Skip to content
CONTRACTUAL OBLIGATIONS

Non-critical ICT third-party provider

ICT provider not designated as critical, but whose services support important functions of a financial entity.

Download this sheet to share or keep it.

Download as PDF

Your obligations

  • 1

    Compliance with the minimum contractual clauses imposed by financial clients: audit rights, exit plans, incident notification (Art. 30).

    These clauses must be included in the contract from the moment it is signed; they cannot be added later in the event of a review.

  • 2

    Cooperation in resilience testing exercises requested by clients.

    The provider may be asked to take part in continuity or failover tests organised by its financial clients.

  • 3

    Documentation of the ICT subcontracting chain, where applicable.

    If the provider itself uses subcontractors, they must be identified and disclosed to the financial client.