The final report outlines guidelines on the authorization of third-country branches in accordance with the CRD directive. It specifies the information required for the authorization application, the authorization procedure, and the assessment conditions. These guidelines are directed at competent authorities and clarify the requirements applicable to third-country branches while considering intragroup funding…
This document is the final report of the guidelines (GL) on the authorization of third-country branches (TCB) published by the European Banking Authority (EBA) in July 2026 (p. 1). It is a 56-page guide, of which about 39 pages were provided, specifying information requirements, the authorization procedure, granting conditions, and modalities for reusing information already provided in other authorization procedures, pursuant to Article 48c(8) of Directive 2013/36/EU (CRD). The scope covers third-country branches providing essential banking services in an EU Member State, including deposit-taking, lending, guarantees, and commitments, for the application period starting January 11, 2027 (p. 3-7, 19).
The guide aims to harmonize at the European level the authorization regime for third-country branches (TCB) in accordance with the CRD, by defining:
- The information to be provided in the authorization application by the direct parent entity (applicant head undertaking), including the business program, business plan, capital and liquidity requirements, internal governance, accounting and reporting modalities, as well as the prudential compliance of the parent company (p. 3).
- The authorization procedure, with standard forms and templates, and the necessary cooperation with the third-country authorities, notably for issuing a certificate of non-objection (p. 3, 11).
- The conditions for granting authorization, which include compliance with prudential requirements, coverage of activities by authorization in the third country, notification to third-country authorities, territorial limitation of activities except for intragroup and reverse solicitation exceptions, access to necessary information for supervision, and absence of money laundering or terrorist financing risks (p. 8-9).
- The possibility for competent authorities to rely on information already provided in a previous procedure, subject to reliability, allowing exemption from repeated submission of certain documents (p. 3, 25).
The guide distinguishes two categories of TCB according to their risk profile, with differentiated requirements (p. 6). It also specifies cooperation modalities between national and third-country authorities, notably via memoranda of understanding (MoU) or exchange of letters (p. 7).
Finally, the guide sets a 6-month deadline for application assessment and emphasizes the need for a balance between transparency and flexibility in the procedure (p. 3, 35).
The importance of this guide lies in establishing a clear and harmonized framework for the market entry of third-country branches in Europe, ensuring financial security, regulatory compliance, and international cooperation. It thus facilitates effective supervision of TCBs and protection of the European financial system.
Competent authorities must comply with these guidelines from January 11, 2027, with a two-month period after publication to notify their compliance (p. 4, 19).
Directive 2013/36/EU (CRD), amended by Directive (EU) 2024/1619, establishes a harmonized minimum regime for third-country branches (TCB) providing essential banking services in the EU (deposit-taking, lending, guarantees) (p. 5-6).
This regime aims to regulate the establishment and supervision of TCBs to ensure financial stability and client protection in the EU. It notably imposes prior authorization, specific prudential requirements (capital, liquidity, governance), and territorial limitation of activities, with regulated exceptions (intragroup, reverse solicitation) (p. 6-8).
The EBA was mandated to develop guidelines specifying the information to be provided, the authorization procedure, granting conditions, and modalities for recognizing information already provided in other procedures (Article 48c(8) CRD) (p. 9).
Objectives are to ensure consistent and effective application of the TCB authorization regime across all Member States, facilitate cooperation between national and third-country authorities, and guarantee that TCBs comply with prudential and anti-money laundering and counter-terrorist financing (AML/CFT) requirements (p. 9-10).
The scope excludes TCBs subject to the regime applicable to national credit institutions (so-called “subsidiary-like” approach), except for certain TCB-specific aspects (p. 10).
The document relies on existing regulations and guidelines, notably on internal governance, capital requirements, accounting modalities, and AML/CFT cooperation (p. 9-10).
The main limitation is that the guide does not cover TCBs subject to stricter national regimes, nor post-authorization aspects (p. 10).
1. Authorization regime and required information:
- The application must contain detailed information on the direct parent entity, intermediate and ultimate entities, including identity, legal structure, group chart, audited financial statements over three years, intended activities, and confirmation that activities are covered by authorization in the third country (p. 20-22).
- A certificate of non-objection issued by the third-country authority is required, attesting consolidated and individual prudential compliance, good reputation of managers and shareholders, and absence of money laundering or terrorist financing risks (p. 21-22).
- The operations program must include a three-year business plan, with baseline and stress scenarios, specifying activities, target clientele, financial projections, prudential requirements, and expected start date (p. 22-24).
