Management of Information Systems

March 2018 Nezihe Boran
% 0

Introduction

As stated under Article 128 of Capital Markets Law No. 6362[1] (“Capital Markets Law”), one of the duties of the Capital Markets Board (“CMB”), among others, is to determine the procedures and principles for the supervision and operation of the management of the information systems of capital markets institutions, publicly held companies, stock exchanges and self-regulatory establishments. To this end, based on the provisions of the Capital Markets Law, Communiqué on the Management of the Information Systems (VII-128.9) (“Management Communiqué”), together with the Communiqué on the Independent Auditing of Information Systems (III-62.2) (“Auditing Communiqué,” Management Communiqué, and the Auditing Communiqué, shall collectively be referred to as the “Communiqués”) have been published in the Official Gazette dated 5 January 2018 and numbered 30292. Both the Management Communiqué and the Auditing Communiqué have entered into force with their publication in the Official Gazette. While the procedures and principals applicable to the management of the information systems for the listed establishments therein are determined under the Management Communiqué, independent auditing of information systems is further regulated under the Auditing Communiqué. This article will mainly focus on the scope of the Management Communiqué, innovations introduced thereunder, especially the obligation to keep the systems in the Republic of Turkey and, finally, the sanctions.

The Scope of the Management Communiqué

Both of the Communiqués are applicable to Borsa Istanbul A.S., other market places organized with the stock exchanges and market operators, pension mutual funds, Istanbul Takas ve Saklama Bankasi A.S., Merkezi Kayit Kurulusu A.S., portfolio depository establishments, Sermaye Piyasasi Lisanslama Sicil ve Egitim Kurulusu A.S., capital markets organizations, publicly held companies, Capital Markets Union of the Republic of Turkey, and the Appraisers Association of the Republic of Turkey. Banks and insurance companies, financial leasing, factoring and financing companies, from amongst the aforementioned institutions, establishments and associations would comply with the requirements of their specific legislation in respect of the management of the information systems. Compliance with such specific legislations would be regarded as satisfaction of the requirements of the Communiqués.

Information Systems: Primary and Secondary Systems

The Management Communiqué defines the primary system as “the complete system comprising of the infrastructure, hardware, software and data, ensuring to save and use the information required for the institutions, establishments and associations to perform their obligations stated under the legislation, if and when required, and enabling the access to such information in a secure manner.” It is set forth in the Management Communiqué that the secondary system means “the primary system backups, which enable uninterrupted access to all information in the event of any interruption to the activities carried out by the primary systems, and if and when required for institutions, establishments and associations to perform their obligations stated under the legislation with an aim to keep the activities in a sustainable manner within the interrupted periods.

In light of the above, the legislator defines the information systems in a broad manner so as to include all information systems used for the performance of the activities within the scope of the Capital Markets Law, or as required by the CMB.

It is stated under Article 26 (Sustainability of the Information Systems) of the Management Communiqué that the institutions, establishments and associations are obliged to keep the primary and secondary systems within the Republic of Turkey. As in practice, so many publicly held companies are currently keeping their iCloud systems abroad; such a newly introduced provision created discussions as to whether those companies will be required to transfer their systems into the Republic of Turkey. However, the CMB announced a public disclosure in the CMB Bulletin dated 8 March 2018 and numbered 2018/10 in order to clarify such discussions. The CMB stated that the information systems of the publicly held companies, which are not subject to independent audit, are not required to keep their primary systems within the Republic of Turkey. The CMB further stipulates that the scope of the publicly held companies, which are subject to independent audit, is planned to be gradually extended. For those companies that will be subject to independent audit, they will be obliged to keep the primary systems from the period, under which they are obliged, within the Republic of Turkey.

Management of the Information Systems

The Management Communiqué is entered into force in order to ensure the formation and management of the information systems in a secure, efficient, sustainable manner, and to determine the procedures and principles applicable thereto.

For this purpose, pursuant to the Management Communiqué, the policies for the establishment of the information systems, operation, management and usage thereof, as well as all sorts of information security related policies, such as confidentiality, integrity and, if and when needed, availability of the information, should be prepared by the top management and approved by the board of directors. Following its approval, the policies should be announced to the employees.

The top management is responsible for the monitoring of the application of the policies; however, the responsibility for organizing effective and sufficient controls is delegated by the board of directors. The Management Communiqué further sets forth that the top management is responsible to create a certain mechanism for review of the policies and all the responsibilities annually, determination of the risks and performing risk management, monitoring of those events that are incompliance with the information security and evaluation of those, providing education to the employees to be aware of the information security, etc.

The Management Communiqué stipulates that the institutions, establishments and associations that fall within the scope of the obligations shall appoint a well-equipped and qualified individual who is responsible for performing the requirements of the processes and principles in respect of the security of the information systems and monitoring of the same and, further, reporting to the top management the risks and the management of the risks. The respective Communiqué further requires institutions, establishments and associations to hire a nationally or internationally certified independent person to run a leakage test at least once a year.

