No Support JavaScript

Financial Supervisory Commission
Laws and Regulations Retrieving System

Print Time:115.08.14 21:37

Content

Title: Implementation Rules of Internal Audit and Internal Control System of Financial Holding Companies and Banking Industries Ch
Date: 2026.05.06
Legislative: 1. Promulgated on March 29, 2010
2. Amended on March 2, 2012
3. Amended on August 8,2014
4. Amended on May 12,2015
5. Amended on July 5,2016
6. Amended on March 22,2017
7. Article 8、15-1、27、32、34、34-1、34-2、38-1、47 and 46 amended and issued on March 31,2018
8. Amended on September 23,2021
9. Amended on May 6,2026
Content: Chapter 1 General Principles
Article 1  These Regulations are enacted in accordance with Article 51 of the Financial Holding Company Act; Paragraph 1, Article 45-1 of the Banking Act of the Republic of China (hereinafter called Banking Act); Paragraph 1, Article 21 of the Credit Cooperatives Act of the Republic of China (hereinafter called Credit Cooperatives Act); Article 43 of the Act Governing Bills Finance Business; Paragraph 3, Article 42 of the Trust Enterprise Act.
Article 2  The "banking business" referred to in these Regulations includes banks, credit cooperatives, bills houses and trust enterprises.
Financial institutions other than banking business that concurrently conduct bills finance business and trust business shall establish and implement internal control and internal audit systems in accordance with these Regulations, unless otherwise provided by other applicable laws and regulations.
Article 3  The subsidiaries of a financial holding company referred to in these Regulations shall be determined in accordance with Article 4 of the Financial Holding Company Act; the subsidiaries of a banking business shall be determined in accordance with Paragraph 3 of Article 5 of the Regulations Governing Establishment of Internal Control Systems by Public Companies.
Article 4  Financial holding companies and the banking business shall establish internal control and internal audit systems and ensure the on-going and effective operation of the system to promote the sound business operation of financial holding companies (including their subsidiary companies) and the banking business.
Financial holding companies and the banking business shall organize overall operation strategies, risk management policies and guidelines, draft operation plans, risk management procedure and execution guidelines.
Financial holding companies shall supervise their subsidiaries in implementing the matters prescribed in the preceding paragraph.
Article 5  The fundamental purpose of internal control is to promote the sound operation of financial holding companies and banks. It shall be jointly complied with by the boards of directors, management, and all employees to reasonably ensure that the following objectives are achieved:
1. Effectiveness and efficiency of operations;
2. Reliability, timeliness, transparency and compliance of reporting; and
3. Compliance with applicable rules and regulations.
The objective of effectiveness and efficiency of operations referred to in subparagraph 1 of the preceding paragraph includes objectives such as profits, performance, and safeguarding asset security.
The "reporting" referred to in Subparagraph 2, Paragraph 1 includes internal and external financial reporting and non-financial reporting of a financial holding company and a banking business. The objective of external financial reporting includes ensuring that financial reports presented to external users are prepared in accordance with the generally accepted accounting principles and that all transactions are properly approved.
Article 6   The internal control system of a financial holding company or banking business shall be approved by the board of directors. If any director expresses a dissenting opinion or reservation, such opinion and the reasons therefore shall be recorded in the minutes of the board meeting and submitted, together with the internal control system approved by the board of directors, to each supervisor (or the board of supervisors) or the audit committee. The same procedure shall apply in the case of any amendment thereto.
Article 7   The board of directors of a financial holding company or banking business shall be aware of the operational risks faced by the company or business, supervise its operating results and bear the ultimate responsibility for ensuring the establishment and maintenance of an appropriate and effective internal control system.
Article 8  The general manager of a financial holding company or a banking business shall supervise all departments (for the financial holding company, including its subsidiaries) to carefully assess and review the status of the operation of its internal control system. The Statement on Internal Control System (as attached) shall be jointly issued by the Chairperson, the general manager, and the Chief Auditor, and submitted to the board of directors for approval. The content of the Statement on Internal Control System shall be disclosed on the website of the financial holding company or banking business, and publicly announced and filed on the website designated by the competent authority, within three months after the end of each fiscal year.
The internal control system statement under the preceding paragraph shall be duly published in the annual report, stock issue prospectuses, and other prospectuses.
The provisions of Paragraph 1 shall not apply to a banking business that has been taken over by the competent authority.
Chapter 2 The Design of Internal Control System
Article 9    Financial holding companies and the banking business shall establish the Three Lines Model for internal control, which shall include a self-inspection system; a legal compliance system, risk management system, and information security system; and an internal audit system.
The structure of the Three Lines Model in the preceding paragraph shall ensure that all units understand their respective duties and functions within the institution's overall risk and internal control framework. Each of the three lines shall fulfill its own duties, and communication and coordination between the units executing internal control tasks and the internal audit unit shall be strengthened to maintain the effective and appropriate operation of the internal control system.
The implementation procedures for the Code of Practice for the Three Lines Model of Internal Control of Banks shall be formulated by the Bankers Association of the Republic of China and submitted to the competent authority for recordation.
Article10  The internal control system of a financial holding company or banking business shall incorporate the following components:
1. Control Environment: The Control Environment is the basis for the design and implementation of internal control systems across a financial holding company or banking business. It encompasses the integrity and ethical values of a financial holding company or banking business, the governance oversight responsibility of its board of directors and supervisors (board of supervisors) or audit committee, organizational structure, assignment of authority and responsibility, human resources policy, performance measures, and awards and disciplines. The board of directors and management shall uphold the principle of treating customers fairly and establish ethical corporate management best practice principles and internal codes of conduct, including codes of conduct for directors and employees.
2. Risk Assessment: A precondition to risk assessment is the identification of objectives, linked at different levels of the financial holding company or banking business, and the suitability of the objectives shall also be taken into consideration. The management shall consider the impact of changes in the external environment and within its own business model and possible fraud scenarios. The risk assessment results can assist the financial holding company or banking business in designing, correcting, and implementing necessary controls in a timely manner.
3. Control Operations: Control operations means the actions of adopting proper policies and procedures by a financial holding company or banking business based on the risk assessment results to control risks within a tolerable range. Control operations shall be performed at all levels of a financial holding company or business, at various stages of business processes, and over the technological environment. They shall include the supervision and management of subsidiaries, appropriate segregation of duties, and measures ensuring that management and employees are not assigned conflicting responsibilities.
4. Information and Communication: Information and communication refers to relevant and high-quality information that a financial holding company or banking business obtains, generates, or uses from both internal and external sources to support the continuous functioning of other components of internal control, and to ensure that information can be effectively communicated within and outside the organization. The internal control system must have mechanisms to generate information necessary for planning, implementation, and supervision and to enable timely access to information by those who need it, and the system shall maintain comprehensive internal financial, operational and compliance data. An effective internal control system shall also establish appropriate channels of communication.
5. Monitoring Operations: Monitoring operations means ongoing evaluations, individual evaluations, or combination of the two undertaken by a financial holding company or banking business to ascertain whether each of the components of internal control is present and continuously functioning. Ongoing evaluations means routine evaluations built into the course of operations at different levels. Individual evaluations are evaluations conducted by different personnel such as internal auditors, supervisors (or board of supervisors) or audit committee, or the board of directors. Findings of deficiencies of the internal control system shall be communicated to management of appropriate levels, the board of directors, and supervisors (board of supervisors) or audit committee, and improvements shall be made in a timely manner.
A financial holding company shall supervise its subsidiaries to ensure that their internal control systems incorporate the components prescribed in the preceding paragraph.
