Skip to main content
Logo
European Insurance and Occupational Pensions Authority
 

2705

Q&A

Question ID: 2705

Regulation Reference: (EU) 2023/894 - ITS with regard to the templates for the submission of information necessary for supervision

Topic: Reporting Templates

Template: S.14.03

Status: Final

Date of submission: 19 Jun 2023

Question

Regards the new Cyber risk template (S.14.03) in 2.8 taxonomy, and the associate LOG guidance (in the draft business package supporting SII taxonomy 2.8.0). We have a question regards the new data point C0060 , "Description of Risk(s) included in the coverage"). This field can hold multiple selections. Normally in such cases EIOPA require (and enforce through a regex based validation rule) a comma-separated list of representative codes (taking the item number from the associated label). Is this also the requirement for this datapoint? For example, if the filing entity wants to report "(1) Network Interruption (refers to a network security failure leading to business interruption. Examples may include a Distributed Denial of Service or “DDoS” attack (i.e. website being overloaded with requests organized by a malicious party) or a hacker accessing the network and deleting critical files, or adding malicious code that causes the system to fail)" and "(2) Network Interruption OSP (where OSP stands for Open Settlement Protocol (OSP), i.e. a client-server protocol that manages access control, accounting, usage data and inter-domain routing to make it easier for Internet service providers (ISPs) to support IP telephony)" together, should this been entered as "1,2"? Additionally, we are not sure if option 24 should only be used on its own, or also in combination with other options? There is some guidance related to this (for C0030) but it is unclear to us what that is actually saying: "The Product Identification is uniquely defined by the combination of Line(s) of Business and Description of Risks included in the Coverage, provided that the latter is not filled in as “Other” or that multiple selections of the items available in the list is performed. If this is the case, two Product Categories characterised by same LoB(s) and Description of Risks included in the Coverage as “Other” cannot be considered as the same Product Identification and will need to be reported as separate lines. Can EIOPA please confirm for the case of option 24 (Other)?

EIOPA answer

EIOPA confirms that standard pattern for multiple value options should be used. Instruction on how to report such fields can be found in the Filling rules table V.5 Multi value elements reporting is applicable. In addition, we also confirm that for ‘Other’ option reported in C0060 a separate line needs to be created. We will also consider implementing suggested checks for the future releases.