of the deferral period at the latest, including the number and value of the financial instruments where the buy-in is partially or fully successful;

(ii) the payment of cash compensation, including the amount of the cash compensation, where the buy-in is not possible, fails or is partially successful;

(iii) the cancellation of the initial settlement instruction;

(iv) for each settlement fail, the amount of the penalties referred to in Article 7(2) of Regulation (EU) No 909/2014.

Article 55
Position (Stock) records
1.

A CSD shall keep records of positions corresponding to all securities accounts that it maintains. Separate records shall be held for each account kept in accordance with Article 38 of Regulation (EU) No 909/2014.

2.

A CSD shall keep records of the following information:

(a) identifier of each issuer for which the CSD provides the core service referred to in point 1 or 2 of Section A of the Annex to Regulation (EU) No 909/2014;

(b) identifier of each securities issue for which the CSD provides the core services referred to in point 1 or 2 of Section A of the Annex to of Regulation (EU) No 909/2014, the law under which the securities recorded by the CSD are constituted and the country of incorporation of the issuers of each securities issue;

(c) identifier of each securities issue recorded in securities accounts not centrally maintained by the CSD, the law under which the securities recorded by the CSD are constituted and the country of incorporation of the issuers of each securities issue;

(d) identifier of the issuer CSD or of the relevant third country entity performing similar functions to an issuer CSD for each securities issue referred to in point (c);

(e) issuers' securities accounts identifiers, in the case of issuer CSDs;

(f) issuers' cash accounts identifiers, in the case of issuer CSDs;

(g) identifiers of settlement banks used by each issuer, in the case of issuer CSDs;

(h) participants' identifiers;

(i) participants' country of incorporation;

(j) participants' securities accounts identifiers;

(k) participants' cash accounts identifiers;

(l) identifiers of settlement banks used by each participant;

(m) country of incorporation of settlement banks used by each participant.

3.

At the end of each business day, a CSD shall record for each position the following details to the extent that they are relevant for the position:

(a) identifiers of participants and of other account holders;

(b) type of securities accounts according to whether a securities account belongs to a participant (‘participant's own account’), to one of its clients (‘individual client segregation’) or to several of its clients (‘omnibus client segregation’);

(c) for each securities issue identifier (ISIN), end-of-day balances of securities accounts covering the number of securities;

(d) for each securities account and ISIN under point (c), the number of securities subject to settlement restrictions, type of the restrictions and the identity of the beneficiary of restrictions at the end of day.

4.

A CSD shall keep records of settlement fails and the measures adopted by the CSD and its participants to prevent and address settlement fails in accordance with Articles 6 and 7of Regulation (EU) No 909/2014.

Article 56
Ancillary Services Records
1.

A CSD shall keep the types of records specified in Annex II to this Regulation for each of the ancillary services provided by a CSD in accordance with Sections B and C of the Annex to Regulation (EU) No 909/2014, including the end-of-day balances of the cash accounts provided by the CSD or the designated credit institution for each currency.

2.

Where a CSD provides ancillary services other than those explicitly mentioned in Sections B or C of the Annex to Regulation (EU) No 909/2014, it shall keep adequate records of those services.

Article 57
Business Records
1.

A CSD shall maintain adequate and orderly records of activities related to its business and internal organisation.

2.

The records referred to in paragraph 1 shall reflect any substantive changes in the documents held by the CSD and shall include the following:

(a) the organisational charts for the management body, senior management, relevant committees, operational units and all other units or divisions of the CSD;

(b) the identities of the shareholders, whether natural or legal persons, that exercise direct or indirect control over the management of the CSD or that have participations in the capital of the CSD and the amounts of those holdings;

(c) participations of the CSD in the capital of other legal entities;

(d) the documents attesting the policies, procedures and processes required under the CSD's organisational requirements and in relation to the services provided by the CSD;

(e) the minutes of management body meetings and of meetings of senior management committees and other committees;

(f) the minutes of meetings of the user committees;

(g) the minutes of consultation groups with participants and clients, if any;

(h) internal and external audit reports, risk-management reports, internal control and compliance reports, including responses from the senior management to the reports;

(i) all outsourcing contracts;

(j) business continuity policy and disaster recovery plan;

(k) records reflecting all assets, liabilities and capital accounts of the CSD;

(l) records reflecting all costs and revenues, including costs and revenues which are accounted separately in accordance with Article 34(6) of Regulation (EU) No 909/2014;

(m) formal complaints received, including information on the complainant's name and address; the date when the complaint was received; the name of all persons identified in the complaint; a description of the nature and content of the complaint; and the date when the complaint was resolved;

(n) records of any interruption of services or dysfunction, including a detailed report on the timing, effects and remedial actions of that interruption or dysfunction;

(o) records of the results of the back and stress tests performed by the CSDs providing banking-type ancillary services;

(p) written communications with the competent authority, ESMA and relevant authorities;

(q) legal opinions received in accordance with the relevant provisions on organisational requirements in accordance with Chapter VII of this Regulation;

(r) documentation regarding link arrangements in accordance with Chapter XII of this Regulation;

(s) tariffs and fees applied to the different services, including any discount or rebate.

Article 58
Additional records

A CSD shall keep the additional records requested by the competent authority for the purpose of enabling the competent authority to monitor compliance of the CSD with Regulation (EU) No 909/2014.

CHAPTER IX

RECONCILIATION MEASURES

(Article 37(4) of Regulation (EU) No 909/2014)

Article 59
General reconciliation measures
1.

A CSD shall perform the reconciliation measures referred to in Article 37(1) of Regulation (EU) No 909/2014 for each securities issue recorded in securities accounts centrally and not centrally maintained by the CSD.

The CSD shall compare the previous end-of-day balance with all the settlements processed during the day and the current end-of-day balance for each securities issue and securities account centrally or not centrally maintained by the CSD.

A CSD shall use double-entry accounting, according to which for each credit entry made on a securities account maintained by the CSD, centrally or not centrally, there is a corresponding debit entry on another securities account maintained by the same CSD.

2.

The audits referred to in Article 26(6) of Regulation (EU) No 909/2014 shall ensure that the records of a CSD related to securities issues are accurate, and that its reconciliation measures referred to in Article 37(1) of Regulation (EU) No 909/2014 and the measures concerning cooperation and exchanges of information with third parties related to reconciliation referred to in Article 37(2) of Regulation (EU) No 909/2014 are adequate.

3.

Where the reconciliation process concerns securities subject to immobilisation, a CSD shall put in place adequate measures to protect the physical securities from theft, fraud, and destruction. Those measures shall at least include the use of vaults whose design and location ensure a high level of protection against floods, earthquakes, fire and other disasters.

4.

Audits referred to in Article 26(6) of Regulation (EU) No 909/2014 with respect to the vaults, including physical inspections, shall be performed at least annually. The CSD shall share the results of those audit controls with the competent authority.

Article 60
Reconciliation measures for corporate actions
1.

