Lex Browse everything How it works For developers

What changed, Commission Implementing Regulation (EU) 2024/2956 of 29 November 2024 laying down implementing technical stand…

2024-11-29 → 2024-12-02 · no interpretation, just the text delta

on 2024-11-29eu-eurlex:32024r2956:2024-11-29 (2024-11-29 → 2024-12-01) · official source ↗
on 2024-12-02eu-eurlex:32024r2956:2024-12-02 (2024-12-02 → open) · official source ↗

Open the structured article comparison → matched by provision anchor, with changed, added, removed and unchanged articles separated

145 line(s) in the old middle, 57 in the new; 1 unchanged leading and 1 trailing lines trimmed.

+ ### Article 1 — Definitions
− ### art_1

− Article 1
+ 1. ‘direct ICT third-party service provider’ means an ICT third-party service provider or ICT intra-group service provider that signed a contractual arrangement with: (a) a financial entity to provide its ICT services directly to that financial entity; (b) a financial or a non-financial entity to pr…
− | 1. | ‘direct ICT third-party service provider’ means an ICT third-party service provider or ICT intra-group service provider that signed a contractual arrangement with:(a)a financial entity to provide its ICT services directly to that financial entity;(b)a financial or a non-financial entity to pr…
− | --- | --- |
− | (a) | a financial entity to provide its ICT services directly to that financial entity; |
− | (b) | a financial or a non-financial entity to provide its services to other financial entities within the same group; |
+ 2. ‘ICT service supply chain’ means a sequence of contractual arrangements connected with the ICT service being provided by the direct ICT third-party service provider to the financial entity, starting with the direct ICT third-party service provider which has one or multiple other ICT third-party s…
− | 2. | ‘ICT service supply chain’ means a sequence of contractual arrangements connected with the ICT service being provided by the direct ICT third-party service provider to the financial entity, starting with the direct ICT third-party service provider which has one or multiple other ICT third-par…
− | --- | --- |
+ 3. ‘rank’ means the position of an ICT third-party service provider in the ICT service supply chain.
− | 3. | ‘rank’ means the position of an ICT third-party service provider in the ICT service supply chain. |
− | --- | --- |
+ ### Article 2 — Ranking of ICT third-party providers in the supply chain
− ### art_2

− Article 2
+ ### Article 3 — General requirements for the templates of the register of information
− ### art_3
+ **1.** Financial entities shall use the templates set out in Annex I to IV to maintain and update the register of information in accordance with Article 28(3) of Regulation (EU) 2022/2554, at entity level, or at sub-consolidated and consolidated level.
− Article 3
+ **2.** Financial entities shall ensure that the templates referred to in paragraph 1 include all of the following:(a) the relevant information in relation to all the ICT services provided by direct ICT third-party providers;(b) information on all subcontractors that effectively underpin ICT services…
− 1. Financial entities shall use the templates set out in Annex I to IV to maintain and update the register of information in accordance with Article 28(3) of Regulation (EU) 2022/2554, at entity level, or at sub-consolidated and consolidated level.
+ **3.** Financial entities shall ensure that the information contained in the templates referred to in paragraph 1 is accurate and consistent. Financial entities shall review the information contained in the templates regularly and shall promptly correct any errors or discrepancies detected.
− 2. Financial entities shall ensure that the templates referred to in paragraph 1 include all of the following:

− | (a) | the relevant information in relation to all the ICT services provided by direct ICT third-party providers; |
− | --- | --- |

− | (b) | information on all subcontractors that effectively underpin ICT services supporting critical or important functions or material parts thereof. |
− | --- | --- |

