Consequences of the FASTER Directive: DORA, platform risk and operational resilience
FASTER
By Ross McGill
Ross is the founder and chairman of TConsult. He has spent over 26 years working in the withholding tax landscape with companies developing tax reclaim software and operating outsource tax reclamation services.
Ross not only sees the big picture but is also incredibly detail oriented. He can make even the most complex issues simple to understand. He has authored 10 books (including two second editions) on various aspects of tax, technology, and regulation in financial services, making him one of the leading authorities in the world of tax.
This the second post in our three part series on the unintended consequences of the FASTER Directive. You can read our earlier post about FASTER and GDPR here.
As financial institutions prepare for the FASTER Directive, many will naturally look to technology platforms to manage the complexity of reporting, validation and payment-chain aggregation.
That creates an important question that extends beyond tax reporting. If FASTER reporting becomes platform-based, how does the Digital Operational Resilience Act (DORA) apply?
The challenge
FASTER introduces two reporting models: direct reporting and indirect reporting. These fundamentally change how Certified Financial Intermediaries (CFIs) exchange information.
Figure 1. FASTER Reporting modalities.
Why FASTER is driving platform adoption
In such a complex regulatory environment, it is likely that a platform-based technological solution will be devised either by an independent vendor or by one of the CSDs or multi-national withholding agents, not least to address security issues stemming from the regular transfer of such large amounts of data up multiple chains of payment, but more likely as a commercial offering.
Any firm, whether they are a CFI or a third-party vendor, could have significant exposure to DORA if they are operating such a reporting platform. Such platforms would be classified as an ICT third-party service provider under DORA. One could surmise that a FASTER reporting platform solution would include the following components:
data ingestion from CFIs and N-CFIs;
validation against the FASTER schema;
eTRC / residence-evidence checks;
declaration acquisition and validation;
payment-chain aggregation;
relief-at-source or quick-refund workflow management;
CFI-to-CFI transmission;
reporting file generation;
submission support to the SMSCA;
retention and audit-trail functionality;
exception management and correction workflows.
When does a FASTER platform become a DORA ICT service?
DORA requires financial entities to maintain a register of information covering contractual arrangements for ICT services provided by ICT third-party service providers. The European Banking Authority (EBA) indicates that all in-scope financial entities must have a comprehensive register of contractual arrangements with ICT third-party service providers.
The DORA obligations platform providers should expect
Given that FASTER is a Council Directive and DORA is a regulation and that penalties apply, a FASTER Reporting platform would reasonably be considered a critical ICT third-party provider and potentially a designated critical ICT third-party provider. This means a FASTER platform provider should expect to be recorded in the CFI’s DORA register, risk-assessed, classified by criticality, monitored and contractually controlled. This will pose significant problems for any firm planning to implement such a platform (See table 1) not least because of the potential increased oversight by CFIs and/or direct oversight and possible periodic penalty payments up to 1% of average daily worldwide turnover in the preceding business year if the platform becomes “designated” critical ICT third-party provider by any of the three European Supervisory Authorities (ESAs).
Anyone considering a platform solution would have to consider DORA. Although FASTER is a tax reporting framework and DORA is an operational resilience regulation, any platform used to collect, validate, aggregate, transmit and evidence FASTER reporting data is likely to constitute an ICT service where it is supplied to DORA-regulated financial entities. The platform provider would therefore likely be treated as an ICT third-party service provider by its CFI customers. This does not mean that every FASTER platform provider will automatically become a designated critical ICT third-party provider under DORA. However, if a platform becomes widely used by major CFIs, withholding agents, custodians or CSDs across multiple Member States, particularly in the indirect reporting model, it could create concentration and substitutability concerns and may become a candidate for critical third-party designation.
Table 1: FASTER Reporting platforms DORA contract exposure
DORA contract area
FASTER platform implication
Service description
Definition of exactly which FASTER functions the platform performs: validation, aggregation, reporting, storage, portal transmission, etc.
Data location
Identification of where investor, tax residence, payment-chain and reporting data is processed and stored.
Availability and resilience
Specify uptime, recovery time, disaster recovery and business continuity, especially around dividend-payment deadlines.
Data integrity
Define controls preventing corruption, duplication, truncation, mapping errors or unauthorised changes to FASTER reports.
Confidentiality and security
Define encryption, access control, privileged access, audit logs and segregation of client data.
Incident support
Identify rapid notification and assistance if an ICT incident affects FASTER reporting or personal data.
Authority cooperation
Ensure cooperation with financial regulators, tax authorities and potentially DORA supervisors.
Exit and portability
Ensure the ability to return or migrate FASTER data in a usable format if the platform fails or is terminated.
Subcontracting
Identify restrictions and transparency around cloud providers, data processors and offshore support teams.
Platform adoption creates new operational risks
Many market participants will look to technology platforms as the practical solution to FASTER. That is understandable. The regime will require data consumption, validation, aggregation, workflow management, reporting, correction handling, storage and auditability. These functions are difficult to perform consistently through manual processes, particularly for firms below the largest custody and withholding-agent tier.
However, platform solutions introduce their own risk. A CFI, CSD or ICSD that builds a FASTER platform for its own internal use may primarily face internal governance, cyber-security and operational resilience obligations. Once that platform is offered to other CFIs, it may become an ICT third-party service from the perspective of those users. The provider should then expect enhanced contractual scrutiny, risk assessment, audit rights, data-location requirements, incident obligations, exit planning and resilience expectations.
If a single platform becomes widely used by major CFIs, withholding agents, CSDs or ICSDs across multiple Member States, the risk profile changes again. The platform may become a point of operational concentration. In that case, a failure, outage, cyber-incident, data corruption event or service-provider failure could affect not only individual firms but the functioning of FASTER reporting across a market or group of markets.
A vendor-led platform faces the same issue. To achieve market adoption, it will probably need one or more major CFIs, withholding agents, CSDs or ICSDs as anchor clients. If successful, it may become a de facto back office for FASTER processing. That may solve individual firm capability problems, but it also concentrates operational, cyber, data-quality and regulatory dependency in a smaller number of providers.
Could tokenisation and DLT help?
Platform providers may also explore tokenisation or permissioned DLT-style controls as part of the FASTER operating model. The most useful application would not be the creation of a tradable tax token or the publication of investor data to a shared ledger. It would be the creation of a controlled evidence layer: a way of proving that a particular data package, entitlement claim, residence-evidence check or correction event existed at a particular time and moved through identified participants in the chain. That could assist with audit trails, reconciliation, dispute resolution and regulatory review. However, it would also increase the importance of governance, access control, data-location rules, retention policy, cyber-security and DORA analysis.
FASTER is also a DORA challenge
FASTER may ultimately accelerate the development of shared reporting platforms across Europe. But platform adoption also creates concentration risk, third-party dependency and operational resilience obligations that fall squarely within DORA.
Firms evaluating FASTER solutions therefore need to think beyond tax reporting. Vendor governance, resilience testing, contractual oversight and ICT risk management will become just as important as technical reporting capability.
In the final part of our three part series, we will explore the data quality challenges that relate to FASTER. And they are many…
Be ready for the future of cross-border tax compliance
The EU FASTER Directive will reshape how withholding tax relief is managed across Europe.
Our experts can help you understand what’s coming, prepare your institution for change, and participate meaningfully in shaping the rules before they take effect.