CyberTRIZPEDIA

NBB Governance Manual 2022

Comprehensive governance requirements for payment institutions. Three lines of defense, compliance, risk, internal audit.

Jurisdiction
Belgium
Issuer
National Bank of Belgium
Effective
2022-10-11

Sectors

Banking & FinanceProfessional ServicesRegulatory / Legal

This regulation may be summarised but not reproduced. Article text is available from the official source. Official source →

Articles (529)

3. Relevant thematic NBB circulars:4. International reference documents:2. Relevant thematic NBB circulars:3. International reference documents:2. NBB Regulation:3. Relevant thematic NBB circulars:4. International reference documents:2. Relevant thematic NBB circulars:3. International reference documents:2. Relevant thematic NBB circulars:3. International reference documents:1. Banking Law: Articles 168, 168/1, 170 (consolidated supervision), 190 to 194 (su2. Relevant thematic NBB circulars:3. International reference documents:5.1. GOVERNANCE RULES APPLICABLE INDIVIDUALLY TO (MIXED) FINANCIAL HOLDING5.2.1. Approval and exemption regime for (mixed) financial holding companies5.2.2. Governance rules applicable to groups where a Belgian entity is responsible for5.2.3. Governance rules applicable to Belgian credit institutions and Belgian (mixed) f5.2.3.1. Basic principle5.2.3.2. Distribution of tasks between the institution governed by the law of another Mem5.2.3.3. Management of intra-group conflicts of interest5.2.4. Governance rules applicable to Belgian credit institutions and Belgian (mixed) f6.1. GOVERNANCE REPORTING2. Relevant thematic NBB circulars:6.1.1.1. Governance memorandum at institutional level6.1.1.2. Group governance memorandum6.1.1.3. Assessment by the supervisory authority2. Relevant thematic NBB circulars:3. Relevant thematic NBB circulars:4. International reference documents:3. Policy as regards composition and functioning of the management bodies (with imp4. Governance structure and organisation chart (with impact on the group, if applic5. Internal control and key functions (with impact on the group, if applicable)6. Organisational structure (with impact on the group, if applicable)7. Remuneration policy8. Code of conduct and behaviour (with impact on the group, if applicable)9. ICT security and continuity11. Status governance memorandum with dateArticle Section 10. Overview of changes ............................................................1. Introduction ...................................................................1.1. Context ........................................................................1.2. Scope ..........................................................................1.3. Methodology ....................................................................1.4. Proportionality ................................................................1.5. Definitions ....................................................................2. Qualities required of significant shareholders .................................2.1. Prudential expectations.........................................................2.2. Suitability assessment .........................................................2.3. Charter of the families/partners ...............................................2.4. Prohibition on granting loans, credits or guarantees to acquire shares .........3. Suitability of directors, senior managers and persons responsible for independen3.1. Fit & proper ...................................................................3.2. Plurality of mandates ..........................................................3.3. Loans to managers ..............................................................4. Appropriate organisation of the business .......................................4.1. Management structure ...........................................................4.1.1. General requirements ...........................................................4.1.2. Statutory governing body .......................................................4.1.3. Management committee ...........................................................4.1.4. Specialised committees .........................................................4.2. Organisational set-up ..........................................................4.2.1. Organisational framework and structure .........................................4.2.2. Outsourcing ....................................................................4.2.3. Central administration in Belgium ..............................................4.3. Risk culture and integrity .....................................................4.3.1. Risk culture ...................................................................4.3.2. Corporate values and code of conduct ...........................................4.3.3. Remuneration ...................................................................4.3.4. Conflicts of interest ..........................................................4.3.5. Internal and external reporting of breaches (whistleblowing) ...................4.3.6. Prevention of money laundering and terrorist financing .........................4.3.7. Diversity ......................................................................4.4. Internal control and independent control functions .............................4.4.1. Internal control framework .....................................................4.4.2. Risk management framework ......................................................4.4.3. New products and significant changes ...........................................4.4.4. Independent control functions ..................................................4.4.4.1. General aspects ................................................................4.4.4.2. Compliance function ............................................................4.4.4.3. Risk management function .......................................................4.4.4.4. Internal audit function.........................................................4.5. ICT security and continuity management .........................................4.5.1. ICT security ...................................................................4.5.2. Business continuity management .................................................5. Governance at group level ......................................................5.1. Governance rules applicable individually to (mixed) financial holding companies5.2. Governance rules applicables to groups .........................................6. Prudential reporting on governance and transparency.............................6.1. Governance reporting ...........................................................6.2. Transparency towards staff and the public ......................................0. OVERVIEW OF CHANGES1. INTRODUCTION1.1. CONTEXT1.2. SCOPE1.3. METHODOLOGY1.4. PROPORTIONALITY1.5. DEFINITIONS2. Relevant thematic NBB circulars:3. International reference documents:2.1. PRUDENTIAL EXPECTATIONS2.2. SUITABILITY ASSESSMENT2.3. CHARTER OF THE FAMILIES/PARTNERS2.4. PROHIBITION ON GRANTING LOANS, CREDITS OR GUARANTEES TO ACQUIRE SHARES3. SUITABILITY OF DIRECTORS, SENIOR MANAGERS1. Banking Law: Articles 3, 83°, 19, 20, 21, 27-31, 60, 61, 62, 62/1, 72, 73, 86,2. NBB Regulation:3. Relevant thematic NBB circulars:4. International reference documents:3.1.1. GENERAL3.1.2. SENIOR MANAGEMENT3.1.3. STAFF MEMBERS OF THE INSTITUTION3.2. PLURALITY OF MANDATES3.3. LOANS TO MANAGERS4. APPROPRIATE ORGANISATION OF THE BUSINESS2. Relevant thematic NBB circulars:3. International reference documents:2. Relevant thematic NBB circulars:3. International reference documents:4.1.2.1.1. Members and status4.1.2.1.2. Independent directors within the meaning of Article 3, 83° of the Banking Law4.1.2.1.3. Selection of directors – suitability and diversity4.1.2.1.4. Chair of the statutory governing body4.1.2.2. Tasks4.1.2.2.1. General policy function4.1.2.2.2. Supervisory function4.1.2.3. Functioning2. Relevant thematic NBB circulars:3. International reference documents:4.1.3.1. Composition4.1.3.1.1. Chair of the management committee (Chief Executive Officer)4.1.3.1.2. Chief Financial Officer (CFO)4.1.3.1.3. Director responsible for the risk management function (Chief Risk Officer)4.1.3.1.4. Senior officer responsible for combating money laundering and terrorist financin4.1.3.1.5. Financial holding companies4.1.3.2. Tasks4.1.3.3. Functioning4.1.3.4. Derogations2. Relevant thematic NBB circulars:3. International reference documents:4.1.4.1. General4.1.4.2. Composition4.1.4.2.1. Audit committee4.4.2.2. Risk committee4.4.2.3. Remuneration committee4.4.2.4. Nomination committee4.1.4.3. Functioning4.1.4.4. Exemptions for non-significant institutions4.1.4.5. Group context2. NBB Regulation:3. Relevant thematic NBB circulars:4. International reference documents:4.2.1.1 Organisational framework4.2.1.2. Decision-making process, reporting lines and distribution of duties4.2.1.3. Administrative and accounting organisation4.2.1.4. Know your structure4.2.1.5. Complex structures and non-standard or non-transparent activities2. Relevant thematic NBB circulars:3. International reference documents:1. Banking Law: Article 434.3. RISK CULTURE AND INTEGRITY2. Relevant thematic NBB circulars:3. International reference documents:2. Relevant thematic NBB circulars:3. International reference documents:2. European regulations:3. Relevant thematic NBB circulars:4. International reference documents:4.3.3.1. Identified staff4.3.3.2. EBA guidelines4.3.3.3. Impact of the