ESMA · ESMA_QA_2456 Question Rejected
Clarification on DORA Compliance for Intra-Group providers
- Regulation
- Regulation (EU) 2022/2554 - The Digital Operational Resilience Act (DORA)
- Topic
- ICT third-party risk management
- Submitted
- 2025-03-07
Question
Can you confirm our understanding of the DORA law: an intra-group entity providing services to a financial entity is subject to the same obligations as a non-critical third-party provider. This includes requirements related to contractual arrangements, provisions for critical functions, exit strategies and termination conditions, information registry, reporting to competent authorities, and pre-contractual assessments. Additionally, if the services involve critical or important functions, further requirements apply, such as TLPT tests and audits by competent authorities.
No answer published yet.
This Q&A is published by European Securities and Markets Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.