The legislator states the minimum requirements to be fulfilled regarding the control of the information systems under the Management Communiqué, which are, briefly, (i) defining the process owner, roles, activities and liabilities, (ii) defining the controlling periods, periodically, and (iii) defining the aims and purposes of each of the controlling periods and measurable performances. The respective Communiqué further regulates, among others, that the asset (comprised from information) management, segregation of duties for the system, database and development of the implementations, security, ID authentication, authorization, audit trail mechanism, the principles for informing the customers and, finally, limited exceptions for certain institutions, establishments and associations in respect of certain obligations.

Sanctions

In the event of any non-compliance with the provisions of the Management Communiqué, Article 103 (General Principles) of the Capital Markets Law will apply. Accordingly, an administrative fine from TRY 27,047 up to TRY 338,088 will be assessed.

Conclusion

With the introduction of the Management Communiqué, which determines the procedures and principals applicable to the management of the information systems, the formation and management of the information systems in a secure, efficient, sustainable manner, and to determine the procedures and principles applicable thereto, are ensured. The scope of the obligations under the Management Communiqué includes the institutions established as per, or subject to, the Capital Markets Law. The discussions regarding the obligation to keep the primary system and the secondary system within the Republic of Turkey has been clarified by the CMB for the time being, which we still believe should be further clarified, and in detail. The respective Communiqué regulates the policies for the establishment of the information systems, operation, management and usage thereof, as well as all types of information security related policies, the responsible parties for the duties, and other details.

[1] Capital Market Law numbered 6362, OG, No. 28513, December 30, 2012.

All rights of this article are reserved. This article may not be used, reproduced, copied, published, distributed, or otherwise disseminated without quotation or Erdem & Erdem Law Firm's written consent. Any content created without citing the resource or Erdem & Erdem Law Firm’s written consent is regularly tracked, and legal action will be taken in case of violation.

Other Contents

ESMA Publishes Expected Sustainability Disclosures in Prospectuses
Newsletter Articles
ESMA Publishes Expected Sustainability Disclosures in Prospectuses

As this newsletter moves into a more sustainable future with eco-friendly Exlibris, so does the EU’s financial markets regulator and supervisor, the European Securities and Markets Authority (“ESMA”). In light of its 2023-2028 strategy , ESMA supports the Environmental, Social and Governance (ESG) transition by...

Capital Markets Law 31.08.2023
Borsa Istanbul's New Venture Capital Market
Newsletter Articles
Borsa Istanbul's New Venture Capital Market

The Communiqué on the Principles Regarding the Companies whose Shares will be Traded on the Venture Capital Market (II-16.3) ("Communiqué") has facilitated for private joint stock companies to sell their shares to qualified investors without a public offering. Thus, a new opportunity is created for joint stock...

Capital Markets Law 31.08.2023
Sustainability and Capital Markets
Newsletter Articles
Sustainability and Capital Markets

In 1987, the United Nations World Commission on Environment and Development published a report entitled “Our Common Future”. The report drew attention to the causes of global environmental problems and defined sustainable development as “development that meets the needs of the present without compromising...

Capital Markets Law 31.07.2023
Investor Protection and Transparency Principle in Light of Credit Suisse AT1 Bonds
Newsletter Articles
Investor Protection and Transparency Principle in Light of Credit Suisse AT1 Bonds

Swiss Financial Markets Supervisory Authority (“FINMA”), through its decision dated 19 March 2023, approved the merger of Credit Suisse with UBS Group AG (“UBS”) and to write down the Additional Tier 1 capital bonds (referred to as AT1) issued by Credit Suisse, with a total value of approximately CHF 17 billion...

Capital Markets Law 30.06.2023
The New Communiqué on Crowdfunding
Newsletter Articles
The New Communiqué on Crowdfunding

The Capital Markets Board’s (“Board”) long-awaited Communiqué on Crowdfunding No. III - 35/A.2 (“Communiqué”) entered into force through its publication in the Official Gazette numbered 31641 and dated 27 October 2021...

Capital Markets Law January 2022
Turkish Mortgage Covered Bonds
Newsletter Articles
Turkish Mortgage Covered Bonds

Mortgage covered bonds are one of today’s most common structured finance products. Although they have a prominent presence in the marketplace today, these bonds have historical roots in the Pfandbrief of 18th century Prussia. In the aftermath of the Seven Years War, King Frederick the Great implemented...

