Home › Academy › Library › Joint Guidelines on oversight cooperation
Synthesis note · Guide

Joint Guidelines on oversight cooperation

European Banking Authority (EBA) · 2024 · Guide · 36 pages · Intermediate

This document presents guidelines on the cooperation between competent supervisory authorities and European supervisory authorities regarding critical ICT service providers. It aims to establish a coherent and effective supervisory framework to monitor the risks associated with these providers. The guidelines will be published after public consultation and will come into effect in January 2025.

General Information

The document is a final report published in July 2024 by the European Banking Authority (EBA) on behalf of the European Supervisory Authorities (ESAs). It is a 36-page guide entitled "Joint Guidelines on oversight cooperation" relating to cooperation and information exchange between the ESAs and competent authorities (CAs) under Regulation (EU) 2022/2554 known as DORA. The scope covers the supervision of third-party ICT service providers designated as critical (CTPPs) in the European financial sector. The document is based on Articles 31 to 44 of DORA and is addressed to the ESAs and competent authorities involved in monitoring risks related to CTPPs, with application planned from 17 January 2025 (p. 1-6).

Executive Summary

The guide addresses the implementation of a harmonized European framework for the supervision of critical third-party ICT service providers (CTPPs) in the financial sector, introduced by the DORA regulation. This framework assigns the ESAs, notably the Lead Overseer (LO), the primary responsibility for supervising CTPPs, while competent authorities (CAs) supervise user financial entities and participate in joint examination teams (JET). Close cooperation and information exchange between ESAs and CAs are essential to ensure a consistent approach, avoid duplication, and guarantee a level playing field for financial entities across Member States. The guidelines define detailed procedures for task allocation, information exchange modalities, deadlines, points of contact, as well as disagreement management. They also specify information to be transmitted for the designation of critical CTPPs, supervision activity planning, recommendation follow-up, and management of binding decisions against financial entities. These guidelines, adopted after public consultation (29 responses received), will be published in multiple languages and come into force on 17 January 2025. They aim to strengthen the digital operational resilience of the financial sector and the stability of the European financial system (p. 2-3, 18-21).

Context and Objectives

The DORA regulation, effective from 16 January 2023 and applicable from 17 January 2025, establishes a European supervisory framework for critical third-party ICT service providers in the financial sector. This framework aims to promote convergence of supervisory practices, strengthen the digital resilience of financial entities, and preserve the stability of the Union's financial system. The main actors are the Lead Overseer (LO), competent authorities (CAs), and other ESAs participating in joint examination teams (JET) and the joint supervisory network. The guide responds to the mandate given to ESAs by Article 32(7) of DORA to define guidelines on cooperation and information exchange between ESAs and CAs, to ensure clear task allocation, effective coordination, and appropriate follow-up of recommendations addressed to CTPPs. The scope excludes cooperation between CAs, between ESAs, with other European authorities, as well as certain specific aspects covered by other technical standards or delegated acts. The objective is to avoid duplication, divergence, and unnecessary burdens for CTPPs and financial entities (p. 4-6).

Summary of Key Points by Theme

1. General principles and cooperation framework:

- The guidelines aim to ensure a coordinated, coherent, and effective approach between ESAs and CAs, with secure information exchange, single points of contact, and communication primarily in English. They emphasize a preventive and risk-based approach, optimizing available human and technical resources (p. 8-10).

- A secure online tool is planned for confidential information exchange, limited to data necessary for supervision (p. 9).

2. Designation of critical providers:

- CAs must promptly transmit to ESAs the complete register of contractual information held by financial entities, as well as any relevant quantitative or qualitative information for assessing provider criticality (p. 10).

- ESAs inform CAs of providers who have requested or obtained critical designation, with details such as legal name, identification code, country of headquarters, and changes in subsidiary management (p. 11-12).

3. Main supervisory activities:

- The Lead Overseer develops an annual inspection plan which is shared with CAs for comments within 30 days. This plan includes activity types, objectives, and approximate schedule (p. 12).

