> For the complete documentation index, see [llms.txt](https://www.mica.wtf/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.mica.wtf/eu-level/guidelines/jc-gl-2024-34-costs-losses.md).

# JC/GL/2024/34 — Joint Guidelines on the estimation of aggregate...

|                  |                                                                                                                                                                                    |
| ---------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Authority**    | Joint (ESAs)                                                                                                                                                                       |
| **Reference**    | JC/GL/2024/34                                                                                                                                                                      |
| **Legal basis**  | [Article 11(11)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-11-response-and-recovery) DORA                                |
| **Status**       | In force                                                                                                                                                                           |
| **Published**    | 5 June 2024                                                                                                                                                                        |
| **Applies from** | 19 May 2025                                                                                                                                                                        |
| **Source**       | [Landing page](https://www.eba.europa.eu/publications-and-media/press-releases/esas-consult-guidelines-estimation-aggregated-costs-and-losses-caused-major-ict-related)            |
| **Documents**    | [Guideline PDF](https://www.eba.europa.eu/sites/default/files/2024-07/48958acb-1c6d-40f0-9784-961713759972/JC%202024-34%20-%20Final%20report%20GL%20on%20costs%20and%20losses.pdf) |

JC 2024 34

5 June 2024

## Final Report

## Joint Guidelines

on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554

## Contents

| 1. Executive Summary | 1. Executive Summary | 3 |
| -------------------- | -------------------- | - |

Full table: see [document](https://www.eba.europa.eu/sites/default/files/2024-07/48958acb-1c6d-40f0-9784-961713759972/JC%202024-34%20-%20Final%20report%20GL%20on%20costs%20and%20losses.pdf).

4

5

5

8

8

9

9

9

9

9

9

## 1. Executive Summary

[Article 11(11)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-11-response-and-recovery) of Regulation 2022/2554 on digital operational resilience for the financial sector (DORA) mandates the European Supervisory Authorities (ESAs), to develop 'common guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents'. These Guidelines aim at harmonising the estimation by financial entities of their aggregated annual costs and losses caused by major information and communication technology (ICT)-related incidents according to [Article 11(10)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-11-response-and-recovery) DORA.

In view of the ESAs, this mandate is closely interlinked with the DORA mandates conferred to the ESAs under Article 18(3) on incident classification and under Article 20 on reporting of incidents as these also require an assessment of costs and losses of ICT-related incidents. Consequently, the ESAs seek to achieve consistency across these mandates to avoid contradictions, increase comparability of the reported figures under the different mandates and, in case the competent authorities request such information from the financial entities, reduce the reporting burden for financial entities. All the criteria in the RTS on classification, including, but not limited to, the one on 'economic impact', are designed to ensure proportionality, meaning that small financial entities are likely to classify ICT-related incidents as 'major' less frequently than bigger financial entities. Proportionality is thereby embedded in all other mandates that build on the classification of ICTrelated incidents as major, including these Guidelines.

In fulfilment of the mandate, the Guidelines therefore set out that financial entities:

* apply the same approach as the regulatory technical standard specifying the criteria for the classification of ICT-related incidents under [Article 18(3)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iii-ict-related-incident-classification-reporting/article-18-classification-of-ict-related-incidents) DORA for assessing gross costs and losses and to apply the same approach as the forthcoming technical standards on incident reporting under [Article 20](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iii-ict-related-incident-classification-reporting/article-20-harmonisation-of-reporting-content-and-templates) DORA for assessing the financial recoveries of major ICT-related incidents;
* include only those ICT-related incidents that have been classified as major and for which the financial entity has provided a final incident report according to [Article 19(4)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iii-ict-related-incident-classification-reporting/article-19-reporting-of-major-incidents)(c) DORA in the reference year, or submitted in previous years if it had an impact on the costs and losses of that reference year; and
* report the breakdown of the gross costs and losses and financial recoveries by major ICTrelated incident to substantiate the aggregate figures.

