|
+RTS ICT third-party service providers ---+RTS ICT third-party service providers Art. 1 Overall risk profile and complexity ------+RTS ICT third-party service providers Art. 1, a ------+RTS ICT third-party service providers Art. 1, b ------+RTS ICT third-party service providers Art. 1, c ------+RTS ICT third-party service providers Art. 1, d ------+RTS ICT third-party service providers Art. 1, e ------+RTS ICT third-party service providers Art. 1, f ------+RTS ICT third-party service providers Art. 1, g ------+RTS ICT third-party service providers Art. 1, h ------+RTS ICT third-party service providers Art. 1, i ------+RTS ICT third-party service providers Art. 1, j ---+RTS ICT third-party service providers Art. 2 Group application ---+RTS ICT third-party service providers Art. 3 Governance arrangements ------+RTS ICT third-party service providers Art. 3, 1 ------+RTS ICT third-party service providers Art. 3, 2 ------+RTS ICT third-party service providers Art. 3, 3 ------+RTS ICT third-party service providers Art. 3, 4 ------+RTS ICT third-party service providers Art. 3, 5 ------+RTS ICT third-party service providers Art. 3, 6 ---------+RTS ICT third-party service providers Art. 3, 6a ---------+RTS ICT third-party service providers Art. 3, 6b ---------+RTS ICT third-party service providers Art. 3, 6c ---------+RTS ICT third-party service providers Art. 3, 6d ------+RTS ICT third-party service providers Art. 3, 7 ------+RTS ICT third-party service providers Art. 3, 8 ---------+RTS ICT third-party service providers Art. 3, 8a ---------+RTS ICT third-party service providers Art. 3, 8b ---------+RTS ICT third-party service providers Art. 3, 8c ---------+RTS ICT third-party service providers Art. 3, 8d ---+RTS ICT third-party service providers Art. 4 Main phases of the life cycle for the adoption and use of contractual arrangements ------+RTS ICT third-party service providers Art. 4, a ------+RTS ICT third-party service providers Art. 4, b ------+RTS ICT third-party service providers Art. 4, c ------+RTS ICT third-party service providers Art. 4, d ------+RTS ICT third-party service providers Art. 4, e ------+RTS ICT third-party service providers Art. 4, f ---+RTS ICT third-party service providers Art. 5 Ex-ante risk assessment ------+RTS ICT third-party service providers Art. 5, 1 ------+RTS ICT third-party service providers Art. 5, 2 ------+RTS ICT third-party service providers Art. 5, 3 ---------+RTS ICT third-party service providers Art. 5, 3a ---------+RTS ICT third-party service providers Art. 5, 3b ---------+RTS ICT third-party service providers Art. 5, 3c ---------+RTS ICT third-party service providers Art. 5, 3d ---------+RTS ICT third-party service providers Art. 5, 3e ---------+RTS ICT third-party service providers Art. 5, 3f ---------+RTS ICT third-party service providers Art. 5, 3g ---------+RTS ICT third-party service providers Art. 5, 3h ---------+RTS ICT third-party service providers Art. 5, 3i ---+RTS ICT third-party service providers Art. 6 Due diligence ------+RTS ICT third-party service providers Art. 6, 1 ---------+RTS ICT third-party service providers Art. 6, 1a ---------+RTS ICT third-party service providers Art. 6, 1b ---------+RTS ICT third-party service providers Art. 6, 1c ---------+RTS ICT third-party service providers Art. 6, 1d ---------+RTS ICT third-party service providers Art. 6, 1e ---------+RTS ICT third-party service providers Art. 6, 1f ------+RTS ICT third-party service providers Art. 6, 2 ------+RTS ICT third-party service providers Art. 6, 3 ---------+RTS ICT third-party service providers Art. 6, 3a ---------+RTS ICT third-party service providers Art. 6, 3b ---------+RTS ICT third-party service providers Art. 6, 3c ---------+RTS ICT third-party service providers Art. 6, 3d ---------+RTS ICT third-party service providers Art. 6, 3e ------+RTS ICT third-party service providers Art. 6, 4 ---+RTS ICT third-party service providers Art. 7 Conflicts of interest ------+RTS ICT third-party service providers Art. 7, 1 ------+RTS ICT third-party service providers Art. 7, 2 ---+RTS ICT third-party service providers Art. 8 Contractual clauses ------+RTS ICT third-party service providers Art. 8, 1 ------+RTS ICT third-party service providers Art. 8, 2 ---------+RTS ICT third-party service providers Art. 8, 2a ---------+RTS ICT third-party service providers Art. 8, 2b ---------+RTS ICT third-party service providers Art. 8, 2c ---------+RTS ICT third-party service providers Art. 8, 2d ------+RTS ICT third-party service providers Art. 8, 3 ---------+RTS ICT third-party service providers Art. 8, 3a ---------+RTS ICT third-party service providers Art. 8, 3b ---------+RTS ICT third-party service providers Art. 8, 3c ---------+RTS ICT third-party service providers Art. 8, 3d ---------+RTS