Skip to Primary Navigation

EU DORA RTS – third party contractual arrangements – Art 1

Outlines the complexity and risk considerations that need to be taken under consideration in a written policy covering services supporting the financial institution's critical or important functions that are provided by third parties.

Rule Overview

Jurisdiction: European Union

Regulator: ESMA

Topic: Resilience, Business Continuity

EUR-Lex (EU) 2024/1773
Overview
Rules in This Collection
Notable
Latest News
Further Reading

Complexity and risk considerations include:

  • Type of service
  • Location of third party (or parent)
  • Nature of shared data
  • Data processing and storage location
  • Intra-group or independent service provision
  • Impact of risks / disruptions on continuity / availability of services

Article 1 distinguishes between third-service providers located within an EU member state  and those located in a third country (Art 1(c)). As well as those providers who are authorised and supervised by a competent authority in an EU member state and those that are not (Art 1(f)).

A practical way of approaching this foundational article is to:

Differentiate between third parties that are:

  • Authorised by EU country Authorised by third country
  • Located in EU country Located in third country

  • Subject to supervision or oversight
  • Not subject to supervision or oversight

  • Intra-group
  • Outside of the group

And two key questions to ask in connection with the location:

  • Where are the services actually provided from?
  • What is the location where data is actually processed and stored?
Notable

Latest News

View More News