← Frameworks / Prudential Regulation

Solvency II Directive (2009/138/EC) — ICT and Security Risk

EU prudential regulation for insurance and reinsurance undertakings. Pillar 2 governance and risk management requirements include ICT risk, operational resilience, outsourcing controls, and key function holder accountability. Supplemented by EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) covering information security policy, logical security, cryptography, operations security, security monitoring, business continuity, and third-party ICT risk management.

Clause Title SP 800-53 Controls
Art.41(1) System of governance — general governance requirements
Art.41(3) System of governance — written policies
Art.42 Fit and proper requirements for persons running the undertaking
Art.44(1) Risk management — effective risk management system
Art.44(2) Risk management — coverage of risks including operational risk
Art.45 Own Risk and Solvency Assessment (ORSA)
Art.46 Internal control — compliance function
Art.47 Internal audit function
Art.48 Actuarial function
Art.49(1) Outsourcing — general requirements and oversight
Art.49(2) Outsourcing — critical or important operational activities or functions
Art.49(3) Outsourcing — data protection and confidentiality
DR.258 Delegated Regulation Art. 258 — general governance requirements
DR.259 Delegated Regulation Art. 259 — remuneration policy
DR.260 Delegated Regulation Art. 260 — risk management function
DR.266 Delegated Regulation Art. 266 — operational risk management including IT risk
DR.266-BCP Delegated Regulation Art. 266 — business continuity and disaster recovery
DR.266-DataSec Delegated Regulation Art. 266 — data security and information classification
DR.267 Delegated Regulation Art. 267 — investment risk management
DR.272 Delegated Regulation Art. 272 — outsourcing policy
DR.274 Delegated Regulation Art. 274 — contingency plans for outsourcing
EIOPA-Cloud-GL3 EIOPA Cloud Outsourcing Guidelines — due diligence and risk assessment
EIOPA-Cloud-GL7 EIOPA Cloud Outsourcing Guidelines — access and audit rights
EIOPA-Cloud-GL9 EIOPA Cloud Outsourcing Guidelines — data protection and data location
EIOPA-Cloud-GL11 EIOPA Cloud Outsourcing Guidelines — exit strategies and portability
EIOPA-ICT-4.1 EIOPA ICT Guidelines — ICT governance and strategy
EIOPA-ICT-4.2 EIOPA ICT Guidelines — ICT risk management framework
EIOPA-ICT-4.3 EIOPA ICT Guidelines — ICT asset management and classification
EIOPA-ICT-4.4 EIOPA ICT Guidelines — logical security and access control
EIOPA-ICT-4.5 EIOPA ICT Guidelines — physical security
EIOPA-ICT-4.6 EIOPA ICT Guidelines — network security
EIOPA-ICT-4.7 EIOPA ICT Guidelines — cryptography and key management
EIOPA-ICT-4.8 EIOPA ICT Guidelines — ICT operations management
EIOPA-ICT-4.9 EIOPA ICT Guidelines — ICT incident and problem management
EIOPA-ICT-4.10 EIOPA ICT Guidelines — business continuity management
EIOPA-ICT-4.11 EIOPA ICT Guidelines — ICT project management and change
Pillar3-Reporting Pillar 3 — supervisory reporting and public disclosure (data integrity)