← Back to DORA Library
EUFinalJC 2024 34

GL on Cost & Loss Estimation

Joint Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554

ESAs (Joint Committee of EBA, ESMA, EIOPA)
Updated Jun 5, 2024
vJC 2024 34

Abstract

Joint Guidelines issued by the European Supervisory Authorities specifying methodologies and reporting templates for estimating aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554. The guidelines define scope, reference years, aggregation methods, treatment of recoveries, and reporting templates to be submitted to competent authorities.

Key Takeaways

  • Provides a harmonised methodology for estimating aggregated annual costs and losses from major ICT-related incidents under DORA.
  • Requires financial entities to aggregate gross costs, losses, and financial recoveries for incidents classified as major.
  • Specifies that estimations should be based on financial statements or other available data where precise data is not available.
  • Defines reporting requirements, including use of a standard template and incident reference identifiers.
  • Applies to competent authorities and financial entities, with expected application from 2025.

Keywords

DORAmajor ICT-related incidentscost estimationfinancial lossesincident reportingJC 2024 34aggregated annual costsESAs guidelines

Need DORA-Aligned AI Architecture?

We build AI systems that satisfy DORA requirements from day one. Audit trails, governance, exit readiness - built in, not bolted on.

Schedule Architecture Reviewviktor@intellectumlab.com | Response within 24 hours