ARTICLE
20 April 2023

Digital Operational Resilience Act (DORA) - CSSF Compliance Preparation Survey For Investment Fund Managers

AM
Arendt & Medernach

Contributor

About Arendt

Arendt combines the entire value chain of services dedicated to Asset Managers, Banks, Insurers, Public Institutions and Private Clients operating in Luxembourg.

-Legal & Tax
-Regulatory & Consulting
-Investor Services

Legal & Tax

We assist clients in structuring and running their business from a legal and tax standpoint across Luxembourg. Our teams directly serve international clients or work in close collaboration with foreign partner law firms.

Together with our regulatory consultants and investor services experts, we bridge the gap between legal/tax advice and its implementation. We deliver best-in-class services along our clients’ business life cycles.

The 450 legal experts of Arendt & Medernach have a wealth of experience in a wide variety of specialisations. Together, they are able to advise on a complete range of 15 complementary practice areas, including Investment Management, Private Equity, Banking and Corporate Law.

For each of the five DORA pillars, the CSSF survey asks whether the IFM has conducted a gap analysis, enquires about the gaps identified and asks whether mitigation plans are already in place...
Luxembourg Compliance
To print this article, all you need is to be registered or login on Mondaq.com.

For each of the five DORA pillars, the CSSF survey asks whether the IFM has conducted a gap analysis, enquires about the gaps identified and asks whether mitigation plans are already in place or intended to be put in place, as well as the planned timeline for implementation. The CSSF also requests IFMs to self-assess their level of DORA readiness.

In force since 16 January 2023, DORA creates a regulatory framework on digital operational resilience whereby European financial entities are required to ensure they can withstand, respond to and recover from all types of ICT-related disruptions and threats. DORA deals with a wide range of operational resilience topics, divided into 5 pillars:

  • ICT risk management
  • ICT-related incident management, classification and reporting
  • Digital operational resilience testing
  • Managing of ICT third-party risk
  • Information-sharing arrangements

The DORA rules will become fully applicable as from 17 January 2025. The designated European Supervisory Authorities are currently developing technical standards with which financial entities must comply, whilst national competent authorities will oversee compliance and enforce the regime as required.

DORA applies to a range of financial entities regulated at EU level. This includes most credit institutions, payment institutions, electronic money institutions, investment firms, managers of alternative investment funds and management companies, as well as insurance and reinsurance undertakings and intermediaries. Microenterprises are also within scope of DORA, subject to specific provisions. DORA also applies to ICT third-party service providers of digital and data services, including providers of cloud computing services, software, data analytics services and data centres.

To learn more about DORA implementation steps, click here_

Read our previous Newsflash to learn more information about DORA here_

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

ARTICLE
20 April 2023

Digital Operational Resilience Act (DORA) - CSSF Compliance Preparation Survey For Investment Fund Managers

Luxembourg Compliance

Contributor

About Arendt

Arendt combines the entire value chain of services dedicated to Asset Managers, Banks, Insurers, Public Institutions and Private Clients operating in Luxembourg.

-Legal & Tax
-Regulatory & Consulting
-Investor Services

Legal & Tax

We assist clients in structuring and running their business from a legal and tax standpoint across Luxembourg. Our teams directly serve international clients or work in close collaboration with foreign partner law firms.

Together with our regulatory consultants and investor services experts, we bridge the gap between legal/tax advice and its implementation. We deliver best-in-class services along our clients’ business life cycles.

The 450 legal experts of Arendt & Medernach have a wealth of experience in a wide variety of specialisations. Together, they are able to advise on a complete range of 15 complementary practice areas, including Investment Management, Private Equity, Banking and Corporate Law.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More