CySEC Advanced · Chapter 1 · Topic 5 of 8

What must CySEC do as supervisor, and how does it work with other authorities?

CySEC's register and authorisation duties, how often it reviews CIFs, its duty to cooperate with other EU authorities, what it may share and when it may refuse, and what it reports to ESMA.

By the ExamPass CY editorial teamLast reviewed 9 min read

Short answer

CySEC keeps a public register of CIFs, notifies ESMA of each authorisation and revocation, and vets shareholders with qualifying holdings to ensure sound and prudent management. It reviews CIFs with a frequency and intensity matched to their size, nature and complexity. It must cooperate with other EU authorities: it exchanges information immediately, carries out or allows inspections, and may share confidential information with ESMA, the ESRB, the Central Bank and the ECB, in confidence. It may refuse an EU request only over court proceedings or a final judgment in Cyprus on the same case.

CySEC's duties at a glance

RegisterPublic register of all CIFs and their authorised services; ESMA told of every authorisation and every revocation
Authorisation decisionWithin 6 months of a complete application
ShareholdersIdentity and size of qualifying holdings known, and holders suitable for sound and prudent management
Review frequencyProportionate to size, nature, scale, complexity and systemic importance; at least annual updates only for CRR firms in the examination programme
Breach abroad by an entity CySEC does not superviseNotify that Member State's authority and ESMA, as specifically as possible
Request for a check or investigationDo it, let the requesting authority do it, or let auditors or experts do it
Confidential informationMay go to ESMA, the ESRB, the Central Bank, other central banks, the ESCB and the ECB, which must keep it confidential
Refusal groundsOnly proceedings already begun, or a final judgment already given, in Cyprus for the same actions and persons
Reporting to ESMAInformation it needs, without undue delay; yearly aggregated sanctions data; each sanction when published, and any left unpublished; the out-of-court redress procedures

Source: Law 87(I)/2017, Articles 5, 7, 8, 11, 72, 76, 80–82, 84, 87 and 88; Law 165(I)/2021, section 29; Law 97(I)/2021, section 55.

In the exam

The exam is written from the exam material, which predates the changes below. Expect its answer. If that answer is not among the options and the current rule is, choose the current rule.

  • Review frequency

    Exam material: CySEC reviews every CIF's arrangements and risks at least once a year, with frequency and intensity scaled to the firm.

    Current law (since 5 November 2021 (Law 165(I)/2021)): No general yearly minimum: CySEC sets frequency and intensity in proportion to each firm and decides case by case for small and non-interconnected firms. At least yearly updates remain only for CRR firms in its supervisory examination programme.

  • Grounds to refuse cooperation

    Exam material: Three grounds: a threat to sovereignty, security or public order in Cyprus; court proceedings already under way; or a final judgment already given.

    Current law (since 3 January 2018 (Law 87(I)/2017, Article 84)): Towards another EU authority, only the two judicial grounds, for the same actions and persons in Cyprus. The sovereignty ground survives only in the CySEC Law, for foreign supervisors generally.

  • Sanctions reported to ESMA

    Exam material: CySEC gives ESMA consolidated information on all administrative penalties once a year.

    Current law (since 3 January 2018 (Law 87(I)/2017, Article 72)): Besides the yearly aggregated data, CySEC reports each sanction to ESMA when it publishes it, and each unpublished sanction with any appeal and its outcome.

  • Authorisation duties

    Exam material: CySEC must know all direct and indirect shareholders, and tells ESMA of every authorisation, rejection and revocation.

    Current law (since 3 January 2018 (Law 87(I)/2017, Articles 5(3), 8(2) and 11(1))): CySEC must know the holders of qualifying holdings and the size of those holdings. ESMA is told of each authorisation and each revocation, not of rejections.

What are CySEC's duties when it authorises and reviews CIFs?

CySEC authorises and supervises CIFs, deciding within 6 months of a complete application; see How does a firm become a Cypriot Investment Firm, and what must it keep doing?. It keeps a public register of every CIF and its authorised services, updates it regularly, and notifies ESMA of every authorisation and every revocation. It may withdraw an authorisation or suspend it in whole or in part; see When can CySEC suspend or withdraw a CIF's authorisation, and what happens to clients?.

Before authorising, CySEC must know the direct or indirect shareholders or members with qualifying holdings and the size of their holdings. It refuses if it is not satisfied that they are suitable, given the need for sound and prudent management, and close links must not obstruct supervision. The exam material speaks of all shareholders and says rejections are reported to ESMA. Law 87, in force since 3 January 2018, requires CySEC to identify only holders of qualifying holdings. Its duties to notify ESMA cover authorisations and revocations, not rejections.

CySEC also reviews the arrangements, strategies, processes and mechanisms CIFs use to comply, and evaluates their risks. The exam material says this happens at least annually. Since 5 November 2021, Law 165(I)/2021, transposing the Investment Firms Directive, has let CySEC set the frequency and intensity by the firm's size, nature, scale, complexity and, where relevant, systemic importance; for small and non-interconnected firms it decides case by case whether to review at all. Law 97(I)/2021 requires at least annual updates only for firms still under the Capital Requirements Regulation that are in the supervisory examination programme.

