My bookmarksSign up free

Commission Delegated Regulation (EU) 2024/1773 Article 5

Commission Delegated Regulation (EU) 2024/1773 Article 5

Ex-ante risk assessment

Article 5

1.   The policy shall require that the business needs of the financial entity are defined before a contractual arrangement is concluded. 2.   The policy shall require that a risk assessment is conducted at financial entity level and, where applicable, at consolidated and sub-consolidated level before a contractual arrangement is concluded. The risk assessment shall take into account all the relevant requirements laid down in Regulation (EU) 2022/2554 and applicable sectoral Union legislation. It shall consider, in particular, the impact of the provision of ICT services supporting critical or important functions by ICT third-party service providers on the financial entity and all the risks posed by the provision of those ICT services supporting critical or important functions by ICT third-party service providers, including the following: (a) operational risks; (b) legal risks; (c) ICT risks; (d) reputational risks; (e) risks linked to the protection of confidential or personal data; (f) risks linked to the availability of data; (g) risks linked to the location where the data is processed and stored; (h) risks linked to the location of the ICT third-party service provider; (i) ICT concentration risks at entity level.

Read the full instrument →

Other provisions in Commission Delegated Regulation (EU) 2024/1773

Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗ · Data as of 2026-07-04

CitationArticle 5 of Commission Delegated Regulation (EU) 2024/1773 (LawPlayer, data as of 2026-07-04)

© European Union, https://eur-lex.europa.eu, 1998-2026. Reuse authorised under Commission Decision 2011/833/EU, provided the source is acknowledged.

What to look at next