Commission Implementing Regulation (EU) 2024/2956 of 29 November 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554
as it stood on 2024-11-29, permalink: /eu-eurlex/32024r2956/2024-11-29
2 versions · click any mark to read the law as it stood that day · ▌ the one you are reading
Article 1
For the purposes of this Regulation, the following definitions apply:
| 1. | ‘direct ICT third-party service provider’ means an ICT third-party service provider or ICT intra-group service provider that signed a contractual arrangement with:(a)a financial entity to provide its ICT services directly to that financial entity;(b)a financial or a non-financial entity to provide its services to other financial entities within the same group; |
|---|---|
| (a) | a financial entity to provide its ICT services directly to that financial entity; |
| (b) | a financial or a non-financial entity to provide its services to other financial entities within the same group; |
| 2. | ‘ICT service supply chain’ means a sequence of contractual arrangements connected with the ICT service being provided by the direct ICT third-party service provider to the financial entity, starting with the direct ICT third-party service provider which has one or multiple other ICT third-party service providers as counterparties (subcontractors); |
|---|
| 3. | ‘rank’ means the position of an ICT third-party service provider in the ICT service supply chain. |
|---|
Article 2
Financial entities shall assign a rank to each ICT third-party service provider. The rank shall be any natural number higher or equal to ‘1’ where the lower the natural number assigned to the rank, the closer the arrangement is to the financial entity.
The rank of the direct ICT third-party service provider in the ICT service supply chain shall always be ‘1’.
The rank of the subcontractor in the ICT service supply chain shall always be higher than ‘1’.
Article 3
Financial entities shall use the templates set out in Annex I to IV to maintain and update the register of information in accordance with Article 28(3) of Regulation (EU) 2022/2554, at entity level, or at sub-consolidated and consolidated level.
Financial entities shall ensure that the templates referred to in paragraph 1 include all of the following:
| (a) | the relevant information in relation to all the ICT services provided by direct ICT third-party providers; |
|---|
| (b) | information on all subcontractors that effectively underpin ICT services supporting critical or important functions or material parts thereof. |
|---|
- Financial entities shall ensure that the information contained in the templates referred to in paragraph 1 is accurate and consistent. Financial entities shall review the information contained in the templates regularly and shall promptly correct any errors or discrepancies detected.
In case of groups, financial entities responsible for maintaining and updating the register of information at sub-consolidated and consolidated level shall ensure that information in relation to entity level in the consolidation is correct and consistent with the information at the sub-consolidated and consolidated level.
- Financial entities shall ensure that the information contained in the templates referred to in paragraph 1 adhere to the following principles of data quality:
| (a) | accuracy; |
|---|
| (b) | completeness; |
|---|
| (c) | consistency; |
|---|
| (d) | integrity; |
|---|
| (e) | uniformity; |
|---|
| (f) | validity. |
|---|
Financial entities shall use a valid and active legal entity identifier (LEI) or the European Unique Identifier referred to in Article 16 of Directive (EU) 2017/1132 (‘EUID’), and where available both of these identifiers, to identify all of their ICT third-party service providers that are legal persons, except for individuals acting in a business capacity.
Where an ICT service provided by a direct ICT third-party service provider is supporting a critical or important function of the financial entities, financial entities shall ensure through the direct ICT third-party service provider, that all the subcontractors of the direct ICT third-party service provider included in the register of information in accordance with paragraph 2, point (b), which effectively underpin/support ICT services supporting critical or important functions, use a valid and active LEI or provide their EUID, and where available both of these identifiers, except if those subcontractors are individuals acting in a business capacity.
Article 4
Unless otherwise specified in the instructions, each template composing the register of information shall be a table with a predefined number of columns and an indefinite number of rows.
Financial entities shall complete each data element with a single value. Where more than one value is valid for a specific data element, financial entities shall add an additional row in the corresponding template for each valid value.
Financial entities shall complete all data elements in the register of information at entity level, sub-consolidated and consolidated level, as applicable.