Article 11  The code of conduct for directors mentioned in Subparagraph 1 of the preceding Article shall contain at least the rules that when a director discovers that the financial holding company or banking business is in danger of sustaining material loss or damage, the director shall promptly take appropriate actions and immediately notify the audit committee or independent director members of the audit committee or supervisors (board of supervisors), and report to the board of directors, and supervise the financial holding company or banking business to report to the competent authority.
Article 12  The internal control system shall cover all business activities, including appropriate policies and procedures as follows, and shall be reviewed and revised in a timely manner:
1. Organizational chart or corporate rules and bylaws, including a clear organizational system, unit functions, scope of operations for each unit, and rules governing authorizations and hierarchical delegation of responsibilities.
2. Related business regulations and handling guides, including:
(1) Investment guidelines.
(2) Customer data confidentiality.
(3) Regulation on interested party transactions.
(4) Shares management.
(5) Management of the preparation process of financial statements, including management of the application of International Financial Reporting Standards, procedures for professional accounting judgments, and processes for making changes in accounting policies and estimates.
(6) Management of administration of general affairs, information, and personnel affairs (for banking business, it shall contain regulations for regular transfer and vacation).
(7) Management of operations for disclosing information externally.
(8) Management of financial examination report.
(9) Management of protection of financial consumers.
(10) Mechanism for handling major contingencies.
(11) Mechanism for anti-money laundering and countering the financing of terrorism (AML/CFT) and management of compliance with relevant laws and regulations, including the management mechanism for identifying, assessing, and monitoring AML/CFT risks.
(12) Management of sustainability information.
(13) Business continuity management mechanisms.
(14) Other business rules and operating procedures.
The business regulations and handling guides of a financial holding company shall also include the management and collaborated marketing management of its subsidiary company.
The business regulations and handling guides of a bank shall additionally include cash handling, deposits, remittances, credit extensions, foreign exchange, new financial products, management of outsourcing operations, the accountability map system, and businesses prescribed in Article 3 of the Banking Act.
The business regulations and handling guides of a credit cooperative shall additionally include cash handling, deposits, credit extensions, remittances, management of outsourcing operations, and businesses prescribed in Article 15 of the Credit Cooperatives Act.
The business regulations and handling guides of a bills finance company shall additionally include bills, bonds, new financial products, and businesses prescribed in Article 21 of The Act Governing Bills Finance Business.
The template for the operation guides of a trust business should be stipulated by the trust association of the R.O.C., with content specifying business operation procedure, accounting operation procedure, computer operation procedure, personnel management system, and other items. A trust business should establish its operation guidelines based on the reference template and make regular revisions in accordance with the alterations in legal regulations, business items, and business procedure.
The internal control system of a financial holding company or banking business whose stock is listed on the stock exchange or traded over the counter shall include the management of the operations of the remuneration committee.
The internal control system of a financial holding company or banking business that has an audit committee set up shall include management of the operation of the audit committee.
A financial holding company or banking business shall establish mechanisms for the supervision and management of its subsidiaries within its internal control system. Where a subsidiary is located in a foreign country, the parent company shall take into account local laws and regulations issued by the host government as well as the actual nature of its operations, so as to supervise the subsidiary in establishing its own internal control system.
Financial holding companies and the banking business shall establish a group-level AML/CFT program, which shall include intra-group information sharing policies and procedures for AML/CFT purposes, based on the laws and regulations of countries or jurisdictions where the foreign branches (or subsidiaries) are located.
The formulation, amendment, or repeal of various operational and management regulations specified in the preceding ten paragraphs shall, when necessary, involve the participation of relevant departments, including dedicated units for legal compliance, risk management, and information security, as well as the internal audit unit.
Article 13  Financial holding companies and the banking business shall establish a whistleblowing mechanism and designate, at their head offices, a unit that independently exercises its functions to receive and investigate whistleblowing cases, thereby promoting their sound operation.
A financial holding company or banking business shall protect the whistleblower as follows:
1. The whistleblower’s identity shall be kept confidential; no information that may be used to identify that person shall be disclosed.
2. The whistleblower shall not be terminated, dismissed, downgraded/relocated, given a reduction in pay, impairment to any entitlement under the law, contract or customs, or other unfavorable disposition due to the reported case.
Any interested person shall recuse himself from the acceptance and investigation of the reported case.
The whistleblower system, in Paragraph 1, shall at least cover the following procedures, and be resolved by the board of directors:
1. Expressly specifies that anyone may file the report when discovering any crime, corruption, or potential legal violation.
2. The types of reporting that will be accepted.
3. Establishes and publishes the channel of reporting.
4. The procedures of investigation and collaborative support, rules of recusal and the standard operating procedure of subsequent disposition mechanism.
5. Whistleblower protection measures.
6. Acceptance of reported cases, investigation processes, investigation results, and the documentation, record-keeping, and retention of relevant files.
7. The whistleblower shall be given appropriate notice in writing or by other means with respect to the progress of the reported case.
If the alleged perpetrator is a director, supervisor, or a managerial officer of an equivalent level higher than vice general manager, the investigation report shall be reviewed by the supervisors (or members of the supervisory board, or the supervisory board), or the audit committee.
Financial holding companies and the banking business shall report or file the critical incident, or material violation discovered in the investigation with relevant authorities.
A financial holding company or banking business shall hold regular promotional program and education training of the whistleblower system for its personnel.
Chapter 3  Management, Supervision, and Audit of the Internal Control System
Section 1 Self-Inspection System
Article 14  Financial holding companies and the banking business shall establish a self-inspection system, wherein the management shall designate the units executing the legal compliance system, risk management system, information security system, or units possessing the second-line functions to supervise the formulation of the contents and procedures for self-inspections and to review the execution of self-inspections by each unit.
Each business, finance, asset safekeeping, and information technology unit, as well as foreign business units of a banking business, shall conduct a general self-inspection at least once every six months and a special self-inspection at least once every month. However, for a month in which a general self-inspection has been conducted, a general business audit has been conducted by the internal audit unit (including the internal audit unit of the parent company), a full-scope examination has been conducted by financial examination authorities, or a self-assessment on legal compliance matters has been performed, the special self-inspection for that month may be waived. If a banking business that has been approved by the competent authority to adopt a risk-based internal audit system, the banking business may determine the frequency, focus, and scope of general and special self-inspections based on the results of risk assessments and implement them after obtaining approval from the board of directors.
A financial holding company shall conduct a self-inspection of its internal control system at least once every year and supervise its subsidiaries in conducting the self-inspection matters of the internal control system specified in the preceding paragraph.
For the self-inspection affairs mentioned in the preceding two paragraphs, the head of the unit shall assign a person of another duty to conduct the audit and be kept secret.
The results of self-inspections mentioned in Paragraph 2 and 3 shall be made as working papers and shall be preserved together with the self-inspection or internal audit reports and relevant materials for no less than five (5) years.
A financial holding company or banking business shall track the improvement status of the deficiencies identified during the self-inspections of each unit.
Article 15  Financial holding companies and the banking business shall conduct annual self-inspection programs and continuously provide appropriate training courses for personnel conducting self-inspections in accordance with the nature of each department.
Section 2  Legal Compliance System
Article 16  Financial holding companies and the banking business shall establish a dedicated legal compliance unit subordinate to the general manager to take charge of the planning, management, and execution of the legal compliance system, and appoint a person ranked vice general manager or above, or a person with equivalent responsibilities, to serve as the Chief Compliance Officer (CCO) to oversee legal compliance affairs. The chief compliance officer shall report to the board of directors and supervisors (board of supervisors) or the audit committee at least semi-annually. Upon discovering a material violation of laws and regulations or a downgrade of its rating by competent financial authorities, the CCO shall immediately notify the directors and supervisors (board of supervisors) and submit a report on legal compliance matters to the board of directors.
