My bookmarksSign up free

Commission Delegated Regulation (EU) 2025/1143 SECTION I — Authorisation requirements for APAs and ARMs

Article 1–Article 7 · 7 articles

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Information to competent authorities

Article 1

1.   An applicant seeking authorisation to operate an APA or an ARM pursuant to Article 27d of Regulation (EU) No 600/2014 shall submit to ESMA or, where relevant, the national competent authority the information set out in Articles 2 to 7, and the information regarding all the organisational requirements set out in Section II of this Chapter. 2.   An APA or ARM shall promptly inform ESMA or, where relevant, the national competent authority of any material change to the information provided at the time of the authorisation or thereafter.

Information on the organisation

Article 2

1.   The programme of operations referred to in Article 27d(1) of Regulation (EU) No 600/2014 shall include the following: (a) information on the organisational structure of the applicant, including an organisational chart and a description of the human, technical, and legal resources allocated to its business activities; (b) information on the operational separation policies and procedures to ensure segregation between the APA or ARM and any other activity performed by the applicant; (c) information on the compliance policies and procedures of the applicant seeking authorisation to operate an APA or an ARM, including: (i) the name of the person or persons responsible for the approval and maintenance of those policies; (ii) the arrangements to monitor and enforce the compliance policies and procedures; (iii) the measures to be undertaken in the event of a breach which may result in a failure to meet the conditions for initial authorisation; (iv) a description of the procedure for reporting to ESMA or, where relevant, the national competent authority any breach which may result in a failure to meet the conditions for initial authorisation; (d) a list of all outsourced functions and resources allocated to the control of the outsourced functions. 2.   An applicant seeking authorisation to operate an APA or an ARM pursuant to Article 27d of Regulation (EU) No 600/2014 offering services other than data reporting services shall describe those services in the organisational chart provided under paragraph 1, point (a).

Information on ownership

Article 3

1.   An applicant seeking authorisation to operate an APA or an ARM pursuant to Article 27d of Regulation (EU) No 600/2014 shall include in its application for authorisation: (a) a list containing the name of each person or entity who directly or indirectly holds 10 % or more of the applicant’s capital or of its voting rights, or whose holding makes it possible to exercise a significant influence on the applicant; (b) a list of all undertakings in which a person or entity referred to in point (a) holds 10 % or more of the capital or voting rights or on which that person or entity exercises a significant influence; (c) a chart showing the ownership links between the parent undertaking, any subsidiaries and any other associated entities or branches. 2.   The undertakings shown in the chart referred to in paragraph 1, point (c), shall be identified by their full name, legal status and legal address.

Information on corporate governance

Article 4

1.   An applicant seeking authorisation to operate an APA or an ARM pursuant to Article 27d of Regulation (EU) No 600/2014 shall include in its application for authorisation information on the internal corporate governance policies and the procedures which govern its management body, senior management, and, where established, committees. 2.   The information set out in paragraph 1 shall include: (a) a description of the processes for selection, appointment, performance evaluation and removal of senior management and members of the management body; (b) a description of the reporting lines and the frequency of reporting to the senior management and the management body; (c) a description of the policies and procedures on access to documents by members of the management body.

