in force 2025-01-17
02009R1060-20240109 → 02009R1060-20250117
Amended by Regulation (EU) 2022/2554 32022R2554
Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (Text with EEA relevance)
detected 2026-08-13
2 provisions touched — 2 substantive, 0 date-only, 0 disputed · every change carries an explanation that passed its citation check
MODIFIED +408 −31 Annex I INDEPENDENCE AND AVOIDANCE OF CONFLICTS OF INTEREST§
applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)
dates added to the text: 2022-12-14
In Section A, point 4, the requirement for effective control and safeguard arrangements for information processing systems is replaced with a requirement for effective control and safeguard arrangements for managing ICT systems in accordance with Regulation (EU) 2022/2554.
The revised text adds a footnote identifying that regulation as the one of 14 December 2022 on digital operational resilience for the financial sector, which also amends several other named regulations.
Cited: Annex I, v1 · Annex I, v2
text before / after
02009R1060-20240109 → 02009R1060-20250117
ANNEX I
INDEPENDENCE AND AVOIDANCE OF CONFLICTS OF INTEREST
Section A
Organisational requirements
1. The credit rating agency shall have an administrative or supervisory board. Its senior management shall ensure that:
(a) credit rating activities are independent, including from all political and economic influences or … 411 unchanged words … establish adequate policies and procedures to ensure compliance with its obligations under this Regulation.
4. A credit rating agency shall have sound administrative and accounting procedures, internal control mechanisms, effective procedures for risk assessment, and effective control and safeguard arrangements for information processing systems. managing ICT systems in accordance with Regulation (EU) 2022/2554 of the European Parliament and of the CouncilRegulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (OJ L 333, 27.12.2022, p. 1)..
Those internal control mechanisms shall be designed to secure compliance with decisions and procedures at all levels of the credit rating agency.
A credit rating agency shall implement and maintain decision-making procedures and organisational structures which clearly and in a documented … 4,994 unchanged words … of that Directive shall be provided by the credit rating agency irrespective of whether it is subject to Directive 2004/25/EC of the European Parliament and of the Council of 21 April 2004 on takeover bidsOJ L 142, 30.4.2004, p. 12..
MODIFIED +66 −31 Annex III ANNEX III§
applies from: unchanged
In point 12 of Section I, the reference to safeguard arrangements for 'information processing systems' has been replaced with a reference to arrangements for 'managing ICT systems in accordance with Regulation (EU) 2022/2554'.
Cited: Annex III, v1 · Annex III, v2
text before / after
02009R1060-20240109 → 02009R1060-20250117
ANNEX III
List of infringements referred to in Article 24(1) and Article 36a(1)
I. Infringements related to conflicts of interest, organisational or operational requirements
1. The credit rating agency infringes Article 4(3) by endorsing a credit rating issued in a third country without … 556 unchanged words … credit rating agency infringes Article 6(2), in conjunction with point 4 of Section A of Annex I, by not having sound administrative or accounting procedures, internal control mechanisms, effective procedures for risk assessment, or effective control or safeguard arrangements for information processing systems; managing ICT systems in accordance with Regulation (EU) 2022/2554; or by not implementing or maintaining decision-making procedures or organisational structures as required by that point.
13. The credit rating agency infringes Article 6(2), in conjunction with point 5 of Section A of Annex I, by not establishing or maintaining a … 4,305 unchanged words … or by not identifying an unsolicited credit rating as such.
11. The credit rating agency infringes Article 11(1) by not fully disclosing or immediately updating information relating to the matters set out in Part I of Section E of Annex I.
The full entry, with the citation mapping v1 = 02009R1060-20240109, v2 = 02009R1060-20250117, is committed at eu/32009R1060/CHANGELOG.md.