TaxxaCompany Logo

Menu

Company

About usCareersBlogContact usLinkedInYouTube

Product

FeaturesPricingFAQ

Legal

Cookie PolicyData Processing AgreementPrivacy PolicyTerms and Conditions
© 2026 Taxxa AI Oy. All rights reserved.
  1. News
  2. /Estonia
  3. /Financial Sector & Markets

Estonia·Riigi Teataja

Estonian banks face 1 October deadline for committee and control changes

Banks must align their activities and documents with amended committee and internal-control provisions by 1 October 2026, including independence and governance requirements.

By Taxxa AI Oy · Published 1 September 2026

Financial Sector & MarketsLegal & Corporate

Estonian credit institutions must bring their activities and documents into line with amended committee and internal-control requirements by 1 October 2026Riigiteataja. The transition provision covers changes to §§ 57⁴–61 of the Credit Institutions ActRiigiteataja adopted on 17 June 2026. Bank boards and control-function leaders should review both their operating arrangements and the documents governing them.

The committee framework requires an audit committee and a credit committee. Institutions considered significant by reference to their size, internal organisation and the nature, scale and complexity of their activities must also establish risk, nomination and remuneration committeesRiigiteataja. The law sets out distinct membership and responsibility requirements for these bodies.

Nomination and remuneration committees may be combined where conflicts of interest are avoidedRiigiteataja. A risk committee and audit committee may be combined only for an institution that is not significant under the specified test, again avoiding conflictsRiigiteataja. Members must have the knowledge, skills and experience needed for both sets of duties, and the institution must separately explain the combination to FinantsinspektsioonRiigiteataja.

The internal-control system comprises internal audit, risk control and complianceRiigiteataja. These functions must be organisationally independent and separate from activities that take risksRiigiteataja. Internal audit cannot be combined with another business line or control functionRiigiteataja. Compliance may be combined with another control unit’s function only where proportionate and without impairing its independence or ability to perform its dutiesRiigiteataja.

Responsibilities for leading the control functions must be clearly defined. Leaders must be independent in carrying out their duties and have the required higher education, knowledge and experienceRiigiteataja. The supervisory board appoints and removes control-function heads and internal-audit staffRiigiteataja. People performing control functions must be able to contact supervisory-board members directly and raise identified shortcomings or risks.

The deadline is stated in § 141²³ of the ActRiigiteataja. The underlying amendments also prescribe committee duties, control-function tasks and rights of access. Banks should map those requirements to committee mandates, internal rules, reporting lines and staffing arrangements before the October deadline, retaining the distinction between the separate control functions.

Review committee mandates, control-function independence and governing documents before 1 October 2026.

Sources

  1. Krediidiasutuste seadus

Share with your network

More on this

  1. 10 Sept 2026

    Estonian FIU urges firms to assign responsibility for AMLA readiness

  2. 10 Sept 2026

    Estonian FIU flags rapid gambling withdrawals in new typology report

  3. 7 Sept 2026

    Estonia revises market-price priority for investor-protection valuations

  4. 7 Sept 2026

    Estonia unifies regulated-market disclosure in UCITS investment reports

  5. 26 Aug 2026

    EMTA corrects the Estonian date for a Russia-sanctions wind-down clause

Estonia news