Home › Academy › Library › Final report on Guidelines on the minimum…
Synthesis note · Guide

Final report on Guidelines on the minimum content of the governance arrangements for issuers of asset-referenced tokens

European Banking Authority (EBA) · 2024 · Guide · 67 pages · Intermediate

This final report presents guidelines on the minimum content of governance arrangements for issuers of asset-referenced tokens. It emphasizes the importance of sound internal governance, focusing on the responsibilities of the management body regarding risk strategy and risk management. The guidelines apply to issuers of tokens in accordance with the relevant European regulation.

General Information

This document is the final report on the guidelines (EBA/GL/2024/06) issued by the European Banking Authority (EBA) in cooperation with ESMA and the ECB, published on 6 June 2024. It concerns the minimum content of governance arrangements for asset-referenced token (ART) issuers in the European Union. The scope covers internal governance requirements, control functions, risk management, business continuity, and transparency, applicable to ART issuers under Regulation (EU) 2023/1114, effective from 20 December 2024. The document is addressed to competent authorities and ART issuers across all sectors, taking into account proportionality according to the size, complexity, and business model of issuers (p. 1-14).

Executive Summary

The report addresses guidelines establishing the minimum content of governance arrangements for ART issuers, in accordance with Regulation (EU) 2023/1114. This topic is crucial as ARTs, as digital financial instruments, present increasing risks to financial stability, consumers, and investors, notably regarding money laundering, operational risks, cyber risks, and compliance. The main findings are that issuers must have strong internal governance, led by a management body responsible for strategy, risk culture, and the risk management framework. Governance must include independent control functions (compliance, risk management, internal audit) according to the principle of proportionality. Issuers must also ensure business continuity, manage third-party risks, and integrate ESG factors into their risk management. The recommendations emphasize effective implementation of these guidelines by competent authorities and issuers, with an application deadline set for 20 December 2024. Compliance aims to strengthen trust in the financial system and protect stakeholders (p. 4-5).

Context and Objectives

The document was drafted to fill gaps in internal governance of ART issuers in a context of rapid evolution of crypto-assets and their increasing integration into the traditional financial system. The issues are consumer protection, financial stability, prevention of money laundering and terrorist financing, as well as consideration of ESG risks. The objective is to define harmonized guidelines at the European level to ensure robust, transparent, and adapted governance arrangements specific to ARTs. These guidelines aim to clarify management responsibilities, promote a sound risk culture, ensure effective operational risk management, and regulate relations with third parties. They apply to all ART issuers, regardless of governance mode, and respect the principle of proportionality. The document also specifies legal bases and coordination with other European financial regulations (p. 5-14).

Summary of Key Points by Theme

Principle of proportionality: Governance requirements must be adapted to the size, complexity, business model, volume, and nature of ARTs issued, as well as the issuer’s internal organization. Criteria include balance sheet, legal form, listing status, ART classification (significant or not), consensus mechanisms, cross-border activities, size and nature of reserve assets, holders (retail or not), and use of third-party providers (p. 15-16).

Role and composition of the management body: The management body is responsible for defining, supervising, and reporting on governance arrangements, including corporate strategy, key policies, risk management, risk culture, remuneration (for significant ARTs), conflict of interest prevention, and stakeholder communication. It must ensure a clear separation between executive and supervisory functions, promote a balance of powers, and ensure members’ competence and integrity. Members must be regularly informed of financial status and risks (p. 16-19).

Organizational framework: The issuer must have a clear, transparent, and appropriate organizational structure, with defined reporting lines and sufficient resources for control functions. The structure must not hinder supervision or risk management. Structural changes must be evaluated and adjusted promptly. Opaque or complex structures without economic justification are prohibited. In a group context, governance policies must be coherent and integrated at group level (p. 20-22).

Outsourcing: The issuer must approve and regularly review an outsourcing policy covering the entire lifecycle of contracts with third parties, including due diligence, risk management, business continuity, conflicts of interest, and exit plans. Outsourcing does not relieve the issuer of its responsibilities. The issuer must retain sufficient substance and not become a mailbox entity (p. 22-23).

Risk culture and business conduct: A sound risk culture is essential, integrated throughout the organization, with clear communication, appropriate training, and accountability at all levels. Management must set the example (“tone from the top”). Corporate values and a code of conduct must promote ethical behavior, prevent discrimination, and include gender-neutral remuneration policies for significant ARTs. Unacceptable behaviors, notably related to fraud, money laundering, corruption, or market manipulation, must be clearly defined and sanctioned (p. 23-26).