Terms used in this note

Qualifying holding
A direct or indirect holding of 10% or more of a firm's capital or voting rights, or one that makes it possible to exercise significant influence over its management.
Remote member
A firm that trades on a regulated market in another Member State without having a branch there.
Host authority
The authority of the Member State where a firm from another Member State provides services or has a branch.

How must CySEC cooperate with other EU authorities?

CySEC and the Central Bank must cooperate with other Member States' authorities whenever needed. They assist them, exchange information and cooperate in investigations and supervision, even where the conduct is not a breach of Cyprus law. Contact points pass on the information needed immediately, and a sender may restrict further disclosure.

If CySEC has good reason to suspect that entities it does not supervise are breaching Law 87, MiFID II or MiFIR in another Member State, it notifies that state's authority and ESMA, as specifically as it can. On receiving such a notice, CySEC acts and tells the notifying authority and ESMA the outcome and, where possible, significant interim developments.

Asked for an on-site check or investigation, CySEC carries it out itself, lets the requesting authority do so, or lets auditors or experts do so. It has no general power to inspect firms elsewhere in the EU. The exception is a CIF's own branch in another Member State, which CySEC may inspect after informing that state's authority. Where a CIF trades as a remote member on a regulated market elsewhere in the EU, that market's authority may deal with it directly; in the reverse case CySEC may do the same and informs the firm's home authority. The exam material adds that ESMA may take part in supervisory work, including joint on-site checks by two or more authorities. That rule is in MiFID II Article 80(2), which has applied since 3 January 2018, and in Article 21 of the regulation establishing ESMA. Law 87 does not repeat it.

What may CySEC share, when may it refuse, and what does it report to ESMA?

Professional secrecy does not stop CySEC passing confidential information to the European Systemic Risk Board, ESMA, the Central Bank of Cyprus, other Member States' central banks, the ESCB and the ECB as monetary authorities, and, where appropriate, overseers of payment and settlement systems. Recipients must keep it confidential; the media and the public never receive it.

The exam material lists three grounds for refusal: a threat to the Republic's sovereignty, security or public order; court proceedings already under way; and a final judgment already given. Since 3 January 2018, Law 87 Article 84, transposing MiFID II Article 83, has allowed CySEC to refuse a request from another EU authority only where judicial proceedings have already begun, or a final judgment has already been given, in Cyprus for the same actions and against the same persons. It must then inform the requesting authority and ESMA, giving as much detail as it can. Law 87 has no sovereignty ground. It remains in the CySEC Law, which covers requests from foreign supervisors generally.

CySEC gives ESMA the information it needs without undue delay. Every year it sends aggregated data on all sanctions and measures. It also tells ESMA of each sanction when it publishes it, and of any sanction it decides not to publish, with any appeal and its outcome. The exam material says CySEC reports complaints and remedial procedures to ESMA; since 3 January 2018, Law 87 Article 76 has required notice of the out-of-court complaint and redress procedures, not of individual complaints. As host authority, if a passporting firm persists in clearly harmful conduct despite the home authority's measures, CySEC informs that authority, takes its own measures, informs the Commission and ESMA, and may refer the case to ESMA. The exam material also says CIFs' difficulties in third countries are reported to the Commission; Law 87, in force since 3 January 2018, has no such rule.

How to think about it

Think of CySEC as one node in a network. At home it registers firms, vets their significant owners and reviews them in proportion to their risk. Outwards it cooperates by default: it shares information immediately, carries out or permits inspections, and alerts the right authority and ESMA about breaches it spots. Its reasons for refusing an EU request are narrow and judicial. Confidential information may travel to other supervisors and central banks, which must keep it confidential.

Common mistakes

  1. Assuming a fixed yearly review for every CIF. Review frequency is set proportionately; only CRR firms in the examination programme need at least annual updates.

  2. Refusing an EU request on sovereignty or public-order grounds. Under Law 87 only existing proceedings or a final judgment on the same actions and persons justify refusal.

  3. Thinking ESMA hears about sanctions only once a year. ESMA gets yearly aggregated data, but it is also told of each sanction when it is published, and of any sanction left unpublished.

  4. Thinking CySEC can inspect anywhere in the EU on its own. Cross-border checks go through requests to, and cooperation with, the other Member State's authority. The one exception is a CIF's own branch abroad, which CySEC may inspect after informing the host authority.

Practise this topic

Test what you just read

The Chapter 1 pack has 68 exam-style questions, 13 of them on this topic. Every question has a hint before you answer and a full explanation after.

Try the free demo

Or revise the numbers first with 24 free Chapter 1 flashcards →

Last reviewed on by the ExamPass CY editorial team against the law in force on that date. Study notes help you prepare for the CySEC exams; they are not legal advice. ExamPass CY is not affiliated with CySEC.

How we write study notesReport an error