Digital Operational Resilience Act (DORA)
Table of Contents
Chapter I – General provisions
Chapter II – ICT risk management
Chapter III – ICT-related incident management, classification and reporting
Chapter IV – Digital operational resilience testing
Chapter V – Managing of ICT third-party risk
Chapter VI – Information-sharing arrangements
Chapter VII – Competent authorities
Chapter VIII – Delegated acts
Chapter IX – Transitional and final provisions
Recitals (106)
Chapter IX – Transitional and final provisions
Article 59
Amendments to Regulation (EC) No 1060/2009
Credit Rating Agencies Regulation (CRA Reg) is amended as follows:
(1) in Annex I, Section A, point 4, the first subparagraph is replaced by the following:
‘A credit rating agency shall have sound administrative and accounting procedures, internal control mechanisms, effective procedures for risk assessment, and effective control and safeguard arrangements for managing ICT systems in accordance with Digital Operational Resilience Act (DORA) of the European Parliament and of the Council.
(2) in Annex III, point 12 is replaced by the following:
‘12. The credit rating agency infringes Article 6(2), in conjunction with point 4 of Section A of Annex I, by not having sound administrative or accounting procedures, internal control mechanisms, effective procedures for risk assessment, or effective control or safeguard arrangements for managing ICT systems in accordance with Regulation (EU) 2022/2554; or by not implementing or maintaining decision-making procedures or organisational structures as required by that point.’.
Related Recitals
Recitals providing context for this provision
No related recitals identified yet.