(21)
Article 76 is amended as follows: paragraph 1 is replaced by the following: ‘1. Member States shall ensure that the management body approves and at least every two years reviews the strategies and policies for taking up, managing, monitoring and mitigating the risks the institution is or might be exposed to, including those posed by the macroeconomic environment in which it operates in relation to the status of the business cycle, and those resulting from the current and short-, medium- and long-term impacts of environmental, social and governance (ESG) factors. Member States may, taking into consideration the principle of proportionality, allow the management bodies of small and non-complex institutions to review the strategies and policies referred to in the first subparagraph every two years.’ ; in paragraph 2, the following subparagraphs are added: ‘Member States shall ensure that the management body develops and monitors the implementation of specific plans that include quantifiable targets and processes to monitor and address the financial risks arising in the short, medium and long term from ESG factors, including those arising from the process of adjustment and from transition trends in the context of the relevant Union and Member State regulatory objectives and legal acts in relation to ESG factors, in particular the objective to achieve climate neutrality, as well as, where relevant for internationally active institutions, third-country legal and regulatory objectives. The quantifiable targets and processes to address the ESG risks included in the plans referred to in the second subparagraph of this paragraph shall consider the latest reports and measures prescribed by the European Scientific Advisory Board on Climate Change, in particular in relation to the achievement of the climate targets of the Union. Where the institution discloses information on ESG matters in accordance with Directive 2013/34/EU of the European Parliament and of the Council (*16), the plans referred to in the second subparagraph of this paragraph shall be consistent with the plans referred to in Article 19a or 29a of that Directive and shall, in particular, include actions with regard to the business model and strategy of the institution that are consistent across both plans. Member States shall ensure a proportionate application of the second and third subparagraphs for the management bodies of small and non-complex institutions, indicating in what areas a waiver or a simplified procedure may be applied. (*16) Directive 2013/34/EU of the European Parliament and of the Council of 26 June 2013 on the annual financial statements, consolidated financial statements and related reports of certain types of undertakings, amending Directive 2006/43/EC of the European Parliament and of the Council and repealing Council Directives 78/660/EEC and 83/349/EEC (OJ L 182, 29.6.2013, p. 19).’;" in paragraph 4, the second subparagraph is replaced by the following: ‘The management body in its supervisory function and, where one has been established, the risk committee shall determine the nature, the amount, the format, and the frequency of the information on risk which it is to receive. In order to assist in the establishment of sound remuneration policies and practices, the risk committee shall, without prejudice to the tasks of the remuneration committee, examine whether incentives provided by the remuneration system take into consideration risks, including those resulting from the impacts of ESG factors, capital, liquidity and the likelihood and timing of earnings.’ ; paragraph 5 is replaced by the following: ‘5. Member States shall, in accordance with the proportionality requirement laid down in Article 7(2) of Commission Directive 2006/73/EC (*17), ensure that institutions have internal control functions independent of the operational functions and which shall have sufficient authority, stature, resources and access to the management body. Member States shall ensure that: (*17) Commission Directive 2006/73/EC of 10 August 2006 implementing Directive 2004/39/EC of the European Parliament and of the Council as regards organisational requirements and operating conditions for investment firms and defined terms for the purposes of that Directive (OJ L 241, 2.9.2006, p. 26).’;" the internal control functions ensure that all material risks are properly identified, measured and reported; the internal control functions provide a comprehensive view of the whole range of risks that the institution is exposed to; the risk management function is actively involved in elaborating the institution’s risk strategy and in all its material risk management decisions and has control over the effective implementation of the risk strategy; the internal audit function performs an independent review of the effective implementation of the institution’s risk strategy; the compliance function assesses and mitigates compliance risk and ensures that the institution’s risk strategy takes into account compliance risk and that compliance risk is adequately taken into account in all material risk management decisions. the following paragraph is added: ‘6. Member States shall ensure that the internal control functions have direct access and can report directly to the management body in its supervisory function. To that end, the internal control functions shall be independent of the members of the management body in its management function and of senior management, and shall in particular be able to raise concerns and warn the management body in its supervisory function, where appropriate, or where specific risk developments affect or can affect the institution, without prejudice to the responsibilities of the management body pursuant to this Directive and Regulation (EU) No 575/2013. The heads of internal control functions shall be independent senior managers with distinct responsibility for the risk management, compliance and internal audit functions. Where the nature, scale and complexity of the activities of the institution do not justify appointing a specific person for the risk management function or the compliance function, another senior person that performs other tasks within the institution may fulfil the responsibilities for the compliance or risk management functions, provided that there is no conflict of interest and that the person responsible for the risk management function and the compliance function: The internal audit function shall not be combined with any other business line or control function of the institution. The heads of the internal control functions shall not be removed without prior approval of the management body in its supervisory function.’ ; fulfils the suitability criteria and requirements of knowledge, skills and experience necessary for the different areas concerned; and has sufficient time to perform both control functions correctly.
← (e) · All articles · (a) →
Source: EUR-Lex CELLAR · retrieved 2026-09-04 · Text as adopted (Official Journal); later amendments are not incorporated in this text.