A CSD shall not determine the entitlements to the proceeds of a corporate action on stock that would change the balance of securities accounts maintained by the CSD until the reconciliation measures specified in Article 59 and in Articles 61, 62 and 63 are completed.

2.

When a corporate action has been processed, a CSD shall ensure that all securities accounts maintained by the CSD, centrally or not centrally, are updated.

Article 61
Reconciliation measures for the registrar model

Where a registrar, issuance agent, or other similar entity is involved in the reconciliation process for a certain securities issue in accordance with Article 37(2) of Regulation (EU) No 909/2014, and maintains records of securities which are also recorded in the CSD, the measures to be taken by the CSD and that entity to ensure the overall integrity of the issue shall include a daily reconciliation of the total balance recorded on the securities accounts maintained by the CSD with the corresponding records of securities maintained by that entity. The CSD and that entity shall also conduct:

(a) where the securities have been transferred during a given business day, an end-of-day reconciliation of the balance of each securities account maintained by the CSD with the balance of the corresponding record of securities maintained by that entity;

(b) at least once every two weeks, a full reconciliation of all balances in a securities issue with all balances on the corresponding record of securities maintained by that entity.

Article 62
Reconciliation measures for the transfer agent model

Where a fund manager, transfer agent or other similar entity is responsible for the reconciliation process for an account that maintains a part of a securities issue recorded in a CSD, the measures to be taken by the CSD and that entity to ensure the integrity of this part of the issue shall include a daily reconciliation of the total balance of the securities accounts maintained by the CSD with that entity's records of securities maintained by the CSD, including the aggregated opening and closing balances.

Where the CSD maintains its accounts in that entity's register through a third party which is not a CSD, the CSD shall require the third party to inform that entity that it is acting on behalf of the CSD and to set up equivalent cooperation and information exchange measures with that entity to ensure that the requirements under this Article are met.

Article 63
Reconciliation measures for the common depository model

Where CSDs that have established an interoperable link use a common depository or any other similar entity, each CSD shall reconcile on a daily basis the total balance per securities issue recorded on the securities accounts it maintains, other than for other CSDs in the interoperable link, with the corresponding records of securities that the common depository or the other similar entity maintains for that CSD.

Where a common depository or any other similar entity is responsible for the overall integrity of a certain securities issue, the common depository or the other similar entity shall conduct a daily comparison of the total balance per securities issue against the balances in the securities accounts it maintains for each CSD.

Where the reconciliation process concerns securities subject to immobilisation, the CSDs shall ensure that the common depository or the other entity meets the requirements set out in Article 59(3).

Article 64
Additional measures where other entities are involved in the reconciliation process
1.

A CSD shall review at least annually its cooperation and information exchange measures with other entities referred to in Articles 61, 62 and 63. This review may be conducted in parallel with a review of the CSD link arrangements. When required by the competent authority, the CSD shall implement other cooperation and information exchange measures in addition to those specified in this Regulation.

2.

When a CSD establishes links, they shall comply with the additional requirements provided in Article 86.

3.

A CSD shall require its participants to reconcile their records with the information received from that CSD on a daily basis.

4.

For the purposes of paragraph 3, the CSD shall provide participants on a daily basis the following information specified for each securities account and for each securities issue:

(a) the aggregated balance of a securities account at the beginning of the respective business day;

(b) the individual transfers of securities in or from a securities account during the respective business day;

(c) the aggregated balance of a securities account at the end of the respective business day.

The CSD shall provide the information referred to in the first subparagraph at the request of other holders of securities accounts maintained by the CSD, centrally or not centrally, where that information is necessary for the reconciliation of those holders' records with the records of the CSD.

5.

A CSD shall ensure that, upon its request, its participants, other holders of accounts in the CSD and the account operators provide the CSD with the information that the CSD deems necessary to ensure the integrity of the issue, in particular to solve any reconciliation problems.

For the purposes of this paragraph, ‘account operator’ shall mean an entity that is contracted by a CSD to record book entries into its securities accounts.

Article 65
1.

A CSD shall analyse any mismatches and inconsistencies resulting from the reconciliation process and endeavour to solve them before the beginning of settlement on the following business day.

2.

Where the reconciliation process reveals an undue creation or deletion of securities, and the CSD fails to solve this problem by the end of the following business day, the CSD shall suspend the securities issue for settlement until the undue creation or deletion of securities has been remedied.

3.

In the event of suspension of the settlement, the CSD shall inform without undue delay its participants, competent authority, relevant authorities and all other entities involved in the reconciliation process referred to in Articles 61, 62 and 63.

4.

The CSD shall take without undue delay all the necessary measures to remedy the undue creation or deletion of securities and shall inform its competent authority and relevant authorities with regard to the measures taken.

5.

The CSD shall inform without undue delay its participants, competent authority, relevant authorities and the other entities involved in the reconciliation process that are referred to in Articles 61, 62 and 63, when the undue creation or deletion of securities has been remedied.

6.

Where a securities issue is suspended from settlement, the settlement discipline measures set out in Article 7 of Regulation (EU) No 909/2014 shall not apply in relation to that securities issue for the period of suspension.

7.

The CSD shall resume settlement as soon as the undue creation or deletion of securities has been remedied.

8.

Where the number of instances of undue creation or deletion of securities referred to in paragraph 2 is higher than five per month, the CSD shall send within one month the competent authority and the relevant authorities a proposed plan of measures for mitigating the occurrence of similar instances. The CSD shall update the plan and shall provide a report on its implementation to the competent authority and the relevant authorities on a monthly basis, until the number of instances referred to in paragraph 2 falls below five per month.

CHAPTER X

OPERATIONAL RISKS

(Article 45(1) to (6) of Regulation (EU) No 909/2014)

SECTION 1

Identifying operational risks

Article 66
General operational risks and their assessment
1.

The operational risks referred to in Article 45(1) of Regulation (EU) No 909/2014 comprise the risks caused by deficiencies in information systems, internal processes, and personnel's performance or disruptions caused by external events that result in the reduction, deterioration or interruption of services provided by a CSD.

2.

A CSD shall identify all potential single points of failure in its operations and assess the evolving nature of the operational risk that it faces, including pandemics and cyber-attacks, on an ongoing basis.

Article 67
Operational risks that may be posed by key participants
1.

A CSD shall, on an ongoing basis, identify the key participants in the securities settlement system that it operates based on the following factors:

(a) their transaction volumes and values;

(b) material dependencies between its participants and its participants' clients, where the clients are known to the CSD, that might affect the CSD;

(c) their potential impact on other participants and the securities settlement system of the CSD as a whole in the event of an operational problem affecting the smooth provision of services by the CSD.

For the purposes of point (b) in the first subparagraph, the CSD shall also identify the following:

(i) the participants' clients responsible for a significant proportion of transactions processed by the CSD;

(ii) the participants' clients whose transactions, based on their volumes and values, are significant relative to the respective participants' risk-management capacity.

2.