The dedicated legal compliance unit mentioned in the preceding paragraph may concurrently handle matters related to anti-money laundering, countering the financing of terrorism, and anti-fraud. The unit shall not concurrently engage in legal affairs unrelated to the planning, management, and execution of the legal compliance system, or other operations that present a conflict of interest with its duties. The chief compliance officer may serve concurrently as the head of the dedicated unit for anti-money laundering, countering the financing of terrorism, and anti-fraud. However, the chief compliance officer shall not serve concurrently as the head of the legal affairs unit or hold other internal positions.
Where the competent authority has provided otherwise for credit cooperatives and bills finance companies regarding the provisions of the preceding two paragraphs, such provisions shall govern.
The CCO of a financial holding company or a bank shall meet the qualification requirements set out respectively in the “Regulations Governing Qualification Requirements for the Promoter or Responsible Persons of Financial Holding Companies and Concurrent Serving Restrictions and Matters for Compliance by the Responsible Persons of a Financial Holding Company” and in the “Regulations Governing Qualification Requirements and Concurrent Serving Restrictions and Matters for Compliance by the Responsible Persons of Banks”.
The dedicated legal compliance unit of the head office, domestic and foreign business units, information unit, assets safekeeping unit, and other management units of a financial holding company or a banking business shall each assign the personnel to act as the compliance officer to take charge of related affairs. Arranging the compliance officer position in the foreign business unit shall comply with the local regulations and the requirements of the local authorities and the compliance officer shall not hold other posts except in any of the following situations:
1 The compliance officer serves concurrently as the AML/CFT compliance officer.
2. The compliance officer holds concurrent posts that do not constitute a conflict of interest according to the local regulations.
3. It is not strictly prohibited in the local regulations regarding the holding of concurrent posts, provided the holding of concurrent post does not result or potentially result in conflict of interest and the matter has been communicated with and confirmed by the local competent authority and reported to the competent authority for recordation.
If a Taiwan branch of a foreign bank is unable to appoint a person to serve as the compliance officer in its business units, information technology units, finance and custody units, and other management units in accordance with the preceding paragraph, it shall adopt appropriate alternative methods to achieve the same functions required in the preceding paragraph.
The chief officer and personnel of the dedicated compliance unit of a financial holding company or the head office of a banking business, as well as the compliance officer of its domestic and foreign business units, information department, assets management department, and other management departments shall meet one of the following qualification requirements:
1. Having worked as personnel or chief officer of legal compliance office at any financial institute for five years in aggregate.
2. Having attended not less than 30 hours of courses offered by institutions recognized by the competent authorities, passed the exams and received completion certificates, therefore.
3. The compliance officer of a foreign business unit who is hired locally, has shown his/her familiarity with local regulations and competence in related matters according to the self-assessment of the assessment procedures resolved by the board of directors, or the review and acknowledgement by the local competent authority.
Article 17  The head office and branches of a financial holding company or banking business shall establish advisory and communication channels for regulatory compliance matters to keep employees informed of rules and regulations, swiftly clarify any questions of the employees on rules and regulations, and ensure regulatory compliance.
The dedicated legal compliance unit shall conduct the following tasks:
1. Establishing a system for clear and adequate conveyance, consultation, coordination and communication of rules and regulations.
2. Keeping operating and management rules and procedures updated in line with relevant regulations to make sure all business activities comply with regulatory requirements.
3. Before a banking business introduces a new product or service or applies to the competent authority for approval to offer a new business, the chief compliance officer shall issue and sign an opinion statement undertaking that the new product, service or business complies with applicable regulations and internal rules.
4. Drafting rules and procedures for evaluating regulatory compliance and overseeing the periodic implementation of self-evaluation by respective units; assessing the compliance self-evaluation operations of respective units and producing a report thereon, which, after being signed off by the general manager, will be used as reference in the performance evaluation of the unit.
5. Providing pertinent regulatory training to employees.
6. Supervising the introduction, establishment and implementation of relevant internal rules by the compliance officer of respective department.
7. Formulating the contents of the reports to be submitted to the board of directors pursuant to Paragraph 1 of the preceding Article, which shall at least include analysis of the causes, potential impacts, and proposed recommendations for improvement regarding material compliance deficiencies or irregularities in each unit.
8. Incorporating the overall implementation of legal compliance from the preceding year into the assessment of the implementation of the internal control system referred to in Paragraph 1 of Article 8 annually.
The internal audit unit may draft the rules and procedures for evaluation of compliance by its subordinate units and perform self-evaluation of compliance by its subordinate units, to which the provisions in Subparagraph 4 of the preceding paragraph do not apply.
A financial holding company or banking business shall perform self-evaluation of compliance at least semiannually. The results shall be sent to the dedicated compliance unit for further reference. The head of a unit shall designate a specific person to conduct the self-assessment activities in each unit. The self-evaluation draft and information for the preceding affairs shall be retained for at least five (5) years.
A financial holding company shall, based on the scale of business operations and characteristics of operational risks of its subsidiaries, supervise its subsidiaries in conducting the assessment of compliance specified in the preceding paragraph.
Article18    A banking business shall establish a bank-wide risk-based management and supervision framework for legal compliance. The basis of such framework, functions and responsibilities is specified as follows; where the competent authority has provided otherwise for credit cooperatives and bills finance companies, such provisions shall govern:
1. The dedicated legal compliance unit shall set up the procedures, plans and mechanisms for identifying, assessing, controlling, measuring, monitoring, and independently reporting any compliance risk in order to generally control, supervise, and support each domestic or foreign department, branch, and subsidiary with respect to individual business unit, cross-department, and cross-territorial legal compliance.
2. The dedicated legal compliance unit shall set up an adequate number of professional units based on the classification or business, or points of legal compliance, to monitor, implement and support the legal compliance of the local or foreign business units related to that business or legislation.
3. The dedicated legal compliance unit may assess the appointment and enhance the independence of each chief compliance officer by risk-based approach. Notwithstanding the requirements in the first part of paragraph 5 of Article 16, an independent chief compliance officer is not required, and the legal compliance office of the head office will be responsible for a unit with lower compliance risk.
4.The dedicated legal compliance unit shall establish the mechanism of independent reporting, assessment and disposition of compliance risk alert.
5.The dedicated legal compliance unit shall assess the risk management of legal compliance for the primary operating activities, products and services, credit or business projects, and critical customer complaints subject to potential legal violation on a regular and ad-hoc basis and shall establish cross-functional communication links with the Risk Management and Information Security units.
6. The dedicated legal compliance unit may request each unit to provide relevant information in order to understand the compliance risks across the bank.
7. The performance evaluation of management and the head of each department shall incorporate the dedicated compliance unit's assessment opinion on their degree of implementation of legal compliance.
8. The banking business and its dedicated legal compliance unit shall fully understand the compliance procedures applicable to the foreign business units, and the criteria required by the local competent authority, and provide full resources and support.
9. The dedicated legal compliance unit shall specify the weakness of the compliance risk management, and supervise the improvement plans and schedules with respect to the local and foreign operations across the bank when reporting the legal compliance to the board of directors, and the supervisors or audit committee at least once every half year pursuant to paragraph 1 of Article 16; the board of directors (or the council) shall provide sufficient resources and appropriate mechanism of rewards and sanctions applicable to the business units in order to progressively establish a bank-wide culture of legal compliance.
