Solvency II governance requirements come in two layers. Articles 40 to 49 of Directive 2009/138/EC say what an insurer must have: a system of governance, a risk management system, an ORSA, internal control, four key functions, fit and proper people and controlled outsourcing. Chapter IX of Commission Delegated Regulation (EU) 2015/35, Articles 258 to 275, says what each of those must contain: twelve general governance duties, the risk policies by area, the tasks of each key function, the content of a fit and proper assessment, the clauses an outsourcing contract must carry, and the principles a remuneration policy must follow. The Delegated Regulation is a regulation, so it applies as written, without national transposition.
This guide covers the second layer. If you need the Directive articles first, start with our guide to Solvency II Pillar 2 requirements. The detail below matters because it is what a supervisor holds your evidence against. Two dates apply: the text in force today, and the version amended by Commission Delegated Regulation (EU) 2026/269, which applies from 30 January 2027. Where that amendment changes a rule, it is flagged.
| Section of Chapter IX | Articles | What it fixes |
|---|---|---|
| Elements of the system of governance | 258 to 267 | General duties, the risk management system and its policy areas, the overall solvency needs in the ORSA, internal control and valuation controls. |
| Functions | 268 to 272 | Independence and access for every function, then the tasks of the risk management, compliance, internal audit and actuarial functions. |
| Fit and proper | 273 | Documented policies, what a fitness assessment covers and what a propriety assessment covers. |
| Outsourcing | 274 | The written outsourcing policy, due diligence on a provider, the twelve contract clauses and ongoing oversight. |
| Remuneration policy | 275 | Principles for the whole policy and specific rules for variable pay, including deferral of at least three years. |
What are the general governance requirements in Article 258?
Article 258(1) lists twelve duties, points (a) to (l). In summary: effective cooperation, internal reporting and communication at all relevant levels; decision making procedures and an organisational structure that specifies reporting lines and allocates responsibilities; a board, meaning the administrative, management or supervisory body (AMSB), that collectively and individually has the qualifications and experience to manage and oversee the undertaking; personnel with the skills their responsibilities need, and who know the procedures; no assignment of multiple tasks that prevents someone from doing a function soundly, honestly and objectively; information systems that produce complete, reliable, timely information; orderly records; security, integrity and confidentiality of information; clear reporting lines; and a written remuneration policy.
The rest of the article adds five requirements that auditors test directly. Article 258(2) says the policies on risk management, internal control, internal audit and, where relevant, outsourcing must set out responsibilities, objectives, processes and reporting procedures, consistent with the business strategy. Article 258(3) requires a business continuity policy. Article 258(4) requires that at least two persons effectively run the undertaking. Article 258(5) requires processes to prevent conflicts of interest. Article 258(6) requires the undertaking to monitor and regularly evaluate the adequacy and effectiveness of its system of governance and fix what it finds.
From 30 January 2027, that evaluation must also assess the adequacy of the AMSB's composition, including gender balance and diversity, its effectiveness and its internal governance, in proportion to the nature, scale and complexity of the risks in the business.
What must the risk management system and its policies contain?
Article 259 asks for four components: a documented risk management strategy consistent with the business strategy, including approved risk tolerance limits; a defined decision making procedure; written policies that define and categorise material risks by type, with tolerance limits for each; and reporting procedures that actively monitor the material risks and the effectiveness of the system. The people who run the undertaking or hold key functions must take that reporting into account in their decisions, and the system must include stress tests and scenario analysis where appropriate.
Article 260 then turns the risk areas in Article 44(2) of the Directive into eight required policies, points (a) to (h): it separates liquidity from concentration risk and adds deferred taxes. The risk management policy must cover underwriting and reserving, asset and liability management, investment risk, liquidity risk, concentration risk, operational risk, reinsurance and other risk mitigation techniques, and deferred taxes. Sustainability risks must be integrated into the underwriting and investment policies, and into the others where relevant. On operational risk the requirement is brief: clear responsibilities to regularly identify, document and monitor operational risk exposures.
Article 262 details the first element of the ORSA, the overall solvency needs in Article 45(1)(a) of the Directive. That assessment must be forward looking and cover the risks the undertaking is or could be exposed to, including operational risks and changes driven by strategy or the economic environment, together with the nature and quality of the own funds that cover them. How a supervisor reviews that is set out in our guide to what to expect from an ORSA review.
What does internal control have to achieve?
Article 266 is one sentence, and it sets three objectives: compliance with applicable laws and regulations, effective and efficient operations, and available, reliable financial and non-financial information. Article 267 adds controls over valuation: documented policies and procedures for the valuation process, regular verification that market prices and model inputs are appropriate, independent review of the data and assumptions behind the valuation, and oversight by the people who run the undertaking. At the supervisor's request, the undertaking must obtain an external, independent valuation or verification of material assets and liabilities.
What does each key function have to do?
Article 268 applies to every function. Each must sit in the structure so that nothing compromises its objectivity, fairness and independence; each operates under the ultimate responsibility of the AMSB and reports to it. The people performing a function must be able to talk to any staff member on their own initiative, have the authority, resources and expertise they need, and have unrestricted access to relevant information. They must promptly report any major problem to the AMSB.
| Function | Article | What the Delegated Regulation adds |
|---|---|---|
| Risk management | 269 | Five tasks: assist the AMSB in running the risk management system, monitor that system, monitor the overall risk profile, report on risk exposures and advise on strategy, mergers and acquisitions and major projects, and identify emerging and sustainability risks. |
| Compliance | 270 | A compliance policy defining its responsibilities and reporting duties, a compliance plan covering all relevant activities, and an assessment of whether the measures to prevent non-compliance are adequate. |
| Internal audit | 271 | Takes no responsibility for any other function. A risk based audit plan for the coming years, reported to the AMSB; a written report on findings and recommendations at least annually; verification that the AMSB's decisions on them are carried out. |
| Actuarial | 272 | Eight tasks in coordinating technical provisions, an assessment of the IT systems behind the calculation, comparison of past best estimates against experience, set content for its underwriting and reinsurance opinions, and a written report to the AMSB at least annually. |
One change to note on internal audit. Article 271(2) today allows the people carrying out internal audit to perform other key functions when three conditions are met, including that separate staffing would impose disproportionate costs. Delegated Regulation (EU) 2026/269 deletes that paragraph from 30 January 2027. From then on, who may combine roles is governed by the amended Directive, which our Pillar 2 guide explains.
What does a fit and proper assessment have to cover?
Article 273 requires documented policies and adequate procedures ensuring that everyone who effectively runs the undertaking or holds a key function is fit and proper at all times, not only on appointment. Fitness covers professional and formal qualifications, knowledge and relevant experience, weighed against the duties the person holds. For the AMSB, it also covers the diversity of qualifications and experience across members. Propriety covers honesty and financial soundness, based on evidence about character, personal behaviour and business conduct, including criminal, financial and supervisory aspects. In practice that means a file per person that can be refreshed, not a one off letter at appointment.
What must an outsourcing arrangement contain?
Article 274 starts with a written outsourcing policy and requires that contract terms are consistent with Article 49 of the Directive. For critical or important functions, the AMSB must ensure a detailed examination of the provider's ability, capacity and authorisations, that conflicts of interest are handled, that a written agreement exists, that its terms are explained to and authorised by the AMSB, that no law is breached, in particular on data protection, and that the provider is bound by the same confidentiality rules as the undertaking.
Article 274(4) lists twelve things the contract must state, points (a) to (l). The ones most often missing are the provider's duty to disclose developments that affect its ability to perform, a notice period long enough to find an alternative, the right to terminate without detriment to policyholders, effective access to information and on-site inspections for the undertaking, its external auditor and the supervisor, the supervisor's right to put questions directly to the provider, and the terms for sub-outsourcing. Article 274(5) then requires ongoing oversight: the provider's risk management and internal control, its financial resources, the qualification of its staff and its contingency plans. For ICT providers, DORA contract rules sit on top of these.
What does the remuneration policy have to follow?
Article 275 sets principles for the whole policy: aligned with the business and risk strategy and long term interests, no encouragement of risk taking beyond the tolerance limits, specific arrangements for the AMSB, key function holders and other material risk takers, clear governance, an independent remuneration committee where appropriate to the undertaking's size and organisation, and disclosure of the policy to all staff. For variable pay, the fixed component must be high enough to allow a bonus of zero; a substantial portion of variable pay must be deferred for at least three years; performance measurement must include a downward adjustment for risk; termination payments must not reward failure; personal hedging is prohibited; and variable pay for the four key functions must be independent of the units they control.
