Financial Examination Focus in 2026
Ⅰ.Preface
The FSC’s 2026 Financial Examination Focuses are developed with reference to: (1) the recent development of domestic and international political and economic conditions; (2) the external stakeholders’ concerns; (3) the FSC’s supervisory priorities; (4) the key focuses of financial regulations in 2025; and (5) matters that needed to be scrutinized and identified by the FEB. The FSC selected a total of 113 examination focuses for different sectors of the financial industry.
Given the frequent occurrence of domestic financial investment fraud in recent years, the fact that fraud takes on evolving forms and that funds obtained fraudulently are often transferred overseas and may be laundered through virtual accounts, and considering that there are continued reports of improper sales practices by wealth management specialists or sales personnel, risks to information security within the financial industry remain. Therefore for 2026, areas of particular concern include “fraud prevention,” “anti-money laundering (AML),” “financial consumer rights protection,” and “cyber resilience.”
Ⅱ. 2026 Financial examination focuses for each type of financial service industries
Financing Holding Companies (FHCs)
A. The Implementation of AML/CFT/CPF requirements: Group-level AML/CFT programs are to be established that include an intra-group information sharing policy as well as procedures for AML/CFT purposes, based on the laws and regulations of countries or jurisdictions where the foreign branches (or subsidiaries) are located; implementation of such programs is to be reviewed.
B. The implementation of compliance system: Effectiveness of the design and operation of FHC’s compliance systems.
C. Management of investee companies:
a. FHC should establish appropriate guidelines and control mechanisms for investment and M&A management, and implement them, including mechanisms for control and management of confidentiality and prevention of insider trading, pre-investment assessments, review and approval procedures, public announcements and filings, compliance, post-investment monitoring of returns, and risk management, establish control, management, and audit mechanisms to regulate conflicts of interest and improper transactions.
b. FHC shall establish investment management policy and procedures for major foreign investee companies (including investments as a co-investor) that includes measures for ensuring the sound operations and compliance with regulations and the establishment of corresponding supervision, control, and management mechanisms.
c. FHC shall establish control and management mechanisms for business risks, regularly ensure the soundness of its subsidiaries and their compliance with applicable regulatory requirements (including the establishment of control and management mechanisms for the prevention of conflicts of interest and related-party transactions as well as managerial operations), and provide guidance to subsidiaries as follows:
(a) Legal compliance: The effectiveness of subsidiaries’ systems established to ensure legal compliance, and the implementation of relevant internal regulations (including understanding and complying with applicable anti-money laundering laws and regulations, and making improvements of examination findings), and the establishment of a sound whistleblower system.
(b) Risk management: Subsidiaries are to implement appropriate risk management for the enterprises in which they have invested (including those made overseas and in mainland China). Such management must address anti-money laundering, credit risk, market risk, and operational risk. Subsidiaries shall report relevant information to the FHC.
(c) Cybersecurity and personal data protection: Subsidiaries’ system updates, network and cybersecurity detection and protection methods, anomaly response and recovery procedures, cybersecurity control over customer databases, personal data protection measures, and personal data leakage response drills mechanisms.
D. Corporate governance:
a. Strengthening of the functions of the board of directors and functional committees: Examinations focus on whether the organization and functions of the board of directors, the establishment and operation of the audit committee, risk management committee, and other functional committees, the rules of order and decision-making procedures of the board of directors, and the implementation of the board’s agenda are in line with applicable laws and regulations as well as the company’s own internal rules (e.g. procedures for convening meetings of the board of directors; whether parties actually recuse themselves from board meetings where they have a personal interest in matters on the agenda; the manner in which a company communicates with directors or other persons who express concerns about the operations of its board of directors, and how the company handles the situation; how accurately and completely a company comments on a summary of its board of directors meeting minutes), the fiduciary duties and responsibilities of directors; and the establishment of a chief corporate governance officer and other corporate governance personnel.
b. Management mechanisms for responsible persons’ concurrent positions and hierarchical delegation of responsibilities: Verify whether the internal management mechanisms for responsible persons’ concurrent positions, concurrent positions held by the responsible persons are in compliance with the law, regulations, and internal rules; for any person holding directorate-level authority other than the chairperson or general manager, and whether the internal hierarchical delegation of responsibilities mechanism is in line with authority.
c. Mechanisms for reporting the holdings of major shareholders: Mechanisms for identifying the beneficial owners of major shareholders, including understanding whether major shareholders accurately report their beneficial owners in accordance with regulations; and procedures for processing cases where it has been found that information on a major shareholder has not been reported in accordance with regulations.
d. Data filing of related parties and control and management of related-party transactions:
(a) Whether FHC has established a database of related parties and verify whether it has filed information correctly and regularly confirmed the accuracy of the related parties’ information.
(b) Mechanisms for control and management of related-party transactions and the legal compliance status, including transactions with substantively related parties and the management of such transactions.
e. Establishment and implementation of the whistleblower system: Whether the whistleblower system is independent and effective, and verify that it truly protects whistleblowers’ interests.
f. Examinations focus on the following questions regarding the internal consultants retained by FHC:
(a) Whether, when appointing or reappointing a consultant, FHC comprehensively evaluates their qualifications, professional skills, any negative news coverage, previous work experience in another institution, and performance in any such previous position.
(b) Whether the scope of a consultant’s job duties is clearly defined, and whether their authority is accompanied by a commensurate level of accountability.
(c) Whether the consultant’s compensation and performance evaluation system are based on quantitative and qualitative standards.
E. Risk management mechanisms:
a. Whether FHC has established proper risk management mechanisms for regional risks (including mechanisms for managing the purchase of shares in foreign financial organizations).
b. Whether FHC has established response strategies and group risk management mechanisms for responding to international economic changes, such as business continuity management plans and stress tests for responding to changes in the financial industry.
c. Examinations focus on whether FHC acts in a timely manner to review its risk appetite control measures for overall risk exposures (including those made overseas and in mainland China), whether it has established risk early warning and handling mechanisms, and whether it conducts rolling adjustments of monitoring indicators.
F. Cross-selling and data sharing: The security maintenance measures and legal compliance for cross-selling operations implemented by FHC and its subsidiaries, whether data sharing among financial institutions is in compliance with the Personal Data Protection Act, and Guidelines for Data Sharing between Financial Institutions, and establish appropriate internal controls and implementation of information security.
G. Internal audit
a. The overall planning, overseeing and executing of internal audits and the adequacy of human resources as well as the independence of internal audit units.
b. Examinations focus on: (a) the internal audit units have implemented suitable division of labor, based on the audited parties and the key points of the audits, to ensure that all subsidiaries are effectively audited; (b) an oversight mechanism for internal audits (included outsourced audits of foreign branches) has been established and implemented; and (c) FHC has strengthened the implementation and management of auditing operations (including the implementation of internal control and information security protection in the operating procedures for remote work and work from home) to ensure the quality of the audit and proper oversight of corrective actions taken to address identified deficiencies.
c. FHC’s confirmation, assessment, and oversight of the effectiveness of the risk-based auditing systems adopted by its banking subsidiaries.
d. The auditing scope for subsidiaries covers their key lines of business.
Domestic Banks
A. Domestic banks’ (including their OBUs) compliance with anti-money laundering, counter-terrorism financing, and non-proliferation of weapons regulations:
a. Institutional risk assessment and internal controls framework: The completeness and reasonableness of institutional risk assessment as well as the appropriateness and effectiveness of overall internal control framework, the implementation of AML-related measures based on a risk-based approach.
b. Due diligence measures for account opening and ongoing reviews, and risk rating assessments: The identification and verification of beneficial owners; the geographical location and reasonableness of the purpose for account opening; verification of the authenticity and reasonableness of the operating locations of corporate clients; understanding the source of wealth of high-risk customers; understanding whether the customer‘s transactions are consistent with their identity, background, business, and given purpose for account opening during an ongoing due diligence; and understanding the reasonableness of the customer‘s source of funds under a risk-based approach; the completeness and reasonableness of customer risk assessment methodology and the review procedures should be commensurate with customers’ risk level (including enterprises or personnel providing virtual asset services or high-risk third-party payment service providers, and measures for enhancing ongoing business relationships).
c. Ongoing monitoring of accounts and transactions and investigation of suspicious transactions alerts: The reasonableness of transaction monitoring patterns and the setting of the monetary amount thresholds, the screening and verification of money laundering red flags or signs that customers and their transaction counterparties may meet the conditions for inclusion on a sanctions list or of being high-risk foreigners as well as the independence and effectiveness of monitoring operations and the implementation of control measures related to international sanctions; and the assessment of whether the sources of funds, as well as customers’ background, business activities, and transaction purposes, are consistent and reasonable.
d. Suspicious transaction reporting procedures and quality of reporting: The handling of suspected ML/TF/PF transactions (including reporting, confidentiality procedures, and record-keeping).
e. Organization and personnel: The professionalism and adequacy of the chief officer and personnel, the adequacy of resource allocation, education/training and conduct management, and the quality and reliability of independent tests conducted by internal audit units and accountants of the effectiveness of AML/CFT/CPF systems.