Within two years after establishing a dedicated legal compliance unit, a bank shall submit its bank-wide compliance risk management and oversight framework to the competent authority for recordation. Thereafter, by the end of April of each year, it shall submit to the competent authority the assessment reports referred to in Subparagraphs 5 and 9 of the preceding paragraphs.
If a banking business has a foreign business unit, the dedicated legal compliance unit shall supervise the following tasks of the foreign business unit:
1. Collecting data on local financial regulations, conducting self-evaluation of compliance operation, and ensuring the suitability of compliance officer and the adequacy of compliance resources (including personnel, equipment and training) so as to ensure compliance with the laws and regulations of the host country or jurisdiction.
2. Establishing self-evaluation and monitoring mechanism for compliance risks, and for large business operation, highly complex business or business involving higher risk, engaging a local, outside, independent expert to verify the effectiveness of the self-assessment and monitoring mechanism.
Article19    The chief compliance officer, the head and personnel of the dedicated legal compliance unit of a financial holding company and banking business, as well as the compliance officers of domestic business units, information technology units, finance and asset safekeeping units, and other management units, shall attend at least fifteen hours of in-service training organized by the competent authority or institutions recognized by the competent authority, or organized internally by their affiliated financial holding company (including subsidiaries) or banking business (including the parent company or the subsidiary bank of the parent group in Taiwan) each year. The content of the training shall at least include newly amended laws and regulations, new types of business operations, or new types of financial products.
The compliance officer of a foreign business unit shall attend at least fifteen hours of in-service training courses on legal compliance organized by the competent authority, institutions recognized by the competent authority, or local relevant authorities, or organized internally by their affiliated financial holding company (including subsidiaries) or banking business (including the parent company) each year.
The training methods for the on-the-job training as set forth in the foregoing two paragraphs held by the company itself shall be approved by the board of directors. The attendance records of relevant personnel shall be kept for review.
Where the dedicated unit for anti-money laundering and countering the financing of terrorism is established under the dedicated legal compliance unit, the required training for the personnel of such dedicated unit prior to assuming office and training required each year shall be handled in accordance with relevant regulations governing anti-money laundering and countering the financing of terrorism, and shall not be subject to the restrictions prescribed in Paragraph 1 of this Article and Paragraph 7 of Article 16.
Financial holding companies and the banking business shall report the roster and training records of the chief compliance officer, as well as the head and personnel of the dedicated legal compliance unit, to the competent authority via an online information system.
Section 3  Risk Management System
Article 20     Financial holding companies and the banking business shall formulate appropriate risk management policies and procedures, and establish an independent and effective risk management framework, which shall include procedures and mechanisms for identifying, assessing, measuring, and monitoring risks in order to control and report the overall risk tolerance, the current status of risks assumed, determination of risk response strategies, and the compliance status of risk management procedures.
The risk management policies and procedures under the preceding paragraph shall be passed by the board of directors and be reviewed and revised in a timely manner.
Article 21  Financial holding companies and the banking business shall establish a dedicated risk management unit subordinate to the general manager to take charge of the planning, management, and execution of the risk management system. The unit shall not concurrently engage in other operations that present a conflict of interest with its duties. A person ranked vice general manager or above, or a person with equivalent responsibilities, shall be appointed to serve as the Chief Risk Officer (CRO) to oversee risk management affairs.
The dedicated risk management unit shall periodically measure relevant risks and submit risk management reports to the board of directors. Upon identifying a significant risk exposure that might adversely affect its financial or business status or compliance with applicable acts and regulations, it shall take immediate and adequate countermeasures and submit a report to the board of directors. The overall implementation of risk management of the preceding year shall be incorporated into the assessment of the implementation of the internal control system referred to in Paragraph 1 of Article 8 annually.
The dedicated risk management unit shall establish clear and appropriate mechanisms for the transmission, consultation, coordination, and communication of risk management.
Where the competent authority has provided otherwise for credit cooperatives and bills finance companies regarding the provisions of Paragraph 1, such provisions shall govern. With respect to the establishment of the dedicated risk management unit, a credit cooperative may designate a head office management unit as an alternative.
Article 22  The risk management mechanism of a financial holding company shall at least include the following matters:
1. Monitoring the capital adequacy of the financial holding company and of all subsidiaries based on their respective business scale, credit, market, and operational risks, and future business trends.
2. Adopting adequate long- and short-term financing principles and guidelines and establishing management mechanisms for measuring and monitoring the liquidity positions of the financial holding company and of all subsidiaries, by which to measure, monitor, and manage the liquidity risks of the financial holding company and of all subsidiaries.
3. Making various investment allocations after having considered the overall risk exposure, equity capital, and characteristics of liabilities of the financial holding company, and establishing various measures to manage investment risks.
4. Establishing uniform assessment methodologies for rating and classifying the quality of assets of the financial holding company and of all subsidiaries, calculating and controlling large risk exposures of the financial holding company and its subsidiaries, carrying out periodic reviews, and faithfully setting aside allowances or reserves for loss.
5. Identifying, assessing, and measuring potential emerging risks, and implementing risk response strategies.
Article 23  The risk management mechanisms of a banking business shall at least include the following matters:
1. Monitoring the capital adequacy based on its business scale, credit, market, and operational risks, and future business trends.
2. Establishing management mechanisms for measuring and monitoring the liquidity positions of the banking business, by which to measure, monitor, and manage the liquidity risks.
3. Making various investment allocations after having considered the overall risk exposure, equity capital, and characteristics of liabilities, and establishing various measures to manage investment risks.
4. Establishing uniform assessment methodologies for rating and classifying the quality of assets, calculating and controlling large risk exposures, carrying out periodic reviews, and faithfully setting aside allowances or reserves for loss.
5. Identifying, assessing, and measuring potential emerging risks, and adopting risk response strategies.
Section 4  Information Security System
Article 24  Financial holding companies and the banking business shall establish a dedicated information security unit subordinate to the general manager, which shall not concurrently handle information technology operations or other operations that present a conflict of interest with its duties, and shall allocate appropriate human resources and equipment, and appoint a person ranked vice general manager or above, or a person with equivalent responsibilities, to serve as Chief Information Security Officer (CISO) to oversee the promotion of information security policies and the allocation of resources. However, where the competent authority has provided otherwise for credit cooperatives and bills finance companies, such provisions shall govern.
The CISO of a financial holding company and banking business shall report the overall implementation of information security from the preceding year to the board of directors each year, and report material information security issues in a timely manner.
Personnel of the dedicated information security unit of a financial holding company and banking business shall receive at least fifteen (15) hours of professional information security training courses or functional training annually; other information technology personnel shall receive at least six (6) hours of professional information security training courses or functional training annually. Personnel of the head office, domestic and foreign business units, finance and custody units, and other management units of a banking business shall receive at least three (3) hours of information security awareness courses annually.
The Bankers Association of the Republic of China, the National Federation of Credit Cooperatives, and the R.O.C. Bills Finance Association shall establish and regularly review the self-disciplinary regulations of information security.
Article 25  The matters to be performed by the dedicated information security unit shall at least include:
1. Taking charge of the planning, management, and execution of the information security system to manage information security risks.
2. Supervising each unit in implementing the information security system, and ensuring the confidentiality, integrity, and availability of communication systems, services, and information.
3. Establishing mechanisms related to cyber security protection, assessment and response to cyber security intelligence, and reporting of and response to cyber security incidents.
