Rättskällor med officiella primärkällor

Utskrivet ·

Skip to main content
Skip to the answer

Agent · dora-2022-2554-33

DORA artikel 33: Tasks of the Lead Overseer

Structural tree: the article's own paragraphs, verbatim.

CELEX 32022R2554 · 2026-08-18 · Weight 86 · minimal-risk

ExtendedOperational weight but lower priority. Metered by volume, not per call, once metering is switched on.

DORAOfficial source

What this page is
Agent, DORA artikel 33
Checked against the official source
2026-08-18Current
Responsible publisher
ExploreWorld Legal, editorial deskLiability position

Jurisdiction

The same agent, read through one country's lens.

Inputs

  • in_scopeThe article applies to the situationboolean
  • punktParagraph of the articleenum (1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14)

Rule tree

  1. If: alla(in_scope = true, punkt = 1)

    Paragraph 1 applies

    1. The Lead Overseer, appointed in accordance with Article 31(1), point (b), shall conduct the oversight of the assigned critical ICT third-party service providers and shall be, for the purposes of all matters related to the oversight, the primary point of contact for those critical ICT third-party service providers.

    Paragraph 1

  2. If: alla(in_scope = true, punkt = 2)

    Paragraph 2 applies

    2. For the purposes of paragraph 1, the Lead Overseer shall assess whether each critical ICT third-party service provider has in place comprehensive, sound and effective rules, procedures, mechanisms and arrangements to manage the ICT risk which it may pose to financial entities.

    Paragraph 2

  3. If: alla(in_scope = true, punkt = 3)

    Paragraph 3 applies

    The assessment referred to in the first subparagraph shall focus mainly on ICT services provided by the critical ICT third-party service provider supporting the critical or important functions of financial entities. Where necessary to address all relevant risks, that assessment shall extend to ICT services supporting functions other than those that are critical or important.

    Paragraph 3

  4. If: alla(in_scope = true, punkt = 4)

    Paragraph 4 applies

    3. The assessment referred to in paragraph 2 shall cover:

    Paragraph 4

  5. If: alla(in_scope = true, punkt = 5)

    Paragraph 5 applies

    (a)

    Paragraph 5

  6. If: alla(in_scope = true, punkt = 6)

    Paragraph 6 applies

    ICT requirements to ensure, in particular, the security, availability, continuity, scalability and quality of services which the critical ICT third-party service provider provides to financial entities, as well as the ability to maintain at all times high standards of availability, authenticity, integrity or confidentiality of data;

    Paragraph 6

  7. If: alla(in_scope = true, punkt = 7)

    Paragraph 7 applies

    (b)

    Paragraph 7

  8. If: alla(in_scope = true, punkt = 8)

    Paragraph 8 applies

    the physical security contributing to ensuring the ICT security, including the security of premises, facilities, data centres;

    Paragraph 8

  9. If: alla(in_scope = true, punkt = 9)

    Paragraph 9 applies

    (c)

    Paragraph 9

  10. If: alla(in_scope = true, punkt = 10)

    Paragraph 10 applies

    the risk management processes, including ICT risk management policies, ICT business continuity policy and ICT response and recovery plans;

    Paragraph 10

  11. If: alla(in_scope = true, punkt = 11)

    Paragraph 11 applies

    (d)

    Paragraph 11

  12. If: alla(in_scope = true, punkt = 12)

    Paragraph 12 applies

    the governance arrangements, including an organisational structure with clear, transparent and consistent lines of responsibility and accountability rules enabling effective ICT risk management;

    Paragraph 12

  13. If: alla(in_scope = true, punkt = 13)

    Paragraph 13 applies

    (e)

    Paragraph 13

  14. If: alla(in_scope = true, punkt = 14)

    Paragraph 14 applies

    the identification, monitoring and prompt reporting of material ICT-related incidents to financial entities, the management and resolution of those incidents, in particular cyber-attacks;

    Paragraph 14

If no rule matches: The article is not stated to apply, or no paragraph is selected. The agent abstains rather than guesses.

The article text as read

  1. 11. The Lead Overseer, appointed in accordance with Article 31(1), point (b), shall conduct the oversight of the assigned critical ICT third-party service providers and shall be, for the purposes of all matters related to the oversight, the primary point of contact for those critical ICT third-party service providers.
  2. 22. For the purposes of paragraph 1, the Lead Overseer shall assess whether each critical ICT third-party service provider has in place comprehensive, sound and effective rules, procedures, mechanisms and arrangements to manage the ICT risk which it may pose to financial entities.
  3. 3The assessment referred to in the first subparagraph shall focus mainly on ICT services provided by the critical ICT third-party service provider supporting the critical or important functions of financial entities. Where necessary to address all relevant risks, that assessment shall extend to ICT services supporting functions other than those that are critical or important.
  4. 43. The assessment referred to in paragraph 2 shall cover:
  5. 5(a)
  6. 6ICT requirements to ensure, in particular, the security, availability, continuity, scalability and quality of services which the critical ICT third-party service provider provides to financial entities, as well as the ability to maintain at all times high standards of availability, authenticity, integrity or confidentiality of data;
  7. 7(b)
  8. 8the physical security contributing to ensuring the ICT security, including the security of premises, facilities, data centres;
  9. 9(c)
  10. 10the risk management processes, including ICT risk management policies, ICT business continuity policy and ICT response and recovery plans;
  11. 11(d)
  12. 12the governance arrangements, including an organisational structure with clear, transparent and consistent lines of responsibility and accountability rules enabling effective ICT risk management;
  13. 13(e)
  14. 14the identification, monitoring and prompt reporting of material ICT-related incidents to financial entities, the management and resolution of those incidents, in particular cyber-attacks;

Lineage

treatyTFEU art. 288 (förordning)
act32022R2554
chapter
article33
paragraphs14
jurisdictionEuropean Union (EU)
supervisorFinansinspektionen — Sweden
national

Interface

callhttps://legal.exploreworldai.com/api/public/v1/agents/dora-2022-2554-33/run
methodGET
outputmatched, outcome, trace, missing, hash
Quota60 anrop per minut och adress, utan nyckel
stabilityRegelträdet versioneras. En ändring byter artefakthash, aldrig adress.

Hashes

textsha256:8a3b4c6c0422dfb8b2cfdd3a6d19b10522ff78eff3f9d555ba32ca6dae4855c9
scriptsha256:c9b1938cf25896a553bebac3e3e84936daf99f970d6c47f93f9918ea7c25a79d
enginesha256:0a4bd50d21f8ec9be383fc091511008b76ad61909cbfb674eab56fe567fbd7a0
agentsha256:b41b99e999984e12d63a03f347197b18e49126d607dcca478bd933f7133a178e
versionagent-engine-1+legal-2026-08-25 / b41b99e999984e12

Artefacts

No legal advice. Deterministisk regeluppslagning. Ingen juridisk rådgivning, inget efterlevnadsbeslut, ingen bedömning av ett enskilt ärende.

Citation: 32022R2554 art. 33, Tasks of the Lead Overseer. ExploreWorld Legal, https://legal.exploreworldai.com/agent/dora-2022-2554/artikel-33 (hämtad 2026-08-18, bevis sha256:6a588ee886bb87b6, bygge legal-2026-08-25).