Law / Taiwan

Bank and Financial Holding Company Internal Control Rules, Dedicated Information Security Unit

Arts. 24-25 of the Implementation Rules of Internal Audit and Internal Control System of Financial Holding Companies and Banking Industries… (金融控股公司及銀行業內部控制及稽核制度實施辦法), full-text revision promulgated May 6, 2026 (Financial Supervisory Commission Order Jin-Guan-Yin-Guo-Zi No. 11502710961), effective on promulgation for the articles cited here

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force 5 months, effective 6 May 2026.

A sector security regimes rule binding private bodies.

As of 19 September 2026.

What it requires

  • This binds a financial holding company or a banking-industry entity (a bank, credit cooperative, bills finance company or trust enterprise) under Financial Supervisory Commission jurisdiction; an entity outside that class carries no duty under this row.
  • Establish a dedicated information security unit reporting to the general manager, that does not also handle information-technology operations or any other function creating a conflict of interest, staffed with adequate personnel and equipment.
  • Appoint a deputy general manager or equivalent as Chief Information Security Officer over that unit, and have that officer report the prior year's overall information-security performance to the board of directors annually and report a material information-security problem promptly when it arises.
  • Have the dedicated unit plan, manage and execute the information security system to control information security risk, supervise every unit's compliance with it, and build the mechanisms for cyber security protection, threat-intelligence assessment, and cyber security incident notification and response.
  • Provide the dedicated unit's personnel at least 15 hours, and other information-technology personnel at least 6 hours, of information-security training annually.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

This regulation sets no penalty of its own for an Article 24 or Article 25 violation; Article 54 gives affected entities until Dec. 31, 2027 to adjust into compliance, and enforcement otherwise runs through the parent statutes' own administrative-sanction provisions, not independently traced to a specific fine.

Who enforces it

Enforcement body

The Financial Supervisory Commission, through the administrative-sanction provisions of the parent statutes this regulation is issued under (the Banking Act, the Financial Holding Company Act, the Credit Cooperatives Act, the Act Governing Bills Finance Business, and the Trust Enterprise Act) rather than a penalty stated in this regulation itself.

Settledness

As of
19 September 2026
Open questions
Which specific provision of the Banking Act, or of the other four statutes this regulation is issued under, sets the administrative fine for a financial holding company's or bank's failure to comply with the Article 24 or Article 25 dedicated-information-security-unit duty?

What it reaches

Obligation class

Security, Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 24 of the Financial Supervisory Commission's internal-control regulation for financial holding companies and the banking business requires each to 'establish a dedicated information security unit subordinate to the general manager, which shall not concurrently handle information technology operations or other operations that present a conflict of interest with its duties,' headed by 'a person ranked vice general manager or above, or a person with equivalent responsibilities' serving as Chief Information Security Officer.

That officer 'shall report the overall implementation of information security from the preceding year to the board of directors each year'. Article 25 requires the dedicated unit to take charge of 'the planning, management, and execution of the information security system to manage information security risks' and to build 'mechanisms related to cyber security protection, assessment and response to cyber security intelligence, and reporting of and response to cyber security incidents.'

When LexLint raises it

  • operates_essential_service
  • provides_financial_services

Read the law

Official English translation
Laws & Regulations Database of the Republic of China (law.moj.gov.tw), read through the kong0107/mojLawSplitJSON mirror per the corpus's #8858 fidelity determination MOJ UpdateDate 20260911

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app