Transcript
Speaker: Welcome to HSBC Global Viewpoint, the podcast series that brings together business leaders and industry experts to explore the latest global insights, trends, and opportunities.
Speaker: Make sure you're subscribed to stay up to date with new episodes.
Speaker: Thanks for listening.
Speaker: And now onto today's show.
Speaker: Welcome to the latest in our DigiTalks podcast series.
Speaker: We are featuring a variety of different topics that are currently trending in the digital world.
Speaker: And we now explore again, the EU's Digital Operational Resilience Act, in short, Dora.
Speaker: Introducing the topic is HSBC Security Services Senior Product Manager for Global Trustee and Fiduciary Services, Vary Sandeman.
Speaker: Vary, over to you.
Speaker: Thanks, Gabriella.
Speaker: Now, in our DigiTalks podcast series, we've previously explored DORA, the EU's Digital Operational Resilience Act, in its draft form when it was introduced as part of the EU's digital finance package.
Speaker: The final DORA regulation has now been published and entered into force in January 2023, with application from January 2025.
Speaker: To help us digest the final DORA rules,
Speaker: and also to consider the steps financial entities need to take to be ready.
Speaker: I am really delighted to welcome back Clare Harrop, Senior Associate in the Financial Institutions Group at Freshfields.
Speaker: Clare, thanks so much for joining me today.
Speaker: Now, could you firstly explain briefly the backdrop and motivation for introducing the DORA regulation, please?
Speaker: Certainly, Vahri, and thank you so much for having me back.
Speaker: As we covered on our last podcast, the Commission originally published the DORA proposal in the OJ on the 24th of September 2020 as part of its digital finance package, along with the markets and crypto asset regulation and a number of other proposals designed to enable innovation and competition in the financial sector whilst mitigating risks.
Speaker: DORA was published in the OJ at the end of December last year.
Speaker: The DORA legislation sets out that the use of information and communications technology, or ICT, has acquired a critical importance in the operation of typical daily functions of financial entities.
Speaker: In addition, increased digitalisation has deepened into connectedness and dependencies within the financial sector and with third-party infrastructure and service providers.
Speaker: This has introduced systemic vulnerability and amplified ICT risk.
Speaker: One particular area that was identified by the legislators is a lack of harmonisation.
Speaker: Of course, the EU financial sector is regulated by a single rulebook and governed by a European system of financial supervision.
Speaker: However, provisions tackling digital operational resilience and ICT security are not yet fully or consistently harmonised.
Speaker: This is despite digital operational resilience being vital for ensuring financial stability and market integrity in the digital age, and it's certainly no less important than, for example, common prudential or market conduct standards.
Speaker: EU legislators have also recognised that differences between legislation and national supervisory or regulatory approaches with regard to ICT risk might be an obstacle to the functioning of the internal market in financial services,
Speaker: and that competition between the same type of financial entities operating in different Member States could also be distorted.
Speaker: Thanks for clarifying the background and rationale, Claire.
Speaker: And who will DORA apply to and will this be limited to EU firms only?
Speaker: DORA will apply to what it terms financial entities, which encompasses most types of financial institution that are subject to EU legislation.
Speaker: And that group includes credit institutions, investment firms, payment institutions, central counterparties, central securities depositories and crypto asset service providers.
Speaker: DORA will also be relevant for ICT third party service providers, including cloud computing service providers providing ICT services to financial entities.
Speaker: That group includes those established in a third country outside the EU providing services to EU financial entities.
Speaker: Indirectly, ICT third party service providers will need to be aware of the obligations with which financial entities will be required to comply.
Speaker: But there are also some direct implications for certain service providers.
Speaker: Those service providers, which are designated as critical by the European supervisory authorities, will be subject to oversight by a lead authority
Speaker: and also subject to certain provisions of DORA directly.
Speaker: Thanks, Claire.
Speaker: A very wide-ranging application then.
Speaker: Now, in terms of the content of DORA, could you please talk us through some of the high-level requirements for risk management, incident reporting and resilience testing?
Speaker: Of course.
Speaker: So financial entities will need to have an internal governance and control framework that ensures effective and prudent management of ICT risk.
Speaker: The management body of the financial entity will have responsibility for defining, overseeing, approving and implementing all arrangements related to the framework.
Speaker: Financial entities will also need to have a sound, comprehensive and well-documented ICT risk management framework in place to help enable them to address ICT risk quickly, efficiently and comprehensively.
Speaker: Further, there are also requirements to have mechanisms in place to detect anomalous activities promptly.
Speaker: For example, ICT network performance issues and ICT-related incidents.
Speaker: On that subject of incidents, firms will also need to have in place ICT-related incident management processes to detect, manage and notify ICT-related incidents and the ability to classify ICT-related incidents and their impact.
Speaker: Major ICT-related incidents will need to be reported to the financial entity's competent authority.
Speaker: and financial entities may also notify significant cyber threats to the relevant competent authority on a voluntary basis when the financial entity deems the threat to be of relevance to the financial system, to service users or to clients.
