General organizational requirements: governance arrangements, internal controls, information security and business continuity
In force since .
An AI sector rules rule binding private bodies.
- Criminal exposure
- No
- Enforcement body
- Financial Conduct Authority
- Instrument type
- a regulation made under an act
- Obligation class
- Governance, Security
- Audit expectation
- continuous
- Who audits it
- Self
As of .
What it requires
- It reaches you if you are a firm to which the common platform requirements apply, which is every firm apart from an insurer, a UK ISPV, a managing agent and the Society unless a specific rule provides otherwise (SYSC 1 Annex 1 2.1R): have robust governance arrangements, which include a clear organizational structure with well defined, transparent and consistent lines of responsibility, effective processes to identify, manage, monitor and report the risks you are or might be exposed to, and internal control mechanisms, including sound administrative and accounting procedures and effective control and safeguard arrangements for information processing systems (SYSC 4.1.1R(1)).
- If you are a common platform firm, make the arrangements, processes and mechanisms in SYSC 4.1.1R comprehensive and proportionate to the nature, scale and complexity of the risks inherent in your business model and activities (SYSC 4.1.2R).
- If you are a common platform firm, have sound security mechanisms in place, while maintaining the confidentiality of the data at all times, to guarantee the security and authentication of the means of transfer of information, to minimise the risk of data corruption and unauthorised access, and to prevent information leakage (SYSC 4.1.1R(3)).
- If you are a common platform firm, taking into account the nature, scale and complexity of your business, establish, implement and maintain decision-making procedures and an organizational structure that specifies reporting lines and allocates functions and responsibilities, adequate internal control mechanisms designed to secure compliance with decisions and procedures at all levels, effective internal reporting and communication of information at all relevant levels, and adequate and orderly records of your business and internal organization (SYSC 4.1.1-AR(1)).
- If you are a common platform firm, establish, implement and maintain systems and procedures that are adequate to safeguard the security, integrity and confidentiality of information, taking into account the nature of the information in question (SYSC 4.1.1-AR(2)).
- If you are a common platform firm, establish, implement and maintain an adequate business continuity policy aimed at ensuring, if your systems and procedures are interrupted, the preservation of essential data and functions and the maintenance of your designated investment business or, where that is not possible, the timely recovery of such data and functions and the timely resumption of that business, and take reasonable steps to ensure continuity and regularity in the performance of your regulated activities (SYSC 4.1.1-AR(3) and SYSC 4.1.6R).
- If you are a common platform firm, monitor and, on a regular basis, evaluate the adequacy and effectiveness of your systems, internal control mechanisms and arrangements, and take appropriate measures to address any deficiencies (SYSC 4.1.1-AR(5)).
- If you are a firm other than a common platform firm or a sole trader with no employee who must be approved under section 59 of the Act, taking into account the nature, scale and complexity of your business, establish, implement and maintain adequate internal control mechanisms designed to secure compliance with decisions and procedures at all levels of the firm and effective internal reporting and communication of information at all relevant levels (SYSC 4.1.4R(2) and (3)).
What this law does
A firm must have robust governance arrangements, which include effective processes to identify, manage, monitor and report the risks it is or might be exposed to, and effective control and safeguard arrangements for information processing systems. The common platform requirements, which include SYSC 4.1, apply to every firm apart from an insurer, a UK ISPV, a managing agent and the Society unless provided otherwise in a specific rule.
The current text of SYSC 4.1.1R took effect on . The Financial Conduct Authority's AI Update cites SYSC 4.1.1R as a provision relevant to the governance and accountability arrangements of a firm using AI safely and responsibly. A contravention of a rule in the common platform requirements does not give rise to a right of action by a private person under section 138D of the Financial Services and Markets Act 2000.
If the appropriate regulator considers that an authorised person has contravened a relevant requirement imposed on the person, section 206 of the Financial Services and Markets Act 2000 lets it impose a penalty of such amount as it considers appropriate.
When LexLint raises it
When your app profile says your app provides financial services.