Article 36
Supervisory review and evaluation
Competent authorities shall review, to the extent relevant and necessary, taking into account the investment firm’s size, risk profile and business model, the arrangements, strategies, processes and mechanisms implemented by investment firms to comply with this Directive and with Regulation (EU) 2019/2033 and evaluate the following as appropriate and relevant, so as to ensure a sound management and coverage of their risks:
the risks referred to in Article 29;
the geographical location of an investment firm’s exposures;
the business model of the investment firm;
the assessment of systemic risk, taking into account the identification and measurement of systemic risk under Article 23 of Regulation (EU) No 1093/2010 or recommendations of the ESRB;
the risks posed to the security of investment firms’ network and information systems to ensure confidentiality, integrity and availability of their processes, data and assets;
the exposure of investment firms to the interest rate risk arising from non‐trading book activities;
governance arrangements of investment firms and the ability of members of the management body to perform their duties.
For the purposes of this paragraph, competent authorities shall duly take into account whether investment firms hold a professional indemnity insurance.
Competent authorities shall decide on a case‐by‐case basis whether and in which form the review and evaluation is to be carried out with regard to investment firms that meet the conditions for qualifying as small and non‐interconnected investment firms set out in Article 12(1) of Regulation (EU) 2019/2033, only where they deem it to be necessary due to the size, nature, scale and complexity of the activities of those investment firms.
For the purposes of the first subparagraph, national law governing segregation applicable to client money held shall be considered.