…
The Fit and Proper Directive refers to industry shorthand for one of the most consequential governance obligations in EU financial regulation: a framework embedded across multiple directives, not a single instrument. CRD IV Article 91 is the legislative start, extended by Solvency II, MiFID II, and the Investment Firms Directive. In June 2024, CRD VI introduced the most significant reforms since 2013, and the EBA is currently revising its joint guidelines following a February 2026 consultation. For legal and compliance teams the most important aspect is to have their documentation ready to withstand supervisory scrutiny.
Key takeaways:
- The fit & proper framework spans CRD IV/V/VI, Solvency II, MiFID II, and IFD, with no single directive bearing that name
- It applies to management body members (executive and non-executive) and key function holders including the CFO, Head of Compliance, and Head of Internal Audit
- Two dimensions: “fit” covers knowledge, skills, and experience; “proper” covers reputation, integrity, and absence of conflicts of interest
- Reassessment is event-triggered, not calendar-based: specific circumstances require a fresh evaluation throughout a mandate
- Legal teams are responsible for building, maintaining, and producing compliant assessment files on demand
What is the fit & proper directive?
Fit stands for knowledge, skills, and experience. Individuals must have the right qualification and track record a role demands. Proper stands for the reputational side, honesty, integrity and financial soundness, and freedom of conflict of interest.
These two dimensions are assessed separately but must both be satisfied.
The framework is distributed across several EU legislative instruments:
| Regulatory sector | Key instrument | Fit & proper article | Supervising authority |
|---|---|---|---|
| Banking | CRD IV/V/VI (Directive 2013/36/EU as amended) | Article 91 (+ Arts. 91a & 91b via CRD VI) | ECB/SSM + NCAs |
| Insurance | Solvency II (Directive 2009/138/EC) | Article 42 | EIOPA + NCAs |
| Investment Services | MiFID II (Directive 2014/65/EU) | Article 9 | ESMA + NCAs |
| Investment Firms | IFD (Directive 2019/2034/EU) | Article 18(1)(i) | NCAs |
CRD IV established the requirement for credit institutions in 2013. CRD V amended it, with a transposition deadline of 28 December 2020, now fully transposed across all EU member states. CRD VI, published 19 June 2024, introduced Articles 91a and 91b, separating for the first time the institution’s assessment role from the NCA’s supervisory role. The EU Commission described fit & proper as “one of the least harmonized areas in EU bank supervisory law” when proposing CRD VI; that reform is now law.
The EBA and ESMA Joint Guidelines (EBA/GL/2021/06), published 2 July 2021 and applicable from 31 December 2021, operationalise the framework in practice. They are currently being revised under the EBA and ESMA consultation on revised suitability assessment requirements (EBA/CP/2026/03), published 25 February 2026, to reflect CRD VI. The scale of the obligation is considerable: the ECB and Single Supervisory Mechanism conduct approximately 4,000 fit & proper assessments annually across roughly 115 significant institutions.
Understanding who bears those obligations is where building a compliant programme begins.
Who must comply?
Scope, roles, and assessment criteria
The framework applies to:
The assessment operates on individual suitability and collective suitability.
Individual suitability evaluates specific people’s suitability for specific roles while collective suitability evaluates the management body as a whole and their capacity to cover. the eleven competences defined in EBA/GL/2021/06, paragraph 70. These are:
For directors of significant institutions, CRD IV Article 91(3) also caps external mandates: a director may hold either (a) one executive directorship and two non-executive directorships, or (b) four non-executive directorships. NCAs may authorize one additional non-executive mandate. Directorships held within the same group count as one. Roles in non-commercial organizations (charities, churches, chambers of commerce, foundations) are excluded from the count.
For the legal and compliance professionals who own this process, those criteria translate into a specific set of documentation obligations.
What this means for legal teams
Legal and compliance teams working for investment firms, banking and all the previously mentioned sectors need to translate the framework into a documented and audit-ready program. But to do so, teams must know exactly who in the organization owns each step of the program.
| Role | Key obligation | Documentation required |
|---|---|---|
| General Counsel / Legal Director | Oversee the fit & proper compliance framework; coordinate NCA notifications | Assessment policy, NCA notification log |
| Compliance Officer | Conduct suitability assessments; maintain individual evidence files | Individual suitability files, collective competence matrix |
| Corporate Secretary / Board Secretary | Maintain board member profiles; track mandate counts; flag material changes | Mandate tracker, director profiles, change log |
| HR / Legal (shared) | Collect supporting documentation at onboarding and reassessment | CVs, qualifications, criminal record certificates, signed declarations |
Building and maintaining assessment files
A fit & proper file is the organization’s documented evidence that each person in scope has been properly assessed across the five fit & proper areas, and according to what they bring to the board’s collective competence.
In terms of documentation, the set is fairly consistent across institutions. For each person, that means a CV, professional qualifications, references, a criminal record certificate, a signed declaration, and a conflict of interest disclosure. This remains unchanged whether the assessment is for a new executive appointment or a non-executive joining for a specific competence.
The ongoing side of this obligation is where most teams feel the pressure. Because files need to stay current throughout a person’s tenure and be available for supervisory review whenever asked. Retention periods are not fixed at EU level; the applicable standard is set by national law in each relevant jurisdiction.
Ongoing monitoring: when reassessment is triggered
Fit & proper reassessment is event-triggered, not calendar-driven. Under EBA/GL/2021/06, paragraphs 26–27, reassessment is required when:
NCA notification timelines are being formalized through CRD VI Articles 91a and 91b, with specifics depending on national transposition. Legal teams should monitor implementation in each relevant jurisdiction and build notification procedures before they are needed.
Multi-entity and cross-border complexity
For groups operating across multiple EU jurisdictions, the fit & proper obligation multiplies. Each NCA applies the framework independently, transposition timelines and documentation requirements vary, and coordinating assessments across subsidiaries creates significant operational load. A group with five regulated entities is effectively running five separate compliance processes, each with its own NCA expectations, notification timelines, and evidence standards. Managing this manually, across spreadsheets and email chains, creates gaps and audit exposure that compound over time.
Building a repeatable governance program is the most reliable way to manage this at scale.
Building a fit & proper governance framework: practical steps
The fit and proper directive is meant to tackle the operational complexity many big financial institutions and other concerned sectors encounter. Handling multiple subsidiaries across large organizations is complex, but by building the right infrastructure early, teams will spend less time scrambling when a regulator asks for evidence.
A simplified step-by-step example
- Map every role subject to fit & proper assessment, including management body members and key function holders across all entities in scope
- Build individual assessment files covering all five ECB dimensions for each person, with a defined and consistent document set
- Establish a trigger-based reassessment process tied to the specific events in EBA/GL/2021/06, paragraphs 26–27
- Maintain a mandate tracker monitoring CRD IV Article 91(3) thresholds for all directors of significant institutions
- Create an audit-ready evidence package that can be produced on demand, rather than assembled under time pressure after a supervisory request
- Define NCA notification procedures and internal escalation paths aligned with CRD VI Articles 91a and 91b, updated as national transposition proceeds
Governance platforms such as entity management tools, or board management solutions, remove the manual coordination work that many legal and compliance teams struggle with. The right tools will address this directly by keeping entity records accurate and current across every jurisdiction, maintaining board member profiles in a secure digital environment, and making the full evidence package available whenever it’s needed.
Conclusion
The EU fit & proper framework ranks among the most operationally demanding governance obligations in financial regulation. The criteria are clear; the difficulty lies in the ongoing documentation, active monitoring, and the ability to produce evidence on short notice. As CRD VI continues to take effect and EBA guidelines evolve through the 2026 revision process, the expectations will only become more specific.
Organizations with mapped roles, structured files, defined reassessment triggers, and clear NCA notification procedures handle supervisory audits from a position of strength; those relying on ad hoc processes face recurring exposure every time a regulator asks for evidence.
See how DiliTrust helps legal and governance teams stay audit-ready across entities and jurisdictions.
Frequently asked questions abut the Fit & Proper directive
The framework applies to management body members — both executive and non-executive directors — and key function holders, typically including the CFO, Head of Compliance, Head of Risk Management, and Head of Internal Audit. Scope varies by sector and entity type.
A compliant assessment file typically includes a CV, professional qualifications, references, a criminal record certificate, a signed declaration, and a conflict of interest disclosure. Files must remain current throughout a person’s tenure and be available for supervisory review on demand. Retention periods are set by national law, not at EU level.
Each national competent authority applies the framework independently. A group operating across five regulated entities is effectively running five separate compliance processes, each with its own NCA expectations, notification timelines, and documentation standards. Without a centralized system, the coordination burden creates audit exposure at every level.