CAC4.3.3.4. Financial instruments4.3.3.5. Termination and severance payments4.3.3.6. Collection of data on remuneration2. NBB Regulation:3. Relevant thematic NBB circulars:4. International reference documents:4.3.4.1. Conflict of interest policy at institutional level4.3.4.2. Conflict of interest policy for staff4.3.4.3. General measures applicable to all types of conflicts of interest4.3.5. INTERNAL AND2. Other laws:3. Relevant thematic NBB circulars:4. International reference documents:4.3.5.1. Internal reporting of breaches4.3.5.2. External reporting of breaches2. NBB Regulation / Relevant thematic NBB circulars and international reference doc1. Law: Article 31 of the Banking Law and Law of 18 September 20172. NBB Regulation:3. Relevant thematic NBB circulars:4. International reference documents:2. Relevant thematic NBB circulars:3. International reference documents:2. Relevant thematic NBB circulars:3. International reference documents:2. NBB Regulations:3. Relevant thematic NBB circulars:4. International reference documents:4.4.4.1.1. Three lines of defence4.4.4.1.2. Persons responsible for control functions4.4.4.1.3. Independence of control functions4.4.4.1.4. Resources of the control functions4.4.4.1.5. Methodology and access4.4.4.1.6. Reporting4.4.4.1.7. Periodic assessment4.4.4.1.8. Removal2. NBB Regulation:ContextPrudential Expectations – Significant ShareholdersOngoing Prudential Requirement for ShareholdersScopeReporting of Capital Structure ChangesInformation Obligations on Significant ShareholdersMethodologyCharter of Families/PartnersProhibition on Loans, Credits or Guarantees to Acquire SharesProportionalityFit & Proper Requirement – GeneralResponsibility for Fit & Proper AssessmentInstitution's Determination of Senior ManagementDefinitionsNotification Requirements for Senior Managers below MC LevelManagers of Foreign Branches as Senior ManagementPrudential expectationsIndependence of Control Function HoldersFit & Proper Assessment for All StaffSuitability assessmentSufficient Time Dedication – General Availability PrincipleInternal Rules on External FunctionsCharter of the families/partnersQuantitative Restrictions on Plurality of Mandates for Significant InstitutionsLoans to Managers – Legal FrameworkProhibition on granting loans, credits or guarantees to acquire sharesNotification Obligation for Loans Exceeding €500,000Requirement for Sound and Appropriate Organisational StructuresFit & properTransparent Management Structure RequirementDivision of Functions at Highest LevelPlurality of mandatesSui Generis Governance Model for Credit InstitutionsClear Definition of Management ResponsibilitiesLoans to managersComposition of the Statutory Governing BodySize of the Statutory Governing BodyManagement structureNatural Persons RequirementSocial Status of DirectorsGeneral requirementsRole of Independent Non-Executive DirectorsIndependent Directors in Specialised CommitteesStatutory governing bodyIndependence Criteria and Comply-or-ExplainGeneral Suitability Requirements for DirectorsManagement committeeIndividual Suitability Criteria for DirectorsCollective Suitability of the Statutory Governing BodySpecialised committeesDiversity Policy and CompositionGender Diversity TargetOrganisational set-upAnnual Review of Diversity ComplianceRole of the Chair of the Statutory Governing BodyOrganisational framework and structureGeneral Responsibility of the Statutory Governing BodyGeneral Policy Function – Strategy SettingOutsourcingScope of Strategy and Policy SettingRisk Tolerance and Strategic Risk DecisionsCentral administration in BelgiumMajor Transaction Criteria and NotificationApproval of Liquidity Recovery PlanRisk culture and integrityPeriodic Assessment of Organisational StructureAssessment of Independent Control FunctionsRisk cultureCollegial Decision-Making – Dominance PreventionMinutes of Statutory Governing Body MeetingsCorporate values and code of conductInternal Rules of ProcedureMeeting FrequencyRemunerationNon-Executive Directors' Self-AssessmentNotification of Task DistributionConflicts of interestInduction and Training of Statutory Governing Body MembersMandatory Establishment of Management CommitteeInternal and external reporting of breaches (whistleblowing)Management Committee – Minimum MembershipPrevention of money laundering and terrorist financingMembership Requirement – Executive MembersSuitability and Employment Status of Management Committee MembersDiversityChair of Management Committee (CEO) – Separation from Chair of Statutory Governing BodyChief Risk Officer – Membership of Management CommitteeInternal control and independent control functionsCRO – Proportionality Derogation for Non-Significant InstitutionsSenior Officer Responsible for AML/CFTInternal control frameworkFinancial Holding