http://data.europa.eu/eli/reg/2022/2554/oj.

(7) To ensure appropriate reporting to the management body, the policy should clearly specify and identify the internal responsibilities for the approval, management, control and documentation of contractual arrangements on the use of ICT services supporting critical or important functions provided by ICT third-party service providers (‘contractual arrangements’), including the ICT services provided under contractual arrangements referred to in Article 28(1), point (a), of Regulation (EU) 2022/2554.

(8) In order to take into account all possible risks that may arise when contracting ICT services supporting critical or important function, the structure of the policy should follow all the steps of the each main phase of the life cycle for contractual arrangements with third-party providers.

(9) To mitigate the risks identified, the policy should specify the planning of contractual arrangements, including the risk assessment, the due diligence, and the approval process for new or material changes to those contractual arrangements. In order to manage the risks that may arise before entering into a contractual arrangement with an ICT third-party service provider, the policy should specify an appropriate and proportionate process to select and assess the suitability of prospective ICT third-party service providers and require that the financial entity takes into account a non-exhaustive list of elements that the ICT third-party service providers should have in place. The list should include elements related to the business reputation of the service providers, their financial, human and technical resources, their information-security, their organisational structure, including risk management, and their internal controls.

(10) To ensure a sound risk management in the provision of ICT services supporting critical or important functions by ICT third-party service providers, the policy should contain information about the implementation, monitoring and management of the contractual arrangements, including at consolidated and sub-consolidated level, where applicable. This includes requirements for the contractual clauses on mutual obligations of the financial entities and the ICT third-party service providers, which should be set out in writing. In order to ensure an efficient supervision and foster resilience in case of changes in the business model or business environment, the policy should ensure the financial entities’ or appointed third parties’ and competent authorities’ rights to inspections and access to information and should also further specify the exit strategies and termination processes.

(11) To the extent personal data are processed by ICT third-party service providers, this policy and any contractual arrangements are without prejudice to and should complement the obligations under Regulation (EU) 2016/679 of the European Parliament and of the Council (2), such as to have a written contract in place describing the personal data processing, requirement to ensure security of personal data processing and setting out all other elements required under that regulation.

(2) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).

(12) The Joint Committee of the European Supervisory Authorities referred to in Article 54 of Regulation (EU) No 1093/2010 of the European Parliament and of the Council (3), in Article 54 of Regulation (EU) No 1094/2010 of the European Parliament and of the Council (4) and in Article 54 of Regulation (EU) No 1095/2010 of the European Parliament and of the Council (5) has conducted open public consultations on the draft regulatory technical standards on which this Regulation is based, analysed the potential costs and benefits of the proposed standards and requested advice of the Banking Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1093/2010, the Insurance and Reinsurance Stakeholder Group and the Occupational Pensions Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1094/2010, and the Securities and Markets Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1095/2010,

(13) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council (6) and delivered an opinion on 24 January 2024,

HAS ADOPTED THIS REGULATION:

" />
+RTS ICT Third-Party Service Providers
---+RTS ICT Third-Party Service Providers Art. 1 Overall risk profile and complexity
---+RTS ICT Third-Party Service Providers Art. 2 Group application
---+RTS ICT Third-Party Service Providers Art. 3 Governance arrangements
------+RTS ICT Third-Party Service Providers Art. 3, 1
------+RTS ICT Third-Party Service Providers Art. 3, 2
------+RTS ICT Third-Party Service Providers Art. 3, 3
------+RTS ICT Third-Party Service Providers Art. 3, 4
------+RTS ICT Third-Party Service Providers Art. 3, 5
------+RTS ICT Third-Party Service Providers Art. 3, 6
------+RTS ICT Third-Party Service Providers Art. 3, 7
------+RTS ICT Third-Party Service Providers Art. 3, 8
---+RTS ICT Third-Party Service Providers Art. 4 Main phases of the life cycle for the adoption and use of contractual arrangements
---+RTS ICT Third-Party Service Providers Art. 5 Ex-ante risk assessment
------+RTS ICT Third-Party Service Providers Art. 5, 1
------+RTS ICT Third-Party Service Providers Art. 5, 2
------+RTS ICT Third-Party Service Providers Art. 5, 3
---+RTS ICT Third-Party Service Providers Art. 6 Due diligence
------+RTS ICT Third-Party Service Providers Art. 6, 1
------+RTS ICT Third-Party Service Providers Art. 6, 2
------+RTS ICT Third-Party Service Providers Art. 6, 3
------+RTS ICT Third-Party Service Providers Art. 6, 4
---+RTS ICT Third-Party Service Providers Art. 7 Conflicts of interest
------+RTS ICT Third-Party Service Providers Art. 7, 1
------+RTS ICT Third-Party Service Providers Art. 7, 2
---+RTS ICT Third-Party Service Providers Art. 8 Contractual clauses
------+RTS ICT Third-Party Service Providers Art. 8, 1
------+RTS ICT Third-Party Service Providers Art. 8, 2
------+RTS ICT Third-Party Service Providers Art. 8, 3
------+RTS ICT Third-Party Service Providers Art. 8, 4
---+RTS ICT Third-Party Service Providers Art. 9 Monitoring of the contractual arrangements
------+RTS ICT Third-Party Service Providers Art. 9, 1
------+RTS ICT Third-Party Service Providers Art. 9, 2
------+RTS ICT Third-Party Service Providers Art. 9, 3
------+RTS ICT Third-Party Service Providers Art. 9, 4
---+RTS ICT Third-Party Service Providers Art. 10 Exit from and termination of the contractual arrangements
------+RTS ICT Third-Party Service Providers Art. 10, 1
------+RTS ICT Third-Party Service Providers Art. 10, 2
---+RTS ICT Third-Party Service Providers Art. 11 Entry into force

1. Übersicht

RTS ICT Third-Party Service Providers

COMMISSION DELEGATED REGULATION (EU) 2024/1773 

of 13 March 2024

supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the detailed content of the policy regarding contractual arrangements on the use of ICT services supporting critical or important functions provided by ICT third-party service providers

(Text with EEA relevance)

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (1), and in particular Article 28(10), third subparagraph, thereof,

Whereas:

(1) The framework on digital operational resilience for the financial sector established by Regulation (EU) 2022/2554 requires that financial entities set out certain key principles to manage ICT third-party risk, which are of particular importance when financial entities engage with ICT third-party service providers to support their critical or important functions.

(2) Financial entities, as part of their ICT risk management framework, are to adopt, and regularly review, a strategy on ICT third-party risk. In accordance with Article 28(2) of Regulation (EU) 2022/2554, that strategy is to include a policy on the use of ICT services supporting critical or important functions provided by ICT third-party service providers. It is to apply on an individual and, where relevant, on a sub-consolidated and consolidated basis.

(3) Financial entities vary widely in size, structure, and internal organisation and in the nature and complexity of their activities and operations. It is necessary to take into account that diversity while imposing certain fundamental regulatory requirements which are appropriate for all financial entities when developing the policy regarding contractual arrangements on the use of ICT services supporting critical or important functions by ICT third-party providers (‘the policy), and to ensure that those requirements are applied in a manner that is proportionate.

(4) Where financial entities belong to a group, the parent undertaking that is responsible for providing the consolidated or sub-consolidated financial statements for the group should therefore ensure that the policy is applied in a consistent and coherent way within the group.

(5) When applying the policy, ICT intra-group service providers, including those fully or collectively owned by financial entities within the same institutional protection scheme, should be considered as ICT third-party services providers. The risks posed by ICT intra-group service providers may be different but the requirements applicable to them are the same under Regulation (EU) 2022/2554. In a similar way, the policy should apply to subcontractors that provide ICT services supporting critical or important functions or material parts thereof to ICT third-party service providers, where a chain of ICT third-party service providers exists.

