Module Application
Banking and lending activities in the European Union are governed by an extensive and interconnected regulatory framework covering market access, prudential safety and soundness, governance, customer treatment, payment services, financial crime prevention, data protection, recovery and resolution, reporting and supervisory enforcement. This module applies to organisations carrying on banking, lending, payment services or related regulated financial services activities within the EU, including credit institutions, payment service providers and other entities subject to relevant EU financial services requirements.
Organisations operating in this area are supervised through a multi-layered framework involving the European Central Bank within the Single Supervisory Mechanism, national competent authorities, national resolution authorities, the European Banking Authority and other EU and national bodies. Depending on their activities and status, organisations are expected to obtain and maintain the necessary authorisations and permissions, meet prudential and governance standards, treat customers fairly, maintain operational and financial resilience, prevent financial crime, protect personal and confidential information, submit accurate regulatory information and cooperate effectively with supervisory authorities.
To meet these expectations, organisations must understand which requirements apply to their business model, products, services, customers, delivery channels and cross-border activities. They must maintain proportionate policies, governance arrangements, risk management frameworks, controls, systems, records and assurance processes capable of demonstrating compliance throughout the lifecycle of regulated activities. This module is designed to support organisations in navigating the EU banking and lending regulatory landscape and in assessing, implementing and maintaining an effective compliance framework.
Module Scope
This module covers the principal EU requirements relating to authorisation and regulatory status, passporting and freedom to provide services, prudential requirements, governance and internal controls, conduct of business, lending practices, payment services, anti-money laundering and financial crime, data protection and confidentiality, reporting and regulatory disclosures, recovery and resolution, consumer protection, and enforcement and sanctions.
The scope further includes the authorisation and ongoing supervision of credit institutions and payment service providers, qualifying holdings and changes in control, third-country branches, own funds, capital, liquidity, leverage and concentration risk, internal capital and liquidity adequacy assessments, management body responsibilities, suitability, remuneration and control functions, product governance and complaints handling, responsible lending, creditworthiness and affordability, payment transparency, execution, strong customer authentication and security,customer due diligence and transaction monitoring, regulatory reporting and public disclosure, recovery planning, MREL and resolvability, consumer rights, vulnerability and forbearance and regulatory investigations, remediation and individual accountability.
This module covers specific questions such as:
• Does the organisation obtain and maintain all authorisations, permissions and approvals required for its banking, lending, payment services or related regulated activities, and keep those activities within the scope of its authorisation?
• Does the organisation comply with notification, passporting and host-state requirements before establishing branches or providing regulated services across borders within the EU?
• Does the management body provide effective oversight of strategy, risk appetite, governance, internal controls, remuneration, suitability and the independent risk, compliance and internal audit functions?
• Does the organisation conduct business honestly, fairly and professionally, provide fair, clear and not misleading communications, manage conflicts of interest and maintain effective product governance and complaints handling?
• Does the organisation apply responsible lending practices, including appropriate pre-contractual information, creditworthiness and affordability assessments, collateral valuation, ongoing monitoring, arrears management and forbearance?
• Does the organisation maintain effective AML/CFT, sanctions, customer due diligence, beneficial ownership, transaction monitoring, screening, reporting, record-keeping and training controls?
• Does the organisation process personal and confidential information lawfully and securely, including in relation to automated decision-making, credit scoring, retention, access rights, breaches, outsourcing and international transfers?
• Does the organisation maintain accurate and timely regulatory reporting, public disclosures, recovery and resolution arrangements, and cooperate effectively with supervisory investigations and information requests?
The key topics covered in this module are:
• Authorisation and Regulatory Status
• Passporting and Freedom of Services
• Prudential Requirements
• Governance and Internal Controls
• Conduct of Business
• Lending Practices
• Payment Services
• Anti-Money Laundering and Financial Crime
• Data Protection and Confidentiality
• Reporting and Regulatory Disclosures
• Resolution and Recovery
• Consumer Protection
• Enforcement and Sanctions
The module encompasses a range of legislative sources including:
• Directive 2013/36/EU on access to the activity of credit institutions and the prudential supervision of credit institutions (Capital Requirements Directive)
• Regulation (EU) No 575/2013 on prudential requirements for credit institutions (Capital Requirements Regulation)
• Directive (EU) 2024/1619 amending Directive 2013/36/EU as regards supervisory powers, sanctions, third-country branches and ESG risks
• Council Regulation (EU) No 1024/2013 conferring specific prudential supervisory tasks on the European Central Bank
• Regulation (EU) No 468/2014 establishing the framework for cooperation within the Single Supervisory Mechanism
• Directive 2014/59/EU establishing a framework for the recovery and resolution of credit institutions and investment firms
• Regulation (EU) No 806/2014 establishing the Single Resolution Mechanism and Single Resolution Fund
• Directive 2014/49/EU on deposit guarantee schemes
• Directive (EU) 2015/2366 on payment services in the internal market (PSD2)
• Commission Delegated Regulation (EU) 2018/389 on strong customer authentication and common and secure open standards of communication
• Directive 2008/48/EC on credit agreements for consumers and Directive (EU) 2023/2225 on credit agreements for consumers
• Directive 93/13/EEC on unfair terms in consumer contracts and Directive 2005/29/EC on unfair business-to-consumer commercial practices
• Directive (EU) 2015/849 on the prevention of the use of the financial system for money laundering or terrorist financing
• Directive (EU) 2018/1673 on combating money laundering by criminal law
• Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets
• Regulation (EU) 2016/679 (General Data Protection Regulation)
Relevant regulators and authorities include:
➢ European Central Bank
➢ European Banking Authority
➢ European Commission
➢ European Systemic Risk Board
➢ Single Resolution Board
➢ European Data Protection Board and national data protection supervisory authorities
➢ National competent authorities responsible for prudential and conduct supervision
➢ National resolution authorities and deposit guarantee scheme authorities
➢ National financial intelligence units and AML/CFT supervisory authorities
➢ National consumer protection, payment services and alternative dispute resolution bodies
Non-compliance with applicable banking and lending requirements can result in serious consequences, including supervisory intervention, additional capital or liquidity requirements, restrictions on distributions or business activities, remediation programmes, public reprimands, administrative fines, periodic penalty payments, customer redress, civil claims, personal accountability consequences, licence suspension or withdrawal, recovery or resolution measures and, where relevant, criminal liability.
The EU Banking and Lending module maps regulatory consequences to the relevant obligations, including consequences arising from failures relating to authorisation, prudential resilience, governance, AML/CFT, payment services, conduct, consumer protection, data protection, reporting, recovery and resolution, cooperation with regulators and record-keeping. The precise consequences depend on the organisation’s status, activities, the applicable legal instrument and the powers of the competent national or EU authority.
This module is designed for credit institutions, banks, lenders, mortgage credit providers and intermediaries, credit servicers and purchasers, payment institutions, electronic money institutions, account information and payment initiation service providers, branches and subsidiaries of EU or third-country groups, and other organisations responsible for banking, lending or payment services compliance within the European Union. It is also relevant to compliance, legal, risk, governance, internal audit, finance, treasury, operations, data protection, financial crime and customer conduct teams supporting those organisations. The precise obligations applicable to an organisation will depend on factors including its regulatory status, activities, products, customers, authorisations, group structure and the Member States in which it operates.