- Before any investigation or inspection, the LO informs CAs of authorized persons involved at least 3 weeks in advance, except in emergencies (p. 12).

- The LO communicates to CAs information requests addressed to CTPPs, major incidents, strategic changes, significant risks, and CTPPs’ statements on supervision plan impact (p. 13).

4. Follow-up of recommendations:

- CAs are responsible for following up on risks identified in recommendations with financial entities, while the LO follows recommendations addressed to CTPPs (p. 13-14).

- The LO must transmit to CAs within 10 days notifications from CTPPs regarding their intention to follow or not the recommendations, remediation plans, and reports on implemented actions (p. 14).

- CAs inform the LO of measures taken towards financial entities, including notifications, warnings, contractual changes, and exit plans (p. 14-15).

5. Binding decisions:

- CAs must inform the LO before notifying a financial entity of a possible decision to suspend or terminate a contract with a CTPP, allowing the LO to assess impact and alert on possible supervisory divergences (p. 15-16).

6. Governance and procedures:

- In case of disagreement between ESAs and CAs, the LO and the joint supervisory network (JON) attempt resolution, then submit the dispute to the Supervisory Forum (OF) for opinion (p. 9).

- Deadlines may be adjusted by the LO in consultation with CAs depending on circumstances (p. 9).

7. Public consultation and feedback:

- 29 responses received, mainly from financial entities and sector associations, with concerns on exchange security, deadlines, and scope of measures. ESAs incorporated adjustments notably on the online tool’s security, role clarification, and removal of certain redundant provisions (p. 21-29).

Main Findings and Lessons Learned

Findings:

- The DORA framework imposes centralized supervision of critical CTPPs with a pivotal role for the Lead Overseer and active involvement of competent authorities (p. 3-6).

- The guidelines specify cooperation and information exchange modalities necessary to avoid duplication and ensure action consistency (p. 8-17).

- A secure tool and single points of contact are required for confidential information exchanges (p. 9).

- CAs must provide ESAs with complete data for the designation of critical CTPPs, and the LO must inform CAs of supervision decisions and plans (p. 10-12).

- Recommendation follow-up is clearly divided: LO for CTPPs, CAs for financial entities, with detailed information exchanges within precise deadlines (p. 13-16).

Assumptions and interpretations:

- Enhanced cooperation is assumed to improve convergence of practices and reduce risks related to critical ICT providers (p. 4-5).

- Flexibility in deadlines and dispute resolution aims to ensure effectiveness without excessive rigidity (p. 9).

Uncertainties:

- Operational implementation of secure tools and management of sensitive information remain to be detailed (p. 22).

- The actual impact on administrative burden for authorities and financial entities will depend on effective coordination and locally adopted practices (p. 18-19).

Conclusions and Author’s Recommendations

The ESAs conclude that implementing these guidelines is essential to ensure effective, coherent, and coordinated supervision of critical third-party ICT service providers in the European financial sector. They recommend:

- Rapid adoption of the guidelines by competent authorities, with compliance notification within two months following their official publication (p. 3, 7).

- Use of a secure tool for confidential information exchange between ESAs and CAs (p. 9).

- Clear communication and single points of contact to facilitate exchanges (p. 9).

- Respect of deadlines set for information transmission and recommendation follow-up (p. 14-16).

- Close coordination between the Lead Overseer and competent authorities, notably before any binding decision against financial entities (p. 15-16).

- Consideration of feedback from the public consultation to improve security and clarity of procedures (p. 21-29).

A periodic review of the guidelines is planned to ensure their adequacy and effectiveness (p. 16).

Key takeaways

References

Year
2024
Type
Guide
Level
Intermediate
Licence
Attribution required
Original document
https://www.eba.europa.eu/sites/default/files/2024-07/e0701aa1-d1a5-4…
Read the original document ← Back to the library

Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.