Recital 62

Recital 62

Digital Operational Resilience Act · UE 2022/2554

(62)

To ensure a sound monitoring of ICT third-party risk in the financial sector, it is necessary to lay down a set of principle-based rules to guide financial entities’ when monitoring risk arising in the context of functions outsourced to ICT third-party service providers, particularly for ICT services supporting critical or important functions, as well as more generally in the context of all ICT third-party dependencies.

Luxembourg specificity
Circulaire CSSF 22/806 relative aux arrangements d'externalisation, telle que modifiee, lue en combinaison avec le reglement (UE) 2022/2554 (DORA)

In Luxembourg, the CSSF is the DORA competent authority for most financial entities (banks, PFS, investment firms, EMIs, payment institutions, UCITS, AIFMs), while the CAA supervises insurance and reinsurance undertakings. CSSF Circular 22/806 on outsourcing arrangements (as amended) remains applicable alongside DORA and requires prior notification to the CSSF for any outsourcing of a critical or important function.

Luxgap practice: we configure the ICT Dependency Radar register with both schemas in parallel (DORA ITS template + CSSF Circular 22/806 grid) to produce in one click the two deliverables required by the CSSF, and we embed the prior notification procedure directly into the supplier onboarding workflow.