CySEC Advanced · Chapter 1 · Topic 4 of 8

Who supervises investment firms in Cyprus, and what happens if someone misleads them?

The two competent authorities and how they split the work, their shared powers, professional secrecy, the tied-agent register, CySEC's contact-point role, and the duty of accuracy with its criminal and administrative consequences.

By the ExamPass CY editorial teamLast reviewed 8 min read

Short answer

Cyprus has two competent authorities: CySEC, which supervises investment firms and enforces Law 87, and the Central Bank of Cyprus, which supervises banks' investment business. Both supervise under EU directives and regulations, cooperate and exchange information. Their shared powers include demanding information, inspections, asset freezing or sequestration and referral for criminal prosecution. CySEC is the single contact point for Law 87 and MiFIR. Anyone who files information with them, or publishes it under the Law, must make it correct, complete and accurate. A breach is a criminal offence and also an administrative one.

Authorities and offences at a glance

Competent authoritiesCySEC and the Central Bank of Cyprus, for Law 87 and MiFIR
Division of workCySEC supervises and enforces the Law; the Central Bank supervises the provisions that apply to banks
Shared powersInformation and summons; documents and records; inspections; auditors or experts; stop orders; asset freezing or sequestration; activity bans; referral for prosecution
Confidential informationUsed only for supervisory duties under Law 87 or MiFIR; covered by professional secrecy
Tied agents' registerCySEC's public register of tied agents established in Cyprus, whether acting for a CIF or another Member State's firm: good repute plus appropriate general, commercial and professional knowledge and competence
Contact pointCySEC, for Law 87 and MiFIR; the Central Bank notifies other authorities and ESMA through CySEC
AML supervisionCentral Bank for banks, CySEC for CIFs; suspicious transactions reported to MOKAS
Duty of accuracyInformation submitted or notified to CySEC or the Central Bank, or published or announced under the Law, must be correct, complete and accurate
BreachCriminal offence punishable by prison (maximum five years), a fine, or both; officers liable only if they consented or took part; also an administrative fine
Fine capsCriminal fine up to €700,000; administrative fine by CySEC or the Central Bank up to €350,000, or €700,000 if the breach is repeated or continues

Source: Law 87(I)/2017, Articles 30, 68–71, 77, 80, 93 and 94; Law 73(I)/2009 (CySEC Law), Articles 6 and 35; Law 188(I)/2007 (AML Law), Article 59(1); CySEC Directive DI87-06 on tied agents, paragraphs 3–4.

In the exam

The exam is written from the exam material, which predates the changes below. Expect its answer. If that answer is not among the options and the current rule is, choose the current rule.

  • Contact point

    Exam material: CySEC is the contact point for MiFID I, Directive 2004/39/EC.

    Current law (since 3 January 2018 (Law 87(I)/2017, Article 80)): CySEC is the contact point for the purposes of Law 87 and MiFIR; the Central Bank notifies other authorities and ESMA through CySEC.

  • Public register

    Exam material: CySEC keeps a public register of everyone acting for a CIF or for another Member State's investment firm, and they must be of good repute and suitably knowledgeable.

    Current law (since 3 January 2018 (Law 87(I)/2017, Article 30(3))): The register is of tied agents established in Cyprus, whether they act for a CIF or for another Member State's firm; the repute and knowledge test applies to them.

How do CySEC and the Central Bank share supervision?

Law 87 designates two competent authorities. CySEC, which operates under the CySEC Law 73(I)/2009, supervises investment firms and enforces the Law generally. The Central Bank of Cyprus, which draws its powers from its own statute and from banking legislation, supervises the provisions that apply to banks providing investment services or selling structured deposits. Each works within EU directives and regulations. They cooperate closely, exchange any information essential or relevant to their functions, and work with the Cyprus supervisors of pension funds and of insurance undertakings and intermediaries. For money laundering the split is similar: the Central Bank supervises banks, CySEC supervises CIFs, and suspicious transactions are reported to MOKAS. See Who supervises firms for AML in Cyprus, and what fines can CySEC impose? and What is MOKAS and what powers does it have?.

CySEC is Cyprus's single contact point for cooperation and information exchange with other Member States. The exam material ties this role to Directive 2004/39/EC (MiFID I). Since 3 January 2018, Law 87 Article 80, mirroring MiFID II Article 79, has made CySEC the contact point for the purposes of Law 87 and MiFIR. When the Central Bank must notify another Member State's authority or ESMA, it does so through CySEC.

