[eu]cite

Home› Payment Services› ZAG-EN

Part 5 · Provisions on the Ongoing Supervision of Institutions › Section 27

Organisational Duties

(1) An institution must have a proper business organisation; the managers are responsible for the institution's proper business organisation. A proper business organisation includes in particular:
1. appropriate measures of corporate governance, control mechanisms and procedures ensuring that the institution meets its obligations, including appropriate and effective risk management, the design of which depends on the type, scope, complexity and risk content of the business activities and the appropriateness and effectiveness of which must be reviewed regularly by the institution, together with an internal audit function;
2. the keeping and maintenance of a loss database and complete documentation of the business activity, ensuring gapless monitoring by BaFin for its area of competence;
3. an appropriate contingency plan for IT systems;
4. internal procedures and control systems ensuring compliance with Regulation (EU) 2021/1230, Regulation (EU) No 260/2012 and Regulation (EU) 2015/751 of the European Parliament and of the Council of 29 April 2015 on interchange fees for card-based payment transactions (OJ L 123, 19.5.2015, p. 1);
5. without prejudice to the obligations under sections 4 to 7 of the Anti-Money Laundering Act, appropriate measures, including data processing systems, ensuring compliance with the requirements of the Anti-Money Laundering Act and of Regulation (EU) 2023/1113; insofar as necessary to comply with that duty, the institution may process personal data.
(2) Sections 6a, 24c, 25i, 25m and 60b of the Banking Act, and section 93(7) and (8) in conjunction with section 93b of the Fiscal Code, apply correspondingly to institutions within the meaning of this Act. Section 24c of the Banking Act applies on condition that BaFin may retrieve individual data from the file system under section 24c(1), first sentence of the Banking Act, insofar as this is necessary for it to perform its supervisory tasks under this Act and the Anti-Money Laundering Act, in particular with regard to unauthorised payment services and unauthorised e-money business, and there is particular urgency in the individual case.
(3) BaFin may, in an individual case, issue orders against an institution that are appropriate and necessary to meet the requirements for a proper business organisation within the meaning of subsection (1). BaFin may determine criteria the presence of which allows institutions to dispense with the use of data processing systems under subsection (1), second sentence, no. 5. The first sentence applies correspondingly to outsourcing undertakings, insofar as outsourced activities and processes are concerned.
(4) BaFin monitors compliance by institutions with the obligations contained in Regulation (EU) 2023/1113 of the European Parliament and of the Council of 31 May 2023 on information accompanying transfers of funds and certain crypto-assets and amending Directive (EU) 2015/849 (OJ L 150, 9.6.2023, p. 1; L, 2023/90032, 17.10.2023), in Regulation (EU) 2021/1230, with the exception of the obligations under Articles 4 and 5, in Regulation (EU) No 260/2012, with the exception of the obligations under Article 5d, and in Regulation (EU) 2015/751. It may issue orders against an institution and its managers that are appropriate and necessary to prevent or put a stop to breaches of the obligations under the Regulations named in the first sentence.

←→ also move between sections