B. Compliance system and its implementation:
a. Compliance system and its implementation: Examinations focus on such matters as qualification requirements and training of the chief compliance officer and compliance personnel, and implementation of the compliance functions for compliance risk management and supervision framework (including establishment of consultation and communication channels for legal compliance, analysis and reporting of material compliance deficiencies or malpractice, legal advice for new business or products, and evaluation of compliance operations.
b. Compliance with key laws and regulations: Examinations focus on such matters as:(a) personal information safeguards (including custody and utilization of customer data, cyber security mechanisms, etc.); (b) consumer protection requirements for trust business (including product suitability and the state of banks’ outsourced administration of contract performance guarantee mechanisms for real estate development trusts and transaction fund trusts for presold properties); (c) wealth management (including customer acceptance standards, appropriateness of customer investment portfolios, and high-risk concentration controls), and (d) the calculation of regulatory capital and risk-weighted assets (including the use of the loan-to-value method for the calculation of property risk exposures), the implementation of and policies concerning liquidity risk management, liquidity stress tests, and emergency response plans.
C. Overseas exposure management:
a. Management of foreign branches / subsidiaries: The oversight by the board of directors; head office oversight and allocation of resources to compliance operations at foreign branches; AML operations; credit risk concentration; assets quality; loan granting and credit checking, post-lending management, and sufficiency of the allowance for doubtful assets; operational risks; reporting mechanism for material events; mechanism for communication with host-country authorities; compliance operations (including the independence and fitness of chief compliance officer and compliance personnel, the state of compliance with local laws and regulations by foreign branches/subsidiaries, and establishment of compliance risk self-assessment, monitoring and control mechanisms); legal education and ethics evaluations for bank employees; and the quality of internal audits and tracking of correction plan of deficiencies.
b. Risk management for foreign securities investment, and risk management for loans, investments, and interbank placements/deposits in New Southbound countries and mainland China (including control and calculations of exposure limits, and loan granting, credit investigation and post-lending management, managing the purchase of shares in foreign financial organizations), and management mechanism for finance-related enterprises in mainland China.
c. Taking risk management measures in response to changes in the international financial situation.
D. Financial derivatives:
a. Customer credit risk control and management system: Compliance of (a) approval and management of hedging/trading purpose credit lines; (b) management mechanism for customer risk concentration; and (c) internal operating systems and procedures for initial margin and margin call requirements 【e.g., types of initial margin (including compliance of types of security eligible for initial margin, and the haircut rates and method for calculating net collateral value of the securities used as initial margin)】.
b. Appropriateness of sales operations for financial derivatives and structured products: Know-your-customer (KYC) procedures, customer identification procedures and review mechanisms for professional investors, product risk rating, product suitability assessment, qualifications of sales personnel, appropriateness and completeness of approaches, contents and record keeping of product risks disclosure.
c. Valuation and management mechanism for financial derivatives: The establishment of a valuation system for high-risk products to offer price quotes and calculate mark-to-market profits and losses on the basis of the product categories and type of linked underlying assets (high-risk and non-high-risk products) and establish verification procedures for the valuation system. With respect to non-high-risk products for which valuation system is not applied and price enquiry approach is used, an internal operation procedure for price reasonability checking should be established.
E. Risk management of securities investments and trading rooms:
a. Control and management of securities investments: The formulation, control, and management of risk limits, the setting and execution of stop-loss limits, and the appropriateness of the hedging strategy.
b. Internal control and management of trading rooms: The appropriateness of trading limits and authorizations, the completeness and credibility of front/middle/back-office internal control mechanisms (including the prevention of conflicts of interest between equity traders), and the integrity and thoroughness of the scope of internal audits and self-inspections for trading rooms.
F. Examinations focus on the following financial consumer protection matters (including the state of implementation of measures to protect the interests of persons with disabilities customers):
a. Know-your-customer (KYC) operations; product suitability assessment; fairness and reasonableness of contract terms; control of sale procedures (including telemarketing, inappropriate bundling or inducements to purchase mortgage-backed life insurance or invest in financial products through credit expansion); new products listing and reviewing procedures; the remuneration scheme for sales personnel; consumer dispute handling mechanism; implementation of principles for fair treatment of consumers (including the calculation and collection of credit card default charges and interest on revolving credit); the establishment and implementation measures (e.g. actions of the board of directors, internal supervision mechanisms, etc.) for friendly financial culture and services (including online banking and mobile app for the visually impaired), protection of personal information (e.g. security measures for the collection, processing, and use of personal information, protection of the personal information of cardholders and credit card applicants that credit card issuers provide to third parties, compliance with the Guidelines for Data Sharing between Financial Institutions, and personal data breach response drills).
b. Implementation of internal control and management measures for preventing wealth management specialists from misappropriating client funds: Examinations focus on a bank’s control mechanisms for bank statements, its verification of the accuracy and authenticity of customer email addresses, its implementation of monitoring mechanisms and establishment of investigation procedures for cases where wealth management specialists are suspected of misappropriating funds from customer accounts (including its definition of different types of suspected misappropriations and how it carries out investigations into suspected misappropriations), how reasonably related the salaries and bonuses of wealth management specialists are to their performance targets, and whether a bank sells financial products that have not been approved by the FSC.
c. Concurrent operation of insurance broker and insurance agent business (including the solicitation of insurance products, control mechanism for verifying application documents signed personally by proposer, and mechanism verifying customers’ sources of funds for the purchase of insurance products).
d. Use of automated tools to provide securities investment consulting services: Examinations focus on a bank’s supervision of the use of algorithms, KYC operations, and recommendations regarding investment portfolios, fairness and impartiality of system operations, investment portfolio rebalancing, oversight by a special committee, and pre-use disclosures to customers.
G. Implementation of digital financial services:
a. Provision of control mechanisms for online account opening and service applications, mechanisms for protecting the security of users’ personal information or transactions, customer due diligence conducted, mechanisms for monitoring unusual transactions, the reporting of and monitoring mechanisms for suspicious or fraudulently-opened accounts, inquiries of customers’ information 【Ownership Rights for Customer Data, Consumer Information Protection, Protection of Customer Rights, Dispute Resolution Mechanisms, and Control Mechanisms Regulating the Management of Third-Party Service Providers (TSPs)】.
b. Security design for e-banking transactions (such as signature certificates, one-time passwords, biometrics, and key storage on mobile devices); provision of security management for application program interface (API) services (including customer data safety in open banking services), and management mechanism (including regular security checks) for the development and launch of mobile apps.
c. Electronic signature mechanisms: management of secure ID verification, secure signatures, and electronic signature platforms.
H. Implementation of corporate governance system:
a. Fulfillment of the functions of the board of directors: The organization and functions of the board of directors; overseeing of the establishment and operations of the audit committee and risk management committee; oversight of various business policies and management mechanism; and appropriateness of the board’s exercise of its powers in handling and responding to material events (such as major violations of laws and regulations, and significant exposures that adversely affect bank’s financial and business status).
b. Internal management mechanism for the responsible persons’ holding of concurrent positions, the compliance of laws and internal rules, and the appointment of a chief corporate governance officer and other corporate governance personnel.
c. Examinations focuses on (a) the compliance of interested-party/substantively interested-party transactions (including loans, real estate, purchase of services and items, and other transactions) and control mechanism (including the self-regulatory mechanism for substantively interested parties); (b) irregularities with respect to strategies, counterparties, and prices for transactions within the group or with substantively interested parties (including major shareholders, directors, and supervisors); (c) whether those transactions involve conflicts of interest or other compliance matters and (d) reasonableness of expense payment.
d. Communication and contact mechanisms for shareholder with controlling interest (including communication and contact principles and management rules, topics of communication, procedures for communication accompanied by a manager, and communication management procedures and records).
e. Independence and effectiveness of the whistleblower system (including internal operating procedures and control mechanisms, such as channels for internal and external whistleblowers and whistleblower protection measures).