From 30 January 2027, deferred pay vests no faster than pro rata, up to 100% of variable pay must be subject to malus or clawback on criteria that cover significant losses and loss of fitness and propriety, and deferral does not apply where annual variable pay is EUR 50,000 or less and no more than one third of total annual pay, unless the supervisor decides otherwise.
What the other results get wrong
Most of page one for this query is law firm and supervisor guidance, and it is good on principles. Two gaps recur. The first is age. One briefing on page one is dated January 2013, before the Delegated Regulation was adopted in October 2014, and a law firm chapter from August 2024 predates both Directive (EU) 2025/2 and Delegated Regulation (EU) 2026/269. Neither the malus and clawback rules nor the deletion of the internal audit combination exception can appear in them.
The second is stopping at the Directive. Governance guidance that lists Articles 41 to 49 without the Delegated Regulation tells you that an internal audit function must exist, but not that it needs a multi year audit plan, an annual written report and a record of whether the AMSB's decisions were implemented. It tells you outsourcing must be controlled, but not which twelve clauses the contract must carry. Those records and clauses are what a review asks to see.

Where do you stand?
Fill this in from your own records. Each row is something a supervisor can ask to see.
| Question | Your answer | Article |
|---|---|---|
| When did you last evaluate the adequacy and effectiveness of the whole system of governance? | 258(6), with AMSB composition from 2027 | |
| Is there a business continuity policy, and who approved it? | 258(3) | |
| Does the risk policy cover all eight areas, with sustainability risks in underwriting and investment? | 260(1) and (1a) | |
| Does internal audit have a multi year plan and an annual written report to the AMSB? | 271(3) | |
| Is there a current fit and proper file for each key function holder? | 273 | |
| Do your critical outsourcing contracts carry all twelve clauses? | 274(4) | |
| Is variable pay for material risk takers deferred for at least three years? | 275(2)(c) |
Our Solvency II governance checklist scores 45 items in a spreadsheet. Venvera's Solvency II module covers Pillar 2 only: it holds these controls with owners, status and evidence, and does not calculate capital or produce Pillar 3 reports. A free compliance check gives you a baseline first.

Frequently asked questions
Where are the detailed Solvency II governance requirements?
In Chapter IX of Commission Delegated Regulation (EU) 2015/35, Articles 258 to 275, which supplement Articles 40 to 49 of Directive 2009/138/EC.
How many people must effectively run an insurer?
At least two, under Article 258(4).
Is a remuneration committee mandatory?
Only where appropriate in relation to the undertaking's significance in terms of size and internal organisation, under Article 275(1)(f). The written remuneration policy is mandatory for everyone, under Article 258(1)(l).
How often must internal audit and the actuarial function report?
Both must submit a written report to the AMSB at least annually, under Articles 271(3)(d) and 272(8).
What changes on 30 January 2027?
Delegated Regulation (EU) 2026/269 applies. For governance it adds AMSB composition, diversity and effectiveness to the Article 258(6) evaluation, deletes the Article 271(2) internal audit exception, and adds pro rata vesting, malus and clawback and a EUR 50,000 deferral threshold to Article 275.
Can a supervisor impose capital for weak governance?
Yes. Article 37(1)(c) of the Directive allows a capital add-on where the system of governance deviates significantly from the standards, and Article 277 of the Delegated Regulation lists factors the supervisor must weigh, including the effect on sound and prudent management and the likelihood and severity of harm to policyholders.
Primary sources
Requirements above are taken from Articles 258 to 275 and 277 of Commission Delegated Regulation (EU) 2015/35, read in the consolidated text of 14 November 2024 and the consolidated text applicable from 30 January 2027, from Commission Delegated Regulation (EU) 2026/269, whose Article 2 sets that application date, and from Articles 37, 44 and 49 of Directive 2009/138/EC. Consolidated texts are documentation tools; the Official Journal versions are authentic. Confirm the current text before relying on a specific provision.





