Retained EU Law 2017 United Kingdom

Commission Delegated Regulation (EU) 2017/392 of 11 November 2016 supplementing Regulation (EU) No 909/2014 of the European Parliament and of the Council with regard to regulatory technical standards on authorisation, supervisory and operational requirements for central securities depositories (Text with EEA relevance)

At a glance

What's here

48 compliance obligations

Who this Act binds

Plus 1 non-business duty on Crown ministers, regulators, local authorities or tribunals — shown collapsed under each section below.

What this Act requires

Sections that create concrete duties on businesses or carry penalties. Procedural and definitional sections are folded into the “Browse other sections” expander at the bottom of each group. Click any section title to read the source text on legislation.gov.uk.

s.art007

Information concerning groups

  • Include group information in CSD authorisation application
s.art011

Risk monitoring tools and governance arrangements

  • Include governance and risk monitoring details in CSD authorisation application
s.art021

Transparency

  • Include pricing policy and accounting information in authorisation application
s.art028

Cash settlement

  • Include cash settlement procedures in your CSD authorisation application
s.art031

Legal risks

  • Provide clear and enforceable rules and contracts across all jurisdictions
s.art032

General business risks

  • Describe your risk-management systems and IT tools to the regulator
s.art040

Information to be provided to the competent authority

  • Provide information and compliance report to the competent authority
s.art041

Periodic information relevant for the reviews

  • Provide periodic information to the competent authority for reviews
s.art042

Statistical data to be delivered for each review and evaluation

  • Provide statistical data to the competent authority each review period
s.art046

Content of the application

  • Submit recognition application in durable medium, paper and electronic, with unique reference numbers
s.art047

Risk monitoring tools of CSDs

  • Set up documented risk management policies and procedures
s.art048

Risk monitoring committees

  • Establish risk, audit and remuneration committees
s.art049

Responsibilities of key personnel in respect to the risks

  • Ensure staffing, governance, and appointment of risk, tech, and compliance officers
s.art050

Conflicts of interest

  • Put in place and maintain a conflicts of interest policy
s.art051

Audit methods

  • Establish and maintain a compliant internal audit function
s.art052

Sharing audit findings with the user committee

  • Share audit findings with your user committee when they relate to certain matters
s.art053

General requirements

  • Maintain full and accurate records of all activities
s.art054

Transaction/settlement instruction (Flow) records

  • Maintain detailed records of all settlement instructions and transactions
s.art055

Position (Stock) records

  • Keep detailed records of securities positions, accounts and settlement fails
s.art056

Ancillary Services Records

  • Keep accurate records of your ancillary services
s.art057

Business Records

  • Maintain adequate business records including specified documents
s.art058

Additional records

  • Keep additional records requested by the regulator
s.art059

General reconciliation measures

  • Perform daily reconciliation for each securities issue and maintain accurate records
s.art060

Reconciliation measures for corporate actions

  • Complete reconciliation before determining corporate action entitlements and update accounts after processing
s.art063

Reconciliation measures for the common depository model

  • Reconcile securities balances daily with the common depository
s.art064

Additional measures where other entities are involved in the reconciliation process

  • Reconcile records daily and provide account data to participants
s.art065

Problems related to reconciliation

Other duties (1) — Crown / regulator
  • CSD must analyse and resolve reconciliation mismatches — and report repeated errors Statutory regulator
s.art066

General operational risks and their assessment

  • Identify and assess operational risks including pandemics and cyber-attacks
s.art067

Operational risks that may be posed by key participants

  • Identify and manage operational risks from key participants
s.art068

Operational risks that may be posed by critical utilities and critical service providers

  • Manage risks from critical utilities and service providers
s.art069

Operational risks that may be posed by other CSDs or market infrastructures

  • Ensure reliable and secure arrangements with other CSDs or market infrastructures
s.art070

Operational risk-management system and framework

  • Have a documented operational risk management framework with clear roles and IT controls
s.art071

Integration of and compliance with the operational and enterprise risk-management system