I. Management of information and communication security: Such matters as control and management measures for preventing abnormalities in the server system (including the container) and program (e.g. information security management, complete testing, and source code inspection for major changes in system architecture); implementation standards for financial institutions’ information operations resilience (including assessments of the effect on bank operations of interruptions to core information systems, as well as the adequacy of backup systems); control measures for storage, transfer, and retrieval of personal information 【including information security management mechanism for the MyData Digital Service Personalization Platform (MyData Platform)】; cyber security measures (e.g. zero trust architecture, firewall, intrusion detection, vulnerability scanning, penetration testing, and other security defense measures and patching cadence, management of IoT device usage, information security incident monitoring, reporting, and handling), and supply chain risk management (e.g. conducting cybersecurity assessment when selecting suppliers, supervision of outsourced contractors, security testing for delivery system and components, and appropriateness of contracts); security controls for cloud services (such as encryption and key management, identity verification and access, configuration security management, audit trails and monitoring) and cloud backup mechanisms.
J. Business operation systems:
a. Internal control mechanism for prevention of loan fraud (including loan granting process, credit check procedures, and post-lending management); whether the security of procedures and risk management on virtual asset custody services are implemented in accordance with established policies and procedures; business continuity management mechanism and the personnel turnover rate.
b. The compliance of outsourcing of operations: the appropriateness of identified and evaluated material standards, the adequacy of revised internal regulations, the appropriateness and effectiveness of management based on risk-based methods (including decision-making assessments, trustee due diligence, risk assessments, day-to-day supervision mechanisms, customer information protection, emergency response, and termination of entrustments), the appropriateness of cross-border outsourcing and use of cloud service management services, and the integrity of reporting information, etc.
K. Fraud prevention measures:
a. Implementation of the “Regulations Governing Fraud Crime Hazard Prevention by Financial Institutions and Businesses or Personnel Providing Virtual Asset Services” (including the criteria for identifying abnormal accounts and credit cards or transactions among deposit-taking institutions and credit card service providers, as well as measures concerning the ongoing due diligence of such accounts and credit card holders; notifications among deposit-taking institutions and credit card service providers, recordkeeping and notification of data transactions and account management; joint defense reporting system and earmarking of funds; and the return of remaining funds).
b. Establishment and implementation of early warning indicators for suspected illegal or obviously irregular transactions.
c. Implementation of in-person customer care inquiry procedures.
d. Implementation of a gray lists mechanism.
e. Review procedures for opening corporate accounts.
f. Control measures for account opening procedures and accounts held by high-risk foreigners.
g. Watch-listed account monitoring indicators and methods to improve making deductions from reported amounts.
h. Situations involving the provision of virtual account services.
L. Risk management and regulatory compliance of credit business: The credit investigation system for credit business (such as financing and factoring of accounts receivable, mortgage, loans for unsold properties, land (including land in industrial zones and idle industrial land) and construction loans, and syndicated loans like project finance); risk assessment and analysis; risk pricing; credit reviews; loan approval procedures; post-lending management; control mechanisms to prohibit loan agency services; compliance with the regulation that prohibits from granting loans to SMEs with condition of re-deposit of the loan proceeds; the reasonableness of reallocating a building firm’s working-capital loan for construction purposes;, and controls on the use and flow of funds for unsold housing unit loans; and the compliance with Article 72-2 of the Banking Act.
M. Operations of internal audits:
a. The independence of the audit unit; the suitability of audit personnel; compliance with requested auditing items by the competent authority; mechanism for reporting of and response to material events; implementation of audits of foreign branches (including the head office’s management of internal audit operations at foreign branches); oversight of follow-up on audit findings and implementation of corrective measures; and benefits achieved by adopting risk-based auditing.
b. Audit unit’s efforts for strengthening audit screening principles, frequency, and audit focuses to prevent wealth management specialists from misappropriating client funds (including business dealings between wealth management specialists and customers as well as specialists’ related accounts).
c. Audits of concurrently operated insurance broker or insurance agent businesses.
N. Management of investees: Such as oversight of subsidiaries’ establishment and implementation of operation and risk control rules (including control mechanism for interested-party transactions); verify the consistency of actual lines of business with those listed in the original business plan; and verify the establishment of regular reporting mechanism and management measures for subsidiaries’ major business plans, transactions, business performance, and exposures, and business related to venture capital within the bank’s control, with regard to the control mechanisms for the raising of capital for venture investment.
O. Concurrent operation by banks of underwriting and proprietary trading involving bonds, beneficiary securities, asset-backed securities: Position limits for the aforementioned lines of business; control procedures for the underwriting of bonds issued by affiliates of the same business group; and risk management and product suitability systems for the aforementioned lines of business.
P. Operation management of concurrent electronic payment businesses (including control mechanism for identity verification and transaction limits).
Foreign Bank Branches in Taiwan
A. Compliance with regulations governing anti-money laundering, counter-terrorism financing, and non-proliferation of weapons (including OBUs):
a. Institutional risk assessment and internal controls framework: The completeness and reasonableness of institutional risk assessment as well as the appropriateness and effectiveness of overall internal control framework, the implementation of AML-related measures based on a risk-based approach.
b. Due diligence measures for account opening and ongoing reviews, and risk rating assessments: The identification and verification of beneficial owners; the geographical location and reasonableness of the purpose for account opening; verification of the authenticity and reasonableness of the operating locations of corporate clients; understanding the source of wealth of high-risk customers; understanding whether the customer’s transactions are consistent with their identity, background, business, and given purpose for account opening during an ongoing due diligence; and understanding the reasonableness of the customer’s source of funds under a risk-based approach; the completeness and reasonableness of customer risk assessment methodology and the review procedures should be commensurate with customers’ risk level (including enterprises or personnel providing virtual asset services or high-risk third-party payment service providers, and measures for enhancing ongoing business relationship).
c. Ongoing monitoring of accounts and transactions and investigation of suspicious transactions alerts: The reasonableness of transaction monitoring patterns and the setting of monetary amount thresholds, the screening and verification of money laundering red flags or signs that customers and their transaction counterparties may meet the conditions for inclusion on a sanctions list or of being high-risk foreigners as well as the independence and effectiveness of monitoring operations and the implementation of control measures related to international sanctions; and the assessment of whether the sources of funds, as well as customers’ background, business activities, and transaction purposes, are consistent and reasonable.
d. Suspicious transaction reporting procedures, and quality of reporting: The handling of suspected ML/TF/PF transactions (including reporting, confidentiality procedures, and record-keeping).
e. Organization and personnel: The professionalism and adequacy of the chief officer and personnel, the adequacy of resource allocation, education/training and conduct management, and the quality and reliability of independent tests by internal audit units and accountants of the effectiveness of AML/CFT/NPW systems.
B. Provision by banks of information and consultation services pertaining to offshore financial derivatives: The state of compliance with respect to such matters as the clientele served, the scope of products offered, the content of services offered, the offering of price quotes, and the distribution of dividend income.
C. Wealth management business: Such as the criteria for accepting customers, the processes for KYC, the appropriateness of the overall investment portfolio of customers, the control of the concentration of high risk, the product review procedures, the management of the sales process, the sales personnel remuneration, and the dispute resolution mechanisms.
D. Financial derivatives:
a. Customer credit risk management system.
b. Appropriateness of sales operations for financial derivatives and structured products (including customer identification procedures and review mechanisms for professional investors).
c. Valuation and control and management mechanism for financial derivatives.
E. Compliance system and implementation status: (a) training for compliance personnel; (b) implementation of compliance functions (including the establishment of consultation and communication system for legal compliance, analysis and reporting of material compliance deficiencies or malpractice, provision of compliance advices for new business or products, and evaluation of compliance self-assessments; and (c) implementation of information security operations.
F. Compliance with legal limits and risk management of the use of funds.:
a. Control and management of credit limits in mainland China.
b. Control and management mechanisms for calculating the regulated total deposit balance.
c. Sources and uses of funding for extending loans and investments, asset and liability maturity allocation, and liquidity risk management.
G. Management of outsourcing processes: the appropriateness of identified and evaluated material standards, the adequacy of revised internal regulations, the appropriateness and effectiveness of management based on risk-based methods (including decision-making assessments, trustee due diligence, risk assessments, day-to-day supervision mechanisms, customer information protection, emergency response, and termination of entrustments), the appropriateness of cross-border outsourcing and use of cloud service management services, the integrity of reporting information, and the appropriateness of the division of authority and responsibilities between the dedicated unit and the head office or authorized regional headquarters, etc.
H. Personal information protection and management of information and communication security.
I. Concurrent operation by banks of underwriting and proprietary trading involving bonds, beneficiary securities, asset-backed securities: Position limits for the aforementioned lines of business; control procedures for the underwriting of bonds issued by affiliates of the same business group; and risk management and product suitability systems for the aforementioned lines of business.
J. Management of project finance: Risk assessment and analysis; measures to strengthen protection of creditor rights; and post-loan management.
K. Implementation of internal control and management measures for preventing wealth management specialists from misappropriating client funds: Such as control mechanisms for bank statements, and systems for monitoring wealth management specialists in cases of suspected misappropriations of client funds (including defining different types of suspected misappropriations and how investigations into suspected misappropriations are carried out).
L. Electronic signature mechanisms: management of secure ID verification, secure signatures, and electronic signature platforms.
Credit Cooperatives
A. Compliance with regulations governing anti-money laundering, counter terrorism financing, and non-proliferation of weapons:
a. Institutional risk assessment and internal controls framework: The completeness and reasonableness of institutional risk assessment as well as the appropriateness and effectiveness of overall internal control framework, the implementation of AML-related measures based on a risk-based approach.
b. Customer due diligence measures and risk rating assessments: The identifying and due diligence of beneficial owners, methodology for customer risk assessments, and the completeness and reasonableness of customer due diligence (it must be commensurate with risks).
c. Ongoing monitoring of accounts and transactions: The reasonableness of transaction monitoring patterns and the setting of monetary amount thresholds, the screening and verification of money laundering red flags or signs that customers and their transaction counterparties may meet the conditions for inclusion on a sanctions list or of being high-risk foreigners as well as the independence and effectiveness of monitoring operations.
d. Suspicious transaction reporting procedures, and quality of reporting: The handling of suspected ML/TF/PF transactions (including reporting, confidentiality procedures, and record-keeping).
e. Organization and personnel: The professionalism and adequacy of the chief officer and personnel, the adequacy of resource allocation, education and training, and the quality and reliability of independent tests by internal audit units and accountants of the effectiveness of AML/CFT/CPF systems.
B. Credit risk management:
a. Operations of the credit review committee.
b. Risk management for related-party loans and large loans.
c. Risk management (including interest rate pricing and post-lending management), compliance, and the implementation of reporting operations for real estate loans: Such as construction loans, residential loans, home improvement loans, unsold properties loans and land loans (including idle land in industrial zones), the reasonableness of reallocating a building firm’s working-capital loan for construction purposes, and controls on the use and flow of funds for unsold housing unit loans, etc.
d. Whether responsible persons, or staff and other interested parties have engaged in irregular financial movements with customers (including applying for loans under the names of other persons).
e. Compliance with the regulation that prohibits from granting loans to SMEs with condition of re-deposit of the loan proceeds.
C. Financial customer protection:
a. Fairness and reasonableness of contract terms; the sales personnel remuneration system; protection of the personal information of customers; consumer dispute resolution mechanisms, principles for fair treatment of consumers; the establishment and implementation measures (e.g., actions of the board of directors, internal supervision mechanisms, etc.) for friendly financial culture and services (including rights and interests protection for persons with disabilities customers) and the supply of information and disclosure of fees for consumer loans and interest rate adjustments in accordance with the contract.
b. Personal information protection: Examinations focus on whether (a) security maintenance measures for the collection, processing, and use of customer data; (b) data sharing between financial institutions are in compliance with the Guidelines for Data Sharing between Financial Institutions; whether the examinee has a personal information incident response plan in place; and whether it carries out awareness, education, and training activities with respect to personal information protection.
c. Cooperation with other industries in the promotion of financial products and implementation of internal control-related measures for insurance business: e.g., KYC, product suitability evaluation, sales process management, and control mechanisms for promotion of insurance business involving credit and deposits; developing control mechanisms to prohibit the bundling of financial products with mortgages or engaging in improper sales methods during the loan process.
d. Implementation of internal control and management measures for preventing employees from misappropriating client funds: e.g., control mechanisms for preventing money transfer between employees and customers, or employees conducting transactions on behalf of customers, use of supervisors’ card (password) and control mechanisms, control mechanisms for online banking transactions, and control mechanisms for bank statements.
D. Fraud prevention measures:
a. Implementation of the “Regulations Governing Fraud Crime Hazard Prevention by Financial Institutions and Businesses or Personnel Providing Virtual Asset Services” (including the criteria for identifying abnormal accounts and credit cards or transactions among deposit-taking institutions and credit card service providers, as well as measures concerning the ongoing due diligence of such accounts and credit card holders; notifications among deposit-taking institutions and credit card service providers, recordkeeping and notification of data transactions and account management; joint defense reporting system and earmarking of funds; and the return of remaining funds).
b. Establishment and implementation of early warning indicators for suspected illegal or obviously irregular transactions.
c. Implementation of in-person customer care inquiry procedures.
d. Implementation of a gray lists mechanism.
e. Review procedures for opening corporate accounts.
f. Control measures for account opening procedures and accounts held by high-risk foreigners.
E. Liquidity control and management measures: formulation of a liquidity risk management policy and the establishment of an appropriate information system to measure and monitor liquidity risks; regular disclosure of qualitative and quantitative information on liquidity risk management; the appropriateness of conducting a regular review of the adequacy of liquidity risk limits and warning standards; regular reviews of the sources of large amounts of funds, usage of such funds, and concentration risk; and the establishment of an emergency response plan and procedures for obtaining funds under emergency circumstances.
F. Management of information and communication security: Manpower, training, and management for information security, system security and control for online financial business (including online financial services); transaction security design; cyber security measures (e.g. firewall, intrusion detection, vulnerability scanning; email social engineering exercises, penetration testing, and other security defense measures and patching, management of IoT device usage, and monitoring, notification, and response mechanisms for cyber-attack incidents); application programming interface (API) security management;control and management measures for storage, transfer, and retrieval of personal information; procedures for collecting and evaluating cyber security intelligence; and information system and services supply chain risk management (e.g. supervision of outsourced contractors, security testing for delivery system and components, and appropriateness of contracts).
G. Operations and implementation of the credit cooperative governance system:
a. Fulfillment of the functions of the board of directors and board of supervisors: The organization and functions of the board of directors and board of supervisors; and the appropriateness of oversight of the various business policies and management mechanisms.
b. Mechanism for control of interested-party loans and transactions and the compliance status and reasonableness of expense payment.
c. Establishment and implementation of the whistleblower system: The independence and effectiveness of the whistleblower system and the integrity of its protection of the whistleblower’s interests.
H. Implementation of the compliance and risk management system:
a. Whether laws and regulations are updated in a timely manner, and the appropriateness of compliance training and compliance reports.
b. Establishment and operations of the risk management committee.
I. Operations of internal audits: Such as whether internal audit units have conducted independent and unbiased audits.
Bills Finance Companies
A. Compliance with regulations governing anti-money laundering, counter-terrorism financing, and non-proliferation of weapons: Institutional risk assessments and internal controls framework; customer due diligence measures and risk rating assessment; ongoing monitoring of accounts and transactions; suspicious transaction reporting procedures and quality of reporting; education and training; and the quality and reliability of independent tests by internal audit units and accountants.
B. Corporate governance and business continuity management mechanisms: Protection of shareholder interests; strengthening of the functions of directors; fulfillment of the functions of supervisors; respect for the rights and interests of interested parties (safeguards for internal whistleblowers); enhancement of information transparency; the establishment and implementation status of business continuity management mechanisms; and the state of compliance with principles for communication with controlling shareholders.
C. The implementation of internal control and compliance mechanisms for the granting of credit to interested parties (including substantively interested parties), and conduct of transactions other than credit extensions with such parties.
D. Implementation of sustainability notes (including compliance with the Self-Regulatory Rules for Sustainability Notes).
E. Control of risks from non-guarantee commercial paper and compliance with self-regulatory rules (including the appropriateness of the underwriting limit for non-guarantee commercial paper from individual issuers and the same industry, control over the multiples of the balance of non-guarantee commercial paper to the issuer’s net worth, and control and management of a company’s holdings of non-guaranteed commercial paper issued by a single group of related parties or by the members of a single corporate group).
F. Internal operating rules for guarantee and endorsement business.
a. Control of the degree of concentration of guarantees and related risks in specific sectors (e.g. the real estate sector).
b. The internal control and internal audit mechanisms established in accordance with the Central Bank Regulations on Real Estate Mortgages Issued by Bills Companies and their implementation.
c. The reasonableness of reallocating a building firm’s working-capital loan to construction purposes, and controls on the use and flow of funds for unsold housing unit loans.
G. The interest-rate pricing of commercial paper guaranteed and underwritten by financial institutions (including whether the institutions consider such factors as market rates, their own funding costs, operating costs, expected credit losses, reasonable profits and so on).
H. Risk control mechanisms for investments and positions in bonds and implementation (including investment valuation, price review, capital allocation, management of interest risks associated with fluctuating interest rates, and investment positions and mechanisms for the control and management of their credit ratings) and implementation of compliance with the foreign-currency risk limits of foreign currency bond brokerages, self-operated businesses, and investment businesses.