Companies – Management Committee CompositionManagement Committee – TasksRisk management frameworkManagement Committee – Annual/Biennial Reporting ObligationManagement Committee – Semi-Annual Declaration on Prudential ReportingNew products and significant changesManagement Committee – Internal Division of TasksManagement Committee – Notification of Task DivisionIndependent control functionsManagement Committee – Minutes and Decision LoyaltyManagement Committee – Internal Rules of ProcedureGeneral aspectsManagement Committee – Regular MeetingsManagement Committee – DerogationsCompliance functionGovernance Model – General Qualitative CriteriaSpecialised Committees – General PrincipleRisk management functionSpecialised Committees – Four Required CommitteesRole of Specialised CommitteesInternal audit functionAdditional Voluntary CommitteesCommittee Composition – Independence RequirementsICT security and continuity managementCommittee Composition – Minimum Members and Overlap RestrictionsCommittee Composition – Good Practice RecommendationsICT securityCommittee Members – Specific Expertise RequirementsSupervisory Assessment of Committee MembersBusiness continuity managementAudit Committee TasksRisk Committee TasksGovernance rules applicable individually to (mixed) financial holding companiesRemuneration Committee TasksNomination committee tasksGovernance rules applicables to groupsNomination committee – succession planningCommittee functioning – open discussionsGovernance reportingCommittee documentation requirementsCommittee internal rules of procedureTransparency towards staff and the publicCommittee member access to information and reportingInter-committee interactionRotation of committee chairs and membersParticipation of external guests in committee meetingsExemptions for non-significant institutions – committee requirementsStatutory governing body responsibilities in absence of committeesGroup context – committee derogationsOrganisational frameworkDecision-making process, reporting lines and distribution of dutiesReporting linesSegregation of dutiesAdministrative and accounting organisationReliable financial and prudential reportingKnow your structure – Directors' understandingStructures for broad/complex/cross-border activitiesGroup structure transparencyComplex structures and non-transparent activities – risk assessmentStatutory governing body responsibilities for complex structuresSpecial mechanisms and fiscal prevention policyOutsourcing – appropriate organisational structuresGENERALOutsourcing – operational risk and internal controlCentral administration in Belgium – authorisation conditionSENIOR MANAGEMENTCentral administration – availability in BelgiumCentral administration – responsiveness to NBBSTAFF MEMBERS OF THE INSTITUTIONCentral administration – registration and meeting locationRisk CultureCorporate Values and Code of Conduct – statutory governing body obligationsCommunication and training on ethical standardsScope of internal codes of conductNon-discrimination, gender-neutral policies and risk awarenessRemuneration policy – general obligationIdentification of staff subject to remuneration requirementsIdentification criteria for identified staffDocumentation of the identification processMinimum proportion of identified staffImpact of the CAC – remuneration of independent directorsCompositionVariable remuneration – financial instruments requirementTermination and severance paymentsMembers and statusTermination Payments as Variable RemunerationExemptions for Severance PaymentsIndependent directors within the meaning of Article 3, 83° of the Banking LawDisclosure of Remuneration DataReporting on High EarnersSelection of directors – suitability and diversityConflict of Interest Policy at Institutional LevelConflict of Interest Policy for StaffChair of the statutory governing bodyScope of Staff Conflict of Interest PolicyGeneral Measures to Manage Conflicts of InterestGeneral policy functionInternal Reporting of Breaches (Whistleblowing)Internal Reporting – Procedures and Management OversightSupervisory functionInternal Reporting – Privacy ComplianceExternal Reporting – NBB Breach Reporting SystemFunctioningExternal Reporting – Protection of ReportersAML/CFT – Policy RequirementAML/CFT – Policy ContentDiversity PolicyCompositionInternal Control Framework – General RequirementsInternal Control Framework – Adaptation and Information ExchangeChair of the management committee (Chief Executive Officer)Internal Control – Policies and ProceduresInternal Control – Approval and Communication of PoliciesChief Financial Officer (CFO)Internal Control – Recommended Governance PoliciesIndependent Control Functions – Verification RoleDirector responsible for the risk management function (Chief Risk Officer)Risk Management