Speaker: Reporting will eventually be harmonised by the European supervisory authorities who will publish draft regulatory technical standards on this subject.
Speaker: Finally, there will also be requirements on financial entities to establish, maintain and review a sound and comprehensive operational resilience testing framework as an integral part of the entity's ICT risk management framework.
Speaker: Thanks, Claire.
Speaker: Some robust requirements there then.
Speaker: And turning now to the management of ICT third party risk, what principles are being introduced?
Speaker: So there are a number of key contractual provisions that financial entities will be required to put in place.
Speaker: In the EU legislators view, despite the fact that many financial entities are subject to outsourcing rules already,
Speaker: There is an absence of clear and bespoke EU standards applying to the contractual arrangements concluded with ICT third-party service providers, so the external source of ICT risk is not comprehensively addressed at the moment.
Speaker: DORA sets out certain key principles to guide financial entities' management of ICT third-party risk, which are particularly important when outsourcing critical or important functions.
Speaker: These principles are complementary to sectoral law applicable to outsourcing.
Speaker: And Article 30 of DORA sets out the minimum requirements which financial entities are required to ensure are included in their contractual arrangements on the use of ICT services.
Speaker: The European supervisory authorities will also have the ability to designate certain third-party service providers that are critical for financial entities, following an assessment that takes into account certain criteria.
Speaker: Such criteria include the systemic impact on the stability, continuity or quality of the provision of financial services in the event that the relevant ICT third-party service provider would face a large-scale operational failure to provide its services,
Speaker: and the degree of substitutability of the ICT third party service provider.
Speaker: Once a service provider has been designated as critical, it will be subject to the oversight of a lead overseer, which will be one of the European supervisory authorities.
Speaker: And that authority will have certain powers relating to the critical third party provider.
Speaker: As we mentioned earlier, third country ICT providers can also be designated as critical.
Speaker: And if they are, the third country provider must set up a subsidiary in the EU within 12 months of becoming designated.
Speaker: and there are express powers for the lead overseer which apply to third country providers.
Speaker: I'd also note just one point that designation as a critical ICT third party service provider won't apply to financial entities that are providing ICT services to other financial entities since they are already subject to supervisory mechanisms established by EU financial services law.
Speaker: Claire thanks for explaining so clearly the key requirements of DORA.
Speaker: Now, what should financial entities be doing now ahead of the January 2025 deadline to be ready?
Speaker: So, as you say, the provisions of DORA will apply from 17th of January 2025.
Speaker: So that's when financial entities will become subject to the obligations that we've just discussed.
Speaker: I should flag that we haven't yet seen drafts of the technical standards yet.
Speaker: So there's quite a bit of detail yet to come, which financial entities should keep an eye out for.
Speaker: But firms can start thinking about the changes that they will need to make themselves in order to manage their ICT risk.
Speaker: So firms should start thinking about things like the internal governance and control framework and their ICT risk management framework and how those will be implemented.
Speaker: Institutions should also think about what systems will need to be put in place in order to ensure that financial entities can comply with their detection obligations and check whether their crisis communication plans are up to date.
Speaker: Firms should also start thinking about the ICT services that they outsource and whether any of those are services which support critical or important functions.
Speaker: The contractual agreements in place with ICT service providers are likely to need to be updated and it may be worth institutions starting to think about whether they should put in place template provisions which cover the minimum requirements.
Speaker: DORA does provide that there may be standard contractual clauses developed by public authorities for specific services, but it's possible that those won't be available for some time or cover all services that the institution receives.
Speaker: And then finally, financial entities might also start thinking about whether they might want to participate in any information sharing arrangements on cyber threat information and intelligence.
Speaker: DORA expressly provides that such information sharing arrangements might be set up
Speaker: Although these arrangements would need to protect the potentially sensitive nature of the information shared and be governed by rules of conduct in full respect of business confidentiality, protection of personal data and guidelines on competition policy.
Speaker: Thanks.
Speaker: Some really helpful considerations there and obviously a lot of important steps that firms should be taking now, Claire.
Speaker: Thank you so much for joining me today to discuss DORA and for providing a deeper insight into all the requirements.
Speaker: And importantly, the steps financial entities will need to take for readiness.
Speaker: If clients do have any questions on this topic, please do follow up with your HSBC representative.
Speaker: Back to you.
Speaker: Thanks, Gabriella.
Speaker: Thanks so much, Ferry and Claire.
Speaker: And I totally agree.
Speaker: This is quite enlightening.
Speaker: I would like to thank you for listening to this edition in our series of DigiTalks podcasts.
Speaker: We hope that you enjoyed learning more about DORA.
Speaker: Stay tuned for more from our podcasts as we explore more trends in the coming weeks.
Speaker: Thank you for joining us at HSBC Global Viewpoint.
Speaker: We hope you enjoyed the discussion.
Speaker: Make sure you're subscribed to stay up to date with new episodes.