A CSD shall review and keep the identification of the key participants up-to-date on an ongoing basis.

3.

A CSD shall have clear and transparent criteria, methodologies and standards in order to ensure that key participants meet the operational requirements.

4.

A CSD shall, on an ongoing basis, identify, monitor, and manage the operational risks that it faces from key participants.

For the purposes of the first subparagraph, the operational risk-management system referred to in Article 70 shall also provide for rules and procedures to gather all relevant information about their participants' clients. The CSD shall also include in the agreements with its participants all terms necessary to facilitate the gathering of that information.

Article 68
Operational risks that may be posed by critical utilities and critical service providers
1.

A CSD shall identify critical utilities providers and critical service providers that may pose risks to CSD's operations due to its dependency on them.

2.

A CSD shall take appropriate actions to manage the dependencies referred to in paragraph 1 through adequate contractual and organisational arrangements, as well as through specific provisions in its business continuity policy and disaster recovery plan, before any relationship with those providers becomes operational.

3.

A CSD shall ensure that its contractual arrangements with any providers identified in accordance with paragraph 1 require a prior approval of the CSD for the service provider to further subcontract any elements of the services provided to the CSD.

Where the service provider outsources its services in accordance with the first subparagraph, the CSD shall ensure that the level of service and its resilience is not impacted and full access by the CSD to the information necessary for the provision of the outsourced services is preserved.

4.

A CSD shall establish clear lines of communication with the providers referred to in paragraph 1 to facilitate the exchange of information in both ordinary and exceptional circumstances.

5.

A CSD shall inform its competent authority about any dependencies on utilities and service providers identified under paragraph 1 and take measures to ensure that authorities can obtain information about the performance of those providers, either directly from utilities or service providers or through the CSD.

Article 69
Operational risks that may be posed by other CSDs or market infrastructures
1.

A CSD shall ensure that its systems and communication arrangements with other CSDs or market infrastructures are reliable, secure and designed to minimise operational risks.

2.

Any arrangement that a CSD enters into with another CSD or another market infrastructures shall provide that:

(a) the other CSD or other financial market infrastructure discloses to the CSD any critical service provider on which the other CSD or market infrastructure relies;

(b) the governance arrangements and management processes in the other CSD or other market infrastructure do not affect the smooth provision of services by the CSD, including the risk-management arrangements and the non-discriminatory access conditions.

SECTION 2

Methods to test, address and minimise operational risks

Article 70
Operational risk-management system and framework
1.

As part of the policies, procedures and systems referred to in Article 47, a CSD shall have in place a well-documented framework for the management of operational risk with clearly assigned roles and responsibilities. A CSD shall have appropriate IT systems, policies, procedures and controls to identify, measure, monitor, report on and mitigate its operational risk.

2.

The management body and the senior management of a CSD shall determine, implement and monitor the risk-management framework for operational risks referred to in paragraph 1, identify all of the CSD's exposures to operational risk and track relevant operational risk data, including any cases where material data is lost.

3.

A CSD shall define and document clear operational reliability objectives, including operational performance objectives and committed service-level targets for its services and securities settlement systems. It shall have policies and procedures in place to achieve those objectives.

4.

A CSD shall ensure that its operational performance objectives and service-level targets referred to in paragraph 3 include both qualitative and quantitative measures of operational performance.

5.

A CSD shall regularly monitor and assess whether its established objectives and service-level targets are met.

6.

A CSD shall have rules and procedures in place that ensure that the performance of its securities system is reported regularly to senior management, members of the management body, relevant committees of the management body, user committees and the competent authority.

7.

A CSD shall periodically review its operational objectives to incorporate new technological and business developments.

8.

A CSD's operational risk-management framework shall include change-management and project-management processes to mitigate operational risk arising from modifications to operations, policies, procedures and controls put in place by the CSD.

9.

A CSD's operational risk-management framework shall include a comprehensive framework for physical security and information security to manage the risks that the CSD faces from attacks, including cyber-attacks, intrusions and natural disasters. That comprehensive framework shall enable the CSD to protect the information at its disposal from unauthorised access or disclosure, ensure data accuracy and integrity and maintain availability of the services provided by the CSD.

10.

A CSD shall put in place appropriate procedures concerning human resources to employ, train and retain qualified personnel, as well as mitigate the effects of personnel turnover or overreliance on key personnel.

Article 71
Integration of and compliance with the operational and enterprise risk-management system
1.

A CSD shall ensure that its operational risk-management system is part of its day-to-day risk-management processes and that their results are taken into account in the process of determining, monitoring and controlling the CSD's operational risk profile.

2.

A CSD shall have in place mechanisms for regular reporting to the senior management of operational risk exposures and losses experienced from operational risks, and procedures for taking appropriate corrective action to mitigate those exposures and losses.

3.

A CSD shall have in place procedures for ensuring compliance with the operational risk-management system, including internal rules on the treatment of failures in the application of that system.

4.

A CSD shall have comprehensive and well-documented procedures to record, monitor and resolve all operational incidents, including:

(a) a system to classify the incidents taking into account their impact on the smooth provision of services by the CSD;

(b) a system for reporting material operational incidents to the senior management, the management body and the competent authority;

(c) a ‘post-incident’ review after any material disruption in the CSD's activities, to identify the causes and required improvements to the operations or business continuity policy and disaster recovery plan, including to the policies and plans of the users of the CSD. The result of that review shall be communicated to the competent authority and relevant authorities without delay.

Article 72
Operational risk-management function

As part of the risk-management function, the operational risk-management function of a CSD shall manage the CSD's operational risk. It shall in particular:

(a) develop strategies, policies and procedures to identify, measure, monitor and report on operational risks;

(b) develop procedures to control and manage operational risks, including by introducing any necessary adjustments in the operational risk-management system;

(c) ensure that the strategies, policies and procedures referred to in points (a) and (b) are properly implemented.

Article 73
Audit and testing
1.

A CSD's operational risk-management framework and systems shall be subject to audits. The frequency of those audits shall be based on a documented risk assessment and shall be conducted at least once every two years.

2.

The audits referred to in the previous paragraph shall include both the activities of the internal business units of the CSD and those of the operational risk-management function.

3.

A CSD shall regularly evaluate and, where necessary, adjust the system for the management of operational risk.

4.

A CSD shall periodically test and review the operational arrangements, policies and procedures with users. The testing and review shall also be performed where substantive changes occur to the securities settlement system operated by the CSD or after operational incidents that affect the smooth provision of services by the CSD.

5.

A CSD shall ensure that data flows and processes associated with the operational risk-management system are accessible to the auditors without delay.

Article 74
Mitigation of operational risk through insurance

A CSD may only contract insurance to mitigate the operational risks referred to in this Chapter where the measures referred to in this Chapter do not fully mitigate operational risks.

SECTION 3

IT systems

Article 75
IT tools
1.

A CSD shall ensure that its information technology (IT) systems are well-documented and that they are designed to cover the CSD's operational needs and the operational risks that the CSD faces.