Terms used in this note

Competent authority
The authority a law designates to supervise and enforce it; under Law 87, CySEC and the Central Bank of Cyprus.
Single contact point
The one authority in each Member State through which cooperation and information exchange with other Member States and ESMA are channelled.
Tied agent
A person who, for one investment firm only and under its full responsibility, promotes its services, receives and transmits orders, places instruments or gives advice.
Sequestration
Placing assets under the control of an authority or court so that they cannot be disposed of while a case is pending.

What powers do the authorities have, and how must they treat information?

The exam material presents a list of powers as the Central Bank's 'in relation to CySEC'. Since Law 87 applied on 3 January 2018, the list in Article 70(2) has belonged to both authorities, on top of the powers each has under its own law. They may see any document; demand information from anyone and summon and question them; inspect on site and investigate; require existing telephone, electronic-communication and data-traffic records held by firms; require assets to be frozen or sequestrated; temporarily ban a person from professional activity; require information from auditors; appoint auditors or experts; order a practice to stop; refer matters for criminal prosecution; and take any measure needed to keep supervised persons compliant. They can also suspend trading or the marketing of products, and remove a person from a CIF's board.

CySEC can act directly, in cooperation with other authorities, by delegation, or by applying to the courts. Imprisonment is for the criminal courts, after a prosecution. Where a suspected breach may be a criminal offence, CySEC prepares a report and sends it, with the evidence, to the Attorney General; it may still impose administrative fines whatever the criminal outcome. Confidential information the authorities receive may be used only in performing their duties under Law 87 or MiFIR, and it is covered by professional secrecy.

What is the public register of tied agents?

The exam material describes a public register of everyone who acts for a CIF or for another Member State's investment firm. Since 3 January 2018, Law 87 Article 30 has required CySEC to keep a public register of tied agents established in Cyprus. It covers tied agents established here whether they act for a CIF or for another Member State's investment firm. CySEC enters a tied agent only if it is of sufficiently good repute and has appropriate general, commercial and professional knowledge and competence. The register is updated regularly and open to the public. A CIF may appoint only tied agents entered in the Cyprus register or in another Member State's register. The appointing firm's duties are covered in What are the rules for tied agents, eligible counterparties and crowdfunding?.

What is the duty of accuracy, and what follows a breach?

Anyone who must, under Law 87, its directives or MiFIR, submit or notify information, data, documents or forms to CySEC or the Central Bank, or make them public or announce them, must ensure they are correct, complete and accurate. Giving false or misleading material, or withholding material information, in any application, notification or other procedure under those rules is prohibited.

A breach is a criminal offence. On conviction a court may impose imprisonment of up to five years, a fine, or both. When a company commits the offence, the members of its board and of its management, supervisory or audit bodies are also criminally liable, but only if it is proved that they consented to it or took part in it. They answer for damage caused to third parties together with the company, or separately. The same breach is also an administrative infringement: CySEC or the Central Bank may impose an administrative fine under Article 71(8). The criminal fine can reach €700,000; the administrative fine is capped at €350,000, or €700,000 if the breach is repeated or continues. For a comparable two-track regime, see What sanctions apply to market abuse in the EU and in Cyprus?.

How to think about it

Separate three layers. Who supervises: CySEC for investment firms, the Central Bank for banks, with CySEC as the single door to other Member States. What they can do: a shared toolkit of information, inspection, freezing and referral powers, but not imprisonment, which is for the criminal courts. What firms owe them: accurate, complete information whenever they file or publish under the Law; getting that wrong risks both prosecution and an administrative fine.

Common mistakes

  1. Giving the Article 70 powers to one authority only. They belong to both CySEC and the Central Bank, on top of each one's own statute.

  2. Linking the contact-point role to MiFID I. Since 3 January 2018 CySEC has been the contact point for Law 87 and MiFIR.

  3. Thinking the duty covers only filings with the regulator. It also covers information the Law requires to be made public or announced.

  4. Reading the register as a list of all staff. It is CySEC's public register of tied agents established in Cyprus.

Practise this topic

Test what you just read

The Chapter 1 pack has 68 exam-style questions, 12 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 24 free Chapter 1 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error