I. Liquidity risk management mechanism and the implementation (including compliance with the “Self-Regulation for the Liquidity Risk Management of Bills Finance Companies”).
J. Implementation of information and communication security management measures:
a. Security measures for IT systems: Implementation of vulnerability scanning and penetration testing of IT systems, and vulnerability patching and improvement measures.
b. Network security measures: Version control of the company website and firewall mechanisms, information security monitoring, and event reporting and response mechanisms.
c. Personal information protection: Security and protection measures for the storage, processing, and transmission of personal information.
Securities Firms
A. Compliance by securities firms (including their OSUs) with regulations governing anti-money laundering, counter-terrorism financing, and non-proliferation of weapons:
a. Institutional risk assessment and internal controls framework: The completeness and reasonableness of institutional risk assessment as well as the appropriateness and effectiveness of overall internal control framework, the implementation of AML-related measures based on a risk-based approach.
b. Customer due diligence measures and risk rating assessments: The identification and due diligence of beneficial owners, methodology for customer risk assessments, and the completeness and reasonableness of customer due diligence (it must be commensurate with customer risks).
c. Ongoing monitoring of accounts and transactions: The reasonableness of transaction monitoring patterns and the setting of monetary amount thresholds, the screening and verification of money laundering red flags or signs that customers and their transaction counterparties may meet the conditions for inclusion on a list of specially designated nationals, and the independence and effectiveness of monitoring operations.
d. Suspicious transaction reporting procedures, and quality of reporting: The handling of suspected ML/TF/PF transactions (including reporting, confidentiality procedures, and record-keeping).
e. Organization and personnel: The professionalism and adequacy of the chief officer and personnel, the adequacy of resource allocation, education and training, and the quality and reliability of independent tests by internal audit units of the effectiveness of AML/CFT/NPW systems.
B. Implementation of the compliance system: establish a risk management structure for legal compliance, ensure the independence of rights and responsibilities related to legal compliance, implement reporting and supervision concerning legal compliance, confirm the timely updating of operational and management regulations, and engage in self-assessments on the implementation of legal compliance.
C. Brokered trading of domestic securities and unrestricted-purpose lending business: Examinations focus on the appropriateness of procedures for account openings, KYC operations, credit checks, credit limit management, processing of customer trading orders, delivery of trade reconciliation statements, handling of out-trades, correction of account numbers, handling of defaults, screening for insider conflicts of interest, and appropriateness of procedures for correction of trading orders executed on behalf of underage financial consumers who have subsequently reached adulthood.
D. Wealth management business: The establishment and implementation of internal control mechanisms for account opening and product sales; services or products provided to customers through sub-brokerage, wealth management trusts, or proprietary trading in the business premises, whether customers meet related qualifications and criteria, and whether the securities firm has fully performed its information disclosure and reporting obligations and established a product suitability system and product review standards, whether trusts have been managed pursuant to the terms provided in trust agreements for the beneficiary’s interests or for another specific purpose, the use of the securities involved, and how earnings from trusts are distributed.
E. Brokerage trading of foreign securities: management mechanisms for the classification and management of investor based on their profiles; KYC operations; customer identification procedures and review mechanisms for professional investors; differentiation of offered investment products based on differences between individual investor, whether criteria for selecting the foreign securities offered to investors and for which investors order for purchase through the financial institution via dollar cost averaging as well as professional investors’ purchase and sale of foreign virtual asset ETFs have been determined based on the securities’ level of risk and liquidity, whether transaction prices are calculated and whether fees are collected based on established fee schedules etc., and whether related information has been adequately disclosed, management mechanisms for rewards or gift certificates provided for bank channels, and asset custody for the sub-brokerage business, etc.
F. Financial derivative transactions: The securities firms’ procedures for signing contracts with customers in financial derivative transactions, product suitability system (KYC and KYP operations), customer identification procedures and review mechanisms for professional investors, control of the marketing process, customer complaint processing, contract rescission and settlement, product appraisal and quotation, risk management, and the status of hedging operations.
G. Implementation of digital financial services: Online services provided for opening accounts and applying for related services (such as applying for API access and DMA electronic trading), control mechanisms for managing customer personal information, identity verification, and abnormal transactions.
H. Risk management mechanism: Whether response measures are formulated for the market risk caused by the pandemic, changes in the global economic and political situation, and rising interest rates; whether the securities firm has formulated and fully implemented business continuity management regulations; examine whether the operations of risk management mechanisms are adequate, such as supervision and management by the board of directors and management, the risk management committee, risk measurement (model verification, sensitivity analysis, and stress testing), management of transaction limits, stop loss management, and mechanisms for addressing exceptions.
I. Oversight and management of foreign subsidiaries (a) the securities firm’s formulation of rules that set out required control tasks for its subsidiary companies; (b) the firm’s supervision of the efforts of its subsidiaries to establish an internal control system; (c) the firm has established review mechanisms to verify that the domestic securities investments of the firm’s customers comply with domestic laws and regulations (including KYC due diligence procedures, confirmation that clients’ funds are not derived from Taiwan or mainland China, and confirmation that clients are not nationals of mainland China); and (d) key matters in the firm’s oversight and management of its subsidiaries (including business management, financial matters, operational matters, legal compliance, and management of internal audits).
J. Operations outsourcing by securities firms: Examinations focus on whether a securities firm is required to use a risk-based approach to assess outsourcing risks, to adopt internal outsourcing rules, and to provide a list of the matters that an outsourcing agreement must specify.
K. Corporate governance implementation: Implementation of corporate governance and strengthening the functions of the board of directors, including such matters as whether the firm has established the internal whistleblower system and implementation thereof; it has created the post of a chief corporate governance officer, and the implementation of compliance matters; and verify that the firm observes the prohibition against any independent director serving more than three consecutive terms, and management mechanisms for employees, financial transactions, and reimbursement of expenses with affiliated enterprises.
L. Implementation of financial consumer protections: Examinations focus on such matters as the establishment and implementation (e.g. actions of the board of directors, internal supervision mechanisms) of friendly financial culture and services (including protection of the rights and interests of persons with disabilities customers), measures to prevent financial and investment fraud schemes (e.g. conduct of employee awareness and education activities, establishment of a special anti-fraud section on the firm’s website, ongoing demonstration of concern for customers), whether KYC and KYP are being implemented on the sales of funds; product suitability assessments, risk disclosure, compensation structures for sales personnel, and whether there is any inducement to customers to invest in financial products through credit expansion, whether the firm fully discloses information on service charges and commissions received, appropriateness of the distribution of performance bonuses and the firm’s handling consumer complaints, and whether data on the MyData platform as well as personal information have been collected, processed, and used appropriately, whether data sharing between financial institutions is in compliance with the Personal Data Protection Act, and Guidelines for Data Sharing between Financial Institutions, and whether the firm has established appropriate internal control regulations.
M. Principles for Fair Treatment of Consumers: Implementation of the Principles for Fair Treatment of Consumers by Financial Services Enterprises.
Securities investment trust companies
A. Compliance with regulations governing anti-money laundering, counter-terrorism financing, and non-proliferation of weapons:
a. Institutional risk assessment and internal controls framework: The completeness and reasonableness of institutional risk assessment as well as the appropriateness and effectiveness of overall internal control framework, the implementation of AML-related measures based on a risk-based approach.
b. Customer due diligence measures and risk rating assessment: The identification of beneficial owners, methodology for customer risk assessment, and the completeness and reasonableness of customer due diligence (it must be commensurate with risks).
c. Ongoing monitoring of accounts and transactions: The reasonableness of transaction monitoring patterns and the setting of monetary amount thresholds, the screening and verification of money laundering red flags or signs that customers and their transaction counterparties may meet the conditions for inclusion on a list of specially designated nationals, and the independence and effectiveness of monitoring operations.
d. Suspicious transaction reporting procedures, and quality of reporting: The handling of suspected ML/TF/PF transactions (including reporting, confidentiality procedures, and record-keeping).
e. Organization and personnel: The professionalism and adequacy of the chief officers and personnel, education and training, and independent tests by internal audit units of the effectiveness of AML/CFT/CPF systems.
B. Disclosure of information related to domestic and offshore funds, and how KYC and KYP procedures have been implemented:
a. The disclosure of dividend distributions of onshore and offshore funds, risk disclosures for high-yield bond funds, warning messages for fund investment risks, the advertisement and marketing documents for target maturity bond funds, the implementation of customer fund suitability assessments, and the implementation of know-your-customer (KYC) and know-your-product (KYP) requirements in the course of fund sales.
b. The accuracy of disclosed investor information provided by offshore funds as well as financial report information of the offshore funds represented by a master agent, and the implementation of required applications for approvals or filings of public announcements:
(a) Whether disclosed investor information provided by offshore funds matches the templates established by industry associations, whether the investor information provides the investment risk warnings set out in the templates, with the principal risks or warnings printed in bold text, whether the investor information matches the information stated in the fund prospectus and fund factsheet, whether matters to be specified in the investor brochure of ESG-related offshore funds and investment portfolio and sales documents will mislead investors.
