The report presents regulatory technical standards aimed at harmonizing the conditions for overseeing critical third-party service providers in the financial sector. It outlines the information requirements that these providers must submit to be designated as critical, as well as the assessments by competent authorities. Changes made to the initial draft are based on feedback from a public consultation, and the…
This document is a final report of 48 pages published by the European Banking Authority (EBA) in July 2024. It presents the Draft Regulatory Technical Standards (RTS) related to the harmonization of conditions enabling the conduct of oversight activities of critical third-party ICT service providers in the European financial sector, pursuant to Regulation (EU) 2022/2554 known as DORA. The scope covers the information to be provided by third-party ICT providers in their voluntary designation request as critical, the content, structure, and format of information to be transmitted to the Lead Overseer, as well as the evaluation by competent authorities of measures taken by these providers based on the Lead Overseer's recommendations. The public consultation period ran from December 8, 2023, to March 4, 2024, with 44 responses received (p. 1-6).
The subject concerns the establishment of a harmonized framework for the oversight of critical third-party ICT service providers in the European financial sector, under the DORA regulation. This framework aims to strengthen the digital operational resilience of the financial sector against risks related to critical ICT services. It is important because these providers play a key role in the continuity and security of financial services, and their failure could have systemic impacts. The main findings are:
- The need for complete and harmonized information in voluntary designation requests as critical providers, to allow rapid and accurate assessment by authorities (p. 3-6).
- The development of a detailed set of information that critical providers must supply to the Lead Overseer, covering organizational structure, subcontracting arrangements, security measures, incident management, remediation plans, and audit reports (p. 7-18).
- The importance of rigorous follow-up of recommendations issued by the Lead Overseer, with remediation plans and progress reports submitted by providers (p. 15-16).
- Close cooperation between the Lead Overseer and competent authorities, notably for risk assessment and information sharing, especially when risks are cross-border and affect multiple financial entities (p. 17-18).
The conclusions are that these RTS, adopted as delegated regulation, will enable effective and harmonized oversight of critical providers, contributing to the stability and integrity of the European financial sector. The recommendations are to implement these RTS from January 17, 2025, ensuring the availability of secure tools for information transmission and maintaining constructive dialogue between providers, the Lead Overseer, and competent authorities (p. 3-4, 18).
The document responds to the obligation set by Article 41(1) of the DORA regulation (EU 2022/2554), which mandates the European Supervisory Authorities (ESAs) to develop RTS to harmonize oversight conditions of critical third-party ICT service providers. The challenge is to ensure effective and coordinated supervision of these providers, which are essential to the functioning of the European financial sector. The objectives are:
- to define the information to be provided in the voluntary designation request as a critical provider;
- to specify the content, structure, and format of information to be transmitted to the Lead Overseer, notably regarding subcontractors;
- to set evaluation criteria for measures taken by critical providers following the Lead Overseer's recommendations.
The scope excludes the composition of joint examination teams, which will be subject to a separate RTS. The public consultation gathered stakeholders' views, which were integrated into the final version (p. 5-6).
Voluntary designation request as a critical provider:
- The request must contain detailed information on the legal entity, its group structure, its estimated market share in the European financial sector, precise description of ICT services provided, the list of financial client entities, critical subcontractors used, a self-assessment of substitutability and competitors, as well as strategic and investment plans (p. 10-12).
- The application must be complete; otherwise, it will be rejected and the provider must complete it (p. 12).
Information to be provided to the Lead Overseer:
- Critical providers must provide, upon request, all information necessary for oversight, including contracts with clients and subcontractors, organizational structure, major shareholders, internal governance, IT security and data protection frameworks, data portability mechanisms, data center locations, services provided from third countries, risk management, major incidents, continuity and recovery plans, performance indicators, audits and certifications, remediation plans, staff training, and financial statements related to security and ICT (p. 12-18).
- Information transmission must be via secure electronic channels and in English (p. 16).
