EIOPA · 2984 - DORA045
ICT third-party risk management (DORA)
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- 3
- Topic
- ICT third-party risk management (DORA)
- Submitted
- 2024-02-14
- Answered
- 2024-11-28
Question
When it comes to specific requirements concerning the ICT-Third-Party Riskmanagement under DORA, reference is regularly made to (core) business activities, e.g. Art. 28 I lit. a. The definition of ICT Services (Art. 3 No. 21) however, is broad, as emphasized in recitals 35 and 63. In the light of DORA objectives, is DORA to be interpreted to the effect that only those ICT Services are included that are related to the core business activities of the financial undertaking and can therefore have a significant impact on the operational business in the event of a failure?
Answer
This question has been rejected because it seeks confirmation of a requirement already clearly set out in the regulation.
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.