2024-03-13

Added · Updated

Commission Delegated Regulation (EU) 2024/1773 on ICT third-party risk policy standards

The European Commission adopted Delegated Regulation (EU) 2024/1773 to supplement Regulation (EU) 2022/2554 by establishing regulatory technical standards for financial entities' policies on ICT third-party risk. The regulation mandates that financial entities define detailed content for policies governing contractual arrangements with ICT third-party service providers supporting critical or important functions. It requires specific governance arrangements, including annual management body reviews, ex-ante risk assessments, and due diligence processes for selecting providers. The standards also prescribe requirements for contractual clauses, conflict of interest management, and exit strategies to ensure digital operational resilience.

European Commission logo

European Union

European Commission

Scan of the document's first page
Share

Get EC alerts — same-day email on every new publication.

Read the rest free, and get an email when EC publishes again

Lineage: In force

amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: European Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from EC

We email you every new EC publication the day it's published.

Topics