- A specific template is provided for describing subcontracting arrangements, adapted to ICT providers' specifics (p. 19-21).
Follow-up of recommendations and cooperation with competent authorities:
- After Lead Overseer recommendations, providers must submit a detailed remediation plan with a timeline, as well as interim and final reports on implementation (p. 15-16).
- Competent authorities assess the impact of measures taken on financial entities under their supervision, using a proportionate and risk-based approach, and share these assessments with the Lead Overseer upon request (p. 17-18).
- Cooperation aims to ensure coherent and effective oversight, especially in case of severe risks affecting multiple Member States (p. 9, 17-18).
Impact and structure of the RTS:
- The RTS are divided into two: the first RTS covers points (a), (b), and (d) of Article 41(1) of DORA, impacting providers and financial entities, and a second RTS addresses point (c) related to joint examination teams (p. 5, 23-24).
- The list of information to be provided is open and adaptable to account for evolving risks and oversight needs (p. 24).
- A remediation plan must include not only completed actions but also those planned and underway (p. 25).
- A specific template is adopted for subcontracting information, distinct from that for financial entities (p. 25).
- Information transmission is via secure channels defined by the Lead Overseer, with flexibility (p. 26).
- Risk assessment by competent authorities is integrated into their supervisory tasks, with sharing of results to the Lead Overseer upon request (p. 27).
Public consultation and adjustments:
- 44 responses received, with requests for clarifications on the scope of information, protection of sensitive data, administrative burden, and definition of terms (p. 32-41).
- Several amendments were integrated, notably the wording "where available" for certain information, removal of elements deemed unnecessary for designation, clarification on the scope of services concerned, securing transmission channels, and detailed definition of information on major shareholders (p. 32-41).
Findings:
- The DORA framework imposes harmonized oversight of critical third-party ICT providers, with precise information and cooperation obligations (p. 1-6).
- The RTS define a comprehensive set of information to be provided, covering structure, services, security, risk management, subcontractors, and remediation plans (p. 7-18).
- Data transmission must be via secure channels and in English (p. 16).
- Competent authorities assess measures taken by providers based on Lead Overseer's recommendations, using a proportionate and risk-based approach (p. 17-18).
Assumptions:
- Information provided by providers is complete and reliable to allow relevant assessment.
- The Lead Overseer and competent authorities have the necessary resources and skills to analyze this information and cooperate effectively.
Interpretations:
- Dividing the RTS into two distinct documents facilitates clarity and adaptation to different audiences (market vs. supervision) (p. 5, 23-24).
- Flexibility in the list of information to be provided allows adapting oversight to technological evolutions and emerging risks (p. 24).
- The requirement for a remediation plan including planned actions improves transparency and continuous monitoring (p. 25).
Uncertainties:
- Providers' capacity to accurately estimate their market share and provide certain sensitive information.
- The actual impact of administrative burden on providers, notably SMEs, and on financial entities.
- Secure management of sensitive data transmitted, although measures are planned (p. 39-40).
The ESAs conclude that the proposed RTS meet the requirements of the DORA regulation to harmonize the oversight of critical third-party ICT service providers in the European financial sector. They recommend:
- Formal adoption of the RTS by the European Commission, followed by their publication and entry into force on January 17, 2025 (p. 3-4, 18).
- Implementation of secure tools for information transmission between providers and the Lead Overseer, ensuring confidentiality and data integrity (p. 39-40).
- Maintaining constructive dialogue with stakeholders to adjust practical implementation modalities.
- Continuing close cooperation between the Lead Overseer and competent authorities to ensure effective follow-up of recommendations and coordinated risk management (p. 17-18).
- Taking into account feedback from the public consultation to clarify requirements and limit unnecessary burdens, while ensuring the quality of information received (p. 32-41).
Synthesis note written from the full document by DataSAI Academy. This note comes from the scientific library of the DataSAI Academy, open to all.