The ESAs conducted a public consultation on a draft version of the Guidelines from November 2023 to March 2024 and received seventy consultation responses. After assessing these responses, the ESAs decided to review their proposal how to set the reference year to allow for more flexibility for financial entities, that will also reduce their reporting burden. To further limit the reporting burden, the ESAs also decided to request only the estimation of gross costs and losses, not net costs and losses, as the competent authorities can calculate those by themselves.

## Next steps

The Joint Guidelines will be translated into the official EU languages and published on the ESAs websites. The deadline for competent authorities to report whether they comply with the Guidelines will be two months after the publication of the translations. The Guidelines should apply from 17 January 2025.

## 2. Background and rationale

## Background

1. Article 11(11) of Regulation 2022/2554 on digital operational resilience for the financial sector (DORA) mandates the European Supervisory Authorities (ESAs), which consist of the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA) and the European Securities and Markets Authority (ESMA), to develop 'common guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents'. 1 These Guidelines aim at harmonising the estimation by financial entities of their aggregated annual costs and losses caused by major information and communication technology (ICT)-related incidents according to [Article 11(10)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-11-response-and-recovery) DORA, which are then to be submitted by financial entities, other than microenterprises, to their competent authority (CA) upon its request. Costs and losses incurred by the financial entities from non-major ICT-related incidents are not in the scope of these Guidelines.
2. In fulfilment of the aforementioned mandate and related provisions and recitals, the ESAs published on 27 November 2023 a Consultation Paper (CP), which set out the ESA's proposals for the Guidelines. The CP laid out the proposed content on how to estimate the annual costs and losses, how to define the one-year period and which figures to use for the estimation of costs and losses. It concludes with a proposal on the aggregation and estimation of gross and net costs and losses incurred across major ICT-related incidents. A public hearing was held on 23 January 2023 before the end of the consultation period on 4 March 2024, by which time the ESAs had received seventy responses which were assessed in detail, as presented in the feedback table in section 4.2 of this Final Report.
3. The Rationale section below provides an overview of the key changes that have been made after the public consultation of the draft Guidelines originally proposed.

## Rationale

4. The respondents to the public consultation commented on all aspects of the proposed draft Guidelines. The key points raised that led to changes to the draft Guidelines are a) reviewing the reference year for which financial entities should provide an estimation to the competent authority; and b) limiting the costs and losses that should be reported to the competent authorities. These two points are discussed in this section. Further comments were received that led to clarifications in the Guidelines, but not to significant changes, as well as comments that did not lead to any changes. These comments and the ESAs' analyses of them are presented in detail in the feedback table in section 4.2.

[1 https://eur-lex.europa.eu/eli/reg/2022/2554/oj](https://eur-lex.europa.eu/eli/reg/2022/2554/oj)

## Reviewing the reference year for which financial entities should provide an estimation

5. Several respondents argued to allow for reporting by calendar year and based on supervisory reporting or internal risk management figures instead of reporting by financial year and based on financial statements, because:

* Financial accounts do not include the types of costs that are listed in the RTS on classification while data on operational risk losses do;
* Reporting requirements under the CRR operational risk framework and DORA should be harmonised;
* Asset managers already use annual cost estimates for risk management purposes on a calendar-year basis. Reporting for the financial year would lead to an additional burden for them.

6. The ESAs' initial proposal in the Consultation Paper aimed at limiting the reporting burden for financial entities, as many of them are not subject to regular reporting requirements like credit institutions that report on operational risks. The responses to the public consultation confirmed that these entities overwhelmingly support the possibility to base the estimations on accounting figures, for which it is necessary to stick to the accounting year.
7. Nevertheless, the ESAs acknowledge that especially for credit institutions and other financial entities that have already established an operational risk framework, it makes more sense to provide the reporting on already existing reporting requirements for operational risk.
8. Consequently, the ESAs have decided to amend the Guidelines to allow financial entities to choose which reference year they intend to use. However, once they have decided whether they will report based on the calendar year or the accounting year, financial entities should also provide future annual reports on the same type of year. If a financial entity wanted to change its decision, it should notify the competent authority, who would have a 2-month period to object to the change of decision. This approach to provide flexibility on which year to use will make it simpler for financial entities to choose the most appropriate and easily accessible data source they have. This will especially benefit financial entities that have such information available via their supervisory reporting, for instance credit institutions.