The CSD IT systems shall be:

(a) resilient, including in stressed market conditions;

(b) have sufficient capacity to process additional information as a result of increasing settlement volumes;

(c) achieve the service level objectives of the CSD.

2.

A CSD systems shall have sufficient capacity to process all transactions before the end of the day even in circumstances where a major disruption occurs.

A CSD shall have procedures for ensuring sufficient capacity of its IT systems, including in the case of the introduction of new technology.

3.

A CSD shall base its IT systems on internationally recognised technical standards and industry best practices.

4.

A CSD's IT systems shall ensure that any data at the disposal of the CSD is protected from loss, leakage, unauthorised access, poor administration, inadequate record-keeping, and other processing risks.

5.

A CSD's information security framework shall outline the mechanisms that the CSD have in place to detect and prevent cyber-attacks. The framework shall also outline the CSD's plan in response to cyber-attacks.

6.

The CSD shall subject its IT systems to stringent testing by simulating stressed conditions before those systems are used for the first time, after making significant changes to the systems and after a major operational disruption has occurred. A CSD shall, as appropriate, involve in the design and conduct of these tests:

(a) users;

(b) critical utilities and critical service providers;

(c) other CSDs;

(d) other market infrastructures;

(e) any other institutions with which interdependencies have been identified in the business continuity policy.

7.

The information security framework shall include:

(a) access controls to the system;

(b) adequate safeguards against intrusions and data misuse;

(c) specific devices to preserve data authenticity and integrity, including cryptographic techniques;

(d) reliable networks and procedures for accurate and prompt data transmission without major disruptions; and

(e) audit trails.

8.

The CSD shall have arrangements for the selection and substitution of IT third party service providers, CSD's timely access to all necessary information, as well as proper controls and monitoring tools.

9.

The CSD shall ensure that the IT systems and the information security framework concerning the CSD's core services are reviewed at least annually and are subject to audit assessments. The results of the assessments shall be reported to the CSD's management body and to the competent authority.

SECTION 4

Business continuity

Article 76
Strategy and policy
1.

A CSD shall have a business continuity policy and associated disaster recovery plan that is:

(a) approved by the management body;

(b) subject to audit reviews that shall be reported to the management body.

2.

A CSD shall ensure that the business continuity policy:

(a) identifies all its critical operations and IT systems and provides for a minimum service level to be maintained for those operations;

(b) includes the CSD's strategy and objectives to ensure the continuity of operations and systems referred to in point (a);

(d) defines and documents the arrangements to be applied in the event of a business continuity emergency or major disruption of the CSD's operations in order to ensure a minimum service level of critical functions of the CSD;

(e) identifies the maximum acceptable period of time which critical functions and IT systems may be out of use.

3.

A CSD shall take all reasonable steps to ensure that settlement is completed by the end of the business day even in case of a disruption, and that all the users' positions at the time of the disruption are identified with certainty in a timely manner.

Article 77
Business impact analysis
1.

A CSD shall conduct a business impact analysis to:

(a) prepare a list with all the processes and activities that contribute to the delivery of the services it provides;

(b) identify and create an inventory of all the components of its IT system that support the processes and activities identified in point (a) as well as their respective interdependencies;

(c) identify and document qualitative and quantitative impacts of a disaster recovery scenario to each process and activity referred to in point (a) and how the impacts change over time in case of disruption;

(d) define and document the minimum service levels considered acceptable and adequate from the perspective of the users of the CSD;

(e) identify and document the minimum resource requirements concerning personnel and skills, work space and IT to perform each critical function at the minimum acceptable level.

2.

A CSD shall conduct a risk analysis to identify how various scenarios affect the continuity of its critical operations.

3.

A CSD shall ensure that its business impact analysis and risk analysis fulfil all of the following requirements:

(a) they are kept up to date;

(b) they are reviewed following a material incident or significant operational changes and, at least, annually;

(c) they take into account all relevant developments, including market and IT developments.

Article 78
Disaster recovery
1.

A CSD shall have in place arrangements to ensure the continuity of its critical operations in disaster scenarios, including natural disasters, pandemic situations, physical attacks, intrusions, terrorist attacks, and cyber-attacks. Those arrangements shall ensure:

(a) the availability of adequate human resources;

(b) the availability of sufficient financial resources;

(c) the failover, recovery and resuming of operations in a secondary processing site.

2.

The CSD's disaster recovery plan shall identify and include a recovery-time objective for critical operations and determine for each critical operation the most suitable recovery strategies. The recovery-time objective for each critical operation shall not be longer than two hours. The CSD shall ensure that back-up systems commence processing without undue delay unless this would jeopardise the integrity of the securities issues or the confidentiality of the data maintained by the CSD. A CSD shall ensure that two hours from a disruption, it is capable of resuming its critical operations. In determining the recovery times for each operation, the CSD shall take into account the potential overall impact on the market efficiency. Those arrangements shall at least ensure that, in extreme scenarios, agreed service levels are met.

3.

A CSD shall maintain at least a secondary processing site with sufficient resources, capabilities, functionalities and staffing arrangements, which are adequate to the CSD's operational needs and risks that the CSD faces in order to ensure continuity of critical operations, at least in case the main location of business is not available.

The secondary processing site shall:

(a) provide the level of services necessary to ensure that the CSD performs its critical operations within the recovery time objective;

(b) be located at a geographical distance from the primary processing site that allows the secondary processing site to have a distinct risk profile and prevents it from being affected by the event affecting the primary processing site;

(c) is immediately accessible by the CSD's staff in order to ensure continuity of its critical operations where the primary processing site is not available.

4.

A CSD shall develop and maintain detailed procedures and plans concerning:

(a) the identification, logging and reporting of all disruptive events for the operations of the CSD;

(b) response measures to operational incidents and emergency situations;

(c) the assessment of damages, and appropriate plans for activating the response measures referred to in point (b);

(d) crisis management and communications, including appropriate contact points, to ensure that reliable and up to date information is transmitted to relevant stakeholders and the competent authority;

(e) the activation and transition to alternative operational and business sites;

(f) IT recovery, including activation of the secondary IT processing site and failover.

Article 79
Testing and monitoring

A CSD shall monitor its business continuity policy and disaster recovery plan and test them at least annually. The CSD shall also test its business continuity policy and disaster recovery plan after substantive changes to the systems or related operations in order to ensure that the systems and operations achieve the CSD objectives. The CSD shall plan and document these tests, which shall include:

(a) scenarios of large scale disasters;

(b) switchovers between the primary processing site and secondary processing site;

Article 80
Maintenance
1.

A CSD shall regularly review and update its business continuity policy and disaster recovery plan. The review shall include all critical operations of a CSD and provide for the most suitable recovery strategy for those operations.

2.

When updating the business continuity policy and disaster recovery plan, a CSD shall take into consideration the outcome of the tests and recommendations from the audit reviews and from the competent authority.

3.