(6) The ultimate responsibility of the management body in managing a financial entity’s ICT risk is an overarching principle which is also applicable regarding the use of ICT third-party service providers. This responsibility should be further translated into the continuous engagement of the management body in the control and monitoring of ICT risk management, including in the adoption and review, at least once per year, of the policy.

(1) OJ L 333, 27.12.2022, p. 1, ELI: http://data.europa.eu/eli/reg/2022/2554/oj.

(7) To ensure appropriate reporting to the management body, the policy should clearly specify and identify the internal responsibilities for the approval, management, control and documentation of contractual arrangements on the use of ICT services supporting critical or important functions provided by ICT third-party service providers (‘contractual arrangements’), including the ICT services provided under contractual arrangements referred to in Article 28(1), point (a), of Regulation (EU) 2022/2554.

(8) In order to take into account all possible risks that may arise when contracting ICT services supporting critical or important function, the structure of the policy should follow all the steps of the each main phase of the life cycle for contractual arrangements with third-party providers.

(9) To mitigate the risks identified, the policy should specify the planning of contractual arrangements, including the risk assessment, the due diligence, and the approval process for new or material changes to those contractual arrangements. In order to manage the risks that may arise before entering into a contractual arrangement with an ICT third-party service provider, the policy should specify an appropriate and proportionate process to select and assess the suitability of prospective ICT third-party service providers and require that the financial entity takes into account a non-exhaustive list of elements that the ICT third-party service providers should have in place. The list should include elements related to the business reputation of the service providers, their financial, human and technical resources, their information-security, their organisational structure, including risk management, and their internal controls.

(10) To ensure a sound risk management in the provision of ICT services supporting critical or important functions by ICT third-party service providers, the policy should contain information about the implementation, monitoring and management of the contractual arrangements, including at consolidated and sub-consolidated level, where applicable. This includes requirements for the contractual clauses on mutual obligations of the financial entities and the ICT third-party service providers, which should be set out in writing. In order to ensure an efficient supervision and foster resilience in case of changes in the business model or business environment, the policy should ensure the financial entities’ or appointed third parties’ and competent authorities’ rights to inspections and access to information and should also further specify the exit strategies and termination processes.

(11) To the extent personal data are processed by ICT third-party service providers, this policy and any contractual arrangements are without prejudice to and should complement the obligations under Regulation (EU) 2016/679 of the European Parliament and of the Council (2), such as to have a written contract in place describing the personal data processing, requirement to ensure security of personal data processing and setting out all other elements required under that regulation.

(2) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).

(12) The Joint Committee of the European Supervisory Authorities referred to in Article 54 of Regulation (EU) No 1093/2010 of the European Parliament and of the Council (3), in Article 54 of Regulation (EU) No 1094/2010 of the European Parliament and of the Council (4) and in Article 54 of Regulation (EU) No 1095/2010 of the European Parliament and of the Council (5) has conducted open public consultations on the draft regulatory technical standards on which this Regulation is based, analysed the potential costs and benefits of the proposed standards and requested advice of the Banking Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1093/2010, the Insurance and Reinsurance Stakeholder Group and the Occupational Pensions Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1094/2010, and the Securities and Markets Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1095/2010,

(13) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council (6) and delivered an opinion on 24 January 2024,

HAS ADOPTED THIS REGULATION:

Bezeichnung Regulierung
RTS ICT Third-Party Service Providers Art. 1 Overall risk profile and complexity

The policy on the use of ICT services supporting critical or important functions provided by ICT third-party service providers (the ‘policy’) shall take into account the size and the overall risk profile of the financial entity, and the nature, scale and elements of increased or reduced complexity of its services, activities and operations, including elements relating to:

