Question ID: DORA124 - 3169
Regulation Reference: (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Topic: ICT risk management (DORA)
Article: Article 3: Definition
Status: Rejected
Date of submission: 16 Oct 2024
Question
In what circumstances are service providers which are financial entities to be considered as ICT third-party service providers and included in the Register of Information?
Background of the question
Recital 7 stipulates that when a financial entity outsources a function that makes use of a supportive ICT service that service provider should be considered a ICT third-party service provider. DORA Dry Run FAQ was published on 4th July which clarified that such regulated entities are not to be considered as ICT third-party service providers. This clarification was later withdrawn DORA Dry Run FAQ was published on 29th July.
EIOPA answer
This question has been rejected because the issue it deals with is already explained or addressed in Article 3 (Definitions) (19) of Regulation (EU) 2022/2554, ‘ICT third-party service provider’ means an undertaking providing ICT services. Therefore if a financial entity is providing ICT services, the FE is considered as an ‘ICT third-party service provider’ and needed to be included in the RoI. Please refer to Q&A DORA030 on the definition of ICT service.