Data Source:Laws and Regulations Retrieving System of the Banking Bureau


Title: Implementation Rules of Internal Audit and Internal Control System of Financial Holding Companies and Banking Industries (2026.05.06 Modified)
  Chapter 3 Management, Supervision, and Audit of the Internal Control System

   Section 2 Legal Compliance System

Article   16    Financial holding companies and the banking business shall establish a dedicated legal compliance unit subordinate to the general manager to take charge of the planning, management, and execution of the legal compliance system, and appoint a person ranked vice general manager or above, or a person with equivalent responsibilities, to serve as the Chief Compliance Officer (CCO) to oversee legal compliance affairs. The chief compliance officer shall report to the board of directors and supervisors (board of supervisors) or the audit committee at least semi-annually. Upon discovering a material violation of laws and regulations or a downgrade of its rating by competent financial authorities, the CCO shall immediately notify the directors and supervisors (board of supervisors) and submit a report on legal compliance matters to the board of directors.
The dedicated legal compliance unit mentioned in the preceding paragraph may concurrently handle matters related to anti-money laundering, countering the financing of terrorism, and anti-fraud. The unit shall not concurrently engage in legal affairs unrelated to the planning, management, and execution of the legal compliance system, or other operations that present a conflict of interest with its duties. The chief compliance officer may serve concurrently as the head of the dedicated unit for anti-money laundering, countering the financing of terrorism, and anti-fraud. However, the chief compliance officer shall not serve concurrently as the head of the legal affairs unit or hold other internal positions.
Where the competent authority has provided otherwise for credit cooperatives and bills finance companies regarding the provisions of the preceding two paragraphs, such provisions shall govern.
The CCO of a financial holding company or a bank shall meet the qualification requirements set out respectively in the “Regulations Governing Qualification Requirements for the Promoter or Responsible Persons of Financial Holding Companies and Concurrent Serving Restrictions and Matters for Compliance by the Responsible Persons of a Financial Holding Company” and in the “Regulations Governing Qualification Requirements and Concurrent Serving Restrictions and Matters for Compliance by the Responsible Persons of Banks”.
The dedicated legal compliance unit of the head office, domestic and foreign business units, information unit, assets safekeeping unit, and other management units of a financial holding company or a banking business shall each assign the personnel to act as the compliance officer to take charge of related affairs. Arranging the compliance officer position in the foreign business unit shall comply with the local regulations and the requirements of the local authorities and the compliance officer shall not hold other posts except in any of the following situations:
1 The compliance officer serves concurrently as the AML/CFT compliance officer.
2. The compliance officer holds concurrent posts that do not constitute a conflict of interest according to the local regulations.
3. It is not strictly prohibited in the local regulations regarding the holding of concurrent posts, provided the holding of concurrent post does not result or potentially result in conflict of interest and the matter has been communicated with and confirmed by the local competent authority and reported to the competent authority for recordation.
If a Taiwan branch of a foreign bank is unable to appoint a person to serve as the compliance officer in its business units, information technology units, finance and custody units, and other management units in accordance with the preceding paragraph, it shall adopt appropriate alternative methods to achieve the same functions required in the preceding paragraph.
The chief officer and personnel of the dedicated compliance unit of a financial holding company or the head office of a banking business, as well as the compliance officer of its domestic and foreign business units, information department, assets management department, and other management departments shall meet one of the following qualification requirements:
1. Having worked as personnel or chief officer of legal compliance office at any financial institute for five years in aggregate.
2. Having attended not less than 30 hours of courses offered by institutions recognized by the competent authorities, passed the exams and received completion certificates, therefore.
3. The compliance officer of a foreign business unit who is hired locally, has shown his/her familiarity with local regulations and competence in related matters according to the self-assessment of the assessment procedures resolved by the board of directors, or the review and acknowledgement by the local competent authority.
Article   17    The head office and branches of a financial holding company or banking business shall establish advisory and communication channels for regulatory compliance matters to keep employees informed of rules and regulations, swiftly clarify any questions of the employees on rules and regulations, and ensure regulatory compliance.
The dedicated legal compliance unit shall conduct the following tasks:
1. Establishing a system for clear and adequate conveyance, consultation, coordination and communication of rules and regulations.
2. Keeping operating and management rules and procedures updated in line with relevant regulations to make sure all business activities comply with regulatory requirements.
3. Before a banking business introduces a new product or service or applies to the competent authority for approval to offer a new business, the chief compliance officer shall issue and sign an opinion statement undertaking that the new product, service or business complies with applicable regulations and internal rules.
4. Drafting rules and procedures for evaluating regulatory compliance and overseeing the periodic implementation of self-evaluation by respective units; assessing the compliance self-evaluation operations of respective units and producing a report thereon, which, after being signed off by the general manager, will be used as reference in the performance evaluation of the unit.
5. Providing pertinent regulatory training to employees.
6. Supervising the introduction, establishment and implementation of relevant internal rules by the compliance officer of respective department.
7. Formulating the contents of the reports to be submitted to the board of directors pursuant to Paragraph 1 of the preceding Article, which shall at least include analysis of the causes, potential impacts, and proposed recommendations for improvement regarding material compliance deficiencies or irregularities in each unit.
8. Incorporating the overall implementation of legal compliance from the preceding year into the assessment of the implementation of the internal control system referred to in Paragraph 1 of Article 8 annually.
The internal audit unit may draft the rules and procedures for evaluation of compliance by its subordinate units and perform self-evaluation of compliance by its subordinate units, to which the provisions in Subparagraph 4 of the preceding paragraph do not apply.