Capital Markets Law October 2021
The Practice of Green Bonds in the World and Turkey
Newsletter Articles
The Practice of Green Bonds in the World and Turkey
Capital Markets Law October 2021
Basic Principles Regarding Public Offering
Newsletter Articles
Basic Principles Regarding Public Offering
Capital Markets Law April 2021
Portfolio Management Companies 101
Newsletter Articles
Portfolio Management Companies 101
Capital Markets Law February 2021
The Communiqué on Board of Debt Instrument Holders
Newsletter Articles
The Communiqué on Board of Debt Instrument Holders
Capital Markets Law September 2020
Communiqué on Significant Transactions and Retirement Right
Newsletter Articles
Communiqué on the Principles of Abolishing Privileges
Newsletter Articles
Contracts of Guarantee Relating to Capital Market Instruments
Newsletter Articles
Draft Communiqué on Equity Based Crowdfunding
Newsletter Articles
Draft Communiqué on Equity Based Crowdfunding
Capital Markets Law May 2019
Issuance of Shares in Registered Capital System
Newsletter Articles
Issuance of Shares in Registered Capital System
Capital Markets Law February 2019
Recent Developments on Corporate Governance Compliance Reporting
Newsletter Articles
Public Disclosure Obligation
Newsletter Articles
Public Disclosure Obligation
Capital Markets Law August 2018
Market Manipulation Offense in terms of Turkish Capital Markets Law
Newsletter Articles
Mandatory Share Purchase Offer
Newsletter Articles
Mandatory Share Purchase Offer
Capital Markets Law June 2018
MiFID II and its Eventual Impacts on Turkey
Newsletter Articles
MiFID II and its Eventual Impacts on Turkey
Capital Markets Law March 2018
Regulatory Approaches to Crowdfunding in European Union
Newsletter Articles
Important Changes in Capital Markets Legislation
Newsletter Articles
Important Changes in Capital Markets Legislation
Capital Markets Law January 2018
Crowdfunding in Turkey
Newsletter Articles
Crowdfunding in Turkey
Capital Markets Law January 2018
Recent Amendments to the Debt Securities Communiqué
Newsletter Articles
Recent Amendments to the Debt Securities Communiqué
Capital Markets Law December 2017
Activities of Foreign Investment Institutions in Turkey
Newsletter Articles
Activities of Foreign Investment Institutions in Turkey
Capital Markets Law September 2017
The Draft Law on Crowdfunding
Newsletter Articles
The Draft Law on Crowdfunding
Capital Markets Law April 2017
Property Certificates
Newsletter Articles
Property Certificates
Capital Markets Law March 2017
Amendments to the Communiqué on Disclosure of Material Events
Newsletter Articles
Recent Developments Regarding Alternative Investment Funds in Europe
Newsletter Articles
Financial Reporting Principles of Mutual Funds
Newsletter Articles
Financial Reporting Principles of Mutual Funds
Capital Markets Law December 2016
Share Buy-Back by Listed Corporations
Newsletter Articles
Share Buy-Back by Listed Corporations
Capital Markets Law December 2016
Communiqué On The Principles Regarding Security Investment Companies
Newsletter Articles
Legal Remedies For Corporate Bondholders in The Event Of Default
Newsletter Articles
Market Abuse Actions in Accordance With Capital Markets Law
Newsletter Articles
Prohibition On Hidden Income Shifting
Newsletter Articles
Prohibition On Hidden Income Shifting
Capital Markets Law January 2015
Asset-Backed And Mortgage-Backed Securities
Newsletter Articles
Asset-Backed And Mortgage-Backed Securities
Capital Markets Law November 2014
The New Era For Mutual Funds – I
Newsletter Articles
The New Era For Mutual Funds – I
Capital Markets Law November 2014
New Regulation in Turkish Capital Markets: Real Estate Investment Funds
Newsletter Articles
Squeeze-out and Sell-out Rights in Public Companies
Newsletter Articles
Squeeze-out and Sell-out Rights in Public Companies
Capital Markets Law October 2014
Renewed Communiqué And Guide For Disclosure Of Material Events
Newsletter Articles
Prominence Of Sukuk in Turkey As An Islamic Finance Instrument
Newsletter Articles
Communiqué On Corporate Governance II
Newsletter Articles
Communiqué On Corporate Governance II
Capital Markets Law May 2014
Communiqué On Corporate Governance I
Newsletter Articles
Communiqué On Corporate Governance I
Capital Markets Law February 2014
Share Purchase Offer
Newsletter Articles
Share Purchase Offer
Capital Markets Law February 2014
Independent Board Of Directors’ Members Under Corporate Governance Principles
Newsletter Articles
Communique Regarding Debt Securities
Newsletter Articles
Communique Regarding Debt Securities
Capital Markets Law July 2013
The Regulation Regarding Angel Investment Capital
Newsletter Articles
The Regulation Regarding Angel Investment Capital
Capital Markets Law February 2013
Corporate Governance
Newsletter Articles
Corporate Governance
Capital Markets Law March 2012
Share Repurchase (Buybacks) Or Pledge Of Shares
Newsletter Articles
Share Repurchase (Buybacks) Or Pledge Of Shares
Capital Markets Law August 2011
Pledging Dematerialized Shares Of Publicly Held Joint-Stock Companies
Newsletter Articles
Preparation By The Capital Market Board Of A New Draft Regarding Takeover Bids
Newsletter Articles
Distribution of Dividends in Public Companies
Newsletter Articles
Distribution of Dividends in Public Companies
Capital Markets Law December 2019

For creative legal solutions, please contact us.