EstoniaRiigi Teataja
Estonian banks face 1 October deadline for committee and control changes
Banks must align their activities and documents with amended committee and internal-control provisions by 1 October 2026, including independence and governance requirements.
By Taxxa AI OyPublished 1 September 2026
Estonian credit institutions must bring their activities and documents into line with amended committee and internal-control requirements by 1 October 2026Riigiteataja. The transition provision covers changes to §§ 57⁴–61 of the Credit Institutions Act
Riigiteataja adopted on 17 June 2026. Bank boards and control-function leaders should review both their operating arrangements and the documents governing them.
The committee framework requires an audit committee and a credit committee. Institutions considered significant by reference to their size, internal organisation and the nature, scale and complexity of their activities must also establish risk, nomination and remuneration committeesRiigiteataja. The law sets out distinct membership and responsibility requirements for these bodies.
Nomination and remuneration committees may be combined where conflicts of interest are avoidedRiigiteataja. A risk committee and audit committee may be combined only for an institution that is not significant under the specified test, again avoiding conflicts
Riigiteataja. Members must have the knowledge, skills and experience needed for both sets of duties, and the institution must separately explain the combination to Finantsinspektsioon
Riigiteataja.
The internal-control system comprises internal audit, risk control and complianceRiigiteataja. These functions must be organisationally independent and separate from activities that take risks
Riigiteataja. Internal audit cannot be combined with another business line or control function
Riigiteataja. Compliance may be combined with another control unit’s function only where proportionate and without impairing its independence or ability to perform its duties
Riigiteataja.
Responsibilities for leading the control functions must be clearly defined. Leaders must be independent in carrying out their duties and have the required higher education, knowledge and experienceRiigiteataja. The supervisory board appoints and removes control-function heads and internal-audit staff
Riigiteataja. People performing control functions must be able to contact supervisory-board members directly and raise identified shortcomings or risks.
The deadline is stated in § 141²³ of the ActRiigiteataja. The underlying amendments also prescribe committee duties, control-function tasks and rights of access. Banks should map those requirements to committee mandates, internal rules, reporting lines and staffing arrangements before the October deadline, retaining the distinction between the separate control functions.
Review committee mandates, control-function independence and governing documents before 1 October 2026.