(b) Whether the publication timing and content of the annual and semi-annual financial reports of an offshore fund represented by a master agent, as well as summary Chinese translations thereof, and the matters that an offshore fund is required to announce and file with the competent authority, are in compliance with the Regulations Governing Offshore Funds and other applicable requirements; and whether the content of publicly announced financial reports match the actual facts of the fund in question.
c. Measures to prevent financial and investment fraud (e.g. conduct of employee awareness and education activities, fraud awareness activities), and measures to protect financial consumers.
C. Scope for conflicts of interest and investment process controls for investment trust funds and discretionary investment accounts (including discretionary investment accounts managed by government-run investment funds):
a. Instances in which a securities investment trust fund’s manager, or a spouse or minor child of such a manager, or anyone else acting as a nominee thereof, trades in the same instruments as those held by the investment trust fund or held in a discretionary investment account that is managed by that fund.
b. Internal control rules governing analysis reports, decisions, execution records, and review reports regarding investments and transactions conducted by an investment trust fund or through a discretionary investment account in such a fund (including discretionary investment accounts managed by government-run investment funds), and the implementation of those internal control rules.
D. The offering, sale, and marketing of ETFs (including futures-based ETFs); disclosure of ETF dividend policies (including use of income equalization arrangements), timing of dividend distributions, and dividend composition details; management of discounts and premiums, the underlying indices tracked by ETFs, and how improvements to ETF information disclosures have been implemented.
E. Information disclosures for the offering of Environmental, Social, and Governance (ESG) funds: Includes information that should be disclosed in offering plans and prospectuses for newly-established funds, and areas of improvement for existing funds.
F. Implementation of information and communication security management measures:
a. Personal information protection: Such as security and protection measures for the storage, processing, and transmission of personal information and data sharing between financial institutions.
b. Verify the procedures taken by those members in response to cyber security information or alerts released by the Financial Information Sharing and Analysis Center (F-ISAC).
G. Status of management and auditing of sub-distributors, and payment of distribution fees: Screening of sub-distributors and on-site visits; eligibility criteria for selected training program participants; the appropriateness of tours incorporated into training programs, and a reasonable ratio of professional courses related to funds, establishes and implements mechanisms for the prior assessment of distribution fees and their subsequent audit, and the reasonableness of distribution fees paid (including whether the distribution fees collected by back-end load and front-end load funds are reasonable, and whether the fund entices investors to buy specific types of funds through distribution fees etc.).
H. Corporate governance, compliance system implementation, and business continuity management mechanisms: Examinations focus on such things as efforts to strengthen the functions of the board of directors; interested-party transactions; whistleblower protections; whether the services performed by persons appointed as consultants constitute disguised performance of internal duties; whether the “Stewardship Principles for Institutional Investors” have been implemented in compliance with internal control rules; and whether the securities firm has formulated and fully implemented business continuity management rules, and the design and implementation of a compliance system.
I. Use of automated tools to provide securities investment consulting services: Examinations focus on supervision of the use of algorithms, KYC operations, and recommendations regarding investment portfolios, fairness and impartiality of system operations, investment portfolio rebalancing, oversight by a special committee, and pre-use disclosures to customers.
Life Insurance Companies
A. Examinations focus on compliance by life insurance companies (including their OIUs) with regulations governing anti-money laundering, counter-terrorism financing, and non-proliferation of weapons:
a. Institutional risk assessment and internal controls framework: The completeness and reasonableness of institutional risk assessment as well as the appropriateness and effectiveness of overall internal control framework, the implementation of AML-related measures based on a risk-based approach.
b. Customer due diligence measures and risk rating assessment: The identification and due diligence of beneficial owners, methodology of customer risk assessment, and the completeness and reasonableness of customer due diligence whether commensurate with risks).
c. Ongoing monitoring of accounts and transactions: The reasonableness of transaction monitoring patterns and the setting of monetary amount thresholds, the screening and verification of money laundering red flags or signs that customers and their transaction counterparties may meet the conditions for inclusion on a sanctions list and the independence and effectiveness of monitoring operations.
d. Suspicious transaction reporting procedures, and quality of reporting: The handling of suspected ML/TF/PF transactions (including reporting, confidentiality procedures, and record-keeping).
e. Organization and personnel: The professionalism and adequacy of the chief officer and personnel, the adequacy of resource allocation, education and training, and the quality and reliability of independent tests by internal audit units and accountants of the effectiveness of AML/CFT/CPF systems.
B. Implementation of the compliance system:
a. The compliance department’s announcement and communication of laws, regulations, and rules.
b. The provision of compliance advices before launching new services or products, or undertaking specific or major use of funds.
c. The procedures for handling each unit’s material discrepancies in compliance or malfeasance, as well as how these procedures have been implemented.
d. Compliance training, implementation of compliance self-assessments, and the insurer’s overseeing and auditing of its foreign branches’ compliance with laws.
e. Compliance of recognition and reversal of special reserve from reclassification of financial assets.
C. Financial consumer protection:
a. What data protection measures are taken prior to the conclusion of contracts with insurance customers (e.g. whether the insurer provides a contract review period; disclosures of important contract content and risks).
b. Examinations focus on establishment of a management system for policy conservation (including applications to change the investment instruments linked to investment-linked insurance contracts), claims settlements, and complaints.
c. Appropriateness of solicitation methods for insurance products denominated in foreign currencies, investment insurance products, and mortgage-backed life insurance products.
d. Protection of the rights of persons with disabilities to obtain insurance (e.g. verification of whether there is any discrimination in the solicitation and underwriting of insurance for persons with physical and mental disabilities; establishment and implementation of insurance underwriting procedures and training for underwriting personnel).
e. Implementation of the Measures to Ensure Friendly Financial Services as well as the Principles for Fair Treatment of Consumers by Financial Services Enterprises.
D. Marketing and management of insurance products:
a. Management of solicitors: The establishment and implementation of internal control procedures for overseeing solicitors to ensure they fill out solicitation reports correctly and do not use inducements to have customers cancel old purchases in favor of new ones; preventing solicitors from using and misappropriating policyholder funds; and reporting to the competent authority in the event of a material incident.
b. Method for the declaration of interest rates and its management of asset segregation and the reasonableness of the commission structure for interest-sensitive insurance products.
c. Performance in convening meetings of the insurance product management team, and in verifying that its products are legally compliant, reasonably priced, and controlling product sales to not exceed regulatory limits.
d. Risk management mechanisms for insurance product sales, and how overall reports on the impact of product sales to the company’s financial condition, business operations, and ability to repay debt have been reported to the company’s board of directors.
e. Management of business dealings with insurance brokers and agents (including telephone marketing, preventing insurance brokers and agents from improperly persuading customers to cancel old policies in favor of new ones, and determining the reasonableness of distribution channels incentive programs).
f. Management of participating insurance policies (including segregated account management, product design and post-sales management, information disclosure and sales conduct guidelines, responsibilities of relevant personnel, and training of soliciting agents).
E. Corporate governance: Such as the fulfillment of the functions of the board of directors and functional committees such as the risk management committee, communication mechanisms for shareholders with controlling interest, compliance and control and management procedures for interested-party transactions, establishment and implementation of the whistleblower system; and management mechanisms for employees, assets, and financial position with affiliated enterprises.
F. Implementation status of foreign investments:
a. The investment terms, risk management, and legal compliance of investments in senior corporate bonds, subordinated corporate bonds, subordinated financial bonds, and international bonds.
b. Pre-investment and post-investment management mechanisms for equity investments in foreign insurance enterprises and mainland China insurance entities as a co-investor and the insurer’s implementation of legal compliance at the investees (including handling mechanisms to ensure an appropriate response when there is a major violation of AML/CFT legislation, material malpractice caused by ineffective internal controls, a material change in the investment plan filed to the competent authority at an investee, or other material incidents that might affect its reputation or impede normal business operations).
c. Risk control mechanisms for risk events that occur due to changes in the international political and economic situation (including interest rate hike decisions of foreign central banks); and risk management mechanism for lending or investment in overseas and China that are either influenced by local government policy or involving industries that are highly subsidized.
d. The maintenance of custody over foreign assets, qualifications and criteria of custodian institutions, and the legality of custodial services contracts.
e. Operating procedures and management system for discretionary investments.
f. Control mechanisms for foreign investment caps.
g. Implementation of compliance with laws and regulations concerning establishing or investing in foreign financing enterprises.
