EBA · 2023_6950 Rejected question

Request for Clarification on Article 28(3) of Regulation (EU) 2022/2554

Regulation
Regulation (EU) No 2022/2554 (DORA Reg)
Article
28, para. 3
Topic
ICT risk management
Submitted by
Consultancy firm
Submitted
2023-12-21

Question

I am reaching out for clarification regarding a specific provision in the Digital Operational Resilience Act (DORA) – particularly the third paragraph of Article 28.  The provision in question stipulates: "As part of their ICT risk management framework, financial entities shall maintain, and keep updated at entity level as well as at sub-consolidated and consolidated levels, a register of information related to all contractual arrangements on the use of ICT services provided by third-party ICT service providers."  Similarly, DORA provides in its article 28(2): "The strategy on ICT third-party risk shall include a policy on the use of ICT services supporting critical or important functions provided by ICT third-party service providers and shall apply on an individual basis and, where relevant, on a sub-consolidated and consolidated basis".  Overall, how should we understand the phrases “where relevant” and “where applicable” in DORA and its policy products when addressing different levels of entities?  we seek your confirmation on whether our client is really obligated to maintain both for its specific entity and at the group level:   The register of information related to all contractual arrangements on the use of ICT services provided by third-party ICT service providers.  The strategy on ICT third-party risk and (or?) the policy on the use of ICT services supporting critical or important functions.    Could you also confirm that whenever the phrases "where relevant" and "where applicable" appear in the presence of corporate group, the latter must each time implement the requirement at the level of the entity, at the sub-consolidated level and at the consolidated level?

Background

At Thot-IT Solutions, we are currently advising a client on DORA compliance, specifically focusing on “Chapter V - Managing of ICT third-party risk”. Our client is part of a corporate group comprising two regulated entities. Our consultancy services are engaged with one of these entities, but not with the overarching group entity.
No answer published yet.

Original source: European Banking Authority, Q&A ID 2023_6950

This Q&A is published by European Banking Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.