4. Incorporating the overall implementation of information security from the preceding year into the assessment of the implementation of the internal control system referred to in Paragraph 1 of Article 8 annually.
Section 5 Internal Audit System
Article 26  The purpose of internal audit is to assist the board of directors and the managerial level to verify and evaluate whether the operation of internal control system works effectively and smoothly and provide appropriate suggestions for revision, which can ensure the on-going performance of effective internal control and serve as the basis of internal control system revisions.
Article 27  Financial holding companies and the banking business shall set up an internal audit unit that is directly subsidiary to the board of directors, which shall perform audit business independently and honestly. The unit is required to report its audit business to the board of directors and supervisors (board of supervisors) or audit committee at a minimum period of every six months.
Financial holding companies and the banking business shall establish a chief auditor system to manage all audit business. The chief auditor shall possess sufficient leadership and ability to carry out effective audit work, and whose qualification requirements shall be equivalent to those prescribed for the responsible persons of each respective type of financial institution, with a rank equivalent to that of a vice general manager. The chief auditor is not allowed to take a job that will cause conflicts or limitations to the audit work.
The employment, dismissal, or transfer of the chief auditor shall have the consent of the majority of audit committee members as well as the consent of more than two-thirds of the board of directors and report to the competent authority for ratification.
Where the matter in the preceding paragraph did not have the consent of the majority of audit committee members, the resolution adopted by the audit committee shall be recorded in the board meeting minutes. If there is no audit committee but independent directors set up and an independent director objects to or expresses reservations about the matter, it shall be recorded in the board meeting minutes.
In the event of a change of the chief auditor, a financial holding company and banking business shall, within five days from the date of occurrence of the fact, report the reasons for and contents of the change in writing to the competent authority, and provide a copy of the notification to the chief auditor involved in the change.
The "date of occurrence of the fact" referred to in the preceding paragraph means the date of the resolution of the board of directors or any other date sufficient to confirm the appointment or dismissal of the chief auditor, whichever is earlier.
The appointment, dismissal, promotion, reward/ discipline, rotation, and performance review of personnel in the internal audit unit shall become effective after being reported by the chief auditor to chairperson of the board. However, if a matter involves personnel of other management or business units, the chief auditor shall first consult the personnel department to refer the matter to the general manager for approval, and then report to the chairperson of the board for final approval.
The Regulations in Paragraph 1 to 7 of this article shall not apply to a company who operates financial and trust business concurrently other than a banking business.
The chief auditor of a financial holding company is allowed to, if required by business, dispatch the internal auditors of a subsidiary company to conduct the internal audit task on the financial holding company or its subsidiary company. The chief auditor shall also take up the final responsibility to ensure appropriate and effective internal audit system in the financial holding company or its subsidiary company.
Financial holding companies and the banking business shall establish communication channels and mechanisms between independent directors, the audit committee, or supervisors (board of supervisors) and the internal audit unit, and the internal audit unit shall report the communication status to the board of directors on an annual basis.
Article 28  When any of the following circumstances applies to a chief auditor in overseeing internal audit work, the competent authority may, having regard to the seriousness of the event, issue an official reprimand, order the chief auditor to make improvements within a specified time limit, or otherwise order the financial holding company to release the auditor general from duty.
1. Has made any improper loan extension, been involved in a material breach of the principles for giving credit or otherwise engaged in any improper transfer of funds with customers, as established by factual proof.
2. Has abused authority of office, there is evidence showing that he or she has carried out improper activities, or he or she has misused power, in an attempt to seek profits for him or herself or for a third party, or to damage the interest of its belonging financial company (including its subsidiaries) or banking business; and therefore, his or her abuse or misuse of power has thus cause losses for its belonging financial company or its subsidiary company or banking business or a third party.
3. The auditor disclose, deliver, or publicize all or part of the contents of its financial examination reports to a person not related to such job without the consent from the competent authority.
4. Has failed to notify the competent authority of any significant malpractice that due to poor internal management has occurred in the financial holding company (including its subsidiaries) or the banking business.
5. Has failed to disclose in an internal audit report any significant deficiency identified in the financial and business operations of the financial holding company (including its subsidiaries) or the banking business.
6. Has issued a fraudulent internal audit report on internal audit findings.
7. As a result of obviously insufficient staffing or staffing operations by obviously incompetent internal auditors in the financial holding company (including its subsidiaries) or banking business, has failed to identify a serious deficiency in financial and business operations.
8. Has failed to follow the instructions of the competent authority in conducting audit work or in providing relevant information.
9. Has otherwise committed any act that impairs the reputation or interests of the financial holding company (including its subsidiaries) or the banking business.
Article 29  Financial holding companies the banking business shall, after having regard to its investment scale, business condition (the number of its branches and amount of business), management needs, and relevant provisions of rules and regulations, staff competent persons in an appropriate number as full-time internal auditors who shall perform their duties in a detached, independent, objective, and impartial manner. Personnel of the internal audit unit shall be deputy to each other to cover each other's absence.
An internal auditor of a financial holding company or banking business shall meet the following qualification requirements:
1. Having not less than two (2) years of experience in financial examination; or having graduated from a college or university or passed a senior civil service examination or an equivalent examination, or the examination of certified internal auditor or certified information systems auditor and having not less than two (2) years of experience in financial business; or having not less than five (5) years of experience in financial business. A person is deemed to meet such requirements if he or she has worked as a professional, such as an auditor in an accounting firm, or a computer programmer or system analyst for not less than two (2) years and has received not less than three (3) months of training in the business operations and management of a financial institution. However, the number of this type of auditor cannot exceed one-half of the total auditors.
2. Free of any record of demerit or more severe disciplinary action from employer in the last three (3) years, unless the demerit record was a result of joint and several disciplinary action on account of the violation or offense of another person, and the demerit has been offset by other merits; and
3. If a lead auditor, have no less than three (3) years of experience in auditing or financial examination, or have no less than one (1) year of experience in auditing and no less than five (5) years of experience in financial business.
The qualifications of the dedicated internal audit personnel of banks’ foreign business units must comply with the local regulations and the requirements of the local competent authority. However, if the local competent authority does not specify the qualifications for internal auditors hired locally, the foreign business unit shall hire employees in accordance with the evaluation and selection regulations passed by the board of directors, and the aforementioned regulations do not apply.
Financial holding companies and the banking business shall examine whether the internal auditors have violated the regulations in the preceding three paragraphs. If the auditor has violated the rules, the company shall order the auditor to make improvement within two (2) months and shall be transferred to other job if he or she fails to make such improvement.
Article 30  The internal auditors of a financial holding company or banking business shall perform their duties in good faith, and may not do any of the following:
1. Conceal or make false or inappropriate disclosures of any of the financial holding company's or the banking business's business activities, reporting, or compliance with rules and regulations that they know to directly cause damage to any interested party.
2. Act beyond the scope of audit functions or engage in other improper activities, or externally disclose any acquired information, attempt to profit therefrom, or otherwise use the information against the interest of the financial holding company (including its subsidiaries) or banking business.
3. Cause losses to the financial holding company (including its subsidiaries) or the banking business or harm the interests of its stakeholders due to negligence.
4. Conduct audit work within one (1) year to the department where the auditor used to work at.
5. Fail to recuse himself or herself from auditing of cases or business within the scope of his or her past duties or matters in which he or she has a personal interest.
6. Directly or indirectly provide, promise, demand or accept any unreasonable gift, hospitality or other improper benefits of any form to or from employees or customers of the same financial holding company (including its subsidiaries) or the banking business.
