DORA - One Year On - What organisations need to know about subcontracting
Moira Cronin
Partner | Risk Assurance | PwC Ireland DORA Lead Partner | Digital Risk, Resilience & Regulation|
The three European Supervisory Authorities (ESAs) have published a draft regulatory technical standard (‘RTS’) to provide guidance on the subcontracting conditions under DORA (the EU’s Digital Operational Resilience Act).
With less than a year remaining until the deadline for compliance with DORA[1], all in-scope organisations – financial entities and their external ICT providers – need to carefully review DORA and the draft RTS on subcontracting and consider what actions must be taken in the coming months to ensure readiness. In this blog, I’ll share an overview of some of the key requirements in the newly released RTS on subcontracting and a brief summary of key issues to consider. These have been carefully pulled together by our DORA team at PwC.
DORA: a recap
Increasing levels of regulation are being introduced to control the risks arising from procurement of ICT services in the financial services sector. DORA is another example of this trend. DORA sets out a wide range of requirements for financial entities engaging ICT service providers, including requirements for specific contractual terms to be included in contracts with ICT service providers. One of the key issues concerns the conditions under which the ICT service provider can further subcontract services to another provider (a very common occurrence for ICT services). The RTS on subcontracting sets out how the financial entity should assess and control the risks when this occurs.?
The requirements of the RTS on subcontracting apply to ICT services supporting critical or important functions. These are functions that, if disrupted, could have a material impact on the financial soundness, business continuity and/or regulatory compliance of a financial entity.
Financial entities impacted by DORA[2] will need to conduct risk assessments on all proposed subcontractors, set out clear contractual arrangements in respect of the proposed subcontracting arrangements,? and continuously monitor the performance of their ICT service providers (and the subcontractors they rely on).
?
Risk assessments: key factors
Before subcontracting, ICT service providers will have to seek consent from the financial entity; the financial entity will need to carry out a risk assessment before it can approve the arrangement. This assessment should encompass factors including:?
Financial entities must also periodically carry out an assessment of any potential changes to the business environment of their ICT service providers and subcontractors.
?
Contractual requirements for financial entities
Where subcontracting is permitted, a financial entity must include additional provisions in its contracts with ICT service providers. These include:
?
领英推荐
Continuous monitoring
The financial entity will need to closely monitor (and document) the entire ICT subcontracting chain. It will also have to review contractual documentation between the ICT service provider and its subcontractors to ensure end-to-end compliance. Difficulties may arise if ICT service providers are reluctant to share full details of their subcontracting arrangements.?
This RTS, together with the main text of DORA, imposes a wide range of requirements for specific contractual terms that financial entities will need to include in their contracts for ICT services. It is therefore advisable that financial entities start reviewing contracts with ICT service providers (and any related subcontracting arrangements) as soon as possible.
A final word: this draft RTS has been published by the ESAs for public consultation. They will consider comments received by 4 March 2024. Comments can be submitted online at www.esma.europa.eu. The ESAs will finalise the draft RTS following the public consultation and they aim to submit the final text in July 2024 to the European Commission for adoption.
?
PwC’s multidisciplinary team has the expertise and experience to support? clients in achieving DORA contractual compliance. Contact us if you would like to discuss how the DORA team at PwC can help.
Rajesh Chavda Fiona Marschollek Samantha Trama Philipp Schulz Georgina D. Rizwan Nazir David O'Sullivan Andrew Schembri Jennifer Chambers Neil Redmond Danny Chamings Ian Fife Rahul Maharaj Job van Ommen
[1] 17 January 2025
[2] DORA will impact an estimated 22,000 financial entities?
[3] DORA sets out additional requirements on audit rights
Head of Department @ Royal Commission | PhD, IoT Expert
1 年yes
EMEA and Germany Cybersecurity and Privacy leader | Building a Secure Digital Society | OT 5G IoT | PwC
1 年Great read on DORA and how it impacts ICT service providers. Nice work, Moira.?
Director at PwC UK - Passionate about helping clients solve problems
1 年Great summary Moira Cronin
Really insightful article on the DORA regulation. Thanks for sharing Moira! ??