emendrix

Art. 45

Central Securities Depositories Regulation · 32014R0909 · every event for this act · on EUR-Lex

Operational risks

1 change recorded across 1 event, newest first.

in force 2025-01-17 MODIFIED+829 −203

Amended by Regulation (EU) 2022/2554 32022R2554

applies from: unknown (the text changed beyond its dates, so no date that moved can be read as the application date)

dates added to the text: 2022-12-14

Paragraph 1 now refers to ICT tools, processes and policies set up and managed under Regulation (EU) 2022/2554, alongside other appropriate tools, controls and procedures for other types of operational risk, replacing the earlier reference to appropriate IT tools, controls and procedures generally.

Paragraph 3 now includes ICT business continuity policy and ICT response and recovery plans established under Regulation (EU) 2022/2554 within the business continuity policy and disaster recovery plan, and paragraph 4 now ties the resumption of critical IT systems to Article 12(5) and (7) of that Regulation instead of describing prompt resumption without such a reference.

Paragraph 6 now excludes incidents relating to ICT risk from the duty to inform authorities of operational incidents, and paragraph 7 now excludes ICT risk from the operational risks that ESMA's regulatory technical standards under paragraphs 1 and 6 are to address.

Cited: Art. 45, v2 · Art. 45, v1

text before / after

02014R0909-2024050102014R0909-20250117

Article 45 Operational risks 1. A CSD shall identify sources of operational risk, both internal and external, and minimise their impact also through the deployment of appropriate IT ICT tools, processes and policies set up and managed in accordance with Regulation (EU) 2022/2554 of the European Parliament and of the CouncilRegulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011 (OJ L 333, 27.12.2022, p. 1)., as well as through any other relevant appropriate tools, controls and procedures, procedures for other types of operational risk, including for all the securities settlement systems it operates. 2. A CSD shall maintain appropriate IT tools that ensure a high degree of security and operational reliability, and have adequate capacity. IT tools shall adequately deal with the complexity, variety and type of services and activities performed so as to ensure high standards of security, and the integrity and confidentiality of the information maintained. 3. For services that it provides as well as for each securities settlement system that it operates, a CSD shall establish, implement and maintain an adequate business continuity policy and disaster recovery plan plan, including ICT business continuity policy and ICT response and recovery plans established in accordance with Regulation (EU) 2022/2554, to ensure the preservation of its services, the timely recovery of operations and the fulfilment of the CSD’s obligations in the case of events that pose a significant risk of to disrupting operations. 4. The plan referred to in paragraph 3 shall provide for the recovery of all transactions and participants’ positions at the time of disruption to allow the participants of a CSD to continue to operate with certainty and to complete settlement on the scheduled date, including by ensuring that critical IT systems can promptly resume operations from the time of disruption. It shall include the setting-up disruption as provided for in Article 12(5) and (7) of a second processing site with sufficient resources, capabilities and functionalities and appropriate staffing arrangements. Regulation (EU) 2022/2554. 5. The CSD shall plan and carry out a programme of tests of the arrangements referred to in paragraphs 1 to 4. 6. A CSD shall identify, monitor and manage the risks that key participants in the securities settlement systems it operates, as well as service and utility providers, and other CSDs or other market infrastructures might pose to its operations. It shall, upon request, provide competent and relevant authorities with information on any such risk identified. It shall also inform the competent authority and relevant authorities without delay of any operational incidents incidents, other than in relation to ICT risk, resulting from such risks. 7. ESMA shall, in close cooperation with the members of the ESCB, develop draft regulatory technical standards to specify the operational risks referred to in paragraphs 1 and 6 6, other than ICT risk, and the methods to test, to address or to minimise those risks, including the business continuity policies and disaster recovery plans referred to in paragraphs 3 and 4 and the methods of assessment thereof. ESMA shall submit those draft regulatory technical standards to the Commission by 18 June 2015. Power is delegated to the Commission to adopt the regulatory technical standards referred to in the first subparagraph in accordance with Articles 10 to 14 of Regulation (EU) No 1095/2010.