## Limiting the costs and losses that should be reported to the competent authorities

9. Some respondents argued to only include the gross costs while others argued to only include the net costs in the estimation. The same applies to the reporting of the gross and net costs and losses and to the reporting template. The gross costs are the costs or losses that the financial entity paid or booked. The net costs are a simple subtraction of financial recoveries from the gross costs and losses. As such, the ESAs are of the view that competent authorities can themselves calculate the net costs and losses. Consequently, the ESAs have arrived at the view that the requirement to include and report the net costs and losses can be deleted from

the Guidelines to simplify the reporting requirements for financial entities. However, the estimate of the financial recoveries has been maintained in the Guidelines, in addition to the gross costs and losses.

## 3. Joint Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents

## Status of these Joint Guidelines

This document contains Joint Guidelines issued pursuant to Article 16 of Regulation (EU) No 1093/2010[^1]; Article 16 of Regulation (EU) No 1094/2010[^2]; and Article 16 of Regulation (EU) No 1095/2010[^3] - 'the ESAs' Regulations'. In accordance with Article 16(3) of the respective ESAs' Regulations, competent authorities and financial institutions must make every effort to comply with the Guidelines.

Joint Guidelines set out the ESAs' view of appropriate supervisory practices within the European System of Financial Supervision or of how Union law should be applied in a particular area. Competent authorities to whom the Joint Guidelines apply should comply by incorporating them into their supervisory practices as appropriate (e.g. by amending their legal framework or their supervisory processes), including where the Joint Guidelines are directed primarily at institutions.

### Reporting Requirements

In accordance with Article 16(3) of the ESAs' Regulations, competent authorities must notify the respective ESA whether they comply or intend to comply with these Joint Guidelines/Recommendations, or otherwise with reasons for non-compliance, by 19.05.2025. In the absence of any notification by this deadline, competent authorities will be considered by the respective ESA to be non-compliant. Notifications should be sent to <compliance@eba.europa.eu>, <compliance@eiopa.europa.eu> and <DORA@esma.europa.eu> with the reference 'JC/GL/2024/34'. A template for notifications is available on the ESAs' websites. Notifications should be submitted by persons with appropriate authority to report compliance on behalf of their competent authorities.

Notifications will be published on the ESAs' websites, in line with Article 16(3).

## Title I - Subject matter, scope, addressees, and definitions

### Subject matter and Scope of application

1. These guidelines are aimed at fulfilling the mandate given to the ESAs under [Article 11(11)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-11-response-and-recovery) of Regulation (EU) 2022/2554[^4], to develop common guidelines on the estimation of aggregated annual costs and losses of major ICT-related incidents referred to Article 11(10) of that Regulation. These guidelines also specify a common template for the submission of the aggregated annual costs and losses.

### Addressees

2. These guidelines are addressed to competent authorities as defined in Article 46 of Regulation 2022/2554 and to financial institutions as defined in Article 4(1) of Regulation (EU) 1093/2010, Article 4(1) of Regulation (EU) 1094/2010 and Article 4(1) of Regulation (EU) 1095/2010 .

