This delegated regulation outlines regulatory technical standards under Regulation (EU) 2022/2554 for financial entities subcontracting ICT services that support critical or important functions. It specifies the elements to be assessed in such arrangements, including risk assessments, monitoring obligations, due diligence, and contractual safeguards. The regulation addresses issues of proportionality, group-wide implementation, and termination rights, emphasizing the responsibility of financial entities to manage digital operational risks when using third-party ICT providers and their subcontractors.
Author: European Commissiomn
Status: Adopted / Published
Adoption date: 2025-03-24
Last updated: 08 Aug 2025
Category: Relevant legislation
Subcategory: Delegated Regulation