Refine By
Clear all filter
About 91312 results for "*"
NEWS
Ireland—Banking and Financial Services analysis: This article, was written by Ian Duffy, Ciara Anderson and Rhiannon Monahan of Arthur Cox LLP and discusses the upcoming submission deadline for the DORA (Digital Operational Resilience Act) Register of Information (RoI) by financial entities, highlighting key updates to the FAQ. Some notable points include the classification of entities offering multiple services, the inclusion of EU-domiciled entities and branches, and clarification on non-EU parent entities. The FAQ also addresses changes from the Dry-Run Exercise conducted in 2024 and stresses the importance of consulting regulators for correct reporting.
NEWS
The European Commission has adopted Commission Delegated Regulation (EU) of 24.3.2025 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the elements that a financial entity has to determine and assess when subcontracting ICT services supporting critical or important functions.
NEWS
The European Commission has adopted Commission Delegated Regulation (EU) …/... of 13.2.25 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria used for identifying financial entities required to perform threat-led penetration testing, the requirements and standards governing the use of internal testers, the requirements in relation to the scope, testing methodology and approach for each phase of the testing, results, closure and remediation stages and the type of supervisory and other relevant cooperation needed for the implementation of TLPT and for the facilitation of mutual recognition.
NEWS
The European Commission has adopted three new regulatory technical standards (RTSs) which aim to complement the EU regulatory frameworks on cybersecurity matters for the financial sector by specifying rules to classify cyber incidents; rules to harmonise information and communication technology (ICT) risk management tools, methods, processes and security policies for the financial entities; and rules to establish the elements of risk that financial entities shall take into account when developing their policy on the use of ICT services supporting critical or important functions provided by ICT third-party service providers
NEWS
The three European Supervisory Authorities (the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority—ESAs) are consulting on draft regulatory technical standards (RTS) for the conduct of oversight activities in relation to the joint examination teams under the Digital Operational Resilience Act (DORA). Responses are sought by 18 May 2024.
NEWS
The three European Supervisory Authorities (the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority—ESAs) have published their joint final report on the draft regulatory technical standards (RTS) specifying how to determine and assess the conditions for subcontracting information and communication technology (ICT) services that support critical or important functions under the Digital Operational Resilience Act (DORA). The RTS are the final element in the ESAs’ second batch of regulatory products under DORA, and aim to enhance the digital operational resilience of the EU financial sector by strengthening the financial entities’ ICT risk management in subcontracting.
NEWS
The European Supervisory Authorities or ESAs (ESMA, EBA and EIOPA) have published a corrigendum (dated 22 January 2025) to their decision (dated 8 November 2024) concerning the reporting by competent authorities to the ESAs of information necessary for the designation of critical ICT third[1]party service providers in accordance with Article 31(1)(a) of Regulation (EU) 2022/2554 (DORA).
NEWS
The three European Supervisory Authorities (the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority—ESAs) have published the first final draft technical standards under the Digital Operational Resilience Act (EU) 2022/2554 (DORA). The three sets of regulatory technical standards (RTS) and one set of implementing technical standards (ITS) aim to enhance the digital operational resilience of the EU financial sector by strengthening financial entities’ information and communication technology (ICT) and third-party risk management and incident reporting frameworks. The final draft technical standards have been submitted to the European Commission for review with the objective that they will be adopted in the coming months.
NEWS
The three European Supervisory Authorities (the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority—ESAs) have published a second batch of policy products under the Digital Operational Resilience Act (DORA). They focus on the reporting framework for ICT-related incidents (reporting clarity, templates) and threat-led penetration testing while also introducing some requirements on the design of the oversight framework, which aim to enhance the digital operational resilience of the EU financial sector.
NEWS
The European Supervisory Authorities (the European Banking Authority, the European Insurance and Occupational Pensions Authority and the European Securities and Markets Authority—ESAs) has issued an opinion on the European Commission’s rejection of the draft implementation technical standards (ITS) on the registers of information under the Digital Operational Resilience Act (DORA). The ESAs are concerned over the impacts and practicalities of the Commission’s proposed changes to the draft ITS on the registers of information in relation to financial entities' contractual arrangements with information and communication technology (ICT) third-party service providers.
NEWS
The European Securities and Markets Authority (ESMA) has published three sets of advice received from its stakeholder groups covering joint European Supervisory Authority (ESA) consultations on: the elements which a financial entity needs to determine and assess when subcontracting information and communication technology (ICT) services supporting critical or important functions; draft regulatory technical standards (RTS) specifying elements related to threat led penetration tests; and draft RTS and draft implementing standards on the content of the notification and reports for major incidents and significant cyber threats and determining the time limits for reporting major incidents.
NEWS
Ireland—Banking & Financial Service analysis: This article, was written by Patrick Brandt, Ciara Brady, Louise Hogan and Sarah Lee of A&L Goodbody LLP. The European Commission has clarified the scope of the definition of ‘ICT services’ in Article 3(21) of the Digital Operational Resilience Act (DORA).