### Definitions

3. Terms used and defined in Regulation (EU) 2022/2554 have the same meaning in these guidelines.

## Title II- Implementation

### Date of application

4. These Guidelines apply from 19.05.2025.

## Title III- Provisions on the estimation of aggregated annual costs and losses of major ICT-related incidents

5. Financial entities should estimate the aggregate annual costs and losses of major ICT-related incidents by aggregating the costs and losses for major ICT-related incidents that fall within the reference year for which the competent authority requested the estimation. The financial entity may choose whether the reference year should correspond to either the completed calendar year, or to the completed accounting year of the financial entity for which the financial entity has finalised its financial statements. Once a financial entity has decided whether it will provide the estimation based on the calendar year or its accounting year, such a decision should be applied to future estimations of aggregated annual costs and losses. The financial entity may change that decision by notifying the competent authority, and provided that the competent authority does not object within two months of receiving the notification. Financial entities should not include costs and losses related to those incidents that fall before or after that reference year.
6. Financial entities should include in the estimation all ICT-related incidents that, irrespective of the reason, were classified as major in accordance with Commission Delegated Regulation \[OJ L, 2024/1772, 25.6.2024] 6 on incident classification and
7. (a) for which the financial entity has submitted a final report in accordance with [Article 19(4)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iii-ict-related-incident-classification-reporting/article-19-reporting-of-major-incidents)(c) Regulation (EU) 2022/2554 in the relevant reference year, or
8. (b) any incident for which the financial entity submitted in previous reference years a final report in accordance with [Article 19(4)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iii-ict-related-incident-classification-reporting/article-19-reporting-of-major-incidents)(c) of Regulation (EU) 2022/2554 that had a quantifiable financial impact on the financial entity in the relevant reference year.
9. Financial entities should estimate the aggregated annual costs and losses by applying the follow sequential steps:
10. (a) estimate the costs and losses of each major ICT-related incident as referred to in paragraph 6 individually. Those estimations should produce the gross costs and losses taking into account the types of costs and losses as set out in Article 7(1) and (2) of the Commission Delegated Regulation \[OJ L, 2024/1772, 25.6.2024];
11. (b) for each major ICT-related incident, financial entities should also estimate the financial recoveries as specified in Annex II to Commission Implementing Regulation \[OJ L, 2025/302, 20.2.2025];

6 Commission Delegated Regulation (EU) 2024/1772 of 13 March 2024 supplementing Regulation (EU) 2022/2554 of the European Parliament and of the Council with regard to regulatory technical standards specifying the criteria for the classification of ICT-related incidents and cyber threats, setting out materiality thresholds and specifying the details of reports of major incidents \[ OJ L, 2024/1772, 25.6.2024, ELI: <http://data.europa.eu/eli/reg\\_del/2024/1772/oj> ]

* (c) financial entities should aggregate the gross costs and losses and the financial recoveries across major ICT-related incidents.

8. As basis for the estimations, financial entities should refer to the costs, losses and financial recoveries that are reflected in their financial statements such as the profit and loss account, or where applicable in their supervisory reporting, of the relevant reference year. In their estimation, financial entities should also include accounting provisions that are reflected in their financial statements such as the profit and loss account of the relevant reference year. Where accurate data is not available, financial entities should base their estimation on other available data and information to the extent possible.
9. Financial entities should include adjustments on the costs and losses of an estimation that it submitted for a previous year in the estimation of the relevant reference year in which the adjustments are made.
10. Financial entities should include in the report of their estimation of the aggregated annual costs and losses also the breakdown of gross costs and losses and of financial recoveries for each major ICT-related incident that were included in the aggregation.
11. Financial entities should use the template in the Annex to submit to the competent authority the estimation of their aggregated annual costs and losses for the reference year. For each item under paragraph 6 and 9 that is included in the estimation of the reference year, financial entities should use the same incident reference codes provided by the financial entity as the ones used in the final report in accordance with [Article 19(4)](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-iii-ict-related-incident-classification-reporting/article-19-reporting-of-major-incidents)(c) of Regulation (EU) 2022/2554.

standard forms, templates, and procedures for financial entities to report a major ICT-related incident and to notify a significant cyber threat \[ OJ L, 2025/302, 20.2.2025, ELI: <http://data.europa.eu/eli/reg\\_impl/2025/302/oj> ]

