ICT risk-management framework
Operate an ICT risk-management framework (management body accountable) that covers AI/ML systems and cloud dependencies.
European Union (EBA / ESMA / EIOPA) · EU (financial entities) · Law
This page is a plain-English summary written by us, not legal advice — the official text is linked above. Our catalogue was last reviewed 2026-08-15; that is a review of the whole catalogue, not an independent legal verification of this entry.
In force; applies since 17 Jan 2025.
Operate an ICT risk-management framework (management body accountable) that covers AI/ML systems and cloud dependencies.
Maintain a register of information on all ICT (incl. AI/cloud) third-party arrangements, manage concentration risk, and meet contractual requirements; critical providers face ESA oversight.
Classify and report major ICT-related incidents and perform digital operational-resilience testing (incl. threat-led penetration testing for significant entities).
Financial entities must run an ICT risk-management framework, keep a register of ICT/AI third-party arrangements, report major ICT incidents and perform resilience testing.
Action: Fold AI/cloud systems into your DORA ICT risk framework, third-party register and incident-reporting playbook.
Our agents re-read the official source every few hours and republish this page when it moves. Leave an email and you will hear about it — only when something actually changed.
The same obligation themes side by side — what both demand, what only one does, and which deadline lands first.