- Internal governance must present at least two persons in charge, their fitness assessment, organizational structure, internal control policies, risk management, remuneration, business continuity, and compliance with DORA requirements for IT risk management (p. 22-24).
- AML/CFT aspects must be covered by a risk assessment, description of dedicated resources, and identification of the compliance officer (p. 23-24).
- Capital endowment and liquidity requirements must be specified, with deposit of eligible instruments in an escrow account in the Member State, and demonstration of the capacity to maintain these requirements continuously (p. 24-25).
- Accounting modalities must ensure autonomous recording of assets and liabilities, with policy approved by the parent entity, and avoid excessive back-to-back practices that would strip the branch of its economic substance (p. 25, 33-34).
2. Authorization procedure:
- Acknowledgment of receipt of the application, completeness check, request for additional information if necessary (p. 35).
- Regular information to the applicant on progress.
- Maximum 6-month deadline for full application assessment (p. 35).
- Close cooperation with the third-country authority, AML/CFT authority, and other concerned authorities (p. 3, 35).
3. Evaluation criteria:
- Verification of TCB classification into category 1 or 2 according to risk profile (p. 6, 27).
- Review of consolidated and individual prudential and financial compliance of the parent entity (p. 27-28).
- Qualitative and quantitative analysis of the business plan, coherence of financial projections, plausibility of assumptions, adequacy of human and operational resources (p. 27-29).
- Assessment of internal governance, risk management, AML/CFT compliance, and third-party arrangements (p. 29-31).
- Control of compliance with capital and liquidity requirements, including verification of deposits in escrow accounts and separation of liquid assets and capital endowment (p. 31-33).
- Verification of accounting policies and risk management related to intragroup operations (p. 33-34).
4. Exemptions and recognition of information already provided:
- Possibility to exempt submission of information on the parent entity if already provided in a previous procedure, subject to reliability, currency, and agreement of competent authorities (p. 25-26).
5. Cross-cutting provisions:
- Necessity of a third-party legal opinion confirming absence of legal obstacles in the third country for TCB compliance with European legislation (p. 21).
- Importance of international cooperation, notably via MoUs or exchange of letters, to ensure access to information and coordination in crisis situations (p. 7).
- Application of the guidelines from January 11, 2027 (p. 19).
Findings:
- The TCB authorization regime is now harmonized at the European level with precise minimum requirements on information to provide, procedure, granting conditions, and cooperation between authorities (p. 3-10).
- TCBs are classified into two categories according to their risk profile, with differentiated requirements notably in governance, capital, liquidity, and supervision (p. 6).
- The authorization procedure must be completed within 6 months, with transparency and possibility of additional requests (p. 35).
- The certificate of non-objection from third-country authorities is a key element to validate prudential compliance and good reputation of the parent entity (p. 21-22).
- Financial forecasts must not include activities based on reverse solicitation at the time of authorization, as the branch does not yet exist (p. 12, 28).
Assumptions and interpretations:
- The pragmatic approach adopted for unauthorized activities in the third country but exercised within ordinary activity aims to avoid unnecessary blockages (p. 11).
- Recognition of information already provided in other procedures aims to reduce administrative burdens while ensuring data reliability (p. 25).
Uncertainties:
- Effective implementation of cooperation with third-country authorities will depend on MoU negotiations or other arrangements, which may vary by jurisdiction (p. 7).
- The impact of new requirements on existing TCBs, notably in terms of costs and structural adaptation, remains to be observed after entry into force (p. 6, 10).
- Precise application modalities of exemptions and TCB classification could evolve according to national practices (p. 25, 27).
The EBA concludes that establishing detailed and harmonized guidelines on TCB authorization is essential to ensure effective supervision, financial stability, and regulatory compliance in the EU (p. 3).
The main recommendations are:
- Competent authorities must apply these guidelines from January 11, 2027, integrating the requirements into their practices and procedures (p. 4, 19).
- They must ensure completeness and reliability of information provided, notably by obtaining the certificate of non-objection from third-country authorities (p. 21).
- Cooperation with third-country authorities, as well as AML/CFT authorities, must be strengthened to guarantee effective control and prevent money laundering and terrorist financing risks (p. 3, 30-31).
- Authorities must respect the 6-month deadline for application assessment and maintain transparent communication with applicants (p. 35).
- Use of the standard forms and templates provided in the annexes should be generalized to facilitate the procedure (p. 13).
- Authorities may rely on information already provided in previous procedures, subject to their currency and reliability, to lighten the process (p. 25).
These measures aim to ensure that TCBs operating in the EU comply with strict prudential standards, thus contributing to safety and confidence in the European banking system.
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.