A CSD shall review its business continuity policy and disaster recovery plan after every significant disruption of its operations. That review shall identify the causes of the disruption and any required improvement to the CSD's operations, the business continuity policy and disaster recovery plan.

CHAPTER XI

INVESTMENT POLICY

(Article 46(2), (3) and (5) of Regulation (EU) No 909/2014)

Article 81
Highly liquid instruments with minimal market and credit risk
1.

Financial instruments shall be considered highly liquid with minimal credit and market risk where they are debt instruments meeting the following conditions:

(b) the CSD can demonstrate to the competent authority that the financial instruments have low credit and market risk based upon an internal assessment by the CSD;

(d) they are freely transferable and without any regulatory constraint or third party claims that impair liquidation;

(e) they have an active outright sale or repurchase market, with a diverse group of buyers and sellers, including in stressed conditions, and to which the CSD has reliable access;

(f) reliable price data on these instruments are publicly available on a regular basis;

For the purposes of point (b), in performing the assessment the CSD shall employ a defined and objective methodology that shall not exclusively rely on external opinions and that takes into consideration the risk arising from the establishment of the issuer in a particular country

2.

By way of derogation to paragraph 1, derivative contracts shall be considered highly liquid financial instruments with minimal credit and market risk where the following conditions are met:

(a) they are entered into for the purpose of hedging currency risk arising from the settlement in more than one currency in the securities settlement system operated by the CSD or interest rate risk that may affect CSD assets and, in both cases, qualify as a hedging contract pursuant to International Financial Reporting Standards (IFRS) adopted in accordance with Article 3 of Regulation (EC) No 1606/2002 of the European Parliament and of the Council (9);

(b) reliable price data is published on a regular basis for those derivative contracts;

(c) they are concluded for the specific period of time necessary to reduce the currency or interest rate risk to which the CSD is exposed.

Article 82
Appropriate timeframe for access to assets
1.

A CSD shall have immediate and unconditional access to cash assets.

2.

A CSD shall have access to financial instruments on the same business day when a decision to liquidate the financial instruments is taken.

3.

For the purposes of paragraph 1 and 2, the CSD shall put in place procedures ensuring that the CSD is able to access cash and financial instruments within the time frames set out therein. The CSD shall inform the competent authority of any change to those procedures in accordance with Article 16(4) of Regulation (EU) No 909/2014 and shall obtain its validation before implementing that change.

Article 83
Concentration limits to individual entities
1.

For the purposes of Article 46(5) of Regulation (EU) No 909/2014, a CSD shall hold its financial assets in diversified authorised credit institutions or authorised CSDs in order to remain within acceptable concentration limits.

2.

For the purposes of Article 46(5) of Regulation (EU) No 909/2014, acceptable concentration limits shall be determined based on the following:

(a) the geographic distribution of the entities with which the CSD holds its financial assets;

(b) the interdependency relationships that the entity holding the financial assets or entities of its group may have with the CSD;

(c) the level of credit risk of the entity holding the financial assets.

CHAPTER XII

(Article 48(3), (5), (6) and (7) of Regulation (EU) No 909/2014)

Article 84
Conditions for the adequate protection of linked CSDs and of their participants
1.

A CSD link shall be established and maintained under the following conditions:

(a) the requesting CSD shall meet the requirements of the receiving CSD's participation rules;

(b) the requesting CSD shall conduct an analysis of the receiving third-country CSD's financial soundness, governance arrangements, processing capacity, operational reliability and any reliance on a third party critical service provider;

(c) the requesting CSD shall take all necessary measures to monitor and manage the risks that are identified following the analysis referred to in point (b);

(d) the requesting CSD shall make the legal and operational terms and conditions of the link arrangement available to its participants allowing them to assess and manage the risks involved;

(e) before the establishment of a CSD link with a third-country CSD, the requesting CSD shall perform an assessment of the local legislation applicable to the receiving CSD;

(f) the linked CSDs shall ensure the confidentiality of information in connection to the operation of the link. The ability to ensure confidentiality shall be evidenced by the information provided by the CSDs, including any relevant legal opinions or arrangements;

(g) the linked CSDs shall agree on aligned standards and procedures concerning operational issues and communication in accordance with Article 35 of Regulation (EU) No 909/2014;

(i) all link arrangements shall be reviewed at least annually by the receiving CSD and the requesting CSD taking into account all relevant developments, including market and IT developments, as well as any developments in local legislation referred to in point (e);

(j) for CSD links that do not provide for DVP settlement, the annual review referred to in point (i) shall also include an assessment of any developments that may allow supporting DVP settlement.

For the purposes of point (e), in performing the assessment, the CSD shall ensure that the securities maintained in the securities settlement system operated by the receiving CSD benefit from a level of asset protection comparable to the one ensured by the rules applicable to the securities settlement system operated by the requesting CSD. The requesting CSD shall require from the third-country CSD a legal assessment addressing the following issues:

(i) the entitlement of the requesting CSD to the securities, including the law applicable to proprietary aspects, the nature of the rights of the requesting CSD on the securities, the possibility of encumbering the securities;

(ii) the impact of insolvency proceedings opened against the receiving third- country CSD on the requesting CSD regarding the segregation requirements, settlement finality, procedures and time limits to claim the securities in the relevant third country.

2.

In addition to the conditions referred to in paragraph 1, a CSD link providing for DVP settlement shall be established and maintained under the following conditions:

(a) the requesting CSD shall assess and mitigate the additional risks resulting from the settlement of cash;

(b) a CSD that is not authorised to provide banking-type ancillary services in accordance with Article 54 of Regulation (EU) No 909/2014, and which is involved in the execution of cash settlement on behalf of its participants, shall not receive credit and shall use prefunding mechanisms covered by its participants in relation to the DVP settlements to be processed through the link;

(c) a CSD that uses an intermediary for the cash settlement shall ensure that the intermediary performs that settlement efficiently. The CSD shall conduct yearly reviews of the arrangements with that intermediary.

3.

In addition to the conditions referred to in paragraphs 1 and 2, an interoperable link shall be established and maintained under the following conditions:

(a) the linked CSDs shall agree on equivalent standards concerning reconciliation, opening hours for the processing of the settlement and of corporate actions and cut-off times;

(b) the linked CSDs shall establish equivalent procedures and mechanisms for transmission of settlement instructions to ensure a proper, secure and straight through processing of settlement instructions;

(c) where an interoperable link supports DVP settlement, the linked CSDs shall reflect at least daily and without undue delay the results of the settlement in their books;

(d) the linked CSDs shall agree on equivalent risk-management models;

(e) the linked CSDs shall agree on equivalent contingency and default rules and procedures referred to in Article 41 of Regulation (EU) No 909/2014.

Article 85
1.

