Recital 88

Recital 88

Digital Operational Resilience Act · UE 2022/2554

(88)

Lead Overseers should be granted the necessary powers to conduct investigations, to carry out onsite and offsite inspections at the premises and locations of critical ICT third-party service providers and to obtain complete and updated information. Those powers should enable the Lead Overseer to acquire real insight into the type, dimension and impact of the ICT third-party risk posed to financial entities and ultimately to the Union’s financial system. Entrusting the ESAs with the lead oversight role is a prerequisite for understanding and addressing the systemic dimension of ICT risk in finance. The impact of critical ICT third-party service providers on the Union financial sector and the potential issues caused by the ICT concentration risk entailed call for taking a collective approach at Union level. The simultaneous carrying out of multiple audits and access rights, performed separately by numerous competent authorities, with little or no coordination among them, would prevent financial supervisors from obtaining a complete and comprehensive overview of ICT third-party risk in the Union, while also creating redundancy, burden and complexity for critical ICT third-party service providers if they were subject to numerous monitoring and inspection requests.

Luxembourg specificity
loi luxembourgeoise du 1er juin 2023 relative aux contrats sur les services financiers, circulaires CSSF 22/806 et 24/856

In Luxembourg, the CSSF remains the national competent authority for DORA supervision of financial entities established on the territory, but it acts in close coordination with the Lead Overseer designated by the ESAs for critical ICT third-party providers. The law of 1 June 2023 on financial services contracts and CSSF circulars 22/806 (outsourcing) and 24/856 (DORA) specify that supervised entities must embed in their contracts the inspection rights extended to the European Lead Overseer, and notify the CSSF of any announced inspection of a critical provider.

Luxgap practice: align your DORA register of information with the CSSF eDesk format before the first mandatory submission and keep timestamped proof of transmission, as the CSSF may cross-check your declarations against feedback from the Lead Overseer.