Taiwan’s Financial Supervisory Commission released its main inspection findings for the first half of 2026 on Sept. 29, covering 10 business categories including financial holding companies and domestic banks. A key issue involved mortgage-related life insurance. After reviewing recorded conversations, the regulator found that some banks did not clearly tell borrowers that buying mortgage life insurance was optional. In some cases, sales staff used the pitch that 「利率可以談低一點」 to persuade customers to take the policy.
Mortgage life insurance cannot be required for loan approval
The FSC said some banks handling home loans failed to make it clear that borrowers could decide for themselves whether to add mortgage life insurance. That left some customers with the impression that a loan would not be approved unless they bought the policy. Kuo Wen-lung, deputy director-general of the FSC’s Examination Bureau, said inspectors found the issue by sampling recorded conversations between bank staff and customers. He said the problem lay in unclear explanations during the sales process, which led to misunderstanding.
Chang Chia-kuei, deputy director-general of the Banking Bureau, said mortgage life insurance is not a product that must be purchased under existing regulations. Banks cannot force customers to buy it as part of a package, and cannot treat it as a precondition for approving a mortgage. After receiving the inspection report, the Banking Bureau will ask the banks involved to explain these scattered cases. Whether penalties are imposed will depend on the banks’ follow-up review and corrective action.
Five deficiencies listed in anti-fraud and AML controls
In the area of fraud prevention, anti-money laundering, counter-terrorist financing, and counter-proliferation financing, the FSC listed five deficiencies.
- Account opening reviews: When a customer moved from a preparatory office to a formally established company, some banks did not conduct a fresh review. They missed multiple abnormal traits for shell-company account openings that had been identified by the National Police Agency. Shortly after the accounts were opened, they were repeatedly flagged by the 165 joint defense mechanism.
- Virtual accounts: Some customers were repeatedly reported as flagged accounts after using virtual account services, and collection amounts rose sharply, but financial institutions did not conduct deeper reviews or verify customer identity before providing the service.
- E-payments: Some institutions did not promptly pass on information about flagged e-payment accounts reported by police to the Joint Credit Information Center.
- Third-party handling: Remittance transactions were often handled by third parties, yet institutions failed to keep records proving the agency relationship.
- Abnormal corporate transactions: Corporate clients repeatedly triggered suspicious money laundering alerts, and their fund flows did not resemble normal business operations, but institutions still failed to investigate whether the claimed business dealings were genuine.
Kuo said banks should conduct real checks at the account-opening stage and reject applications when there are signs of shell entities or fake businesses. He also said transaction monitoring must continue after a customer starts using virtual account services. The FSC has required firms to notify the Joint Credit Information Center immediately after receiving reports on flagged e-payment accounts, so that other financial institutions can see the information at the same time.
Misappropriation controls and fund sales were also cited
The FSC said matching communication data between both sides is an important way to prevent relationship managers or sales staff from misappropriating client funds. Some institutions, however, had not set up an effective mechanism to detect whether a customer’s contact address matched that of a relationship manager, salesperson, or solicitation channel.
In fund sales, some firms failed to disclose required information or risk warnings in advertisements, or did not prepare simplified fund prospectuses in line with the rules. The regulator also found cases in which institutions accepted orders from non-professional investors to buy total loss-absorbing capacity, or TLAC, bonds, or recommended trades in specific securities to clients who had not signed recommendation agreements.
The FSC said fund advertisements should present both potential returns and risks. For entrusted trading of foreign securities, institutions must first explain the possible risks to clients, sign recommendation agreements, and then recommend suitable products.
Related-party reporting and transaction checks exposed internal control gaps
The regulator listed three internal management deficiencies. In one, directors failed to file declarations properly, leaving related-party information unregistered. In another, institutions handling non-credit transactions did not check in advance whether counterparties were related parties and did not keep supporting records. In a third, institutions reviewing whether credit terms granted to related parties were more favorable than those given to comparable clients failed to use credit customers from the most recent one-year period as required.
The FSC said financial institutions should fully declare and register related-party information, check that information before extending credit or carrying out transactions, and keep records of those checks. Credit terms offered to related parties must also be compared with those of similar counterparties under the rules.
Cybersecurity findings ranged from websites to servers and mobile apps
The FSC also listed four cybersecurity deficiencies, covering public-facing websites, server permissions, asset and log management, and mobile applications.
- Websites: Improperly configured security headers, or the use of insecure third-party libraries on external websites without evaluation and remediation.
- Servers: Failure to set security hardening standards and review them regularly; privileged accounts were not centralized and reclaimed, and there were no proper pre-approval or post-check mechanisms. Some servers were not even included in permission reviews.
- Assets and logs: Incomplete asset inventories, with operating system and network equipment logs and audit trails not centrally managed, and no suitable alert indicators configured.
- Mobile apps: Inadequate permission reviews, incomplete basic security testing, no source and integrity verification for software delivery, parameter settings that allowed plaintext transmission of data, failure to scan or test embedded security software supplied by vendors, or unresolved medium- to high-risk vulnerabilities.
Kuo said financial institutions should establish system security hardening standards, bring privileged accounts under control, and carry out permission reviews in full. Before app updates are released, institutions must complete security testing and remediate vulnerabilities.
Why the FSC publishes inspection findings on a regular basis
The FSC said the purpose of regularly publishing major inspection deficiencies and suggested corrective measures is to help firms understand supervisory priorities, adjust operating procedures on their own, or build control mechanisms that improve governance while also taking financial market development into account.
As for why virtual asset businesses and insurance broker and agent sectors were not included in this release, Kuo said those two categories are not part of the routine semiannual disclosure process. They will be disclosed separately through project-based inspections from time to time.

