Recital 73
Digital Operational Resilience Act · UE 2022/2554
| (73) | Contracts for the provision of ICT services supporting critical or important functions should also contain provisions enabling the rights of access, inspection and audit by the financial entity, or an appointed third party, and the right to take copies as crucial instruments in the financial entities’ ongoing monitoring of the ICT third-party service provider’s performance, coupled with the service provider’s full cooperation during inspections. Similarly, the competent authority of the financial entity should have the right, based on notices, to inspect and audit the ICT third-party service provider, subject to the protection of confidential information. |
In Luxembourg, the CSSF is the competent authority that directly exercises the inspection right set out in recital 73 over ICT providers of supervised financial entities. CSSF Circular 22/806 on IT outsourcing, read together with CSSF Regulation 20-04, already requires ICT contracts to contain audit rights extended to the CSSF and its agents, with physical access to the provider's premises and its subcontractors, including those established outside the EU.
Luxgap practice: we map each ICT contract against the dual DORA + Circular 22/806 grid and prepare the compliance addenda ahead of the next SREP cycle or CSSF information request.