Updated 22/10/2024
In force

Initial Legal Act
Amendments
Search within this legal act

Article 51 - Audit methods

Article 51

Audit methods

1.   The internal audit function of a CSD shall ensure the following:

(a)

establish, implement and maintain an all-encompassing audit plan to examine and evaluate the adequacy and effectiveness of the CSD's systems, risk-management processes, internal control mechanisms, remuneration policies, governance arrangements, activities and operations, including outsourced activities;

(b)

review and report the audit plan to the competent authority at least annually;

(c)

establish a comprehensive risk-based audit;

(d)

issue recommendations based on the result of work carried out in accordance with point (a) and verify compliance with those recommendations;

(e)

report internal audit matters to the management body;

(f)

be independent from the senior management and report directly to the management body;

(g)

ensure that special audits may be performed at short notice on an event-driven basis.

2.   Where the CSD belongs to a group, the internal audit function may be carried out at group level provided that the following requirements are complied with:

(a)

it is separate and independent from other functions and activities of the group;

(b)

it has a direct reporting line to the management body of the CSD;

(c)

the arrangement concerning the operation of the internal audit function does not prevent the exercise of supervisory and oversight functions, including on-site access to acquire any relevant information needed to fulfil those functions.

3.   The CSD shall assess the internal audit function.

Internal audit assessments shall include an on-going monitoring of the performance of the internal audit activity and periodic reviews performed through self-assessment carried out by the audit committee or by other persons within the CSD or the group with sufficient knowledge of internal audit practices.

An external assessment of the internal audit function shall be conducted by a qualified and independent assessor from outside the CSD and its group structure at least once every five years.

4.   A CSD's operations, risk-management processes, internal control mechanisms and records shall be subject to regular internal or external audits.

The frequency of the audits shall be determined on the basis of a documented risk assessment. Audits referred to in the first subparagraph shall be carried out at least every two years.

5.   A CSD's financial statement shall be prepared on an annual basis and be audited by statutory auditors or audit firms approved in accordance with Directive 2006/43/EC.