In addition to complying with the requirements under Article 84, where a requesting CSD uses an indirect link or an intermediary to operate a CSD link, it shall ensure that:

(b) the intermediary complies with the rules and requirements of the requesting CSD, as evidenced by the information provided by that intermediary, including any relevant legal opinions or arrangements;

(c) the intermediary ensures the confidentiality of information concerning the operation of the CSD link, as evidenced by the information provided by that intermediary, including any relevant legal opinions or arrangements;

(e) the intermediary adheres to and complies with the risk-management policies and procedures of the requesting CSD and it has an appropriate risk-management expertise;

(f) the intermediary has put in place measures that include business continuity policies and associated business continuity and disaster recovery plans, to ensure the continuity of its services, the timely recovery of its operations and the fulfilment of its obligations in events that pose a significant risk of disrupting its operations;

(g) the intermediary holds sufficient financial resources to fulfil its obligations towards the requesting CSD and to cover any losses for which it may be held liable;

(h) an individually segregated account at the receiving CSD is used for the operations of the CSD link;

(i) the condition referred to in point (e) of Article 84(1) is fulfilled;

(j) the requesting CSD is informed of the continuity arrangements between the intermediary and the receiving CSD;

(k) the proceeds from settlement are promptly transferred to the requesting CSD.

For the purposes of the first indent in point (a)(i), the third indent in point (a)(ii) and point (h), the requesting CSD shall ensure that it can have access to the securities held in the individually segregated account at any point in time. Where an individually segregated account at the receiving CSD is however not available for the operations of a CSD link established with a third-country CSD, the requesting CSD shall inform its competent authority about the reasons justifying the unavailability of individually segregated accounts and shall provide it with the details on the risks resulting from the unavailability of individually segregated accounts. The requesting CSD shall in any case ensure an adequate level of protection of its assets held with the third-country CSD.

2.

In addition to complying with the requirements under paragraph 1, when a requesting CSD uses an intermediary to operate a CSD link and that intermediary operates the securities accounts of the requesting CSD on its behalf in the books of the receiving CSD, the requesting CSD shall ensure that:

(a) the intermediary does not have any entitlement to the securities held;

(b) the account in the books of the receiving CSD is opened in the name of the requesting CSD and the liabilities and obligations as regards the registration, transfer and custody of securities are only enforceable between both CSDs;

(c) the requesting CSD is able to immediately access the securities held with the receiving CSD, including in the event of a change or insolvency of the intermediary.

3.

Requesting CSDs referred to in paragraphs 1 and 2 shall perform a yearly due diligence to ensure that the conditions referred to therein are fulfilled.

Article 86
Reconciliation procedures for linked CSDs
1.

The reconciliation procedures referred to in Article 48(6) of Regulation (EU) No 909/2014 shall include the following measures:

(b) the requesting CSD shall conduct a daily comparison of the opening balance and the closing balance communicated to it by the receiving CSD or by the intermediary with the records maintained by the requesting CSD itself.

In the case of an indirect link, the daily statements referred to in point (a) of the first subparagraph shall be transmitted through the intermediary referred to point (a) of Article 85(1).

2.

Where a CSD suspends a securities issue for settlement in accordance with Article 65(2), all CSDs that are participants of or have an indirect link with that CSD, including in the case of interoperable links, shall subsequently suspend the securities issue for settlement.

Where intermediaries are involved in the operation of CSD links, those intermediaries shall establish appropriate contractual arrangements with the CSDs concerned in order to ensure compliance with the first subparagraph.

3.

In the event of a corporate action that reduces the balances of securities accounts held by an investor CSD with another CSD, settlement instructions in the relevant securities issues shall not be processed by the investor CSD until the corporate action has been fully processed by the other CSD.

In the event of a corporate action that reduces the balances of securities accounts held by an investor CSD with another CSD, the investor CSD shall not update the securities accounts that it maintains to reflect the corporate action until the corporate action has been fully processed by the other CSD.

An issuer CSD shall ensure the timely transmission to all its participants, including investor CSDs, of information on the processing of corporate actions for a specific securities issue. The investor CSDs shall in turn transmit the information to their participants. That transmission shall include all necessary information for investor CSDs to adequately reflect the outcome of those corporate actions in the securities accounts they maintain.

Article 87

Delivery versus payment (DVP) settlement shall be regarded as practical and feasible where:

(a) there is a market demand for DVP settlement evidenced through a request from any of the user committees of one of the linked CSDs;

(b) the linked CSDs may charge a reasonable commercial fee for the provision of DVP settlement, on a cost-plus basis, unless otherwise agreed by the linked CSDs;

(c) there is a safe and efficient access to cash in the currencies used by the receiving CSD for settlement of securities transactions of the requesting CSD and its participants.

CHAPTER XIII

ACCESS TO A CSD

(Articles 33(5), 49(5), 52(3) and 53(4) of Regulation (EU) No 909/2014)

Article 88
Receiving and requesting parties
1.

For the purposes of this Chapter, a receiving party shall include one of the following entities:

(a) a receiving CSD as defined in point (5) of Article 2(1) of Regulation (EU) No 909/2014, in respect of paragraphs 1, 4, 9, 13 and 14 of Article 89 and Article 90 of this Regulation;

(b) a CSD which receives a request from a participant, an issuer, a central counterparty (CCP) or a trading venue to have access to its services in accordance with Articles 33(2), 49(2) and 53(1) of Regulation (EU) No 909/2014 in respect of paragraphs 1 to 3, 5 to 8 and 10 to 14 of Article 89 and Article 90 of this Regulation;

(c) a CCP which receives a request from a CSD to have access to its transaction feeds in accordance with Article 53(1) of Regulation (EU) No 909/2014 in respect of Article 90 of this Regulation;

(d) a trading venue which receives a request from a CSD to have access to its transaction feeds in accordance with Article 53(1) of Regulation (EU) No 909/2014 in respect of Article 90 of this Regulation.

2.

For the purposes of this Chapter, a requesting party shall include one of the following entities:

(a) a requesting CSD as defined in point (6) of Article 2(1) of Regulation (EU) No 909/2014 in respect of paragraphs 1, 4, 9 and 13 of Article 89 and Article 90 of this Regulation;

(b) a participant, an issuer, a CCP or a trading venue which requests access to the securities settlement system operated by a CSD or to other services provided by a CSD in accordance with Articles 33(2), 49(2) and 53(1) of Regulation (EU) No 909/2014 in respect of paragraphs 1 to 3, 5 to 8 and 10 to 14 of Article 89 and Article 90 of this Regulation;

(c) a CSD which requests access to the transaction feeds of a CCP in accordance with Article 53(1) of Regulation (EU) No 909/2014 in respect of Article 90 of this Regulation;

(d) a CSD which requests access to the transaction feeds of a trading venue in accordance with Article 53(1) of Regulation (EU) No 909/2014 in respect of Article 90 of this Regulation.

SECTION 1

Criteria justifying refusal of access

(Articles 33(3), 49(3), 52(2) and 53(3) of Regulation (EU) No 909/2014)

Article 89
Risks to be taken into account by CSDs and competent authorities
1.