− 3. Financial entities shall ensure that the information contained in the templates referred to in paragraph 1 is accurate and consistent. Financial entities shall review the information contained in the templates regularly and shall promptly correct any errors or discrepancies detected.
+ **4.** Financial entities shall ensure that the information contained in the templates referred to in paragraph 1 adhere to the following principles of data quality:(a) accuracy;(b) completeness;(c) consistency;(d) integrity;(e) uniformity;(f) validity.
− 4. Financial entities shall ensure that the information contained in the templates referred to in paragraph 1 adhere to the following principles of data quality:
+ **5.** Financial entities shall use a valid and active legal entity identifier (LEI) or the European Unique Identifier referred to in Article 16 of Directive (EU) 2017/1132 (‘EUID’), and where available both of these identifiers, to identify all of their ICT third-party service providers that are le…
− | (a) | accuracy; |
− | --- | --- |
+ **6.** Where an ICT service provided by a direct ICT third-party service provider is supporting a critical or important function of the financial entities, financial entities shall ensure through the direct ICT third-party service provider, that all the subcontractors of the direct ICT third-party s…
− | (b) | completeness; |
− | --- | --- |
+ ### Article 4 — Data format requirement
− | (c) | consistency; |
− | --- | --- |
+ **1.** Unless otherwise specified in the instructions, each template composing the register of information shall be a table with a predefined number of columns and an indefinite number of rows.
− | (d) | integrity; |
− | --- | --- |
+ **2.** Financial entities shall complete each data element with a single value. Where more than one value is valid for a specific data element, financial entities shall add an additional row in the corresponding template for each valid value.
− | (e) | uniformity; |
− | --- | --- |
+ **3.** Financial entities shall complete all data elements in the register of information at entity level, sub-consolidated and consolidated level, as applicable.
− | (f) | validity. |
− | --- | --- |
+ ### Article 5 — Content of the register of information
− 5. Financial entities shall use a valid and active legal entity identifier (LEI) or the European Unique Identifier referred to in Article 16 of Directive (EU) 2017/1132 (‘EUID’), and where available both of these identifiers, to identify all of their ICT third-party service providers that are legal …
+ **1.** Financial entities shall include in the register of information, in accordance with the instructions set out in Annex I, the following information:(a) general information on the financial entity maintaining and updating the register of information at entity, sub-consolidated and consolidated …
− 6. Where an ICT service provided by a direct ICT third-party service provider is supporting a critical or important function of the financial entities, financial entities shall ensure through the direct ICT third-party service provider, that all the subcontractors of the direct ICT third-party servi…
+ **2.** Where relevant for their risk management or contract management purposes, financial entities may include into the register of information additional information in the format that is most appropriate for the purposes of such additional information.
− ### art_4
+ ### Article 6 — Scope of the register of information at sub-consolidated and consolidated level
− Article 4
+ **1.** In the case of groups, the parent undertakings shall take into account the relevant sectorial Union legislation when determining which entities to be included in the register of information.
− 1. Unless otherwise specified in the instructions, each template composing the register of information shall be a table with a predefined number of columns and an indefinite number of rows.
+ **2.** A register of information maintained and updated at sub-consolidated and consolidated levels shall include all financial entities and ICT intra-group service providers, which are part of the sub-group and group.
− 2. Financial entities shall complete each data element with a single value. Where more than one value is valid for a specific data element, financial entities shall add an additional row in the corresponding template for each valid value.
+ ### Article 7 — Entry into force
− 3. Financial entities shall complete all data elements in the register of information at entity level, sub-consolidated and consolidated level, as applicable.
+ This Regulation shall enter into force on the twentieth day following that of its publication in the *Official Journal of the European Union*.
− ### art_5

− Article 5

− 1. Financial entities shall include in the register of information, in accordance with the instructions set out in Annex I, the following information:

− | (a) | general information on the financial entity maintaining and updating the register of information at entity, sub-consolidated and consolidated level, respectively, as specified in template B_01.01 of Annex I; |
− | --- | --- |

− | (b) | general information on the entities in the consolidation as specified in template B_01.02 of Annex I; |
− | --- | --- |

− | (c) | identification of the branches of financial entities located outside the home country listed in template B_01.02, where applicable, as specified in template B_01.03 of Annex I; |
− | --- | --- |

− | (d) | general information on the contractual arrangements as specified in template B_02.01 of Annex I; |
− | --- | --- |

− | (e) | specific information on the contractual arrangements as specified in template B_02.02 of Annex I; |
− | --- | --- |

− | (f) | information on the links between intra-group contractual arrangements and contractual arrangements with ICT third-party service providers which are not part of the group using the contractual reference numbers when part of the ICT service supply chain is intra-group as specified in template …
− | --- | --- |

− | (g) | information on the entities signing the contractual arrangements with the direct ICT third-party service providers for receiving ICT services or on behalf of the entities using the ICT services as specified in template B_03.01 of Annex I; |
− | --- | --- |

− | (h) | identification of the ICT third-party service providers signing the contractual arrangements for providing ICT services as specified in template B_03.02 of Annex I; |
− | --- | --- |

− | (i) | identification of the entities signing the contractual arrangements for providing ICT services to other entities in the consolidation as specified in template B_03.03 of Annex I; |
− | --- | --- |

− | (j) | information on the entities making use of the ICT services provided by the ICT third-party service providers as specified in template B_04.01 of Annex I; |
− | --- | --- |

− | (k) | information on the direct ICT third-party service providers and subcontractors, as specified in template B_05.01 of Annex I; |
− | --- | --- |

− | (l) | information on the ICT service supply chain, as specified in template B_05.02 of Annex I; |
− | --- | --- |

− | (m) | information on the identification of functions as specified in template B_06.01 of Annex I; |
− | --- | --- |

− | (n) | information on the assessment of the ICT services provided by ICT third-party service providers supporting a critical or important function or material parts thereof as specified in template B_07.01 of Annex I; |
− | --- | --- |

− | (o) | information on the terminology used by financial entities and the terms included in the closed lists and classification systems used when filling in the templates as specified in template B_99.01 of Annex I. |
− | --- | --- |

− 2. Where relevant for their risk management or contract management purposes, financial entities may include into the register of information additional information in the format that is most appropriate for the purposes of such additional information.

− ### art_6

− Article 6

− 1. In the case of groups, the parent undertakings shall take into account the relevant sectorial Union legislation when determining which entities to be included in the register of information.

− 2. A register of information maintained and updated at sub-consolidated and consolidated levels shall include all financial entities and ICT intra-group service providers, which are part of the sub-group and group.

− ### art_7

− Article 7

− This Regulation shall enter into force on the twentieth day following that of its publication in the Official Journal of the European Union.
tierA, publisher-supplied validity dates
history beginspublisher
index built2026-08-07T19:46:23Z · corpus 8d5e859
stamp signaturevalid (ECDSA-P256)