EIOPA · 2752
ICT third-party risk management (DORA)
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- 30
- Topic
- ICT third-party risk management (DORA)
- Submitted
- 2023-08-07
- Answered
- 2024-03-14
Question
Is our understanding correct that this provision allows to include an obligation on the financial entity to provide details on the scope, procedures to be followed and the frequency of such inspections and audits, but that it does not constitute a requirement to include such an obligation?
Background
Art. 30 para 3(e)(i) requires an unrestricted right of access, inspection and audit. An obligation to provide details on the scope, procedures to be followed and frequency of such inspections and audits could be seen as restrictions counter to the requirement of unrestricted access. However, if unrestricted access is provided without any obligation to provide details, it would lessen the financial entity’s position to be forced to include such an obligation.
Answer
This question has been rejected because the issue it seeks confirmation of a requirement already clearly set out in the regulation.
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.