Recital 31
Digital Operational Resilience Act · UE 2022/2554
| (31) | Taking into account the potential systemic risk entailed by increased outsourcing practices and by the ICT third-party concentration, and mindful of the insufficiency of national mechanisms in providing financial supervisors with adequate tools to quantify, qualify and redress the consequences of ICT risk occurring at critical ICT third-party service providers, it is necessary to establish an appropriate Oversight Framework allowing for a continuous monitoring of the activities of ICT third-party service providers that are critical ICT third-party service providers to financial entities, while ensuring that the confidentiality and security of customers other than financial entities is preserved. While intra-group provision of ICT services entails specific risks and benefits, it should not be automatically considered less risky than the provision of ICT services by providers outside of a financial group and should therefore be subject to the same regulatory framework. However, when ICT services are provided from within the same financial group, financial entities might have a higher level of control over intra-group providers, which ought to be taken into account in the overall risk assessment. |
In Luxembourg, the CSSF is the competent authority for DORA supervision of financial entities and coordinates with the ESAs on CTPP designation. The law of 1 June 2023 on operational transposition and CSSF circular 22/806 on outsourcing arrangements (updated to align with DORA) remain applicable: the CSSF expects prior notification of critical outsourcing arrangements, including intra-group, and requires a register in the ESAs format. Local specificity: for critical or important functions under circular 22/806, intra-group must be documented with a group outsourcing policy approved by the board of the Luxembourg entity, even when the service is delivered from the parent.
Luxgap practice: for Luxembourg private banks and depositaries depending on a group IT in Zurich, Paris or Frankfurt, we rebuild the intra-group outsourcing matrix with the evidence of effective control (exercised audit rights, joint committees, tested exit plan) expected by the CSSF during on-site inspections.