SkarpSkarp

Chapter 8 of 11

Regulation 2024/1773: Third-Party ICT Policy Governance and Contractual Lifecycle

A contract supporting a critical or important function must be governed as a lifecycle risk, not treated as a procurement artifact. This chapter situates Regulation 2024/1773 and examines proportional policy design, group consistency, management-body oversight, independent review, reporting lines, and lifecycle governance.

19 min readen

1. Start with the policy, not the contract

What Regulation 2024/1773 does

Regulation 2024/1773 supplements DORA by specifying the detailed content of a policy for contractual arrangements involving ICT services that support critical or important functions.

The required policy

Recital (2) states that "that strategy is to include a policy on the use of ICT services supporting critical or important functions provided by ICT third-party service providers."

Think lifecycle risk

The Regulation places contractual arrangements inside ICT risk management: policy, governance, oversight, monitoring, documentation, and exit all matter.

2. Recitals (3)-(5): proportionate, group-aware application

Proportionate does not mean optional

Recital (3) says requirements should be applied "in a manner that is proportionate." Article 1 turns proportional design of the policy into a mandatory "shall" requirement.

Intra-group services

Recital (5) says intra-group providers, including certain providers owned within the same institutional protection scheme, should be considered ICT third-party service providers.

Group implementation

Where sub-consolidated or consolidated application applies, Article 2 requires the responsible parent undertaking to ensure consistent implementation across group financial entities.

3. Thought exercise: apply proportionality without weakening the rule

Scenario: two financial entities

  • Entity A: A small financial entity uses one externally hosted ICT service for a critical customer-facing process.
  • Entity B: A cross-border group uses several providers, processes data in multiple locations, and relies heavily on a small number of cloud providers.

Your task

For each entity, identify which Article 1 factors could make its policy more or less complex. Do not conclude that Entity A can dispense with the policy: Article 1 says the policy shall take proportionality factors into account.

Consider:

  1. The type of ICT service.
  2. Provider, parent-company, service-delivery, data-processing, and data-storage locations.
  3. The nature of shared data.
  4. Group membership.
  5. Authorisation, registration, supervision, oversight, or lack of those features.
  6. Provider concentration.
  7. Transferability, including technology-specific constraints.
  8. The impact of disruption on activity continuity and service availability.

Reflect: Which factors make Entity B's policy likely to require more extensive analysis? Which factors still matter for Entity A?

Which statement best reflects Article 1?

  1. Only large financial entities need a policy for critical or important ICT services.
  2. The policy shall take account of the entity's size, overall risk profile, and the nature, scale, and complexity of its services, activities, and operations.
  3. A provider located in a Member State automatically removes the need for risk assessment.
  4. Intra-group ICT services are excluded from the policy.
Show Answer

Answer: B) The policy shall take account of the entity's size, overall risk profile, and the nature, scale, and complexity of its services, activities, and operations.

Article 1 requires the policy to take account of size, overall risk profile, and operational nature, scale, and complexity. Proportionality shapes application; it does not eliminate the policy requirement.

4. Article 1: build the proportionality assessment

Article 1 is a policy-design rule

Article 1 requires the policy to take account of listed risk and complexity factors. It does not provide a scoring formula, numeric threshold, or prescribed weighting method.

Location and data

The assessment includes provider and parent-company location, service-delivery location, data-processing and storage location, and the nature of data shared.

Concentration and transferability

The policy must take account of concentration with one or few providers, transferability to another provider, and the potential disruption impact on continuity and service availability.

5. Example: why a cloud contract is a lifecycle risk

Before signing

For a critical cloud-hosted payments function, Article 1 makes location, data, concentration, transferability, and disruption impact relevant inputs to the policy.

After signing

Article 4 means governance continues through implementation, monitoring, documentation, exit strategies, and termination processes. Signing is not the final control point.

Do not invent thresholds

Articles 1-4 contain no cloud-specific concentration percentage, migration deadline, or prescribed scoring system. Do not attribute one to Regulation 2024/1773.

6. Article 3(1)-(3): annual review, classification, and ownership

Annual policy review

Article 3(1): "The management body shall review the policy at least once a year and update it where necessary." Policy changes must then be implemented timely, with a documented plan.

