This document outlines the regulatory technical standards regarding the composition of the joint examination team for ICT service providers designated as critical. It specifies the information to be provided by these providers when applying for designation and the criteria for forming the examination team. A public consultation allowed for amendments to the draft standards before submission to the European…
This document is the final report and draft regulatory technical standards (RTS) developed by the European Supervisory Authorities (ESAs) in July 2024. It concerns the specification of criteria to determine the composition of joint review teams under the European regulation DORA (Regulation (EU) 2022/2554) relating to digital operational resilience in the financial sector. The scope covers the criteria for composition, designation, tasks, and working methods of joint review teams involving the ESAs and national competent authorities, within the framework of supervising critical third-party ICT service providers (CTPPs) for the financial sector. The 21-page document fits within the 2023-2025 period, with RTS application planned for 17 January 2025 (p. 1-6).
The document addresses the development of a draft regulatory technical standard (RTS) aiming to harmonize conditions enabling supervision activities of critical third-party ICT service providers (CTPPs) in the financial sector, in accordance with the DORA regulation (EU 2022/2554). This topic is crucial as it establishes a common European framework to ensure the digital resilience of the financial sector against risks related to critical ICT providers. The main findings are: (i) the need for structured and continuous cooperation between the ESAs and national authorities via joint review teams and a Supervisory Forum; (ii) the technical complexity and scarcity of expertise required for these supervision activities; (iii) the need to ensure a balanced composition of joint review teams, including members from the ESAs and competent authorities, with technical and operational risk management skills; (iv) the possibility for a joint review team to supervise multiple CTPPs to optimize resources. The conclusions emphasize that the RTS draft precisely defines the criteria for composition, designation, tasks, and working methods of joint teams, considering risk profile, geographic distribution, size and number of financial entities involved, as well as available skills. Recommendations include adopting a two-RTS approach (this one for joint teams, another for CTPP information), adopting flexibility allowing one review team to cover multiple CTPPs, and ensuring confidentiality, training, and ethics of members. The draft will be submitted to the European Commission for adoption, with entry into force planned for 17 January 2025 (p. 3-5, 14-17).
The DORA regulation establishes a European framework for digital operational resilience in the financial sector, including supervision of critical third-party ICT service providers (CTPPs). Article 41(1) of the regulation mandates the ESAs to develop regulatory technical standards harmonizing supervision conditions, notably the composition of joint review teams (Article 41(1)(c)). The document responds to this mandate by specifying criteria for composition, designation, tasks, and working methods of joint teams composed of members from the ESAs and national competent authorities. The scope is limited to the part of the mandate related to joint review teams, distinct from other aspects related to CTPP information. Challenges include the technical complexity of supervision activities, the need for effective cooperation between European and national authorities, and optimal management of qualified human resources. The document aims to ensure effectiveness, balance, and flexibility in team composition while ensuring confidentiality and regulatory compliance (p. 5-7).
- Composition and designation of joint review teams: The Lead Overseer, in agreement with the joint supervisory network, establishes the teams after designation of critical CTPPs. Members are appointed by competent authorities identified in Article 40(2) of DORA, with technical expertise in ICT, operational risk management, and communication and supervisory skills. The Lead Overseer may request modification of appointments if profiles do not match needs. Composition considers the number of CTPPs, risk profile, geographic distribution, size and number of financial entities involved, as well as proportionate sector representation (p. 7-12).
- Members' tasks: Under the coordination of the Lead Overseer, members assist in preparing and executing annual supervision plans, assessing CTPPs, collecting and analyzing information, conducting investigations and inspections, drafting recommendations, evaluating remediation plans, preparing decisions, contributing to transversal activities, sharing relevant information, and managing unplanned ad hoc activities (p. 9-10).
- Working methods: Members must act with competence, diligence, impartiality, and according to the Lead Overseer's instructions. They must respect common supervision procedures, confidentiality and data management rules, and follow arrangements defining time commitment, costs, training, and ethical considerations. Members remain employed by their appointing authority, under their usual working conditions (p. 12-13).
- Organizational flexibility: A joint review team may supervise multiple CTPPs, optimizing the use of scarce and technical resources. The Lead Overseer adapts team composition based on material changes affecting CTPPs or supervision plans (p. 8, 11-12).
- Access to information and confidentiality: Access to necessary information is granted to members on a need-to-know basis and within assigned tasks. Compliance with professional secrecy and security obligations is mandatory, in accordance with DORA and ESAs rules (p. 8, 20).
- Economic impact: Costs related to authorities' contributions to teams are covered by fees charged to CTPPs under Article 43 of DORA. The proposed structure aims to minimize organizational and financial impacts while ensuring supervision effectiveness (p. 14-17).
- Consultation and adjustments: The ESAs conducted a public consultation in April-May 2024, incorporating feedback to clarify certain points, notably access to information, task definitions, flexibility in team composition, and confidentiality (p. 18-21).
- Established facts: The DORA framework requires the creation of joint review teams composed of members from the ESAs and national authorities to supervise critical CTPPs. The RTS draft specifies criteria for composition, tasks, and working methods, with application planned for 17 January 2025. The public consultation confirmed the relevance of provisions and led to targeted clarifications.
- Assumptions: Flexibility in team composition, notably the possibility for one team to supervise multiple CTPPs, is assumed to optimize the use of scarce technical resources. Financial impact for authorities is offset by fees charged to CTPPs.
- Interpretations: The division of the Article 41(1) mandate into two distinct RTS responds to the difference in impact between requirements affecting the market and those affecting only the supervisory community. Stability and knowledge retention within teams are considered essential for supervision effectiveness.
- Uncertainties: Authorities' capacity to continuously provide qualified experts remains a challenge, although RTS foresee justification in case of temporary lack of expertise. Evolution of CTPPs and associated risks may require frequent team adjustments, which must be balanced with member stability.
The ESAs recommend adopting the RTS draft defining criteria for composition, designation, tasks, and working methods of joint review teams for supervising critical CTPPs. They advocate a flexible approach allowing one review team to supervise multiple CTPPs to optimize available technical resources. Implementation must guarantee confidentiality, continuous training, and ethics of members. The ESAs emphasize the importance of close cooperation between the ESAs and national authorities via the Supervisory Forum and joint teams. The draft will be submitted to the European Commission for adoption, with entry into force planned for 17 January 2025. The ESAs will continue to periodically assess team composition and effectiveness to ensure their adequacy for supervision needs (p. 3-5, 12-13, 14-17, 18-21).
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.