## Annex: Reporting template for gross costs and losses and financial recoveries in a reference year

| Name of the financial entity                                     | Name of the financial entity                                     | Name of the financial entity                                     |                                                                               |                                                                   |
| ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ----------------------------------------------------------------------------- | ----------------------------------------------------------------- |
| Legal Entity Identifier                                          | Legal Entity Identifier                                          | Legal Entity Identifier                                          |                                                                               |                                                                   |
| Start and end date of the reference year of the financial entity | Start and end date of the reference year of the financial entity | Start and end date of the reference year of the financial entity |                                                                               |                                                                   |
| Currency                                                         | Currency                                                         | Currency                                                         |                                                                               |                                                                   |
| Number of incident                                               | Date of the submission of the final incident report              | Incident reference number                                        | Gross costs and losses of the incident in the reference year (1000s of units) | Recoveries of the incident in the reference year (1000s of units) |
| 1                                                                |                                                                  |                                                                  |                                                                               |                                                                   |
| 2                                                                |                                                                  |                                                                  |                                                                               |                                                                   |
| ...                                                              |                                                                  |                                                                  |                                                                               |                                                                   |
| Total for reference year                                         | -----------                                                      | -----------                                                      |                                                                               |                                                                   |

## 4. Accompanying documents

### 4.1 Cost- Benefit Analysis / Impact Assessment

As per Article 16(2) of Regulation (EU) No 1093/2010 (EBA Regulation), 1093/2010 (EIOPA Regulation) and 1095/2010 (ESMA regulation), any guidelines and recommendations developed by the ESAs shall be accompanied by an Impact Assessment (IA) which analyses 'the potential related costs and benefits'.

This analysis presents the IA of the main policy options included in this Consultation Paper (CP) on Joint Guidelines (RTS) on the estimation of aggregated annual costs and losses caused by major ICTrelated incidents.

#### A. Problem identification

According to [Article 11](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-11-response-and-recovery) of the Regulation 2022/2554 (DORA), financial entities, other than microenterprises, shall report to the competent authorities, upon their request, an estimation of aggregated annual costs and losses caused by major ICT-related incidents.

The costs and losses can be measured in various ways and also may be estimated differently across sectors and financial entities. Without further specifications, the data on costs and losses reported by financial entities may be based on different methodologies and assumptions. These divergences can lead to a lack of comparability of data across financial entities and would undermine the usefulness of this information for the Competent Authorities with respect to their supervisory role.

#### B. Policy objectives

The general objective of the guidelines is to harmonise across sectors the estimation of the aggregated annual costs and losses caused by major ICT-related incidents to be reported to the CAs.

More specific objectives of the guidelines are to enable CAs to use the reported aggregated costs and losses to improve their assessment of the efficiency of the ICT risk management framework of financial entities.

#### C. Baseline scenario

The baseline scenario is the situation when the current definitions and taxonomy is kept, without further changes or further harmonisation.

With the entry into force of DORA, financial entities must comply with [Article 11](https://www.mica.wtf/dora/digital-operational-resilience-act/chapter-ii-ict-risk-management/article-11-response-and-recovery) of DORA. The above legal requirements form the baseline scenario of the impact assessment, i.e. the impact caused by DORA is not assessed within this impact assessment, which focuses only on areas where further specifications have been provided in the Guidelines.

The following aspects have been considered when developing the Guidelines.

#### Policy issue 1: Start and end dates for aggregating costs and losses

## Options considered

Option A: CAs can specify start and end date, which may have to be calculated on other figures than the profit and loss statements

Option B: Start and end date of accounting years, based on the profit and loss statement of that accounting year

Option C: The financial entities can decide themselves whether they want to set the start and end dates of the reference year according to the calendar year or according to their accounting year, but they would need to stick to that decision.

Option A, whereby the CA is free to specify the start and end date for the estimation, allows the CA to decide which period is most relevant for its purposes. The disadvantage of this approach is that depending on the CA request, the financial entities will need to recalculate the costs for the respective periods.