Classify the services

Article 3(2) requires a methodology, or a reference to one, for determining which ICT services support critical or important functions and when that assessment occurs and is reviewed.

Make ownership clear

Article 3(3) requires clearly assigned internal responsibility for approval, management, control, and documentation, plus appropriate skills, experience, and knowledge.

7. Article 3(4)-(8): oversight, reporting, and auditability

Outsourcing does not transfer final responsibility

Article 3(4) preserves the financial entity's final responsibility for effective oversight, while requiring an assessment of whether the provider has sufficient resources.

Reporting must be designed

Article 3(5) requires a named role or senior-management member, cooperation with control functions where applicable, reporting lines, report content, documents, and frequency.

Independent review and access

Article 3(7) requires independent review and audit-plan inclusion. Article 3(8) requires terms preserving supervision, provider cooperation, and effective access to data and premises.

8. Flashcards: governance essentials

Review the terms

Flip each card, then explain the connection between the term and the relevant Article 3 requirement.

Annual review
Article 3(1): The management body shall review the policy at least once a year and update it where necessary.
Classification methodology
Article 3(2): The policy shall establish or refer to a methodology for determining which ICT services support critical or important functions, and specify when assessment and review occur.
Internal responsibilities
Article 3(3): The policy shall clearly assign responsibilities for approval, management, control, and documentation of relevant contractual arrangements.
Reporting lines
Article 3(5): The policy shall identify the responsible role or senior-management member and set out reporting lines, information, documents, and frequency.
Independent review
Article 3(7): ICT services supporting critical or important functions provided by ICT third party service providers shall be subject to independent review and included in the audit plan.

9. Article 4: govern every main lifecycle phase

Recital and Article language differ

Recital (8) says the policy should follow lifecycle phases. Article 4 says the policy shall specify requirements, rules, responsibilities, and processes for every main phase.

At least six coverage areas

Article 4 covers management-body involvement; planning and approval; organisational involvement; implementation and monitoring; documentation and records; and exit and termination.

Lifecycle, not procurement artifact

The policy must address the arrangement from decision-making through exit. It cannot be limited to selecting and signing with a provider.

10. Final check: lifecycle and accountability

Choose the best answer

Focus on the operative Articles rather than upgrading recital language from should to shall.

Which option accurately states requirements in Articles 3 and 4 of Regulation 2024/1773?

  1. The management body may review the policy when a major provider outage occurs, and the lifecycle ends once the contract is approved.
  2. The management body shall review the policy at least once a year; the policy shall specify responsibilities, rules, and processes for each main lifecycle phase, including exit strategies and termination processes.
  3. Only the ICT third-party service provider is responsible for compliance once the contract is signed.
  4. Independent review is needed only where the provider is located in a third country.
Show Answer

Answer: B) The management body shall review the policy at least once a year; the policy shall specify responsibilities, rules, and processes for each main lifecycle phase, including exit strategies and termination processes.

Article 3(1) requires review at least once a year and updating where necessary. Article 4 requires lifecycle coverage, including exit strategies and termination processes. Article 3(7) requires independent review and audit-plan inclusion; it is not limited by provider location.

Key Terms

policy
The policy on the use of ICT services supporting critical or important functions provided by ICT third-party service providers.
management body
The body that, under Article 3(1), shall review the policy at least once a year and update it where necessary.
financial entity
An entity within the scope of Regulation (EU) 2022/2554. In Articles 1-4, it is the entity whose policy and contractual arrangements are governed.
consolidated basis
A group-level basis involving the group for which consolidated financial statements are provided.
independent review
A review required by Article 3(7) for ICT services supporting critical or important functions provided by ICT third party service providers; those services must also be included in the audit plan.
sub-consolidated basis
A group-level basis below the consolidated group level, where the Regulation applies in that manner.
contractual arrangement
The contractual arrangement between a financial entity and an ICT third-party service provider for ICT services supporting critical or important functions.
critical or important function
A function supported by ICT services whose classification must be determined through the methodology required or referenced by Article 3(2).
ICT third-party service provider
A provider of ICT services. Regulation 2024/1773 addresses providers supporting critical or important functions.
exit strategies and termination processes
The lifecycle area that Article 4(f) requires the policy to cover, as set out in Article 10.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself