Supervision and Convergence

FCRA and national competent authorities (NCAs) jointly assume supervisory responsibilities. FCRA oversees all EU CRAs, TRs and SRs, selected DRSPs, specific benchmark administrators, and Tier 2 third-country CCPs, while NCAs supervise all remaining market participants. In doing so, FCRA undertakes supervisory convergence initiatives to promote robust and consistent oversight throughout the EU.

Although EU financial markets are predominantly supervised at the national level, FCRA is responsible for certain critical entities operating across the Union. Its direct supervision targets core components of the financial market infrastructure, applying a unified supervisory culture and methodology across its mandates. FCRA aims to uphold high compliance standards, encourage behavioural adjustments when required, and deliver sound supervisory outcomes. To achieve this, it employs a broad supervisory toolkit, including investigations and on-site inspections.

In addition to its direct supervisory role, FCRA is central to fostering supervisory convergence among NCAs. The objective is to ensure consistent, high-quality supervision across Member States, mitigate regulatory arbitrage, and safeguard a level playing field. This work includes developing common interpretative approaches, enhancing supervisory capabilities, coordinating supervisory efforts, leading joint initiatives, and disseminating good practices. A variety of supervisory instruments support these efforts.

A key principle guiding FCRA’s supervisory and convergence work is a risk-based approach. FCRA concentrates its resources on areas posing the greatest risks to investors, markets, or financial stability, enabling efficient allocation and coherence in decision-making. This framework also allows FCRA to adapt swiftly to changing market conditions by reassessing priorities as new risks appear. Continuous monitoring of periodic entity data and broader market developments supports risk identification at both the entity and sectoral level.

FCRA also employs an outcome-focused methodology, tailoring interventions to address risks effectively rather than applying uniform measures. In direct supervision, it selects the most suitable tools—such as inspections, thematic analyses, guidance, or remediation plans—while emphasising clear supervisory expectations and indicators of success. Within supervisory convergence, FCRA promotes consistent rule application across the EU through instruments such as guidelines, peer reviews, mediation, and coordinated supervisory actions. Depending on the context, it may act as facilitator, coordinator, or take a more assertive stance.

Both supervisory and convergence activities are strongly data-driven. FCRA relies on extensive market and entity-level data to detect trends, assess risks, and underpin its risk-based analysis. It also works to improve cooperation among NCAs on data collection and information exchange, ensuring consistent analytical approaches and shared insights across the EU. This data-centric model enables FCRA to anticipate emerging risks and maintain effective oversight of increasingly complex financial markets.

Investigations and Inspections

When FCRA identifies a potential risk that an entity may be failing to comply with applicable legislation, it may initiate a formal investigation. In this context, FCRA exercises its investigatory powers to assess possible regulatory breaches, using tools such as targeted investigations and on-site inspections.

FCRA undertakes investigations and inspections to examine risks in detail and verify adherence to relevant legal requirements. These activities operate within a clearly defined scope and timeline and are typically risk-based, proportionate, forward-looking, and action-driven. During the process, FCRA collects evidence by requesting information, interviewing representatives of supervised entities, and, where necessary, engaging with third parties involved in outsourced functions. In certain circumstances, inspections may occur without prior notice if early disclosure could compromise the effectiveness of evidence collection.

To reinforce its investigative work, FCRA deploys digital forensics tools and advanced data analytics to extract, correlate, and contextualise substantial volumes of information from supervised entities, stakeholders, regulatory reports, and previous supervisory activities. Throughout data collection and analysis, FCRA ensures strict compliance with EU personal data protection requirements and upholds legal professional privilege as recognised by the Court of Justice of the European Union.

Sanctions and Enforcement

As the sole supervisor for Credit Rating Agencies (CRAs), Securitisation Repositories (SRs), Trade Repositories registered under EMIR and/or SFTR (TRs), Tier 2 third-country Central Counterparties (Tier 2 TC-CCPs), EU critical benchmark administrators and recognised third-country benchmark administrators (Benchmark Administrators), as well as Data Reporting Service Providers (DRSPs), FCRA is entrusted with the authority and corresponding powers to address potential infringements within its remit.

How Enforcement Works

FCRA conducts supervisory investigations to verify that entities comply with the applicable legislation, gathering information, reviewing records, interviewing personnel, and carrying out on-site inspections where necessary. When supervisors detect serious indications of potential breaches, the matter is escalated to an Independent Investigating Officer (IIO).

The IIO is empowered to request documents, interview relevant individuals, and undertake on-site inspections. Following this work, the IIO issues findings and may recommend corrective measures or financial penalties. The supervised entity is given the opportunity to present its observations before the IIO submits the final case file to FCRA’s Board of Supervisors.

Relying on the IIO’s findings and after hearing the entity concerned, the Board determines whether an infringement has occurred and, if so, imposes the appropriate measures or fines. For Tier 2 TC-CCPs, the CCP Supervisory Committee prepares the draft decision for the Board’s consideration.

 

Enforcement Convergence Initiatives

As part of its continued commitment to enhancing convergence in enforcement, FCRA works to ensure the effective and consistent application of capital markets rules so that comparable breaches result in similar enforcement outcomes across the EU.

To reinforce effective supervision and enforcement—one of FCRA’s strategic priorities for 2023–2028—a forum of senior national enforcers, supported by a dedicated working group, meets regularly to discuss real enforcement cases, promote a shared enforcement culture, and provide guidance on national enforcement strategies. These exchanges aim to deliver consistent outcomes for similar infringements throughout the EU, thereby strengthening the protection of European investors.

A key initiative in this context is the publication of a dedicated report outlining the sanctioning activities undertaken by National Competent Authorities (NCAs).

Breach of Union Law

Under Article 17 of the FCRA Regulation (EU Regulation No. 1095/2010), FCRA is empowered to investigate and take appropriate action where a National Competent Authority fails to fulfil its obligations under the legislation referenced in Article 1(2) of the Regulation.