2024-12-02
Added · Updated
Financial entities must use standardized templates to maintain and update their register of information regarding ICT third-party service providers, covering entity, sub-consolidated, and consolidated levels. The regulation mandates that entities assign a numerical rank to each provider in the supply chain, with direct providers ranked as '1' and subcontractors ranked higher. Entities are required to include specific data on contractual arrangements, service chains, critical functions, and risk assessments using predefined formats and identifiers such as LEI or EUID. These implementing technical standards enter into force on the twentieth day following publication in the Official Journal of the European Union.