The operator shall have appropriate corporate governance rules and procedures in place. These include, in particular:
an organisational structure and framework which define the tasks, responsibilities, powers and reporting duties of the board of directors, the senior management and the internal audit function;
a risk management framework for the identification, measurement, management and monitoring of risk;
a system of internal controls which, inter alia, ensures compliance with statutory, regulatory and internal company rules and regulations (compliance function).
The operator shall have mechanisms in place that allow participants’ needs with regard to services provided by the financial market infrastructure to be surveyed.