  • (a) the type of ICT services included in the contractual arrangement on the use of ICT services supporting critical or important functions provided by ICT third-party service providers (the ‘contractual arrangement’) between the financial entity and the ICT third-party service provider;
  • (b) the location of the ICT third-party service provider or the location of its parent company;
  • (c) whether the ICT services supporting critical or important functions are provided by an ICT third-party service provider located within a Member State or in a third country, also considering the location from where the ICT services are provided and the location where the data is processed and stored;
  • (d) the nature of the data shared with the ICT third-party service provider;
  • (e) whether the ICT third-party service provider is part of the same group as the financial entity to which the services are provided;
  • (f) the use of ICT third-party service providers that are authorised, registered or subject to supervision or oversight by a competent authority in a Member State or subject to the oversight framework under Chapter V, Section II, of Regulation (EU) 2022/2554, and the use of ICT third-party service providers that are not;
  • (g) the use of ICT third-party service providers that are authorised, registered or subject to supervision or oversight by a supervisory authority in a third country, and the use of ICT third-party service providers that are not;
  • (h) whether the provision of ICT services supporting critical or important functions are concentrated to a single ICT third-party service provider or a small number of such service providers;
  • (i) the transferability of the ICT services supporting critical or important functions to another ICT third-party service provider, including as a result of technology specificities;
  • (j) the potential impact of disruptions in the provision of the ICT services supporting critical or important functions on the continuity of the financial entity’s activities and on the availability of its services.
RTS ICT Third-Party Service Providers Art. 2 Group application Where this Regulation applies on a sub-consolidated or consolidated basis, the parent undertaking that is responsible for providing the consolidated or sub-consolidated financial statements for the group shall ensure that the policy is implemented consistently in all financial entities that are part of the group and is adequate for the effective application of this Regulation at all relevant levels of the group.
RTS ICT Third-Party Service Providers Art. 3 Governance arrangements Governance arrangements
RTS ICT Third-Party Service Providers Art. 4 Main phases of the life cycle for the adoption and use of contractual arrangements

The policy shall specify the requirements, including the rules, the responsibilities and the processes, for each main phase of the lifecycle of the contractual arrangement, covering at least the following:

  • (a) the responsibilities of the management body, including its involvement, as appropriate, in the decision-making process on the use of ICT services supporting critical or important functions provided by ICT third-party service providers;
  • (b) the planning of contractual arrangements, including the risk assessment, the due diligence as set out in Articles 5 and 6 and the approval process regarding new or material changes to contractual arrangements as set out in Article 8(4);
  • (c) the involvement of business units, internal controls and other relevant units in respect of contractual arrangements;
  • (d) the implementation, monitoring and management of contractual arrangements as referred to in Articles 7, 8 and 9, including at consolidated and sub-consolidated level, where applicable;
  • (e) the documentation and record-keeping, taking into account the requirements with regard to the register of information laid down in Article 28(3) of Regulation (EU) 2022/2554;
  • (f) the exit strategies and termination processes as set out in Article 10.
RTS ICT Third-Party Service Providers Art. 5 Ex-ante risk assessment Ex-ante risk assessment
RTS ICT Third-Party Service Providers Art. 6 Due diligence Due diligence
RTS ICT Third-Party Service Providers Art. 7 Conflicts of interest Conflicts of interest
RTS ICT Third-Party Service Providers Art. 8 Contractual clauses Contractual clauses
RTS ICT Third-Party Service Providers Art. 9 Monitoring of the contractual arrangements Monitoring of the contractual arrangements
RTS ICT Third-Party Service Providers Art. 10 Exit from and termination of the contractual arrangements Exit from and termination of the contractual arrangements
RTS ICT Third-Party Service Providers Art. 11 Entry into force

This Regulation shall enter into force on the twentieth day following its publication in the Official Journal of the European Union.

This Regulation shall be binding in its entirety and directly applicable in all Member States.

Done at Brussels, 13 March 2024.

For the Commission

The President

Ursula VON DER LEYEN

1.1 Referenzen

1.2 Identifizierte Anforderungen

1.3 Related Standards

2. Identifizierte Anforderungen

Anforderungen
Source Anforderung

3. Related Standards

Standards
Source Anforderung
Impressum