A financial holding company or banking business shall perform self-evaluation of compliance at least semiannually. The results shall be sent to the dedicated compliance unit for further reference. The head of a unit shall designate a specific person to conduct the self-assessment activities in each unit. The self-evaluation draft and information for the preceding affairs shall be retained for at least five (5) years.
A financial holding company shall, based on the scale of business operations and characteristics of operational risks of its subsidiaries, supervise its subsidiaries in conducting the assessment of compliance specified in the preceding paragraph.
Article   18    A banking business shall establish a bank-wide risk-based management and supervision framework for legal compliance. The basis of such framework, functions and responsibilities is specified as follows; where the competent authority has provided otherwise for credit cooperatives and bills finance companies, such provisions shall govern:
1. The dedicated legal compliance unit shall set up the procedures, plans and mechanisms for identifying, assessing, controlling, measuring, monitoring, and independently reporting any compliance risk in order to generally control, supervise, and support each domestic or foreign department, branch, and subsidiary with respect to individual business unit, cross-department, and cross-territorial legal compliance.
2. The dedicated legal compliance unit shall set up an adequate number of professional units based on the classification or business, or points of legal compliance, to monitor, implement and support the legal compliance of the local or foreign business units related to that business or legislation.
3. The dedicated legal compliance unit may assess the appointment and enhance the independence of each chief compliance officer by risk-based approach. Notwithstanding the requirements in the first part of paragraph 5 of Article 16, an independent chief compliance officer is not required, and the legal compliance office of the head office will be responsible for a unit with lower compliance risk.
4.The dedicated legal compliance unit shall establish the mechanism of independent reporting, assessment and disposition of compliance risk alert.
5.The dedicated legal compliance unit shall assess the risk management of legal compliance for the primary operating activities, products and services, credit or business projects, and critical customer complaints subject to potential legal violation on a regular and ad-hoc basis and shall establish cross-functional communication links with the Risk Management and Information Security units.
6. The dedicated legal compliance unit may request each unit to provide relevant information in order to understand the compliance risks across the bank.
7. The performance evaluation of management and the head of each department shall incorporate the dedicated compliance unit's assessment opinion on their degree of implementation of legal compliance.
8. The banking business and its dedicated legal compliance unit shall fully understand the compliance procedures applicable to the foreign business units, and the criteria required by the local competent authority, and provide full resources and support.
9. The dedicated legal compliance unit shall specify the weakness of the compliance risk management, and supervise the improvement plans and schedules with respect to the local and foreign operations across the bank when reporting the legal compliance to the board of directors, and the supervisors or audit committee at least once every half year pursuant to paragraph 1 of Article 16; the board of directors (or the council) shall provide sufficient resources and appropriate mechanism of rewards and sanctions applicable to the business units in order to progressively establish a bank-wide culture of legal compliance.
Within two years after establishing a dedicated legal compliance unit, a bank shall submit its bank-wide compliance risk management and oversight framework to the competent authority for recordation. Thereafter, by the end of April of each year, it shall submit to the competent authority the assessment reports referred to in Subparagraphs 5 and 9 of the preceding paragraphs.
If a banking business has a foreign business unit, the dedicated legal compliance unit shall supervise the following tasks of the foreign business unit:
1. Collecting data on local financial regulations, conducting self-evaluation of compliance operation, and ensuring the suitability of compliance officer and the adequacy of compliance resources (including personnel, equipment and training) so as to ensure compliance with the laws and regulations of the host country or jurisdiction.
2. Establishing self-evaluation and monitoring mechanism for compliance risks, and for large business operation, highly complex business or business involving higher risk, engaging a local, outside, independent expert to verify the effectiveness of the self-assessment and monitoring mechanism.
Article   19    The chief compliance officer, the head and personnel of the dedicated legal compliance unit of a financial holding company and banking business, as well as the compliance officers of domestic business units, information technology units, finance and asset safekeeping units, and other management units, shall attend at least fifteen hours of in-service training organized by the competent authority or institutions recognized by the competent authority, or organized internally by their affiliated financial holding company (including subsidiaries) or banking business (including the parent company or the subsidiary bank of the parent group in Taiwan) each year. The content of the training shall at least include newly amended laws and regulations, new types of business operations, or new types of financial products.
The compliance officer of a foreign business unit shall attend at least fifteen hours of in-service training courses on legal compliance organized by the competent authority, institutions recognized by the competent authority, or local relevant authorities, or organized internally by their affiliated financial holding company (including subsidiaries) or banking business (including the parent company) each year.
The training methods for the on-the-job training as set forth in the foregoing two paragraphs held by the company itself shall be approved by the board of directors. The attendance records of relevant personnel shall be kept for review.
Where the dedicated unit for anti-money laundering and countering the financing of terrorism is established under the dedicated legal compliance unit, the required training for the personnel of such dedicated unit prior to assuming office and training required each year shall be handled in accordance with relevant regulations governing anti-money laundering and countering the financing of terrorism, and shall not be subject to the restrictions prescribed in Paragraph 1 of this Article and Paragraph 7 of Article 16.
Financial holding companies and the banking business shall report the roster and training records of the chief compliance officer, as well as the head and personnel of the dedicated legal compliance unit, to the competent authority via an online information system.