Where, in accordance with Articles 33(3), 49(3), 52(2) or 53(3) of Regulation (EU) No 909/2014, a CSD carries out a comprehensive risk assessment following a request for access by a requesting participant, an issuer, a requesting CSD, a CCP or a trading venue, as well as where a competent authority assesses the reasons for refusal by the CSD to provide services, they shall take into account the following risks resulting from access to the services of the CSD:

(a) legal risks;

(b) financial risks;

(c) operational risks.

2.

When assessing legal risks following a request for access by a requesting participant, a CSD and its competent authority shall take into account the following criteria:

(a) the requesting participant is not able to comply with the legal requirements for participation in the securities settlement system operated by the CSD, or does not provide the CSD with the information necessary for the CSD to assess the compliance, including any required legal opinions or legal arrangements;

(b) the requesting participant is not able to ensure, in accordance with the rules applicable in the home Member State of the CSD, the confidentiality of the information provided through the securities settlement system, or does not provide the CSD with the information necessary for the CSD to assess its ability to comply with those rules on confidentiality, including any required legal opinions or legal arrangements;

3.

When assessing legal risks following an issuer's request for recording its securities in the CSD in accordance with Article 49(1) of Regulation (EU) No 909/2014, the CSD and its competent authority shall take into account the following criteria:

(a) the issuer is not able to comply with the legal requirements for the provision of services by the CSD;

(b) the issuer is not able to guarantee that the securities have been issued in a manner that enables the CSD to ensure the integrity of the issue in accordance with Article 37 of Regulation (EU) No 909/2014.

4.

When assessing legal risks following a request for access by a requesting CSD, the receiving CSD and its competent authority shall take into account the criteria set out in points (a), (b) and (c) of paragraph 2.

5.

When assessing legal risks following a request for access by a CCP, a CSD and its competent authority shall take into account the criteria set out in points (a), (b) and (c) of paragraph 2.

6.

When assessing legal risks following a request for access by a trading venue, a CSD and its competent authority shall take into account the following criteria:

(a) the criteria set out in point (b) of paragraph 2;

(b) where a trading venue is established in a third country, the requesting trading venue is not subject to a regulatory and supervisory framework comparable to the regulatory and supervisory framework applicable to a trading venue in the Union;

7.

When assessing financial risks following a request for access by a requesting participant, a CSD and its competent authority shall take into account whether the requesting participant holds sufficient financial resources to fulfil its contractual obligations towards the CSD.

8.

When assessing financial risks following an issuer's request for recording its securities in the CSD in accordance with Article 49(1) of Regulation (EU) No 909/2014, a CSD and its competent authority shall take into account the criterion set out in paragraph 7.

9.

When assessing financial risks following a request for access by a requesting CSD, the receiving CSD and its competent authority shall take into account the criterion set out in paragraph 7.

10.

When assessing financial risks following a request for access by a CCP or a trading venue, a CSD and its competent authority shall take into account the criterion set out in paragraph 7.

11.

When assessing operational risks following a request for access by a requesting participant, a CSD and its competent authority shall take into account the following criteria:

(a) the requesting participant does not have the operational capacity to participate in the CSD;

(b) the requesting participant does not comply with the risk-management rules of the receiving CSD, or it lacks the necessary expertise in that regard;

(c) the requesting participant has not put in place business continuity policies or disaster recovery plans;

(d) the granting of access requires the receiving CSD to undertake significant changes of its operations affecting its risk-management procedures and endangering the smooth functioning of the securities settlement system operated by the receiving CSD, including the implementation of ongoing manual processing by the CSD.

12.

When assessing operational risks following an issuer's request for recording its securities in the CSD in accordance with Article 49(1) of Regulation (EU) No 909/2014, a CSD and its competent authority shall take into account the following criteria:

(a) the criterion set out in point (d) of paragraph 11;

(b) the securities settlement system operated by the CSD cannot process the currencies requested by the issuer.

13.

When assessing operational risks following a request for access by a requesting CSD, or a CCP, the receiving CSD and its competent authority shall take into account the criteria set out in paragraph 11.

14.

When assessing the operational risks following a request for access by a trading venue, the receiving CSD and its competent authority shall take into account at least the criteria set out in point (d) of paragraph 11.

SECTION 2

Procedure for refusal of access

(Articles 33(3), 49(4), 52(2) and 53(3) of Regulation (EU) No 909/2014)

Article 90
Procedure
1.

In the event of a refusal of access, the requesting party shall have the right to complain within one month from the receipt of the refusal to the competent authority of the receiving CSD, CCP or trading venue that has refused access to it in accordance with Articles 33(3), 49(4), 52(2) or 53(3) of Regulation (EU) No 909/2014.

2.

The competent authority referred to in paragraph 1 may request additional information concerning the refusal of access from the requesting and receiving parties.

The responses to the request for information referred to in the first subparagraph shall be sent to the competent authority within two weeks from the date of the receipt of the request.

In accordance with Article 53(3) of Regulation (EU) No 909/2014, within two business days from the date of the receipt of the complaint referred to in paragraph 1, the competent authority of the receiving party shall transmit the complaint to the relevant authority referred to in point (a) of Article 12(1) of Regulation (EU) No 909/2014 from the Member State of the place of establishment of the receiving party.

3.

The competent authority referred to in paragraph 1 shall consult the following authorities on its initial assessment of the complaint within two months from the date of the receipt of the complaint, as appropriate:

(a) the competent authority of the place of establishment of the requesting participant in accordance with Article 33(3) of Regulation (EU) No 909/2014;

(b) the competent authority of the place of establishment of the requesting issuer in accordance with Article 49(4) of Regulation (EU) No 909/2014;

(c) the competent authority of the requesting CSD and the relevant authority referred to in point (a) of Article 12(1) of Regulation (EU) No 909/2014 responsible for the oversight of the securities settlement system operated by the requesting CSD in accordance with Articles 52(2) and 53(3) of Regulation (EU) No 909/2014;

(d) the competent authority of the requesting CCP or trading venue in accordance with Article 53(3) of Regulation (EU) No 909/2014 and the relevant authority referred to in point (a) of Article 12(1) of Regulation (EU) No 909/2014 responsible for the oversight of the securities settlement systems in the Member State where the requesting CCP and trading venues are established in accordance with Article 53(3) of Regulation (EU) No 909/2014.

4.

The authorities referred to in points (a) to (d) of paragraph 3 shall respond within one month from the date of the request for consultation specified in paragraph 3. Where an authority referred to in points (a) to (d) of paragraph 3 does not provide its opinion within that time limit, it shall be deemed to have a positive opinion on the assessment provided by the competent authority referred to in paragraph 3.

5.

The competent authority referred to in paragraph 1 shall inform the authorities referred to in points (a) to (d) of paragraph 3 of its final assessment of the complaint within two weeks from the time limit provided in paragraph 4.

6.

