Source: OJ L, 2024/1505, 30.5.2024

Current language: EN

Article 1 Estimation of the expenditures of the Lead Overseers when performing their oversight duties


Summary What does Article 1 of the Oversight fees say?

This foundational article establishes how the Lead Overseer and the other European Supervisory Authorities must calculate the overall annual costs of their oversight activities, as this figure directly determines the total oversight fees that will be charged to critical ICT third-party service providers.

It sets out the cost categories that must be factored in, covering the full lifecycle of oversight activity from the initial designation of providers as critical through to the governance of the oversight framework itself.

Important points:

  • The Lead Overseer and the other European Supervisory Authorities are required to estimate overall annual costs each year, and this estimate is the direct basis for the oversight fees charged.
  • The cost estimation must cover both direct and indirect costs, spanning designation, appointment, active oversight, follow-up on recommendations, and framework governance.
  • The overall annual costs estimated under this article feed directly into the fee calculation methodology set out in the subsequent articles of this regulation.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. In each year, the Lead Overseer and the other European Supervisory Authorities shall estimate the overall annual costs that are expected to be incurred for the performance of their oversight duties. The amount of the overall annual costs estimated shall be the basis for determining the overall amount of oversight fees charged.

    1. When estimating the annual overall costs, the Lead Overseer shall take into account the following direct and indirect costs:

      1. costs related to the designation of ICT third-party service providers as critical;

      2. costs related to the appointment of the Lead Overseer;

      3. costs related to the actual oversight of critical ICT third-party service providers, including the following:

        1. costs related to the work carried out by the joint examination team;

        2. costs of advice provided by independent experts;

      4. costs related to the follow-up of the recommendations issued by the Lead Overseers in accordance with Article 35(1), point (d), of Regulation (EU) 2022/2554;

      5. costs related to the governance of the oversight framework.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod