| Article 48 | To secure the confidentiality level of the financial examination report of a financial holding company or a banking business, unless otherwise provided by law or permitted by the competent authority, the responsible person or the employee is not allowed to read or disclose, deliver, publicize all or part of the contents of the report to another person irrelevant of the performing of the task.
A financial holding company or banking business shall follow the provisions of the competent authority to prescribe the related internal management regulations and business procedures of the financial examination reports and submit them to the board of directors for consent. |
| Article 49 | A financial holding company or a banking business shall set out in its internal control system penalties for violations of these Regulations or its internal control system rules by management and relevant personnel. |
| Article 50 | Where a financial holding company or a banking business makes any concealment of poor internal management, unsatisfactory internal controls, inadequate implementation of the internal audit system and regulatory compliance system, or the results of implementation of improvement of any deficiency specified by a financial examination agency in an examination opinion requiring review and follow-up, or the internal audit unit (including the internal audit unit of parent company) otherwise conceals any audit findings, and where such concealment constitutes significant malpractice, the personnel involved shall be held responsible for negligence in their duties. A financial holding company (including its subsidiaries) or a banking business shall commend an internal auditor who identifies any significant malpractice or negligence and thereby averts material loss to the company. |
| Article 51 | The internal auditors and compliance officers of a financial holding company or a banking business shall immediately prepare a report for submission, and notify to the independent directors and supervisors (board of supervisors) or violations of laws and regulations the audit committee and report to the competent authority, when their recommendations for improvements regarding significant deficiencies or noncompliance identified in internal controls are not accepted by management and as a result the financial holding company (including its subsidiaries) or the banking business might incur a material loss. |
| Article 52 | The competent authority shall prescribe the formats required formats specified in the Regulations herein. |
| Article 53 | If the relevant internal control and audit system regulations prescribed by the head office of a foreign bank are not less than the provisions of these Regulations, the internal control and audit systems of its Taiwan branch may be implemented in accordance with the head office system and comply with the following provisions:
1. The internal control system statement shall be jointly issued by the person in charge in Taiwan, the chief compliance officer, the officer in charge of audit business for the Taiwan region, the officer in charge of information security for the Taiwan region, and the officer in charge of risk management for the Taiwan region. The statement shall be disclosed on the bank's website within three months after the end of each fiscal year, and the provisions of Article 8 shall not apply.
2. Formulate relevant business regulations and handling guides based on its business items in Taiwan with reference to Subparagraph 2 of Paragraph 1 of Article 12.
3.Where it establishes a whistleblowing system in Taiwan in accordance with the system of the head office and designates a unit or personnel to take charge of receiving whistleblower reports, it may be exempted from the provisions of Paragraph 1 of Article 13 regarding the designation of a unit that independently exercises its functions and powers. However, the contents of the whistleblowing system shall include at least the provisions of the subparagraphs of Paragraph 4 of Article 13.
4. Where the Taiwan branch adopts a risk-based self-inspection system in alignment with its head office, explains the implementation methods for self-inspections and the evaluation mechanism for self-inspections, and submits the explanation of such implementation methods and evaluation mechanism to the competent authority for recordation, it may be exempted from the provisions of Paragraph 1 of Article 14 regarding the designation of units to conduct supervision and review, and the provisions of Paragraph 2 of Article 14.
5. Where the Taiwan branch complies with the compliance risk management and supervision framework of its head office, explains the framework principles and provisions on powers and responsibilities, and submits the explanation of such framework principles and provisions to the competent authority for recordation, it may be exempted from the provisions of Article 18.
6. Where the Taiwan branch adopts a risk-based internal audit system in alignment with its head office, explains the operating mechanism and implementation methods, and submits the explanation of such the operating mechanism and implementation methods to the competent authority for recordation, it may be exempted from the provisions of Article 31, Paragraph 1 of Article 32, Paragraph 1 of Article 35, and Article 39.
7. Where the Taiwan branch operates in accordance with the head office system and allocates appropriate human resources and equipment to ensure proper communication and risk management, it may be exempted from the provisions of Paragraph 2 of Article 16 regarding the restriction that the dedicated legal compliance unit shall not concurrently handle legal affairs and that the chief compliance officer shall not concurrently serve as the head of the legal affairs unit; and it may also be exempted from the provisions of Article 21 regarding the establishment of a dedicated risk management unit and the appointment of a chief risk officer, Article 24 regarding the establishment of a dedicated information security unit and the appointment of a chief information security officer, and Subparagraph 1 of Paragraph 2 of Article 29 regarding the headcount ratio of internal audit personnel.
8. Unless otherwise provided by the competent authority, where the internal audit is conducted by the audit unit of the Taiwan branch, the internal audit report shall be submitted to the competent authority within two months after the completion of the audit; where it is conducted by the head office or regional headquarters, the Taiwan branch shall submit the report to the competent authority within one month after receiving the report. If the content of said report is not in Chinese, a Chinese summary of key points shall be attached.
9. For managers serving in the business units of a Taiwan branch for the first time who possess experience and training in internal control related to their duties, the provisions of Paragraph 3 of Article 41 shall not apply.
Where the internal control and audit systems of a Taiwan branch of a foreign bank do not fall under the circumstances of the preceding paragraph, and are not less than the provisions of these Regulations under the head office system, it may, upon issuing a statement of comparison in application of the head office regulations and the provisions of these Regulations, and having the same signed by the person in charge of the Taiwan branch, operate in accordance with the system of the head office. In the event of any change to the head office system, a statement of comparison in application shall be re-issued and signed by the person in charge of the Taiwan branch.
Where the internal control and audit systems of a Taiwan branch of a foreign bank do not fall under the circumstances of the preceding two paragraphs, it may, based on its business scale or nature, state reasons for specific matters, and, upon reporting to and obtaining approval from the competent authority, operate in accordance with the system of the head office. In the event of any change to the approved matters, the branch must re-submit the matter for approval and obtain approval from the competent authority.
Where a Taiwan branch of a foreign bank violates the internal control system or audit system implemented pursuant to the provisions of this Article, it shall be deemed as a violation of the provisions of these Regulations. |
| Article 54 | Financial holding companies and the banking business that do not comply with the provisions of Article 9, Article 10, Item 13 of Subparagraph 2 of Paragraph 1 of Article 12, Article 14, Article 16, Paragraphs 4 and 5 of Article 17, Article 20, Article 21, Article 24, Article 25, and Paragraph 2 of Article 31 regarding the Three Lines Model for internal control, ethical corporate management best practice principles, formulation of business continuity management mechanisms, self-inspection system, consolidation of legal compliance self-inspections and self-assessment operations, appointment of the CCO,CRO, CISO, and dedicated legal compliance, risk management, and information security units subordinate to the general manager, as well as the risk management framework, and the powers and responsibilities of the dedicated risk management and information security units, shall implement adjustments to comply with the provisions by December 31, 2027.
A credit cooperative that does not comply with the provisions of Article 35 regarding the inclusion of sustainability information management in the disclosure items of the internal audit report shall implement adjustments to comply with the provisions by December 31, 2027. |
| Article 55 | These Regulations shall enter into force on the date of promulgation, except for Articles 44 to 47, for which the enforcement dates shall be prescribed by the competent authority. |