Framework – Holistic RequirementNew Products and Significant ChangesSenior officer responsible for combating money laundering and terrorist financingIndependent Control Functions – Three Functions RequiredThree Lines of DefenceFinancial holding companiesCoordination Among Control FunctionsUniversal Scope of Control FunctionsFunctioningAML/CFT Responsible Person (AMLCO)Hierarchical Level of Persons Responsible for Control FunctionsDerogationsIndependence of Control FunctionsReporting Lines of Control Function HeadsResources of Independent Control FunctionsMethodology of Control FunctionsGeneralAccess Rights of Control FunctionsRegular Reporting to Statutory Governing BodyCompositionContent of Annual Activity ReportOwn-Initiative Reports to Statutory Governing BodyAudit committeeReporting via Specialised CommitteesPeriodic Assessment of Independent Control FunctionsRisk committeeRemoval of Independent Control Function HeadsCompliance Function – ResponsibilitiesRemuneration committeeCompliance Function – Expertise and Training RequirementsAnnual Report on Compliance FunctionNomination committeeRisk Management Function – Core ResponsibilitiesRisk Management Function – Head (CRO) Membership and ResponsibilitiesFunctioningInternal Audit Function – Role and PurposeInternal Audit Function – Reporting LinesExemptions for non-significant institutionsICT Control and Security MechanismsStatutory Governing Body – ICT and Information Security Risk ManagementGroup contextICT Staffing and TrainingICT Strategy – Governing Body ResponsibilityInformation Security PolicyInformation Security FunctionChief Information Security Officer (CISO)Independence and Seniority of the Information Security FunctionOrganisational frameworkBusiness Continuity Management and Recovery PlanGood Governance Requirements at Group LevelDecision-making process, reporting lines and distribution of dutiesGovernance Rules Applicable Individually to (Mixed) Financial Holding CompaniesApproval and Exemption Regime for (Mixed) Financial Holding CompaniesAdministrative and accounting organisationExemption regime for (mixed) financial holding companiesScope of group governance rulesKnow your structureConsolidated compliance obligations of the Belgian institution responsible for the groupApplication of governance rules at group levelComplex structures and non-standard or non-transparent activitiesGroup-wide governance arrangementsSpecific group governance requirementsGovernance rules for Belgian institutions within foreign-led groupsResponsibility of the subsidiary regarding group coherence and information flowGoverning bodies' obligations to ensure group compliance with subsidiary rulesManagement of intra-group conflicts of interestIntra-group mechanisms for conflict of interest identificationInternal mechanisms supporting conflict of interest managementGovernance rules for Belgian institutions within third-country groupsIntermediate parent undertaking requirement for third-country groupsGovernance memorandum – description and approvalMain Prudential Governance ReportsGovernance Memorandum – ConfidentialityGovernance Memorandum – Updates and ResponsibilityIdentified staffGovernance Memorandum – Outline and AnnexesGroup Governance Memorandum – IntegrationEBA guidelinesGroup Governance Memorandum – Content RequirementsGovernance Memorandum – Communication to Supervisory AuthorityImpact of the CACReport on Assessment of Internal Control – ContentReport on Assessment of Internal Control – FrequencyFinancial instrumentsTransparency Towards StaffTransparency Towards the Public – Governance Memorandum PublicationTermination and severance paymentsDisclosure of Risk Management InformationDisclosure of Remuneration Policy InformationCollection of data on remunerationDisclosure of ESG Risk InformationConflict of interest policy at institutional levelConflict of interest policy for staffGeneral measures applicable to all types of conflicts of interestInternal reporting of breachesExternal reporting of breachesThree lines of defencePersons responsible for control functionsIndependence of control functionsResources of the control functionsMethodology and accessReportingPeriodic assessmentRemovalApproval and exemption regime for (mixed) financial holding companiesGovernance rules applicable to groups where a Belgian entity is responsible for complianceGovernance rules applicable to Belgian credit institutions and Belgian (mixed) financial holdingBasic principleDistribution of tasks between the institution governed by the law of another Member StateManagement of intra-group conflicts of interestGovernance rules applicable to Belgian credit institutions and Belgian (mixed) financial holdingGOVERNANCE MEMORANDUMGovernance memorandum at institutional levelGroup governance memorandum