G. Establishment and implementation of internal control systems for domestic securities investments: The establishment of investment policies and procedures, post-investment review mechanisms, control and management mechanisms for front/middle/back-office powers and responsibilities; operating procedures and management system for discretionary investments; preventing conflicts of interest among equity investment staff; and management of the use of information and communications equipment at office locations.
H. Implementation status of real estate investments: The investment procedures and internal control mechanism for real estate investments, compliance with the requirement for prompt utilization and income, and the procedures for subsequent measurement of real estate investments included in the accounts.
I. Risk management, internal control mechanisms, and legal compliance for insurers’ use of funds in special projects and investments in private investment funds or venture capital firms.
J. Implementation of Own Risk and Solvency Assessments (ORSA):
a. Periodically implement and review the effectiveness and reasonableness of the ORSA mechanism, and adopt and implement suitable strategies accordingly.
b. The implementation of risk management mechanisms and provisions concerning capital adequacy ratio, such as executing a risk management code of practice, self-owned capital tier structures, the deduction of self-owned capital from investments in foreign insurance-related enterprises that are related parties, and the provision of risk capital for investments in domestic and foreign REITs and bonds.
c. Implementation of compliance with laws and regulations regarding the issuance abroad of capital bonds by foreign financing enterprises.
K. Implementation of digital financial services: Whether digital business activities are compliant with laws and regulations, management mechanism for the development and launch (including regular safety checks) of mobile apps; administration of electronic insurance policies, identity verification for customers purchasing insurance policies through mobile apps or online (including mobile identity verification), confirmation of bona fide intent to purchase insurance; and control and management mechanisms for underwriting and notifications.
L. Management mechanism for information and communication security as well as personal information protection:
a. Management mechanisms and security and protection measures for the collection, processing, and use of personal information, and the compliance (including the supervision and management of personal information protection for the insured in operations outsourced to third-party service providers), whether data sharing between financial institutions is in compliance with the Personal Data Protection Act, and Guidelines for Data Sharing between Financial Institutions, and establish appropriate internal controls and implementation of information security.
b. Business continuity management mechanism, information system security controls, mechanism for data breach response drills, application programming interface (API) security management, and information system and services supply chain risk management (e.g. supervision of outsourced contractors, security testing for delivery systems and components, and appropriateness of contracts).
c. Security controls for cloud services (such as encryption and key management, identity verification and access, configuration security management, audit trails, and monitoring) and cloud backup mechanisms.
Non-life Insurance Companies
A. Compliance with regulations governing anti-money laundering, counter-terrorism financing, and non-proliferation of weapons (including international insurance branches): The internal control system for anti-money laundering and counter-terrorism financing; implementation of risk assessment and risk reduction measures; customer due diligence; name screening; ongoing monitoring of accounts and transactions; establishing and integrating the information system; screening for money laundering transactions and filing of suspicious transaction reports; and AML training.
B. Implementation of the legal compliance system:
a. The compliance department’s announcement and communication of laws, regulations, and rules.
b. The provision of compliance advices before launching new services or products, or undertaking specific or major use of funds.
c. The procedures for handling each unit’s material discrepancies in compliance or malfeasance, as well as how these procedures have been implemented.
d. Compliance training, implementation of compliance self-assessments, and the insurer’s supervision and inspections of its foreign branches’ compliance with laws.
C. Financial customer protection: e.g., establishment of procedures for soliciting and underwriting insurance products for customers., protection of the insurance rights and interests of persons with disabilities (e.g.: whether there is any discrimination in the solicitation and underwriting of insurance for persons with physical and mental disabilities, establishment and implementation of insurance underwriting procedures and training for underwriting personnel, and the implementation of the Measures to Ensure Friendly Financial Services as well as the Principles for Fair Treatment of Consumers by Financial Services Enterprises.
D. Development and design of insurance products, marketing management, and review and adjustment of premium rates:
a. The insurance product evaluation team and insurance product management team’s evaluation of product design, pre-sale inspection, and after-sale inspection (including the reasonableness of product pricing and premium adjustments), and implementation of submission the overall assessment report on the impact of product sales on the company’s financial position, business performance, and solvency to the board of directors.
b. The state of review and adjustment of rates for commercial fire insurance, private passenger car physical damage insurance, and third-party liability insurance.
c. The setting and management of commissions for solicitation of commercial fire insurance products via various channels.
d. Management of business dealings with insurance brokers and agents.
E. The implementation status of solicitation, premium collection, underwriting, and claim procedures for insurance: Such as how premiums for car insurance, fire insurance, accident insurance, and health insurance are determined, what the underwriting procedures are, how insurance claims are processed, and controls on the authorized collection of cash premiums.
F. Risk management mechanisms for funds utilization: The compliance of the insurer’s investments in securities and foreign assets, related transaction control mechanisms and risk management measures, appropriateness of mechanisms for preventing conflicts of interest among equity investment staff, and operating procedures and management system for discretionary investments.
G. Implementation of Own Risk and Solvency Assessments (ORSA):
a. Periodically implement and review the effectiveness and reasonableness of the ORSA mechanism, and adopt and implement suitable strategies accordingly.
b. The implementation of risk management mechanisms and provisions concerning capital adequacy ratio, such as executing a risk management code of practice, self-owned capital tier structures, the deduction of self-owned capital from investments in foreign insurance-related enterprises that are related parties, and the provision of risk capital for investments in domestic and foreign REITs and bonds.
H. Implementation of digital financial services: Whether digital business activities are compliant with laws and regulations, management mechanism for the development and launch (including regular safety checks) of mobile apps, administration of electronic insurance policies, implementation of customer due diligence for mobile device applications and online applications for insurance, confirmation of bona fide intent to purchase insurance, and control mechanisms for underwriting and notifications.
I. Management mechanisms for information and communication security as well as personal information protection:
a. Management mechanisms and security and protection measures for the collection, processing, and use of personal information, and the compliance (including the supervision and management of personal information protection for the insured in operations outsourced to third-party service providers), whether data sharing between financial institutions is in compliance with the Personal Data Protection Act, and Guidelines for Data Sharing between Financial Institutions, and establish appropriate internal controls and implementation of information security.
b. Business continuity management mechanism, information system security controls, and mechanism for data breach response drill, application programming interface (API) security management, and information system and services supply chain risk management (e.g. supervision of outsourced contractors, security testing for delivery systems and components, and appropriateness of contracts).
c. Security controls for cloud services (such as encryption and key management, identity verification and access, configuration security management, audit trails and monitoring) and cloud backup mechanisms.
J. Corporate governance: Such as the fulfillment of the functions of the board of directors and functional committees such as the risk management committee, communication mechanisms for shareholders with controlling interest, compliance and control and management procedures for interested-party transactions, establishment and implementation of the whistleblower system; and management mechanisms for employees, assets, and financial position with affiliated enterprises.
K. Management mechanisms for outward reinsurance: Management mechanisms for obtaining documents confirming acceptance and reinsurance contract documents from reinsurers, criteria for foreign insurance brokers appointed by reinsurers and reinsurance brokers, and mechanisms for reviewing reinsurance arrangements and the underwriting conditions of the original insurance contract.
Enterprises or Individuals Providing Virtual Asset Services (VASP)
A. Compliance with regulations governing anti-money laundering, counter terrorism financing, and non-proliferation of weapons:
a. Institutional risk assessment and internal controls framework: The completeness and reasonableness of institutional risk assessment as well as the appropriateness and effectiveness of overall internal control framework, the implementation of AML-related measures based on a risk-based approach.
b. Customer due diligence measures and risk rating assessments: the reasonableness of customer risk assessment methodology and the review procedures should be commensurate with customers’ risk level, and the identification of beneficial owners.
c. Ongoing monitoring of accounts and transactions: The transaction monitoring policies and procedures established under the risk-based approach, and the reasonableness of transaction monitoring patterns such as the thresholds for triggering alerts, the screening and verification of money laundering red flags or signs that customers and their transaction counterparties may meet the conditions for inclusion on a sanctions list (including wallet address) or of being high-risk foreigners as well as the independence and effectiveness of monitoring operations and control measures related to international sanctions.
d. Suspicious transaction reporting procedures, and quality of reporting: The handling of suspected ML/TF/PF transactions (including reporting, confidentiality procedures, and record-keeping).
e. Organization and personnel: The professionalism and adequacy of the chief officer and personnel, the adequacy of resource allocation, education and training, and the reliability of independent tests for the effectiveness of control measures by internal audit units.
B. Information security management system: design and deploy a stable and secure information system commensurate with the size and nature of the business and take appropriate measures and procedures to ensure that data and its transmission, exchange, and processing remain accessible, accurate, confidential, and secure.
