2024-11-06
Added · Updated
Financial entities must acquire and maintain a Legal Entity Identifier (LEI) by 17 January 2025 to report on arrangements with ICT Third-Party Service Providers in the Register of Information. They must also ensure their corporate profile in the LH portal is updated with the LEI code. This requirement supports the standard template established by the Implementing Technical Standard for the Register of Information.
Circular Triq l-Imdina, Zone 1 Central Business District, Birkirkara CBD 1010 +356 2144 1155 communications@mfsa.mt www.mfsa.mt Regulation (EU) 2022/2554 on Digital Operational Resilience for the Financial Sector – Legal Entity Identifier (‘LEI’) for Register of Information Reporting This circular is an update to Circular titled Regulation (EU) 2022/2554 and Amending Directive (EU) 2022/2556 on Digital Operational Resilience for the Financial Sector published on the EU Official Journal published by the Authority in January 2023. As detailed by the latter circular, Regulation (EU) 2022/2554 (“the Regulation”) is to be supplemented by, inter alia, a series of Technical Standards and Guidelines. Once the DORA Regulation becomes applicable (17 January 2025), pursuant to Article 28(3), financial entities shall maintain a Register of Information (‘RoI’) with information on all of their arrangements with ICT Third-Party Service Providers (‘ICT TPPs’) and upon request, make the full RoI available or, as requested, specific sections, along with any information deemed necessary to the competent authority. According to Article 28(9) of the DORA Regulation, the RoI is to be supplemented by an Implementing Technical Standard (the ‘ITS’) that establishes a standard template. The latest draft version of such standard template can be found in the Final Report on Draft Implementing Technical Standards on the standard templates for the purposes of the register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers under Article 28(9) of Regulation (EU) 2022/2554 (note that the ITS is not yet in its final version and is subject to change). For the purpose of the RoI reporting using the standard template established by the ITS, financial entities must acquire and maintain a Legal Entity Identified (LEI) by the date of applicability of the DORA Regulation (17 January 2025). Financial entities should also ensure that their corporate profile within the LH portal is kept updated with the financial entity’s LEI code. Authorised Persons may request further information by sending an email to the Supervisory ICT Risk and Cybersecurity function on sirc@mfsa.mt. 06 November 2024
More like this from MFSA
MFSA published 5 documents in the last 30 days. We email you each new one the day it's published.