ICT third-party service providers Art. 8, 3e ---------+RTS ICT third-party service providers Art. 8, 3f ---------+RTS ICT third-party service providers Art. 8, 3g ---------+RTS ICT third-party service providers Art. 8, 3h ------+RTS ICT third-party service providers Art. 8, 4 ---+RTS ICT third-party service providers Art. 9 Monitoring of the contractual arrangements ------+RTS ICT third-party service providers Art. 9, 1 ------+RTS ICT third-party service providers Art. 9, 2 ---------+RTS ICT third-party service providers Art. 9, 2a ---------+RTS ICT third-party service providers Art. 9, 2b ---------+RTS ICT third-party service providers Art. 9, 2c ---------+RTS ICT third-party service providers Art. 9, 2d ---------+RTS ICT third-party service providers Art. 9, 2e ------+RTS ICT third-party service providers Art. 9, 3 ------+RTS ICT third-party service providers Art. 9, 4 ---+RTS ICT third-party service providers Art. 11 Entry into force ---+RTS ICT third-party service providers Art. 10 Exit from and termination of the contractual arrangements ------+RTS ICT third-party service providers Art. 10, 1 ---------+RTS ICT third-party service providers Art. 10, 1a ---------+RTS ICT third-party service providers Art. 10, 1b ---------+RTS ICT third-party service providers Art. 10, 1c ------+RTS ICT third-party service providers Art. 10, 2 |
1. OverviewRTS ICT third-party service providersCOMMISSION DELEGATED REGULATION (EU) 2024/1773 of 13 March 2024supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the detailed content of the policy regarding contractual arrangements on the use of ICT services supporting critical or important functions provided by ICT third-party service providers(Text with EEA relevance)THE EUROPEAN COMMISSION,Having regard to the Treaty on the Functioning of the European Union,Having regard to Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (1), and in particular Article 28(10), third subparagraph,thereof,Whereas:(1) The framework on digital operational resilience for the financial sector established by Regulation (EU) 2022/2554 requires that financial entities set out certain key principles to manage ICT third(1) OJ L 333, 27.12.2022, p. 1, ELI: http://data.europa.eu/eli/reg/2022/2554/oj.ELI: http://data.europa.eu/eli/reg_del/2024/1773/ojOJ L, 25.6.2024(7) To ensure appropriate reporting to the management body, the policy should clearly specify and identify the internal responsibilities for the approval, management, control and documentation of contractual arrangements on the use of ICT services supporting critical or important functions provided by ICT third-party service providers (‘contractual arrangements’), including the ICT services provided under contractual arrangements referred to in Article 28(1), point (a), of Regulation (EU) 2022/2554.(8) In order to take into account all possible risks that may arise when contracting ICT services supporting critical or important function, the structure of the policy should follow all the steps of the each main phase of the life cycle for contractual arrangements with third-party providers.(9) To mitigate the risks identified, the policy should specify the planning of contractual arrangements, including the risk assessment, the due diligence, and the approval process for new or material changes to those contractual arrangements. In order to manage the risks that may arise before entering into a contractual arrangement with an ICT third (2) Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).2/9 ELI: http://data.europa.eu/eli/reg_del/2024/1773/oj OJ L, 25.6.2024(12) The Joint Committee of the European Supervisory Authorities referred to in Article 54 of Regulation (EU) No 1093/2010 of the European Parliament and of the Council (3), in Article 54 of Regulation (EU) No 1094/2010 of the European Parliament and of the Council (4) and in Article 54 of Regulation (EU) No 1095/2010 of the European Parliament and of the Council (5) has conducted open public consultations on the draft regulatory technical standards on which this Regulation is based, analysed the potential costs and benefits of the proposed standards and requested advice of the Banking Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1093/2010, the Insurance and Reinsurance Stakeholder Group and the Occupational Pensions Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1094/2010, and the Securities and Markets Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1095/2010,(13) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation(EU) 2018/1725 of the European Parliament and of the Council (6) and delivered an opinion on 24 January 2024,HAS ADOPTED THIS REGULATION:
1.1 References1.2 Identified Requirements1.3 Related Standards2. Identified Requirements
3. Related Standards
|