Source: OJ L, 2024/1773, 25.6.2024

Current language: FR

Article 10 Sortie et résiliation d’accords contractuels


Summary What does Article 10 of the RTS on ICT third-party service provider policy say?

This article closes out the lifecycle requirements for contractual arrangements introduced in Article 4 by addressing the exit phase.

It requires that the policy includes documented exit plans for each contractual arrangement, and that those plans are periodically reviewed and tested.

The article also sets out the quality standards an exit plan must meet, ensuring that plans are grounded in reality rather than being purely theoretical exercises.

Important points:

  • Include a documented exit plan for each contractual arrangement within the policy, covering scenarios such as service interruptions, failed delivery, and unexpected termination.
  • Periodically review and test each documented exit plan.
  • Each exit plan must be realistic, feasible, based on plausible scenarios and reasonable assumptions, and include an implementation schedule compatible with the exit and termination terms in the contractual arrangements.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

  1. La politique exige que chaque accord contractuel s’accompagne d’un plan de sortie documenté et que ce plan soit régulièrement réexaminé et testé. Il est tenu compte, lors de l’établissement de ce plan de sortie, des éléments suivants:

    1. interruptions de service imprévues et persistantes;

    2. prestation de services défaillante ou inadaptée;

    3. résiliation imprévue de l’accord contractuel.

  2. Le plan de sortie est réaliste, applicable, fondé sur des scénarios plausibles et des hypothèses raisonnables et comporte un calendrier prévisionnel de mise en œuvre compatible avec les conditions de sortie et de résiliation définies dans l’accord contractuel.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod