GOV-028 Regulatory Cooperation and Supervisory Access
Description
A named role owns contact with the authorities that supervise the organisation's customers, and a documented procedure states how a request from such an authority, or from a resolution authority acting for one of them, is received, verified, escalated and answered within a committed period. The procedure states the access to data relating to the service, and the access to the premises the service is provided from, that is granted to a customer's auditors and to its supervising authority, and it names whether that commitment reaches sites a subcontractor operates. A register records each request received with the authority making it, the customer it concerned, the date answered and what was provided, and a response outside the committed period carries a recorded reason. A recorded review establishes that no term of a customer agreement and no operating practice in force prevents that access or contravenes a restriction the authority has placed on the customer's activities.
Rationale
The counterparty is a supervisor the organisation has no contract with and no relationship with, reaching it through a customer it does have both with. Without a named owner the request lands on an account manager or a sales team and is answered late or not at all, which is the failure the control exists to stop. The premises limb is the expensive one: it is a facilities commitment as much as a compliance one, and a provider operating from leased offices or co-location space has to know before the request arrives whether it can admit anyone. Provider seat (ADR-031): what is written is the duty the organisation owes as the supplier of the service, and the customer's own regulatory obligations are not written here. Boundary with VND-012: that control governs a compelled disclosure of customer data under a legal instrument, narrowed and approved, with the customer notified unless notification is prohibited. GOV-010 records the obligation and the contract that transmits it, GOV-020 produces the independent assessment a supervisor often reads first and GOV-021 governs the internal audit function; none of them answers the authority. VND-014 states the audit and inspection rights granted; GOV-028 answers the supervisor who exercises one.
Applicability (9 profiles)
The provider seat is what brings a customer's supervisor to the organisation: the duty arrives through a customer contract rather than through a law binding the organisation directly. A provider whose customers are unregulated still holds the row, because what is tested is that the route exists, that the access is committed and that no contract term obstructs it. The register may legitimately be empty for a period, in which case the route is tested instead.
A deployer is the customer in this relationship, so the supervisory access it needs is its provider's: contracted under VND-002, obtained with the service under VND-004 and reviewed under VND-006. Where the deployer supplies a service of its own to a regulated customer, the row is its own and reads as it does on saas-ai-provider.
The provider seat is what brings a customer's supervisor to the organisation: the duty arrives through a customer contract rather than through a law binding the organisation directly. A provider whose customers are unregulated still holds the row, because what is tested is that the route exists, that the access is committed and that no contract term obstructs it. The register may legitimately be empty for a period, in which case the route is tested instead.
On the base the reason for this control is the provider seat: a customer's supervisor reaches the organisation through the customer's contract. Art.21 removes the intermediary. A competent authority addresses a reasoned request to the provider itself and is owed the information and documentation demonstrating conformity with Section 2, in an official Union language the Member State indicates, plus access to the Art.12(1) logs the provider controls. The register this control keeps therefore holds requests with no customer in them and the committed response period is measured against a counterparty that needs no contract to ask. The reason code moves from role-duty to risk-class-duty for that reason. AIG-043 holds the case record and the conformity evidence; GOV-028 holds the route, the named owner and the review that no customer term obstructs the access.
A deployer is the customer in this relationship, so the supervisory access it needs is its provider's: contracted under VND-002, obtained with the service under VND-004 and reviewed under VND-006. Where the deployer supplies a service of its own to a regulated customer, the row is its own and reads as it does on saas-ai-provider.
The provider seat is what brings a customer's supervisor to the organisation: the duty arrives through a customer contract rather than through a law binding the organisation directly. A provider whose customers are unregulated still holds the row, because what is tested is that the route exists, that the access is committed and that no contract term obstructs it. The register may legitimately be empty for a period, in which case the route is tested instead.
This is the control the instrument creates. Art. 30(2)(g) puts full cooperation with the customer's competent authorities and resolution authorities, including persons they appoint, into every contractual arrangement rather than only those covering critical or important functions, so it reaches the whole EU financial customer base. RTS 2024/1773 Art. 3(8) adds the statements the arrangement carries: it neither prevents effective supervision nor contravenes a supervisory restriction, it requires cooperation with the competent authorities, and it gives the financial entity, its auditors and the competent authorities effective access to data and to premises. Premises, not systems, which makes it a facilities commitment as much as a compliance one. Arts. 31 to 44 remain excluded to a designated provider under the condition already recorded against this profile.
The provider seat is what brings a customer's supervisor to the organisation: the duty arrives through a customer contract rather than through a law binding the organisation directly. A provider whose customers are unregulated still holds the row, because what is tested is that the route exists, that the access is committed and that no contract term obstructs it. The register may legitimately be empty for a period, in which case the route is tested instead.
The provider seat is what brings a customer's supervisor to the organisation: the duty arrives through a customer contract rather than through a law binding the organisation directly. A provider whose customers are unregulated still holds the row, because what is tested is that the route exists, that the access is committed and that no contract term obstructs it. The register may legitimately be empty for a period, in which case the route is tested instead.
Framework Mappings (3)
| DORA-Art.30.2.g | Cooperation with competent and resolution authorities | full |
| DORA-RTS-2024/1773-Art.3.8 | Statements the contractual arrangement must carry | partial |
| EU-AI-Art.21 | Provider Obligations — Cooperation with Competent Authorities | informative |
Evidence (2)
Regulatory cooperation procedure for requests from the authorities that supervise the organisation's customers, naming the accountable role, the verification step, the escalation path, the committed response period and the data and premises access granted.
Example: Supervisory Request Handling Procedure v2.0, approved by the General Counsel on 9 March 2026.
Test: Verify: (1) the procedure names the accountable role and the escalation path that reaches it from wherever a request first lands, (2) it states how the authority and the mandate it acts under are verified before anything is released, (3) it states the period the organisation commits to respond in, (4) it states the access granted to data relating to the service and to the premises the service is provided from, and says whether sites a subcontractor operates are inside that commitment, (5) a recorded review of the customer agreement template and of the operating practices the procedure depends on shows no term that would obstruct the access, rather than the procedure asserting that none exists.
Register of requests received from authorities supervising the organisation's customers, with the customer concerned, the verification performed, the response date and what was provided.
Example: Supervisory request register 2026-H1, exported 3 July 2026, four requests from two authorities.
Test: Verify: (1) each entry names the authority, the customer whose supervision it concerned, the date received, the date answered and what was provided, (2) the verification of the authority and its mandate is recorded as completed before anything was released, (3) each response falls inside the committed period or carries a recorded reason, (4) a request that arrived through an account or sales channel appears in the register with the date it reached the accountable role, so the escalation path is shown working rather than described, (5) where no request was received in the period, a record states that and a test of the route was performed and dated instead.
Questions (3)
Is a named role accountable for requests from the authorities that supervise the organisation's customers?
Answer for the authority that supervises a customer, not for the organisation's own regulator and not for a law enforcement demand, which is the vendor data request control. A role named in a procedure nobody has routed a request through is still a yes; a request handled ad hoc by whoever received it is a no.
Which of the following does the procedure cover?
Options follow the order a request moves through, from arrival to the record left behind. The last item is the one most often missing: a contract that grants access and an operating practice that makes it impossible are a common pairing, and only a review that reads both together finds it.
What access to premises is committed to an authority supervising a customer?
Options run from the widest commitment to the narrowest. Answer on what the published terms actually commit, not on what would probably be agreed. A commitment that stops at the organisation's own sites is the second option even where every site it operates is covered.