EBA · 2024_6991 Rejected question

Grace period for existing contractual arrangements in the register of information

Regulation
Regulation (EU) No 2022/2554 (DORA Reg)
Article
28, para. 3
Topic
ICT third-party risk management
Submitted by
Credit institution
Submitted
2024-01-30

Question

As stated in Regulation (EU) No 2022/2554 (DORA) Article 28, paragraph 3 - As part of their ICT risk management framework, financial entities shall maintain and update at entity level, and at sub-consolidated and consolidated levels, a register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers. Is there a grace period for the existing contractual arrangements, or does all the information have to be collected and recorded in the register of information before the regulatory deadline in January 2025?

Background

This could be relevant to the companies with the large amount of contractual arrangements.
No answer published yet.

Original source: European Banking Authority, Q&A ID 2024_6991

This Q&A is published by European Banking Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.