-
European Commission rejects draft technical standards on sub-contracting ICT services under Digital Operational Resilience Act
31 January 2025The European Commission has published a letter (dated 21 January 2025) addressed to the Joint Committee of the European Supervisory Authorities (ESAs) rejecting certain draft regulatory technical standards (RTS) the ESAs submitted under the Digital Operational Resilience Act in July 2024. The draft RTS specified the elements which a financial entity should determine when subcontracting ICT services supporting critical or important functions. These include the overall risk profile of the financial entity and its services and operations, the need for due diligence processes and a risk assessment of service providers, and the need for a description of the services and the conditions under which they would be provided. The Commission rejected the draft RTS on the grounds that proposed Article 5, on subcontracting in relation to the chain of ICT subcontractors for critical or important functions, went beyond the scope of the mandate granted to the ESAs under DORA, because it introduced requirements not specifically linked to the conditions for subcontracting. The Commission has also proposed certain non-substantive drafting amendments to the draft RTS. The Commission intends to adopt the RTS once these modifications have been made by the ESAs.
Return to main website.
Financial Regulatory Developments Focus