Chapter 9 of 11
Regulation 2024/1773: Due Diligence, Contract Clauses, Monitoring, and Exit
The quality of a third-party arrangement is tested before signature, during performance, and at the point of exit. This chapter follows that sequence through ex-ante risk assessment, provider due diligence, conflicts management, mandatory contractual protections, continuous monitoring, remediation, termination, and tested exit plans.
1. The Contracting Lifecycle: Before, During, and Exit
The lifecycle
Articles 5 to 11 move through a third-party arrangement's lifecycle: before signature, at signature, during delivery, and at exit.
The control sequence
Read the Regulation as a sequence: justify -> assess -> select -> contract -> monitor -> remediate -> exit.
Current status
As of 17 August 2026, Regulation (EU) 2024/1773 is in force. It entered into force on 15 July 2024, following publication on 25 June 2024.
2. Article 5: Ex-ante Risk Assessment
Business need first
Article 5(1): "The policy shall require that the business needs of the financial entity are defined before a contractual arrangement is concluded."
Risk assessment timing
Article 5(2): "The policy shall require that a risk assessment is conducted at financial entity level and, where applicable, at consolidated and sub-consolidated level before a contractual arrangement is concluded."
Risk categories
The assessment shall consider operational, legal, ICT, reputational, confidential or personal-data, data-availability, location, and entity-level ICT concentration risks.
3. Risk-Mapping Activity: A Proposed Cloud Service
Apply Article 5
A bank proposes to use an ICT third-party service provider for a cloud platform that hosts customer-facing payment processing.
Before a contractual arrangement is concluded, make a short risk map. For each prompt, identify what the financial entity should assess under Article 5(2):
- The provider stores backups outside the European Union.
- Several major internal systems would depend on the same provider.
- A regional outage could interrupt payment processing.
- A cyberattack could expose customer account information.
- The provider operates in a jurisdiction that might be affected by restrictive measures, embargos, or sanctions.
Suggested self-check
- Item 1: risks linked to where data are processed and stored.
- Item 2: ICT concentration risks at entity level.
- Item 3: operational risks, ICT risks, and availability-of-data risks.
- Item 4: ICT risks and risks linked to protection of confidential or personal data.
- Item 5: risks linked to the provider's location; Article 6 also addresses third-country and restrictive-measures considerations.
Do not treat this as a substitute for the required assessment. The activity simply shows how one service can create several Article 5 risk categories at once.
4. Article 6: Due Diligence Before Selection
Proportionate selection
Article 6(1) requires an appropriate and proportionate provider-selection and assessment process, taking account of whether the provider is an intragroup ICT service provider.
Capability and controls
The assessment asks whether the provider "has the business reputation, sufficient abilities, expertise and adequate financial, human and technical resources, information security standards, appropriate organisational structure, risk management and internal controls".
Auditability
The provider must consent to arrangements making audits effectively possible, including onsite audits by the entity, appointed third parties, and competent authorities.
Assurance is not optional
Article 6(4): "Financial entities shall ensure an appropriate level of assurance on the ICT third-party service provider’s performance". Where appropriate, more than one assurance element shall be used.
5. Knowledge Check: Due Diligence
Choose the best answer
A financial entity plans to rely only on a prospective provider's marketing materials and a single certificate. It does not assess business continuity, subcontracting, auditability, or third-country data processing.
Which answer best reflects Article 6?
Which statement is correct?
- The approach is sufficient whenever the provider has a well-known brand.
- The policy shall provide an appropriate and proportionate due-diligence process, including the specified pre-contractual assessments; assurance may require more than one element where appropriate.
- Only providers located in a third country require due diligence.
- Auditability is relevant only after an ICT-related incident.
Show Answer
Answer: B) The policy shall provide an appropriate and proportionate due-diligence process, including the specified pre-contractual assessments; assurance may require more than one element where appropriate.
Article 6 requires a pre-contractual, appropriate and proportionate selection and assessment process. It covers matters such as capability, subcontracting, third-country issues, audit consent, risk mitigation, and business continuity. Article 6(4) states that financial entities shall ensure an appropriate level of assurance, using more than one listed element where appropriate.
6. Articles 7 and 8: Conflicts and Contractual Protections
Conflicts before and during
Article 7 requires measures to identify, prevent, and manage actual or potential conflicts before contracting, plus ongoing monitoring of those conflicts.
Written contract
Article 8(1): "the relevant contractual arrangement are to be in written form and are to include all the elements referred to in Article 30(2) and (3) of Regulation (EU) 2022/2554."
Audit and testing rights
Contracts must give access, inspection, audit, and ICT-testing rights. Methods can include internal audit, appointed third parties, pooled audits, certifications, and available audit reports.
Change control
Material changes must be formalised in a written document that is dated and signed by all parties. The policy shall also specify renewal.
7. Article 8 in Practice: Certificates Are Not Enough
The restriction
Article 8(3): "The financial entity shall not over time rely solely on certifications referred to in paragraph 2, point (c), or audit reports referred to in point (d) of that paragraph."
Conditions for using them
The financial entity must assess scope and content on an ongoing basis, ensure key systems and controls are covered, verify that evidence is not obsolete, and assess the auditor or certifier.
Keep an audit right
The entity must "has the contractual right to perform individual and pooled audits at its discretion with regard to the contractual arrangements and execute those rights in line with the agreed frequency."
8. Article 9: Ongoing Monitoring and Remediation
Continuous monitoring
Contracts must specify measures and key indicators to monitor provider performance on an ongoing basis, including data confidentiality, availability, integrity, and authenticity.
Performance evidence
Performance is assessed through KPIs, KCIs, audits, self-certifications, and independent reviews, supported by service, incident, ICT-security, and continuity reports.
Document and update
Article 9(3) requires the assessment to be documented and its results used to update the financial entity's Article 6 risk assessment.
Remediate proportionately
Measures for shortcomings must be monitored to "ensure that they are effectively complied with within a defined timeframe, taking into account the materiality of the shortcomings."
9. Article 10: Exit and Termination Planning
A plan for every arrangement
The policy must require a documented exit plan for each contractual arrangement, plus periodic review and testing of that plan.
Plan for three triggers
The exit plan must take account of unforeseen and persistent service interruptions, inappropriate or failed service delivery, and unexpected contract termination.
The Article 10 standard
The plan must be realistic, feasible, based on plausible scenarios and reasonable assumptions, and have a schedule compatible with contractual exit and termination terms.
10. Final Review: Key Rules and Legal Effect
Flip to review Articles 5 to 11
Finish by connecting the lifecycle controls to the Regulation's legal effect.
- Article 5 timing
- Business needs must be defined, and the required risk assessment must be conducted, before a contractual arrangement is concluded.
- Article 6 assurance
- Financial entities shall ensure an appropriate level of assurance on the provider's performance. Where appropriate, more than one assurance element shall be used.
- Article 7 intragroup rule
- For ICT intra-group service providers, decisions on conditions, including financial conditions, are to be taken objectively.
- Article 8 long-term reliance rule
- The financial entity shall not over time rely solely on specified third-party certifications or provider-made-available audit reports.
- Article 9 remediation
- Measures addressing shortcomings must be monitored so that they are effectively complied with within a defined timeframe, taking account of materiality.
- Article 10 exit-plan standard
- The exit plan shall be realistic, feasible, based on plausible scenarios and reasonable assumptions, with a schedule compatible with contractual exit and termination terms.
- Article 11 entry into force
- "This Regulation shall enter into force on the twentieth day following its publication in the Official Journal of the European Union." It entered into force on 15 July 2024.
- Binding effect and identification
- "This Regulation shall be binding in its entirety and directly applicable in all Member States." Done at Brussels, 13 March 2024. ELI: http://data.europa.eu/eli/reg_del/2024/1773/oj
Key Terms
- exit plan
- A documented plan required for each contractual arrangement, subject to periodic review and testing under Article 10.
- pooled audit
- An audit organised jointly with other contracting financial entities or firms using ICT services of the same provider, where appropriate.
- key control indicator
- A control-focused measure used under Article 9(2)(b) to assess an ICT third-party service provider.
- ICT concentration risk
- A risk expressly listed in Article 5(2) at entity level, arising from concentration in ICT-service dependencies.
- contractual arrangement
- An arrangement for the use of ICT services supporting critical or important functions, addressed by the policy requirements in Regulation (EU) 2024/1773.
- ex-ante risk assessment
- A risk assessment conducted before a contractual arrangement is concluded.
- key performance indicator
- A performance measure used under Article 9(2)(b) to assess an ICT third-party service provider.
- threat-led penetration testing
- A form of pooled ICT testing expressly mentioned in Article 8(2)(b).
- ICT intra-group service provider
- An ICT service provider within the same group; Article 7(2) addresses objective decisions on conditions for its services.
- ICT third-party service provider
- The provider supplying ICT services considered in Articles 5 to 10.