Where one of the authorities referred to in points (a) to (d) of paragraph 3 disagrees with the assessment provided by the competent authority referred to in paragraph 1, any of them may refer the matter to ESMA within two weeks from the date when the competent authority referred to in paragraph 1 provides the information concerning its final assessment of the complaint in accordance with paragraph 5.

7.

When the matter has not been referred to ESMA, the competent authority referred to in paragraph 1 shall send a reasoned reply to the requesting party within two working days from the time limit provided in paragraph 6.

The competent authority referred to in paragraph 1 shall also inform the receiving party and the authorities referred to in points (a) to (d) of paragraph 3 of the reasoned reply referred to in the first subparagraph of this paragraph within two working days from the date where it sends the reasoned reply to the requesting party.

8.

In the event of a referral to ESMA referred to in paragraph 6, the competent authority referred to in paragraph 1 shall inform the requesting party and the receiving party of the referral within two working days from the date where the referral has been made.

9.

Where the refusal by the receiving party to grant access to the requesting party is deemed to be unjustified following the procedure provided for in paragraphs 1 to 7, the competent authority referred to in paragraph 1 shall, within two weeks from the time limit specified in paragraph 7, issue an order requiring that receiving party to grant access to the requesting party within three months from the date when the order enters into force.

The time limit referred to in the first subparagraph shall be extended to eight months in case of customised links that require significant development of IT tools, unless otherwise agreed by the requesting and receiving CSDs.

The order shall include the reasons why the competent authority referred to in paragraph 1 concluded that the refusal by the receiving party to grant access was unjustified.

The order shall be sent to ESMA, the authorities referred to in points (a) to (d) of paragraph 3, the requesting party and the receiving party within two working days after the date when it enters into force.

10.

The procedure referred to in paragraphs 1 to 9 shall also apply when the receiving party intends to withdraw access to a requesting party to whom it already provides its services.

CHAPTER XIV

AUTHORISATION TO PROVIDE BANKING TYPE OF ANCILLARY SERVICES

(Article 55(1) and (2) of Regulation (EU) No 909/2014)

Article 91
CSDs offering banking-type ancillary services themselves

An application for authorisation in accordance to point (a) of Article 54(2) of Regulation (EU) No 909/2014 shall include the following information:

(a) a copy of the decision of the management body of the applicant CSD to apply for authorisation and the minutes from the meeting where the management body approved the content of the application file and its submission;

(b) the contact details of the person responsible for the application for authorisation, where that person is not the one submitting the application for authorisation referred to under Article 17 of Regulation (EU) No 909/2014;

(c) evidence that proves the existence of an authorisation referred to in point (a) of Article 54(3) of Regulation (EU) No 909/2014;

(d) evidence that the applicant CSD meets the prudential requirements referred to in Article 59(1), (3) and (4) of Regulation (EU) No 909/2014 and the supervisory requirements referred to in Article 60 of that Regulation;

(e) evidence, containing any relevant documents including articles of incorporation, financial statements, audit reports, reports from risk committees, which proves that the applicant CSD complies with point (d) of Article 54(3) of Regulation (EU) No 909/2014;

(f) details concerning the recovery plan referred to in point (f) of Article 54(3) of Regulation (EU) No 909/2014;

(h) evidence supporting the reasons for not settling the cash payments of the CSD's securities settlement system through accounts opened with a central bank of issue of the currency of the country where the settlement takes place;

Article 92
CSDs offering banking-type ancillary services through a designated credit institution

An application for authorisation in accordance with point (b) of Article 54(2) of Regulation (EU) No 909/2014 shall contain the following information:

(a) a copy of the decision of the management body of the applicant CSD to apply for authorisation and the minutes from the meeting where the management body approved the content of the application file and its submission;

(b) the contact details of the person responsible for the application for authorisation, where the person is not the same person as the one submitting the application for authorisation referred to in Article 17 of Regulation (EU) No 909/2014;

(c) the corporate name of the credit institution to be designated in accordance with point (b) of Article 54(2) of Regulation (EU) No 909/2014, its legal status and registered address in the Union;

(d) evidence that the credit institution referred to in point (c) has obtained an authorisation referred to in point (a) of Article 54(4) of Regulation (EU) No 909/2014;

(e) the articles of incorporation and other relevant statutory documentation of the designated credit institution;

(f) the ownership structure of the designated credit institution, including the identity of its shareholders;

(g) the identification of any common shareholders of the applicant CSD and the designated credit institution and any participations between the applicant CSD and the designated credit institution;

(h) evidence that the designated credit institution meets the prudential requirements referred to in Article 59(1), (3) and (4) of Regulation (EU) No 909/2014 and the supervisory requirements referred to in Article 60 of that Regulation;

(i) evidence, including a memorandum of association, financial statements, audit reports, reports from risk committees, or other documents, which proves that the designated credit institution complies with point (e) of Article 54(4) of Regulation (EU) No 909/2014;

(j) the details of the recovery plan referred to in point (g) of Article 54(4) of Regulation (EU) No 909/2014;

(l) evidence supporting the reasons for not settling the cash payments of the CSD's securities settlement system through accounts opened with a central bank of issue of the currency of the country where the settlement takes place;

Article 93
Specific requirements
1.

Where the CSD applies for authorisation to designate more than one credit institution to provide banking-type ancillary services, its application shall include the following information:

(a) the information referred to Article 91 for each of the designated credit institution;

(b) a description of the role of each designated credit institution and the relations between them.

2.

Where the application to be authorised in accordance with point (a) or (b) of Article 54(2) of Regulation (EU) No 909/2014 is submitted after the authorisation referred to in Article 17 of that Regulation has been obtained, the applicant CSD shall identify and inform the competent authority of substantive changes referred to in Article 16(4) of Regulation (EU) No 909/2014 unless it has already provided the information in the process of review and evaluation referred to in Article 22 of that Regulation.

Article 94
Standard forms and templates for the application
1.

An applicant CSD shall provide an application for the authorisations referred to in points (a) and (b) of Article 54(2) of Regulation (EU) No 909/2014 in the format provided in Annex III to this Regulation.

2.

An applicant CSD shall submit the application referred to in paragraph 1 in a durable medium.

3.

An applicant CSD shall provide a unique reference number for each document that it submits in the application referred to in paragraph 1.

4.

An applicant CSD shall ensure that the information submitted in the application referred to in paragraph 1 clearly identifies to which specific requirement of this Chapter that information refers to and in which document that information is provided.

Reading this document does not replace reading the official text published in the Official Journal of the European Union. We assume no responsibility for any inaccuracies arising from the conversion of the original to this format.

This text is published under EUR-Lex's own terms of reuse, not a Legalize or public-domain licence. EUR-Lex
Creative Commons Attribution 4.0 International (CC BY 4.0)
© European Union, https://eur-lex.europa.eu — Source: EUR-Lex (Publications Office of the European Union). Reused under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence. Only EU legislation published in the printed Official Journal of the European Union is deemed authentic; consolidated texts are reproduced here for documentation purposes and have been reformatted to Markdown.