← Back to DORA Library
EUFinalJC/GL/2024/36

Oversight Cooperation & Information Exchange – JC/GL/2024/36

Joint Guidelines on the oversight cooperation and information exchange between the ESAs and the competent authorities under Regulation (EU) 2022/2554

European Supervisory Authorities (EBA, ESMA, EIOPA) – Joint Committee
Updated Nov 6, 2024
vJC/GL/2024/36

Abstract

Joint Committee Guidelines issued under DORA Article 32(7) establishing a common operational approach for cooperation and information exchange between the ESAs (including the Lead Overseer) and competent authorities for the oversight framework of critical ICT third-party service providers, covering procedures, roles, responsibilities, communication means, timelines, and follow-up information flows for recommendations.

Key Takeaways

  • Sets detailed procedures and conditions for allocating and executing oversight-related tasks between the ESAs (including the Lead Overseer) and competent authorities under DORA Article 32(7).
  • Defines practical rules for communication (English by default), single points of contact, and use of secure electronic channels/tools for confidential exchanges.
  • Establishes timelines and escalation approach for differences of opinion (via the Joint Oversight Network and Oversight Forum).
  • Specifies information exchanges for criticality assessment/designation, oversight plans, general investigations/inspections, and additional oversight-related notifications affecting financial entities.
  • Details reciprocal information flows to support follow-up of Lead Overseer recommendations (including remediation plans, assessments, penalty-payment decisions, and competent authority measures such as warnings/exit actions).

Keywords

JC/GL/2024/36Regulation (EU) 2022/2554DORA Article 32(7)critical ICT third-party service providersLead OverseerOversight ForumJoint Oversight Networkregister of information (Article 28)designation (Article 31)oversight plans (Article 33)investigations and inspections (Articles 38-39)recommendations follow-up (Article 42)

Need DORA-Aligned AI Architecture?

We build AI systems that satisfy DORA requirements from day one. Audit trails, governance, exit readiness - built in, not bolted on.

Schedule Architecture Reviewviktor@intellectumlab.com | Response within 24 hours