Information on the members of the management body

Article 5

1.   An applicant seeking authorisation to operate an APA or an ARM pursuant to Article 27d of Regulation (EU) No 600/2014 shall include in its application for authorisation the following information in respect of each member of the management body: (a) name, date and place of birth, personal national identification number or an equivalent thereof, address and contact details; (b) the position for which that member is or will be appointed; (c) a curriculum vitae evidencing sufficient experience and knowledge to adequately perform the conferred responsibilities; (d) proof of the absence of criminal records relating to money laundering, terrorist financing, provision of financial or data services, acts of fraud or embezzlement, notably through an official certificate, or, where such a certificate is not available in the relevant Member State, a self-declaration of good repute and the authorisation to ESMA or, where relevant, the national competent authority, to request information about whether that member has been convicted of a criminal offence in connection with money laundering, terrorist financing, the provision of financial or data services or in relation to acts of fraud or embezzlement; (e) a self-declaration of good repute and the authorisation to ESMA or, where relevant, the national competent authority, to request information about whether that member: (i) has been subject to an adverse decision in any proceedings of a disciplinary nature brought by a regulatory authority or government body; (ii) has been subject to an adverse judicial finding in civil proceedings before a court in connection with the provision of financial or data services, or for misconduct or fraud in the management of a business; (iii) has been part of the management body of an undertaking which was subject to an adverse decision or penalty by a regulatory authority or whose registration or authorisation was withdrawn by a regulatory authority; (iv) has been refused the right to carry on activities which require registration or authorisation by a regulatory authority; (v) has been otherwise fined, suspended, disqualified, or been subject to any other sanction in relation to fraud, embezzlement or in connection with the provision of financial or data services, by a professional body; (vi) has been disqualified from acting as a director, disqualified from acting in any managerial capacity, dismissed from employment or other appointment in an undertaking as a consequence of misconduct or malpractice; (f) an indication of the minimum time that is to be devoted to the performance of the member’s functions within the APA or ARM; (g) a declaration of any potential conflicts of interest that may exist or arise in performing the duties and how those conflicts are managed. 2.   The information set out in paragraph 1 shall also be included in the notifications referred to in Article 27f(2) of Regulation (EU) No 600/2014 as regards APAs and ARMs. An APA or ARM shall notify electronically to ESMA, or, where relevant, its national competent authority of any change to the membership of its management body before such change takes effect. Where, for substantiated reasons, it is not possible to make the notification before that change takes effect, it shall be made within 10 working days after the change has occurred. 3.   An APA or an ARM shall record the information set out in paragraph 1 in a medium which enables its storage in a way that ensures that the information is accessible for future reference and which allows for the unchanged reproduction of the information stored. An APA or an ARM shall keep that information up-to-date. 4.   An APA or an ARM shall keep the information set out in paragraph 1, points (d) and (e), for no longer than five years after the concerned member has ceased to perform its function. 5.   Where the proof referred to in paragraph 1, point (d), contains information on other criminal convictions than those listed in that provision, an APA or an ARM shall ensure that only persons responsible for the assessment of the suitability of the members of the management body have access to that information. That information shall be stored separately from other information regarding a member of the management body. Access to that information shall be recorded. That information shall not be stored where it concerns candidate members of the management body that have not been appointed. 6.   ESMA or, where relevant, the national competent authority shall keep the information set out in paragraph 1, points (d) and (e), for no longer than five years after the concerned member of the management body has ceased to perform its function.

Information on internal controls

Article 6

1.   An applicant seeking authorisation to operate an APA or an ARM pursuant to Article 27d of Regulation (EU) No 600/2014 shall include in its application for authorisation detailed information regarding its internal controls’ environment. This shall include information regarding its internal control function, compliance function, risk management and its internal audit function. 2.   The detailed information referred to in paragraph 1 shall contain: (a) an outline of the organisation of the applicant’s internal control, risk management, compliance and internal audit functions, including where the applicant relies on outsourced functions; (b) an assessment of the key risks that may arise in the operation of the APA or ARM; (c) the applicant’s internal control policies and procedures to ensure the consistent and effective implementation of those policies; (d) any policies, procedures and manuals for monitoring and evaluating the adequacy and effectiveness of the applicant’s systems; (e) any policies, procedures and manuals for controlling and safeguarding the applicant’s information processing systems; (f) the identity of the internal bodies in charge of evaluating any findings resulting from the performance of the internal control and deciding on their outcome. 3.   With respect to the applicant’s internal audit function, the detailed information referred to in paragraph 1 shall contain the following: (a) information on the applicant’s adherence to national or international professional standards; (b) any internal audit function charter, methodologies, and procedures; (c) an explanation of how the internal audit methodology, if any, is developed and applied taking into account the nature of the applicant’s activities, complexities and risks; (d) where there is an internal audit committee: (i) information on its composition, competences and responsibilities; (ii) its work plan for the three years following the date of application, taking into account the nature and extent of the applicant’s activities, complexities and risks.

Information on digital operational resilience

Article 7

1.   An applicant seeking authorisation to operate an APA or an ARM pursuant to Article 27d of Regulation (EU) No 600/2014 shall include in its application for authorisation evidence of compliance with the requirements on ICT risk management organisation and capabilities, operational resilience strategy and testing, incident management and ICT third-party risk management under Regulation (EU) 2022/2554. 2.   The information set out in paragraph 1 shall include documents regarding the applicant’s arrangements, in accordance with Regulation (EU) 2022/2554, on: (a) ICT risk-management; (b) ICT-related incident management; (c) digital operational resilience testing; (d) ICT third-party risk monitoring. 3.   The information set out in paragraph 1 shall take into account the size and overall risk profile, and the nature, scale and complexity of the applicant’s services, activities and operations.

Back to Commission Delegated Regulation (EU) 2025/1143 — full text

Articles on this page are reproduced verbatim from official open data. See the attribution line.

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next