Updated 09/05/2025
In force

Initial Legal Act
Search within this legal act

Recitals

COMMISSION DELEGATED REGULATION (EU) 2025/420

of 16 December 2024

supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards to specify the criteria for determining the composition of the joint examination team ensuring a balanced participation of staff members from the ESAs and from the relevant competent authorities, their designation, tasks and working arrangements

(Text with EEA relevance)

THE EUROPEAN COMMISSION,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2022/2554 of the European Parliament and of the Council, of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (1), and in particular Article 41(2), second subparagraph, thereof,

Whereas:

(1)

The oversight framework established by Regulation (EU) 2022/2554 should be built on a structured and continuous cooperation between the European Supervisory Authorities (ESAs) and the competent authorities through the Oversight Forum and the joint examination teams.

(2)

The authorities referred to in Article 40(2) of Regulation (EU) 2022/2554 should ensure that their staff members that are to be appointed as members of the joint examination team referred to in Article 40(1) of that Regulation has the technical expertise required in the profiles needed in the joint examination teams. The demonstration that an authority does not have staff meeting the specific technical expertise needed in the joint examination teams should be considered by the Lead Overseer as a justification to discharge, at that point in time, the authorities of their obligation to nominate staff members to the joint examination teams. In that case, the authority should nevertheless commit on the best effort basis to address that shortfall of expertise and try to reinforce its capabilities to contribute to the joint examination teams in the context of the next exercise.

(3)

Staff members of the authorities referred to in Article 40(2) of Regulation (EU) 2022/2554 that are designated as members of a joint examination team as referred to in Article 40(1) of that Regulation should continue to be employees of the nominating authority and therefore subject to working hours and permanent location of work as included in their employment contracts.

(4)

To ensure the most effective use of resources in the execution of oversight activities, members of joint examination teams should be able to be part of several joint examination teams and to oversee multiple critical ICT third-party service providers. The number of the critical ICT third-party service providers to be assigned to a specific member of joint examination team, and overall staffing needs of the joint examination teams, should take into account the risk profile of the critical ICT third-party service providers and the envisaged level of intensity of oversight activities. That possibility to oversee multiple critical ICT third-party service providers is taken into account in the strategic multi-annual oversight plan, updated annually by the Lead Overseers to the extent necessary, and reflected into the individual annual oversight plan. To ensure the reliability of the planned and ongoing commitment of resource staffing of the joint examination teams by the nominating authorities, the Lead Overseer should consult both the Joint Oversight Network and the Oversight Forum on the strategic multi-annual oversight plan.

(5)

The Lead Overseer should apply a combination of criteria and principles when identifying the number of staff members in each joint examination team and the resulting composition. Given the diverse technological and geographical footprint and the use made by various financial entities of critical ICT third-party service providers, those criteria and principles should take into account the technical nature of the oversight tasks, the different grade of dependency of financial entities on the services provided by the critical ICT third-party service providers, the geographical distribution, the size and the number of financial entities relying on those services and, where possible, a proportionate cross-sectoral representation. In performing that task, the Lead Overseer should rely on the information provided by the competent authorities in the context of the designation of the critical ICT third-party service providers, including information needed for all the sub-criteria as laid down in Commission Delegated Regulation (EU) 2024/1502 (2) and consider the criticality of the critical ICT third-party service providers for the provisioning of specific financial services both at Member State and Union level.

(6)

To ensure that the structure and the composition of the joint examination teams are fit for purpose and to ensure the efficiency and effectiveness of the Oversight Framework continuously, the Lead Overseer and the members of the joint examination teams should periodically assess the achievements of the joint examination teams. The Lead Overseer and the nominating authorities should use those assessments to verify whether the members of the joint examination teams are still fit for performing their tasks and make changes to the membership of the joint examination teams, where appropriate.

(7)

In order to ensure that the members of the joint examination teams work as a single team and oversight activities are conducted in a consistent manner, the ESAs should specify the oversight procedures to be followed by the members of the joint examination teams and the Lead Overseer coordinator in the performance of their duties.

(8)

Since the oversight tasks involve the processing of confidential information, the Lead Overseer should grant members of the joint examination team access to such information and to the relating IT (including tools, applications and datasets) and non-IT (including policy, procedures and documentation) resources on a need-to-know basis and within the specified scope of their assignments if that is necessary for members of the joint examination team to assist the Lead Overseer in the fulfilment of its statutory functions or tasks. When laying down arrangements between the Lead Overseer and the competent authorities to implement this Regulation, consistent with Commission Delegated Regulation (EU) 2024/1505 (3), to ensure the proper financing of the costs associated to the resources provided by the nominating authorities, the Lead Overseer should include in such arrangements a section detailing the procedure of reimbursement of the direct and indirect costs of all nominating authorities involved in the joint examination teams. Furthermore, to ensure a transparent and trustworthy execution of the oversight activities, those arrangements should also ensure that the members of the joint examination teams are free from any conflict of interests while performing their duties.

(9)

This Regulation is based on the draft regulatory technical standards submitted to the European Commission by the European Banking Authority, the European Insurance and Occupational Pensions Authority, and the European Securities and Markets Authority.

(10)

The Joint Committee of the European Supervisory Authorities referred to in Article 54 of Regulation (EU) No 1093/2010 of the European Parliament and of the Council (4), in Article 54 of Regulation (EU) No 1094/2010 of the European Parliament and of the Council (5) and in Article 54 of Regulation (EU) No 1095/2010 of the European Parliament and of the Council (6) has conducted open public consultations on the draft regulatory technical standards on which this Regulation is based, analysed the potential costs and benefits of the proposed standards and requested advice of the Banking Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1093/2010, the Insurance and Reinsurance Stakeholder Group and the Occupational Pensions Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1094/2010, and the Securities and Markets Stakeholder Group established in accordance with Article 37 of Regulation (EU) No 1095/2010,

HAS ADOPTED THIS REGULATION:


(1)   OJ L 333, 27.12.2022, p. 1, ELI: http://data.europa.eu/eli/reg/2022/2554/oj.

(2)  Commission Delegated Regulation (EU) 2024/1502 of 22 February 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council by specifying the criteria for the designation of ICT third-party service providers as critical for financial entities (OJ L, 2024/1502, 30.5.2024, ELI: http://data.europa.eu/eli/reg_del/2024/1502/oj).

(3)  Commission Delegated Regulation (EU) 2024/1505 of 22 February 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council by determining the amount of the oversight fees to be charged by the Lead Overseer to critical ICT third-party service providers and the way in which those fees are to be paid (OJ L, 2024/1505, 30.5.2024, ELI: http://data.europa.eu/eli/reg_del/2024/1505/oj).

(4)  Regulation (EU) No 1093/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Banking Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/78/EC (OJ L 331, 15.12.2010, p. 12, ELI: http://data.europa.eu/eli/reg/2010/1093/oj).

(5)  Regulation (EU) No 1094/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Insurance and Occupational Pensions Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/79/EC (OJ L 331, 15.12.2010, p. 48, ELI: http://data.europa.eu/eli/reg/2010/1094/oj).

(6)  Regulation (EU) No 1095/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Securities and Markets Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/77/EC (OJ L 331, 15.12.2010, p. 84, ELI: http://data.europa.eu/eli/reg/2010/1095/oj).