  • Integrate operational risk management and report incidents
s.art073

Audit and testing

  • Audit and test operational risk management framework every two years
s.art075

IT tools

  • Maintain resilient, secure, and tested IT systems
s.art076

Strategy and policy

  • Maintain business continuity policy and ensure settlement resilience
s.art077

Business impact analysis

  • Conduct and maintain a business impact analysis and risk analysis
s.art078

Disaster recovery

  • Maintain a disaster recovery plan with a two-hour recovery target for critical operations
s.art079

Testing and monitoring

  • Monitor and test your business continuity and disaster recovery plans at least annually
s.art080

Maintenance

  • Regularly review and update business continuity policy and disaster recovery plan
s.art081

Highly liquid instruments with minimal market and credit risk

  • Use defined and objective methodology for internal risk assessment of financial instruments
s.art082

Appropriate timeframe for access to assets

  • Implement procedures for timely access to assets and notify regulator of changes
s.art083

Concentration limits to individual entities

  • Hold financial assets within acceptable concentration limits
s.art084

Conditions for the adequate protection of linked CSDs and of their participants

  • Meet all conditions when linking your CSD to another CSD
s.art085

Monitoring and management of additional risks resulting from the use of indirect links or intermediaries to operate CSD links

  • Manage risks when using intermediaries for CSD links
s.art086

Reconciliation procedures for linked CSDs

  • Reconcile securities accounts daily with linked CSDs
s.art089

Risks to be taken into account by CSDs and competent authorities

  • CSDs must consider legal, financial and operational risks when assessing access requests
s.art094

Standard forms and templates for the application

  • Submit authorisation application in standard format with supporting documents
Browse 49 other sections — procedural / definitional / commencement
uri:annex/iii/division/templates/division/2

uri:annex/iii/division/templates/division/2

s.art001

Definitions

s.art002

Determination of most relevant currencies

s.art003

Practical arrangements for the consultation of the relevant authorities referred to in Article 12(1)(b) and (c) of Regulation (EU) No 909/2014

s.art004

Identification and legal status of applicant CSDs

s.art005

General information concerning policies and procedures

s.art006

Information concerning services and activities of the CSD

s.art008

Financial reports, business plan, and recovery plan

s.art009

Organisational chart

s.art010

Staffing policies and procedures

s.art012

Compliance, internal control and internal audit functions

s.art013

Senior management, management body and shareholders

s.art014

Management of conflicts of interest

s.art015

Confidentiality

s.art016

User committee

s.art017

Record-keeping

s.art018

Goals and objectives

s.art019

Handling of complaints

s.art020

Requirements for participation

s.art022

Communication procedures with participants and other market infrastructures

s.art023

Book-entry form

s.art024

Intended settlement dates and measures for preventing and addressing settlement fails

s.art025

Integrity of the issue

s.art026

Protection of participants' and their clients' securities

s.art027

Settlement finality

s.art029

Participant default rules and procedures

s.art030

Transfer of participants and clients' assets in case of a withdrawal of authorisation

s.art033

Operational risks

s.art034

Investment policy

s.art035

Capital requirements

s.art036

CSD links

s.art037

Access rules

s.art038

Request for additional information

s.art039

Criteria for participation of a CSD

s.art043

Other information

s.art044

Information to be supplied to the authorities referred to in Article 22(7) of Regulation (EU) No 909/2014

s.art045

Exchange of information between the competent authorities referred to in Article 22(8) of Regulation (EU) No 909/2014

s.art061

Reconciliation measures for the registrar model

s.art062

Reconciliation measures for the transfer agent model

s.art072

Operational risk-management function

s.art074

Mitigation of operational risk through insurance

s.art087

DVP settlement through CSD links

s.art088

Receiving and requesting parties

s.art090

Procedure

s.art091

CSDs offering banking-type ancillary services themselves

s.art092

CSDs offering banking-type ancillary services through a designated credit institution

s.art093

Specific requirements

s.art095

Transitional provisions

s.art096

Entry into force and application

Explore more

Browse legislation

Find other UK business legislation with related guidance.