2024-03-13
Added · Updated
The European Commission adopted Delegated Regulation (EU) 2024/1773 to supplement Regulation (EU) 2022/2554 by establishing regulatory technical standards for financial entities' policies on ICT third-party risk. The regulation mandates that financial entities define detailed content for policies governing contractual arrangements with ICT third-party service providers supporting critical or important functions. It requires specific governance arrangements, including annual management body reviews, ex-ante risk assessments, and due diligence processes for selecting providers. The standards also prescribe requirements for contractual clauses, conflict of interest management, and exit strategies to ensure digital operational resilience.