What Commission Delegated Regulation (EU) 2024/1773 - Regulatory Technical Standards on the Detailed Content of the Policy Regarding Contractual Arrangements on the Use of ICT Services Supporting Critical or Important Functions Provided by ICT Third-Party Service Providers (DORA Level 2 RTS, Article 28(10)) requires
Commission Delegated Regulation (EU) 2024/1773 of 13 March 2024 supplements DORA (Regulation (EU) 2022/2554) by setting out regulatory technical standards on the detailed content of the policy that financial entities must adopt regarding contractual arrangements on the use of ICT services supporting critical or important functions provided by ICT third-party service providers. Adopted under DORA Article 28(10) third subparagraph and published in the Official Journal on 25 June 2024 (entering into force 20 days after publication), the RTS treats ICT intra-group service providers and subcontractors that provide material parts of critical or important functions as ICT third-party service providers (Recital 5). The RTS requires financial entities to: tailor the policy to entity size, risk profile, and complexity using ten enumerated factors (Article 1: type of ICT service, provider location, third-country status, data nature, group affiliation, EU/third-country authorisation, oversight framework status, concentration, transferability, business continuity impact); apply the policy consistently across groups (Article 2); establish governance with at-least-annual management body review (Article 3(1)) and an identified senior management role for contractual oversight (Article 3(5)); cover six lifecycle phases (Article 4: management body responsibilities, planning, business unit involvement, implementation/monitoring, documentation/record-keeping, exit); conduct an ex-ante risk assessment covering nine specific risk categories (Article 5: operational, legal, ICT, reputational, data protection, data availability, data location, provider location, ICT concentration); perform due diligence on six assessment criteria (Article 6); identify and manage conflicts of interest (Article 7); include the elements of DORA Article 30(2) and (3) plus audit and inspection rights in contractual clauses (Article 8); monitor performance via KPIs/KCIs and incident notification (Article 9); and maintain a documented, periodically tested exit plan covering unforeseen interruptions, failed delivery, and unexpected termination (Article 10).
Pillar: Banking & Global Finance · Authority: European Commission (delegated regulation under DORA Article 28(10), based on draft RTS by the Joint Committee of the European Supervisory Authorities - EBA, EIOPA, ESMA) · Version: 1.0.0 · Last updated:
Primary source: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32024R1773
SHA-256 integrity: 176f3130b0720bd1b6ab50684195ad446a622faf789ee3e1b1ee327c93ce79db
Primary Citations — 9 traced to source
- Commission Delegated Regulation (EU) 2024/1773 of 13 March 2024, Article 1: Overall risk profile and complexity - ten enumerated factors (a) type of ICT services, (b) provider location, (c) Member-State vs third-country provision, (d) nature of data, (e) intra-group status, (f) EU competent-authority authorisation/oversight, (g) third-country supervisory authority status, (h) concentration to single or few providers, (i) transferability, (j) impact of disruptions on continuity
- Commission Delegated Regulation (EU) 2024/1773, Article 3 Governance arrangements: management body shall review the policy at least once a year (Art 3(1)); methodology for classifying ICT services supporting critical or important functions (Art 3(2)); internal responsibilities assigned (Art 3(3)); senior management role identified (Art 3(5)); consistency with DORA Articles 6, 9(4), 11 and 19 required (Art 3(6))
+ 7 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/eu-dora-rts-ict-third-party-policy-2024-1773.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/eu-dora-rts-ict-third-party-policy-2024-1773.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/eu-dora-rts-ict-third-party-policy-2024-1773
- Back to registry: Browse all 10,090 compliance nodes