7. Fail to audit matters that the competent authority has instructed to him or her to audit or to provide relevant information.
8. Any other violation of rules, regulations or practices prohibited by the competent authority.
Financial holding companies and the banking business shall examine at all time whether the internal auditors have violated the regulations in the preceding two paragraphs. If the auditor has violated the rules, the company shall order the auditor to make improvement within one (1) month and shall be transferred to other job if he or she fails to make such improvement.
Article 31  The internal audit unit shall undertake the following tasks:
1. Plan the organization structure, size and duty of the internal audit unit. Prepare internal audit working manuals and working papers, which shall at least include assessing the various rules and operating procedures of the internal control system to determine whether adequate internal controls are already in place in the current rules and procedures, whether each department has realistically carried out the internal controls, and whether the internal controls are carried out in a reasonably effective manner, and from time to time provide recommendations for improvement.
2. Formulate annual audit plans and, based on the business risk profile of and implementation of internal audits by each subsidiary or department, determine audit plans targeted at each individual subsidiary or department
Financial holding companies and the banking business shall conduct self-inspections, and the internal audit unit shall audit the implementation of the self-inspections of the internal control system by each unit (including its subsidiary companies if it is a financial holding company). Such audit results, together with the improvement status of internal control deficiencies and irregularities identified by the internal audit unit, shall serve as the basis for the issuance of the Internal Control System Statement.
When a significant deficiency or malpractice arises within the management or business departments of a financial holding company or a banking business, the internal audit unit shall have the power to suggest penalties and shall make a full disclosure of the responsible negligent personnel in an internal audit report.
Article 32  The internal audit unit of a banking business shall conduct one routine audit and one special audit annually on its operation, finance, asset custody, information departments and dedicated information security unit; at least one special audit annually on other management departments; and at least one routine audit annually on its all-business centers, foreign business units and foreign subsidiary companies. For foreign representative offices, the internal audit method may be replaced by audit documentary review, or the frequency of internal audit may be flexibly adjusted.
The contents of the routine audit or the special audit, which is performed by the internal audit unit of a banking business to its business unit, shall cover whether there are improper marketing activities when dealing with trust business, financial management, and the sale of financial products; whether the contents of the products are clearly disclosed; whether the risks are well notified; whether the contract is fair and other obligations are performed appropriately following the law or self-regulatory guidelines.
The internal auditing unit of a financial holding company shall conduct a routine audit at least annually; a special audit on its finance, risk management, and compliance with applicable acts and regulations at least semiannually; where the routine audit has covered the scope of the special audit and its audit results reveal no significant deficiency, and it expressly states such in the internal audit report, it is not required to conduct a special audit for that current half-year.
The internal audit unit shall include the execution status of the regulatory compliance system into the routine audit or special audit of the business and management units.
Article 33   A domestic bank may apply to the competent authority for approval to adopt a risk-based internal auditing system. A subsidiary that was evaluated and exempted from adopting the system for implementation in accordance with Paragraph 2 of Article 34 shall provide evaluation documents. The competent authority may ask a domestic bank to apply for approval to adopt a risk-based internal auditing system in view of the bank's asset size, business risks, and other necessary conditions.
A domestic bank that applies for approval to adopt a risk-based internal auditing system must meet the following criteria:
1. The bank's most recently filed ratio of regulatory capital to risk-weighted assets meets the requirements set out in Article 5 of the Regulations Governing the Capital Adequacy and Capital Category of Banks;
2. The bank does not show insufficient loan loss provision and reserves based on the most recent financial examination and the most recent CPA-audited and certified financial statements;
3. The bank's non-performing loan ratio of the most recent quarter does not exceed 1%; and
4. The bank has an effective internal control system.
    The provisions on auditing frequency in Paragraph 1 of the preceding article and Paragraph 2 of Article 34 do not apply to domestic banks that have been approved to adopt a risk-based internal auditing system.
Article34   Financial holding companies and the banking business shall formulate annual audit plans and, based on the business risk profile of and implementation of internal audits by each subsidiary, determine audit plans targeted at each individual subsidiary.
The internal audit unit of a financial holding company or a banking business, except those foreign subsidiary banks of a banking business and other business ratified by the competent authority, conduct a target audit on its subsidiaries' finance, risk management, and compliance with applicable acts and regulations at least semiannually and incorporate the audit results into its annual audit project.
Financial holding companies and the banking business shall supervise its subsidiaries to submit their board meeting minutes, CPA audit reports, examination reports issued by the financial examination agency, and other relevant materials, and, for subsidiaries having established an internal audit unit, audit plans and reports on significant deficiencies identified in internal audit reports and the status of improvements thereof; the parent company shall review such documents and monitor the implementation of improvements by each subsidiary.
  The chief auditor of a financial holding company or a banking business shall periodically evaluate the efficacy of the internal control activities of a subsidiary as set forth in the preceding paragraph and, after having reported to the board of directors, send the evaluation results to the relevant subsidiary's board of directors for their reference in personnel evaluations.
Article 35  Financial holding companies and the banking business shall disclose at least the following information in its internal audit report for routine audits:
1.Audit scope; summary commentary; financial status; capital adequacy; operation performance; asset quality; equity management; management of the operation of board of directors and audit committee; compliance with major acts, regulations, and rules; internal controls; interested party transactions; the control and internal management of all business tasks; employee confidentiality education; information management and information security; management of customer data confidentiality; protection measures of consumers and investors; management of sustainability information and the results of self-inspection, and the evaluation to above matters.
2. Opinions for the major illegal errors or faults in all departments, and the suggestions for punishment for employees fail to fulfill their duties.
3. The examination comments or faults listed by the financial examination agency, accountants, internal audit unit (including the internal audit unit of the parent company), and self-inspection people, and the improvement status of items that enlisted as 'need further improvement' by the internal control system statement.
The record of the results in working papers shall be preserved together with the self-inspection or internal audit reports and relevant materials for no less than five (5) years.
Article 36 The internal audit report of a financial holding company or banking business shall be delivered to the supervisors (board of supervisors) or audit committee for review and unless it is otherwise provided by the competent authority, shall be submitted to the competent authority within two (2) months following completion of the audit. The audit report shall also be delivered to the independent directors if such positions are set up by the financial holding company or the banking business.
Article 37  Before assuming the following post, the person shall enroll in the following trainings held by the institutes recognized by the competent authority and obtain completion certificate from them:
1. When acting as an internal auditor for the first time, the auditor shall participate in the audit training course, computer audit training course or billing audit training course for no less than sixty (60) hours. The auditor shall also pass the exam and obtain the completion certificate.
2. An internal auditor with leadership duty shall participate in the internal auditor leader train course for no less than nineteen (19) hours.
3. The chief auditor and official, deputy managers shall participate in audit manager training course for no less than twelve (12) hours.
The regulations in the preceding paragraph do not apply to the training required for locally hired internal audit personnel hired by the foreign business unit. However, where the local competent authority has other regulations, such regulations shall apply.
Internal auditors (including the official, deputy managers and chief auditor) of a financial holding company (including its subsidiary companies) or a banking business (including the parent company) each year shall attend a finance-related professional training held by a competent authority-designated institution or by the financial holding company or a subsidiary thereof. For the minimum number of training hours, the total hour shall be no less than twenty (20) for the official, deputy managers and chief auditors; no less than thirty (30) for the other internal auditors. If an auditor has obtained an international internal auditor certificate within the current year, the certificate can be transferred to the training hours.
  The total hour of a finance-related professional training held by a competent authority-designated institution shall not be less than half of the training hours in the preceding paragraph.
The number of required training hours each year for an auditor stationed in a foreign country or locally hired internal audit personnel hired by the foreign business unit shall meet requirements in local regulations, and the regulations in the two preceding paragraphs do not apply. However, where requirements are not specified in the local regulations, the number of on-the-job training hours required each year for the supervisor and the personnel of the internal audit unit of the head office in Taiwan shall be adopted. The training hours can also be recognized by enrolling with a financial training institute established according to the local regulations.
  A financial holding company or a banking business shall verify that its internal auditors meet the qualification requirements set forth herein. The verification documentation and records for such purpose shall be kept on file for future reference.
Article 38  Financial holding companies and the banking business shall, in a prescribed format and via an Internet-based information system, file with the competent authority for recordation the information on the name and years of service of its internal auditors by the end of January annually.
  When preparing the basic information of internal auditors, the financial holding company or the banking business shall verify whether these auditors have met the requirements stipulated in Paragraph 2 and Paragraph 3, Article 29 and Article 37. If the auditor fails to meet the requirements, it shall be improved within two (2) months, if not, the auditor shall be re-assigned to another job.
Article39   Financial holding companies and the banking business shall, in a prescribed format and via an Internet-based information system, file with the competent authority for recordation its next year's audit plan by the end of each fiscal year and a report on the execution of its preceding year's annual audit plan within two (2) months from the end of each fiscal year.
By the end of each accounting year, the financial holding company or the banking business shall deliver a written audit plan for the next year to the supervisors (supervisors, board of supervisors) or the audit committee for examination and compilation. If the company doesn't have an audit committee, the report shall be delivered to the independent directors for comments. The annual audit plan and changes thereof shall be approved by the board of directors.
The contents of audit plan mentioned in the preceding paragraph shall at least include: an explanation of the audit plan, annual audit points, units that will receive the audit, nature of audit (routine audit or special audit), and whether the frequency of audit comply with the regulation of the competent authority. If the audit is a special audit, then it is necessary to notify the range of audit.
Article 40  Financial holding companies and the banking business shall, in a prescribed format and via an Internet-based information system, file with the competent authority for recordation their improvements of deficiencies and irregularities identified in the internal control system in preceding year within five (5) months from the end of each fiscal year.
Article 41  For a banking business, officers with business or transaction approval authority shall meet any of the requirements below prior to taking office:
1. Have served as auditors in the internal audit unit and worked for over one (1) year with actual auditing affairs.
2. Have enrolled in the audit training course or computer audit training course held by a competent authority-designated institution and passed the exam and obtained the completion certificate.
3. Obtaining the qualification certificates in banking business internal control and internal audit exam held by a competent authority-designated institution. The contents of the exam shall be similar to the contents mentioned in the preceding paragraph.
For the foreign businesses of domestic banks, officers with business or transaction approval authority, they are allowed to enroll in professional audit training held by a foreign professional institute or obtain a similar certificate from a foreign institute to replace the certificate mentioned in Paragraph 1.
When acting as the manager of a local business unit, the person shall meet the conditions listed in Paragraph 1. Furthermore, if such person meets the qualifications in Subparagraph 2 or 3 of Paragraph 1, they shall participate in internal audit practices no less than four (4) times with the internal audit unit before actually assuming the post or within six (6) months after assuming the post. During these internships, such person shall inspect at least one (1) item per session, with cumulative coverage of no less than four (4) items, prepare a report on the practice, and submit it to the chief auditor for verification. The chief auditor shall issue a certificate and retain it together with the report for further reference
 For the banks of a foreign bank in Taiwan, the officers with business or transaction approval authority have finished the internal audit trainings requirement by the bank, when the training is higher than the requirements listed in Paragraph 1, then they can be exempt for the regulations in this article. The officers with business or transaction approval authority referred to therein shall mean managers who report directly to the person in charge in Taiwan and possess business or transaction approval authority.
Article 42 The internal audit unit shall continually conduct follow-up reviews on any examination opinions or audit deficiencies brought up by the financial examination authority, CPA and internal audit unit (including the internal audit unit of the parent  company), as well as matters specified in the internal control system statement as requiring stronger improvement efforts, and submit a written report on the implementation of improvement of deficiencies to the board of directors, together with a copy to the supervisors (supervisors, the board of supervisors), and list these as an important factor in the relevant department's performance evaluations.
The major points of audit task for a financial holding company or a banking business shall be prescribed by the competent authority.
Article 43 The audit business matters reported by the internal audit unit of a banking business to the board of directors  and supervisors or the audit committee at least once every six months pursuant to Paragraph 1 of Article 27 shall include the performance evaluation of the dedicated units for legal compliance, risk management, and information security, as well as evaluation opinions on the bank-wide level of legal compliance, risk management, and information security.
After the end of examination conducted by the competent authority or the local competent authority at where a foreign branch is located or after receiving an examination report, the internal audit unit at a financial holding company or the head office of a banking business shall, based on the principle of materiality, promptly inform the directors (council members) and supervisors (board of supervisors), and make a report to the forthcoming board of directors' meeting. The report items shall include the content of examination communication meeting, major deficiencies found in the examination, the rating downgrade by the financial competent authority, improvement actions required by the competent authority or possible disciplinary measures to be taken.
Section 6 Audit System with engaged CPAs
Article 44  If the annual financial report of a banking business is audited and certified by a certified public accountant (CPA), the business shall also engage the CPA to conduct a special audit on its internal control system. The CPA shall also comment on the correctness of the report submitted to the competent authority for the banking business, the execution status of the internal control system and regulatory compliance system, and the appropriateness of policies for loan loss reserves, including those of the foreign business units of the banking business.
A banking business shall engage a certified public accountant (CPA) to conduct a special audit on its personal data protection and anti-money laundering and countering the financing of terrorism mechanisms.
Certified public accountants conducting the audits referred to in the preceding two paragraphs shall provide a reasonable assurance report.
The special audit fees for the CPA shall be negotiated by the banking business and the CPA. The banking business shall pay the special audit fees to the CPA.
The provisions of Paragraph 1 and Paragraph 2 are not applicable to banking business taken over by the competent authority.
Article45  The competent authority may, where necessary, invite a banking business and its appointed CPA to discuss matters related to the special audit under the preceding Article. If the competent authority finds that the CPA engaged by the banking business is not fully competent to perform the engaged audit work, it may order the banking business to replace the CPA and re-conduct the special audit.
Article 46  When performing the assurance work prescribed in Article 44, the CPA shall immediately notify the competent authority in the event of any of the following conditions:
1. During the process of assurance work, the business fails to provide the required reports, certificates, account books, and meeting minutes to the CPA, or refuses to make further explanation of the queries submitted by the accountant, or there are other objective environment restrictions to render the CPA unable his or her assurance work.
2. Where there are severe falsifications, forged data, or material omissions in its accounting or other records.
3. Where its assets are insufficient to discharge its liabilities, or its financial condition has significantly deteriorated.
4. Where there is evidence indicating that its transactions will cause material damage to the banking business’s net assets.
Where the banking business under audit has the conditions set forth in Subparagraphs 2 through 4 of the preceding paragraphs, the CPA shall also first submit a summary report on the results of the assurance procedures executed to the competent authority.
Article 47   When a banking business engages a CPA to conduct a special audit as provided in Paragraph 1 and 2 of Article 44, the business shall provide the CPA’s audit report of the previous year to the competent authority by the end of April each year for recordation. The assurance report shall at least entail the scope, basis, procedures, and results of the audit.