Option B would be to set the start and end date to be identical with the accounting year of the financial entity. The advantage of this approach is that it would allow financial entities to base their estimates on existing figures from the profit and loss statement. The reporting of costs on losses based on the profit and loss statement will thus be the easiest to implement for the financial entity. However, as some financial entities already calculate the figures for their operational risk management based on the calendar year, this option would impose that these financial entities recalculate the figures for their accounting years, if that is not identical to the calendar year.

Option C would leverage on the most conveniently available data for financial entities as those that have already an operational risk management framework in place can re-use the data from that. Other financial entities that do not have such a framework in place could rely more on using their accounting figures, which will be a source of information for all financial entities. As financial entities should report consistently by calendar or accounting year over the years, this will ensure that the figures will be coherent for each financial entity over time, since it will rely on a similar established estimation methodology. As a result, in cases when data will be requested over several years, the information provided will be comparable and consistent over time.

Considering the above arguments, Option C is the preferred one.

#### Policy issue 2: Granularity of reported data

## Options considered

Option A: Aggregated data per year only

## Option B: Also report the breakdown of the data per year by incident

The mandate requires that financial entities report data on aggregated costs and losses, which would justify Option A. While this option entails reporting of one datapoint per financial entity per year, this figure may not be meaningful for the CA in case they would request the financial entities to report their estimations, since it may hide information on incidents of various sizes and incidents spanning over several years, for which the costs will be split across periods.

Option B, whereby costs and losses are reported at incident level, has several advantages:

* -Costs and losses at incident level are more meaningful for the CA being reported separately for each incident;
* -In case of incidents spanning over multiple years, the CA would be able to reconstruct the chain of losses from one single incident incurred over several periods.

Furthermore, Option B, despite requiring the reporting of disaggregated data, will not create additional material burden, since the raw data will be estimated at incident level, and therefore will already exist in a disaggregated form.

Option B is therefore preferred.

## Cost and benefit analysis

Overall, the guidelines are expected to provide advantages to both financial entities and competent authorities by clarifying the way aggregated costs and losses should be reported, without adding any additional material burden.

|                       | Advantages                                                                                                           | Disadvantages |
| --------------------- | -------------------------------------------------------------------------------------------------------------------- | ------------- |
| Financial entities    | Clarity on the way data is estimated                                                                                 | None          |
| Competent authorities | Ensuring comparability of data across sectors and Member States Ensuring the data is meaningful to the CA and usable | None          |

### 4.2 Feedback on the public consultation

The ESAs publicly consulted on the draft proposal contained in the Consultation paper.

The consultation period lasted for more than three months and ended on 4 March 2024. 70 responses were received.

This section presents a summary of the key points and other comments arising from the consultation, the analysis and discussion triggered by these comments and the actions taken to address them if deemed necessary. In many cases several industry bodies made similar comments or the same body repeated its comments in the response to different questions. In such cases, the comments, and ESAs' analysis are included in the section of this paper where ESAs consider them most appropriate.

Changes to the draft Guidelines have been incorporated as a result of the responses received during the public consultation.

## Summary of the responses to the consultation and the ESAs' analysis

| Topic | Summary of responses received | ESAs' analysis | Proposed amendments to the GL |
| ----- | ----------------------------- | -------------- | ----------------------------- |

Full table: see [document](https://www.eba.europa.eu/sites/default/files/2024-07/48958acb-1c6d-40f0-9784-961713759972/JC%202024-34%20-%20Final%20report%20GL%20on%20costs%20and%20losses.pdf).

### Table

| Topic | Summary of responses received | ESAs' analysis | Proposed amendments to the GL |
| ----- | ----------------------------- | -------------- | ----------------------------- |

Full table: see [document](https://www.eba.europa.eu/sites/default/files/2024-07/48958acb-1c6d-40f0-9784-961713759972/JC%202024-34%20-%20Final%20report%20GL%20on%20costs%20and%20losses.pdf).

