{
  "node_id": "eu-dora-rts-ict-third-party-policy-2024-1773",
  "title": "Commission Delegated Regulation (EU) 2024/1773 - Regulatory Technical Standards on the Detailed Content of the Policy Regarding Contractual Arrangements on the Use of ICT Services Supporting Critical or Important Functions Provided by ICT Third-Party Service Providers (DORA Level 2 RTS, Article 28(10))",
  "domain": "Banking & Global Finance",
  "version": "1.0.0",
  "last_updated": "2024-06-25",
  "bluf": "Commission Delegated Regulation (EU) 2024/1773 of 13 March 2024 supplements DORA (Regulation (EU) 2022/2554) by setting out regulatory technical standards on the detailed content of the policy that financial entities must adopt regarding contractual arrangements on the use of ICT services supporting critical or important functions provided by ICT third-party service providers. Adopted under DORA Article 28(10) third subparagraph and published in the Official Journal on 25 June 2024 (entering into force 20 days after publication), the RTS treats ICT intra-group service providers and subcontractors that provide material parts of critical or important functions as ICT third-party service providers (Recital 5). The RTS requires financial entities to: tailor the policy to entity size, risk profile, and complexity using ten enumerated factors (Article 1: type of ICT service, provider location, third-country status, data nature, group affiliation, EU/third-country authorisation, oversight framework status, concentration, transferability, business continuity impact); apply the policy consistently across groups (Article 2); establish governance with at-least-annual management body review (Article 3(1)) and an identified senior management role for contractual oversight (Article 3(5)); cover six lifecycle phases (Article 4: management body responsibilities, planning, business unit involvement, implementation/monitoring, documentation/record-keeping, exit); conduct an ex-ante risk assessment covering nine specific risk categories (Article 5: operational, legal, ICT, reputational, data protection, data availability, data location, provider location, ICT concentration); perform due diligence on six assessment criteria (Article 6); identify and manage conflicts of interest (Article 7); include the elements of DORA Article 30(2) and (3) plus audit and inspection rights in contractual clauses (Article 8); monitor performance via KPIs/KCIs and incident notification (Article 9); and maintain a documented, periodically tested exit plan covering unforeseen interruptions, failed delivery, and unexpected termination (Article 10).",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "dora_level_1",
      "gdpr",
      "dora_ict_risk_framework",
      "esma_eba_eiopa_consultation"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "eu-dora-articles-28-44-third-party-ict-risk",
    "gdpr-article-5-data-principles"
  ],
  "primary_citations_count": 9
}