ESAs Publish New Guide Outlining DORA Oversight for ICT Providers
The European Supervisory Authorities (EBA, ESMA, and EIOPA) have jointly published a Guide on Oversight Expectations under the Digital Operational Resilience Act (DORA). This guide outlines how Joint Examination Teams (JETs) will oversee critical ICT third-party service providers (CTPPs) and clarifies the tools, governance, and procedures involved in this supervisory process.
Key Highlights:
-
Defines non-binding oversight expectations for entities designated as CTPPs under DORA.
-
Establishes how JETs will operate, including assessment methodologies and engagement protocols.
-
Offers clarity for financial institutions and ICT providers preparing for DORA-mandated oversight.
The publication supports stakeholders in aligning with the broader DORA compliance framework, particularly the Register of Information (RoI), which took effect in January 2025.
Why This Matters
With oversight activities ramping up in 2025, financial institutions and their ICT providers need to ensure their digital reporting systems are not only accurate and automated—but also ready for regulatory scrutiny.
At Ez-XBRL, we’re already helping our clients:
-
Streamline RoI data submissions.
-
Ensure data integrity across ICT provider disclosures.
-
Build structured reporting workflows aligned with DPM(1.0) and EBA(4.0) validation rules.
Read the official release:
ESAs publish guide on DORA oversight activities – EBA