Skip to main content
Version status: In force | Document consolidation status: Assimilated law updated to reflect all known changes
Version date: 31 December 2020 - onwards
Version 2 of 2

Article 76 Strategy and policy

1. A CSD shall have a business continuity policy and associated disaster recovery plan that is:

(a) approved by the management body;

(b) subject to audit reviews that shall be reported to the management body.

2. A CSD shall ensure that the business continuity policy:

(a) identifies all its critical operations and IT systems and provides for a minimum service level to be maintained for those operations;

(b) includes the CSD's strategy and objectives to ensure the continuity of operations and systems referred to in point (a);

(c) takes into account any links and interdependencies to at least:

(i) users;

(ii) critical utilities and critical service providers;

(iii) other CSDs and third-country CSDs;

(iv) other market infrastructures;

(d) defines and documents the arrangements to be applied in the event of a business continuity emergency or major disruption of the CSD's operations in order to ensure a minimum service level of critical functions of the CSD;

(e) identifies the maximum acceptable period of time which critical functions and IT systems may be out of use.