Chapter V – Managing of ICT third-party risk (Art. 28-44)

Art. 28 DORA - General principles arrow_right_alt

Art. 29 DORA - Preliminary assessment of ICT concentration risk at entity level arrow_right_alt

Art. 30 DORA - Key contractual provisions arrow_right_alt

Art. 31 DORA - Designation of critical ICT third-party service providers arrow_right_alt

Art. 32 DORA - Structure of the Oversight Framework arrow_right_alt

Art. 33 DORA - Tasks of the Lead Overseer arrow_right_alt

Art. 34 DORA - Operational coordination between Lead Overseers arrow_right_alt

Art. 35 DORA - Powers of the Lead Overseer arrow_right_alt

Art. 36 DORA - Exercise of the powers of the Lead Overseer outside the Union arrow_right_alt

Art. 37 DORA - Request for information arrow_right_alt

Art. 38 DORA - General investigations arrow_right_alt

Art. 39 DORA - Inspections arrow_right_alt

Art. 40 DORA - Ongoing oversight arrow_right_alt

Art. 41 DORA - Harmonisation of conditions enabling the conduct of the oversight activities arrow_right_alt

Art. 42 DORA - Follow-up by competent authorities arrow_right_alt

Art. 43 DORA - Oversight fees arrow_right_alt

Art. 44 DORA - International cooperation arrow_right_alt

  1. Without prejudice to Article 36, EBA, ESMA and EIOPA may, in accordance with Article 33 of Regulations (EU) No 1093/2010, (EU) No 1095/2010 and (EU) No 1094/2010, respectively, conclude administrative arrangements with third-country regulatory and supervisory authorities to foster international cooperation on ICT third-party risk across different financial sectors, in particular by developing best practices for the review of ICT risk management practices and controls, mitigation measures and incident responses.
  2. The ESAs shall, through the Joint Committee, submit every five years a joint confidential report to the European Parliament, to the Council and to the Commission, summarising the findings of relevant discussions held with the third countries’ authorities referred to in paragraph 1, focusing on the evolution of ICT third-party risk and the implications for financial stability, market integrity, investor protection and the functioning of the internal market.
  • 94

Recital 94

To promote convergence at international level as regards the use of best practices in the review and monitoring of ICT third-party service providers’ digital risk-management, the ESAs should be encouraged to conclude cooperation arrangements with relevant supervisory and regulatory third-country authorities.