Article 5
- Financial entities shall include in the register of information, in accordance with the instructions set out in Annex I, the following information:
| (a) | general information on the financial entity maintaining and updating the register of information at entity, sub-consolidated and consolidated level, respectively, as specified in template B_01.01 of Annex I; |
|---|
| (b) | general information on the entities in the consolidation as specified in template B_01.02 of Annex I; |
|---|
| (c) | identification of the branches of financial entities located outside the home country listed in template B_01.02, where applicable, as specified in template B_01.03 of Annex I; |
|---|
| (d) | general information on the contractual arrangements as specified in template B_02.01 of Annex I; |
|---|
| (e) | specific information on the contractual arrangements as specified in template B_02.02 of Annex I; |
|---|
| (f) | information on the links between intra-group contractual arrangements and contractual arrangements with ICT third-party service providers which are not part of the group using the contractual reference numbers when part of the ICT service supply chain is intra-group as specified in template B_02.03 of Annex I; |
|---|
| (g) | information on the entities signing the contractual arrangements with the direct ICT third-party service providers for receiving ICT services or on behalf of the entities using the ICT services as specified in template B_03.01 of Annex I; |
|---|
| (h) | identification of the ICT third-party service providers signing the contractual arrangements for providing ICT services as specified in template B_03.02 of Annex I; |
|---|
| (i) | identification of the entities signing the contractual arrangements for providing ICT services to other entities in the consolidation as specified in template B_03.03 of Annex I; |
|---|
| (j) | information on the entities making use of the ICT services provided by the ICT third-party service providers as specified in template B_04.01 of Annex I; |
|---|
| (k) | information on the direct ICT third-party service providers and subcontractors, as specified in template B_05.01 of Annex I; |
|---|
| (l) | information on the ICT service supply chain, as specified in template B_05.02 of Annex I; |
|---|
| (m) | information on the identification of functions as specified in template B_06.01 of Annex I; |
|---|
| (n) | information on the assessment of the ICT services provided by ICT third-party service providers supporting a critical or important function or material parts thereof as specified in template B_07.01 of Annex I; |
|---|
| (o) | information on the terminology used by financial entities and the terms included in the closed lists and classification systems used when filling in the templates as specified in template B_99.01 of Annex I. |
|---|
- Where relevant for their risk management or contract management purposes, financial entities may include into the register of information additional information in the format that is most appropriate for the purposes of such additional information.
Article 6
In the case of groups, the parent undertakings shall take into account the relevant sectorial Union legislation when determining which entities to be included in the register of information.
A register of information maintained and updated at sub-consolidated and consolidated levels shall include all financial entities and ICT intra-group service providers, which are part of the sub-group and group.
Article 7
This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
Provenance and validity dates, identifier, hash
| as of | 2024-11-29 → this version applied |
| valid | 2024-11-29 → 2024-12-01 publisher-asserted |
| type | REG_IMPL Commission Implementing Regulation (EU) 2024/2956 of 29 November 2024 laying down implementing technical standards for the application of Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to standard templates for the register of information |
| language | en |
| published | 2024-11-29 |
| lex_id | eu-eurlex:32024r2956:2024-11-29 |
| record sha256 | c11bbf2bf96b45452ea92efbd7e56936e64060b02fe6571af79d7db902d975d4 |
New here? What am I looking at?
This is a consolidated text: the original law with every later amendment merged in, as the official publisher produced it for a given date. Laws are amended constantly, so “the law” has no single text, only a text per date. That date is the banner above.
It has no legal force. Only the version published in the official gazette (Mémorial / Official Journal) is authentic, the publishers say so themselves, and so do we. Lex reproduces their text without altering a byte, and links the source on every page. This is legal information, never legal advice: it reports what the text said, never what it means for your situation.
“Valid from → to” = the window in which this text applied. “Open” = still current as far as the publisher has consolidated. Each article carries its own hash so you can prove it was not tampered with , here is how.
timeline next version (2024-11-29) →
| tier | A, publisher-supplied validity dates |
| history begins | publisher |
| index built | 2026-08-07T19:46:23Z · corpus 8d5e859 |
| stamp signature | valid (ECDSA-P256) |