### Table

| Topic | Summary of responses received | ESAs' analysis | Proposed amendments to the GL |
| ----- | ----------------------------- | -------------- | ----------------------------- |

Full table: see [document](https://www.eba.europa.eu/sites/default/files/2024-07/48958acb-1c6d-40f0-9784-961713759972/JC%202024-34%20-%20Final%20report%20GL%20on%20costs%20and%20losses.pdf).

### Table

| Topic | Summary of responses received | ESAs' analysis | Proposed amendments to the GL |
| ----- | ----------------------------- | -------------- | ----------------------------- |

Full table: see [document](https://www.eba.europa.eu/sites/default/files/2024-07/48958acb-1c6d-40f0-9784-961713759972/JC%202024-34%20-%20Final%20report%20GL%20on%20costs%20and%20losses.pdf).

### Table

| Summary of responses received | ESAs' analysis | Proposed amendments to the GL |
| ----------------------------- | -------------- | ----------------------------- |

Full table: see [document](https://www.eba.europa.eu/sites/default/files/2024-07/48958acb-1c6d-40f0-9784-961713759972/JC%202024-34%20-%20Final%20report%20GL%20on%20costs%20and%20losses.pdf).

### Table

| Topic | Summary of responses received | ESAs' analysis | Proposed amendments to the GL |
| ----- | ----------------------------- | -------------- | ----------------------------- |

Full table: see [document](https://www.eba.europa.eu/sites/default/files/2024-07/48958acb-1c6d-40f0-9784-961713759972/JC%202024-34%20-%20Final%20report%20GL%20on%20costs%20and%20losses.pdf).

### Table

| Topic | Summary of responses received | ESAs' analysis | Proposed amendments to the GL |
| ----- | ----------------------------- | -------------- | ----------------------------- |

Full table: see [document](https://www.eba.europa.eu/sites/default/files/2024-07/48958acb-1c6d-40f0-9784-961713759972/JC%202024-34%20-%20Final%20report%20GL%20on%20costs%20and%20losses.pdf).

### Table

| Topic | Summary of responses received | ESAs' analysis | Proposed amendments to the GL |
| ----- | ----------------------------- | -------------- | ----------------------------- |

Full table: see [document](https://www.eba.europa.eu/sites/default/files/2024-07/48958acb-1c6d-40f0-9784-961713759972/JC%202024-34%20-%20Final%20report%20GL%20on%20costs%20and%20losses.pdf).

### Table

| Topic | Summary of responses received | ESAs' analysis | Proposed amendments to the GL |
| ----- | ----------------------------- | -------------- | ----------------------------- |

Full table: see [document](https://www.eba.europa.eu/sites/default/files/2024-07/48958acb-1c6d-40f0-9784-961713759972/JC%202024-34%20-%20Final%20report%20GL%20on%20costs%20and%20losses.pdf).

### Table

| Topic | Summary of responses received | ESAs' analysis | Proposed amendments to the GL |
| ----- | ----------------------------- | -------------- | ----------------------------- |

Full table: see [document](https://www.eba.europa.eu/sites/default/files/2024-07/48958acb-1c6d-40f0-9784-961713759972/JC%202024-34%20-%20Final%20report%20GL%20on%20costs%20and%20losses.pdf).

[^1]: Regulation (EU) No 1093/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Banking Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/78/EC, (OJ L 331, 15.12.2010, p.12)

[^2]: Regulation (EU) No 1094/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Insurance and Occupational Pensions Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/79/EC, ( OJ L 331, 15.12.2010, p. 48-83)

[^3]: Regulation (EU) No 1095/2010 of the European Parliament and of the Council of 24 November 2010 establishing a European Supervisory Authority (European Securities and Markets Authority), amending Decision No 716/2009/EC and repealing Commission Decision 2009/77/EC, (OJ L 331, 15.12.2010, p. 84-119)

[^4]: Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011, ( OJ L 333, 27.12.2022, p. 1-79)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://www.mica.wtf/eu-level/guidelines/jc-gl-2024-34-costs-losses.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