Internal control framework: The issuer must establish a robust internal control framework covering all activities, with permanent and effective compliance functions, and, according to proportionality, risk management and internal audit functions. This framework must ensure operational effectiveness, risk management (including operational and ICT risks), reliability of financial information, and compliance with laws and internal policies. Management is responsible for implementation, monitoring, and updating of this framework, with clear decision-making processes and internal communication of policies (p. 27-29).

Risk management: The risk management framework must be holistic, covering all financial and non-financial risks, including ESG, operational, ICT, reputational, legal, conduct, concentration, liquidity, and reserve asset risks. It must include policies, procedures, limits, and controls for risk identification, measurement, monitoring, management, mitigation, and reporting, with escalation mechanisms in case of limit breaches. The framework must be regularly reviewed and subject to independent audits (p. 29-30).

Operational risk management and resilience: The issuer must have a specific framework to manage operational risks and ensure operational resilience, including identification, assessment, monitoring, response, and recovery from disruptive events. Management must approve and supervise these policies, which must be integrated into the overall risk management framework. The issuer must map critical functions, interconnections, and dependencies, and conduct scenario analyses including rare but severe events. ICT risk management must comply with the DORA regulation (p. 30-32).

Approval of new products, systems, and processes: The issuer must have procedures to assess and approve new products, systems, and processes, considering all risks, including legal and ICT, and their impact on critical functions and overall risk profile throughout the lifecycle (p. 31).

Relations with third parties: The issuer must adopt a policy governing relations with third parties for operation, investment, custody of reserve assets, and ART distribution. This policy must cover planning, risk assessment, due diligence, conflict of interest management, business continuity, performance monitoring, regulatory compliance, and exit plans. The issuer must ensure the reputation, capabilities, and compliance of third parties, notably regarding anti-money laundering and counter-terrorism financing (p. 32-35).

Internal control functions: Compliance, risk management, and internal audit functions must be permanent, effective, and independent. Heads of these functions must have sufficient hierarchical level and authority, report directly to the management body, and be protected from conflicts of interest. In the absence of dedicated functions, the issuer must demonstrate that its policies achieve the same objectives. Human and financial resources must be adequate (p. 35-38).

Main Findings and Lessons Learned

Findings:

- ART issuers present multiple risks (ML/TF, operational, ICT, ESG) requiring robust internal governance (p. 4-6).

- The European regulatory framework imposes precise governance requirements, notably via Regulation (EU) 2023/1114 and the MiCAR directive (p. 10-14).

- The guidelines specify functions, responsibilities, and processes to be implemented, including risk management, compliance, internal audit, business continuity, and third-party relationship management (p. 15-38).

Assumptions:

- Application of the proportionality principle will adapt requirements to issuer characteristics (p. 15-16).

- Effective implementation of the guidelines will strengthen financial stability and investor protection (p. 4).

Interpretations:

- Internal governance is a key lever to control ART-specific risks and ensure trust in the financial system (p. 5).

- Integration of ESG factors into risk management is a necessary evolution to address climate and social challenges (p. 6, 21).

Uncertainties:

- Precise application modalities in different Member States, notably depending on national governance structures, may vary (p. 8-9).

- Effectiveness of controls over third parties will depend on the quality of outsourcing policies and ongoing supervision (p. 33-35).

Conclusions and Recommendations

The EBA concludes that solid, adapted, and proportionate governance arrangements are essential to ensure effective risk management related to ARTs and protection of holders. The main recommendations are:

- Apply the guidelines from 20 December 2024, taking into account the principle of proportionality.

- Establish a responsible, competent, and balanced management body, with independent control functions adequately resourced.

- Integrate a strong risk culture and clear ethical values, including conflict of interest prevention and anti-money laundering and counter-terrorism financing measures.

- Establish a comprehensive risk management framework covering all risk types, including ESG and operational, with rigorous approval procedures for new products and services.

- Strictly govern relations with third parties, with detailed outsourcing policies and continuity and exit plans.

- Ensure transparency and regular communication with competent authorities and stakeholders.

- Competent authorities must integrate these guidelines into their supervisory practices and notify compliance to the EBA before 20 November 2024.

These measures aim to strengthen trust in the ART market and ensure consistent supervision within the European Union (p. 4, 12-14, 18-38).

Key takeaways

References

Year
2024
Type
Guide
Level
Intermediate
Licence
Attribution required
Original document
https://www.eba.europa.eu/sites/default/files/2024-06/611ef3d4-4d67-4…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.