When a credit cooperative conducts such audit in accordance with the preceding paragraph, the audit report shall be submitted through the finance department of the municipal government or the county (city) government.
When the competent authority has queries concerning the contents of the assurance report, the CPA shall truthfully provide relevant information and explanation.
Chapter 4 Supplementary Principles
Article 48  To secure the confidentiality level of the financial examination report of a financial holding company or a banking business, unless otherwise provided by law or permitted by the competent authority, the responsible person or the employee is not allowed to read or disclose, deliver, publicize all or part of the contents of the report to another person irrelevant of the performing of the task.
A financial holding company or banking business shall follow the provisions of the competent authority to prescribe the related internal management regulations and business procedures of the financial examination reports and submit them to the board of directors for consent.
Article 49  A financial holding company or a banking business shall set out in its internal control system penalties for violations of these Regulations or its internal control system rules by management and relevant personnel.
Article 50  Where a financial holding company or a banking business makes any concealment of poor internal management, unsatisfactory internal controls, inadequate implementation of the internal audit system and regulatory compliance system, or the results of implementation of improvement of any deficiency specified by a financial examination agency in an examination opinion requiring review and follow-up, or the internal audit unit (including the internal audit unit of parent company) otherwise conceals any audit findings, and where such concealment constitutes significant malpractice, the personnel involved shall be held responsible for negligence in their duties. A financial holding company (including its subsidiaries) or a banking business shall commend an internal auditor who identifies any significant malpractice or negligence and thereby averts material loss to the company.
Article 51  The internal auditors and compliance officers of a financial holding company or a banking business shall immediately prepare a report for submission, and notify to the independent directors and supervisors (board of supervisors) or violations of laws and regulations the audit committee and report to the competent authority, when their recommendations for improvements regarding significant deficiencies or noncompliance identified in internal controls are not accepted by management and as a result the financial holding company (including its subsidiaries) or the banking business might incur a material loss.
Article52  The competent authority shall prescribe the formats required formats specified in the Regulations herein.
Article 53   If the relevant internal control and audit system regulations prescribed by the head office of a foreign bank are not less than the provisions of these Regulations, the internal control and audit systems of its Taiwan branch may be implemented in accordance with the head office system and comply with the following provisions:
1. The internal control system statement shall be jointly issued by the person in charge in Taiwan, the chief compliance officer, the officer in charge of audit business for the Taiwan region, the officer in charge of information security for the Taiwan region, and the officer in charge of risk management for the Taiwan region. The statement shall be disclosed on the bank's website within three months after the end of each fiscal year, and the provisions of Article 8 shall not apply.
 2. Formulate relevant business regulations and handling guides based on its business items in Taiwan with reference to Subparagraph 2 of Paragraph 1 of Article 12.
3.Where it establishes a whistleblowing system in Taiwan in accordance with the system of the head office and designates a unit or personnel to take charge of receiving whistleblower reports, it may be exempted from the provisions of Paragraph 1 of Article 13 regarding the designation of a unit that independently exercises its functions and powers. However, the contents of the whistleblowing system shall include at least the provisions of the subparagraphs of Paragraph 4 of Article 13.
4. Where the Taiwan branch adopts a risk-based self-inspection system in alignment with its head office, explains the implementation methods for self-inspections and the evaluation mechanism for self-inspections, and submits the explanation of such implementation methods and evaluation mechanism to the competent authority for recordation, it may be exempted from the provisions of Paragraph 1 of Article 14 regarding the designation of units to conduct supervision and review, and the provisions of Paragraph 2 of Article 14.
5. Where the Taiwan branch complies with the compliance risk management and supervision framework of its head office, explains the framework principles and provisions on powers and responsibilities, and submits the explanation of such framework principles and provisions to the competent authority for recordation, it may be exempted from the provisions of Article 18.
6. Where the Taiwan branch adopts a risk-based internal audit system in alignment with its head office, explains the operating mechanism and implementation methods, and submits the explanation of such the operating mechanism and implementation methods to the competent authority for recordation, it may be exempted from the provisions of Article 31, Paragraph 1 of Article 32, Paragraph 1 of Article 35, and Article 39.
7. Where the Taiwan branch operates in accordance with the head office system and allocates appropriate human resources and equipment to ensure proper communication and risk management, it may be exempted from the provisions of Paragraph 2 of Article 16 regarding the restriction that the dedicated legal compliance unit shall not concurrently handle legal affairs and that the chief compliance officer shall not concurrently serve as the head of the legal affairs unit; and it may also be exempted from the provisions of Article 21 regarding the establishment of a dedicated risk management unit and the appointment of a chief risk officer, Article 24 regarding the establishment of a dedicated information security unit and the appointment of a chief information security officer, and Subparagraph 1 of Paragraph 2 of Article 29 regarding the headcount ratio of internal audit personnel.
8. Unless otherwise provided by the competent authority, where the internal audit is conducted by the audit unit of the Taiwan branch, the internal audit report shall be submitted to the competent authority within two months after the completion of the audit; where it is conducted by the head office or regional headquarters, the Taiwan branch shall submit the report to the competent authority within one month after receiving the report. If the content of said report is not in Chinese, a Chinese summary of key points shall be attached. 
9. For managers serving in the business units of a Taiwan branch for the first time who possess experience and training in internal control related to their duties, the provisions of Paragraph 3 of Article 41 shall not apply.
Where the internal control and audit systems of a Taiwan branch of a foreign bank do not fall under the circumstances of the preceding paragraph, and are not less than the provisions of these Regulations under the head office system, it may, upon issuing a statement of comparison in application of the head office regulations and the provisions of these Regulations, and having the same signed by the person in charge of the Taiwan branch, operate in accordance with the system of the head office. In the event of any change to the head office system, a statement of comparison in application shall be re-issued and signed by the person in charge of the Taiwan branch.
Where the internal control and audit systems of a Taiwan branch of a foreign bank do not fall under the circumstances of the preceding two paragraphs, it may, based on its business scale or nature, state reasons for specific matters, and, upon reporting to and obtaining approval from the competent authority, operate in accordance with the system of the head office. In the event of any change to the approved matters, the branch must re-submit the matter for approval and obtain approval from the competent authority.
Where a Taiwan branch of a foreign bank violates the internal control system or audit system implemented pursuant to the provisions of this Article, it shall be deemed as a violation of the provisions of these Regulations.
Article54  Financial holding companies and the banking business that do not comply with the provisions of Article 9, Article 10, Item 13 of Subparagraph 2 of Paragraph 1 of Article 12, Article 14, Article 16, Paragraphs 4 and 5 of Article 17, Article 20, Article 21, Article 24, Article 25, and Paragraph 2 of Article 31 regarding the Three Lines Model for internal control, ethical corporate management best practice principles, formulation of business continuity management mechanisms, self-inspection system, consolidation of legal compliance self-inspections and self-assessment operations, appointment of the CCO,CRO, CISO, and dedicated legal compliance, risk management, and information security units subordinate to the general manager, as well as the risk management framework, and the powers and responsibilities of the dedicated risk management and information security units, shall implement adjustments to comply with the provisions by December 31, 2027.
A credit cooperative that does not comply with the provisions of Article 35 regarding the inclusion of sustainability information management in the disclosure items of the internal audit report shall implement adjustments to comply with the provisions by December 31, 2027.
Article55  These Regulations shall enter into force on the date of promulgation, except for Articles 44 to 47, for which the enforcement dates shall be prescribed by the competent authority.
Attachments:
Data Source:Financial Supervisory Commission Laws and Regulations Retrieving System