C. Consumer protection:
a. A virtual asset custodian shall segregate customer assets in its custody from its proprietary assets. Upon receiving a customer’s virtual assets, the custodian shall keep them segregated from its proprietary virtual assets and shall not agree with a customer to commingle the customer’s virtual assets with the custodian’s proprietary virtual assets.
b. The ratio at which VASP stores customer virtual asset positions in cold wallets and hot wallets.
c. Any fiat currency deposited by customers is to be placed in trust, or a full performance guarantee is to be obtained from a bank.
d. Records concerning virtual asset services provided to customers are to be retained for a minimum of five years following the date the service relationship is terminated. However, in the event of any dispute, they shall be kept until the dispute is extinguished.
e. Customer complaint handling procedures should be established to ensure the fair and prompt resolution of disputes.
D. Trading platform management: The virtual asset trading platform provider shall establish review standards and procedures for the listing and delisting of virtual assets and shall implement measures to prevent unfair market transactions, including measures for detection of and alerting to anomalies in price and volume.
E. Fraud prevention measures:
a. VASPs shall implement enhanced customer due diligence to verify the identity of a customer in cases of abnormal virtual asset accounts suspected of fraud, and may adopt control measures such as continual review, suspension of deposits or withdrawals, suspension of outward remittance of virtual assets or funds, suspension of all or partial transaction functions, refusing to establish a business relationship or provide services, and may make a report to the judicial police authority.
b. Review, control, reporting, and legal compliance concerning information on abnormal virtual asset accounts suspected of fraud or watch-listed virtual asset accounts, virtual deposit accounts notified by banks or noted by the National Police Agency, accounts and wallet address reported to the government’s 165 hotline, and blacklists and blacklisted wallet addresses maintained by the VASP.
c. Reporting and handling of industrywide joint fraud prevention mechanisms.
d. Reporting and handling of cross-industry joint fraud prevention mechanisms.
e. Policies governing the return of customers’ remaining funds or virtual assets, the related handling and settlement procedures, and their implementation status.
Specialized Electronic Payment Institutions
A. Compliance with regulations governing anti-money laundering, counter terrorism financing, and non-proliferation of weapons:
a. Measures to confirm customer identity as well as monitoring mechanisms to determine the efficacy of implementation taking a risk-based approach.
b. Based on a national risk assessment, profiles of suspected money laundering or terrorist financing transactions will be drawn up, an understanding of high-threat crime patterns obtained, and links drawn from this to businesses so as to formulate appropriate control measures.
B. Business management:
a. When signing a contract with a specialized agency selling deferred goods or services, the contract should stipulate that a performance or delivery guarantee be provided in accordance with relevant regulations, and that information on said performance or delivery guarantee be disclosed to users.
b. Offer users the option of collecting and making payment for the actual transaction as an agent of an unspecified amount in advance, and confirm the adequacy of transaction security mechanisms and transaction dispute handling processes of the specially contracted agency.
c. When a specialized agency engages in the business of collecting and making payments for real transactions as an agent, a contracted institution must, in principle, be the ultimate recipient. However, where the contracted agency such as a delivery platform operator, a taxi passenger service platform operator, or a parking service platform operator, is not the final recipient of funds, said agency shall establish appropriate selection principles.
C. Fraud prevention measures:
a. Implementation of the ''Regulations Governing Fraud Crime Hazard Prevention by Financial Institutions and Businesses or Personnel Providing Virtual Asset Services".
b. Identifying electronic payment accounts and registered stored-value cards suspected of being used for illegal or obviously irregular transactions and ascertaining the adequacy of related internal operating rules.
c. Upon receipt of a joint prevention mechanism notification form faxed by the previous beneficiary institution, inquiry should be made into the recipient’s electronic payment account transactions and information concerning the transfer should be faxed to the notification window of the following beneficiary institution.
d. Where it has been confirmed that the reason for reporting is financial fraud, and where, in the account, there remain funds that have been remitted (transferred) by the victim, said funds should be returned in an appropriate fashion.
D. Financial customer protection mechanisms:
a. The terms and conditions found in a standard electronic payment contract must be in compliance with the FSC’s directions concerning items that must appear in and must not appear in a standardized contract. The rights and responsibilities of users, as well as the procedures concerning both applications and operations, are to be announced on the official website.
b. A mechanism to handle complaints and resolve transaction disputes must be established, while consumers are to be clearly informed of relevant operating procedures.
c. Where there is a business information system failure or where other reasons prevent the execution of a user’s payment instructions, the user shall be notified in a timely manner.
d. A management mechanism is to be established concerning the inventory of personal data files concerned in system functions, reports, documents or electronic files. Moreover, regular inspections are to be carried out and relevant operating records are to be retained. Appropriate encryption and monitoring mechanisms are to be established concerning the transfer of personal data, and complete documentary evidence is to be kept.
E. Information systems security controls:
a. Information security personnel: Where total assets or the number of users reaches a certain level, firms should establish a dedicated information security unit and appoint a supervisor (who shall not be assigned to perform information management or other tasks where there is a conflict of interest). Sufficient personnel and equipment must also be allocated. Where the dedicated information security unit is part of the information management organization, it should be set up as a separate entity from other information management units to meet the management mechanisms for independent operations.
b. Network security: implementation of network security defense mechanisms including firewalls, vulnerability scanning, intrusion detection, and penetration testing; and the adequacy of system security control procedures and vulnerability patching and improvement.
c. System operations management: Control measures and tracking and review mechanisms are to be established for privileged accounts and administrative (high-level-access) accounts. Necessary permissions are to be granted to personnel in accordance with the principle of division of labor and the principle of least privilege. Appropriate access control and monitoring measures are to be established concerning personal data files and databases. Methods for ensuring information security control, comprehensive testing, and data verification should be put in place in connection with major changes to core system architecture.
d. Disaster response and information security incident management: Information security incidents and emergency contingency plans should be formulated and drills and reviews held in accordance with these plans.
e. Managing electronic payment platforms: Enhance API security management and security testing of mobile APPs.
F. Managing outsourced operations:
a. Where a portion of an electronic payment institution’s business is handled by a third party, this must be reported to the competent authority for approval and verification; the scope of outsourced business must be in compliance with related regulations.
b. When the personnel of a commissioned agency provide services on-site at an electronic payment institution, the institution should have in place access control, portable equipment, network segmentation of the area the individual is working in, and both system and data access controls.
c. Establish cloud service information security control mechanisms (such as encryption and key management, access control, and emergency response plans).
G. Legal compliance procedures:
a. A clear and appropriate system for providing information, consultations, coordination, and communication concerning laws and regulations should be established, while confirmation should be made that all operating and managerial regulations are updated in a timely manner to reflect relevant laws and regulations, such that all operations comply with legal requirements.
b. Both the content and procedures related to ensuring legal compliance are to be formulated. Each department must be supervised as it undertakes regular self-assessments of its compliance. The effectiveness of each unit’s self-assessment should itself be assessed.
H. Internal audit:
a. An internal audit unit under the board of directors should be established that should report on its auditing activities to both the board as well as the supervisors. The audit supervisor is not to concurrently hold any position that would conflict with audit work.
b. The adequacy of internal audit plans, audit instructional manuals, and work papers drafted by the internal audit department, the appropriateness of both the frequency of audits and the items covered, internal audit implementation, and the tracking of deficiencies and the improvement thereof.
I. Corporate governance:
a. Fulfillment of the functions of the board of directors: The organization and functions of the board of directors; overseeing of the establishment and operations of the audit committee and risk management committee; oversight of various business policies and management mechanisms; and appropriateness of the board’s exercise of its powers in handling and responding to material events (such as major violations of laws and regulations, and significant exposures that adversely affect a bank’s financial and business status).
b. Internal management mechanism for the responsible persons’ holding of concurrent positions, the compliance of laws and internal rules, and the appointment of a chief corporate governance officer and other corporate governance personnel.
c. The compliance of stakeholders/substantively related parties transactions (including real estate, purchase of services and items, and other transactions) and control mechanisms (including the self-regulatory mechanism for substantively related parties); irregularities with respect to strategies, counterparties, and prices for transactions within the group or with substantively related parties (including major shareholders, directors, and supervisors); whether those transactions involve conflicts of interest or other compliance matters; and reasonableness of expense payment.
d. Communication and contact mechanisms for shareholders with a controlling interest (including communication and contact principles and management rules, topics of communication, procedures for communication accompanied by a manager, and communication management procedures and records).
e. Independence and effectiveness of the whistleblower system (including internal operating procedures and control mechanisms, such as channels for internal and external whistleblowers and whistleblower protection measures).
