1. Where the automated processing laid down in Article 20(2) to (5) has reported one or several hits, the application shall be processed manually by the ETIAS National Unit of the Member State responsible. That ETIAS National Unit shall have access to the application file and any linked application files, as well as to any hits triggered during the automated processing laid down in Article 20(2) to (5). The ETIAS Central Unit shall inform the ETIAS National Unit of the Member State responsible whether one or several other Member States or Europol were identified as having entered or supplied the data that triggered the hit pursuant to Article 20(2) or (4). Where one or several Member States have been identified as having entered or supplied the data that triggered such a hit, the ETIAS Central Unit shall also specify the Member States concerned.
2.
Following the manual processing of the application, the ETIAS National Unit of the Member State responsible shall:
(a)
issue a travel authorisation; or
(b)
refuse a travel authorisation.
3.
Where the automated processing laid down in Article 20(2) has reported a hit, the ETIAS National Unit of the Member State responsible shall:
(a)
refuse a travel authorisation where the hit corresponds to one or several of the verifications referred to in points (a) and (c) of Article 20(2);
(b)
assess the security or illegal immigration risk and decide whether to issue or refuse a travel authorisation where the hit corresponds to any of the verifications referred to in points (b) and (d) to (o) of Article 20(2).
3a.
Where the automated processing under point (o) of Article 20(2) has reported a hit, the ETIAS National Unit of the Member State responsible shall:
(a)
refuse the applicant’s travel authorisation where the verification under the third subparagraph of Article 23(2) led to the deletion of the alert on return and the entry of an alert for refusal of entry and stay;
(b)
assess the security or illegal immigration risk and decide whether to issue or refuse a travel authorisation in all other cases.
The ETIAS National Unit of the Member State having entered the data shall consult its SIRENE Bureau to verify whether the deletion of the alert on return in accordance with Article 14(1) of Regulation (EU) 2018/1860 and, where applicable, the entry of an alert for refusal of entry and stay in accordance with Article 24(3) of Regulation (EU) 2018/1861 is required.
4. Where automated processing under Article 20(3) has reported that the applicant replied affirmatively to one of the questions referred to in Article 17(4), the ETIAS National Unit of the Member State responsible shall assess the security or illegal immigration risk and decide whether to issue or refuse a travel authorisation.
Where the automated processing under point (n) of Article 20(2) has reported a hit, but has not reported a hit under point (c) of that paragraph, the ETIAS National Unit of the Member State responsible shall give particular consideration to the absence of such a hit in its assessment of the security risk in order to decide whether to issue or refuse a travel authorisation.
5. Where automated processing under Article 20(4) has reported a hit, the ETIAS National Unit of the Member State responsible shall assess the security risk and decide whether to issue or refuse a travel authorisation.
6. Where automated processing under Article 20(5) has reported a hit, the ETIAS National Unit of the Member State responsible shall assess the security, illegal immigration or high epidemic risk and decide whether to issue or refuse a travel authorisation. In no circumstances may the ETIAS National Unit of the Member State responsible take a decision automatically on the basis of a hit based on specific risk indicators. The ETIAS National Unit of the Member State responsible shall individually assess the security, illegal immigration and high epidemic risks in all cases.
7. The ETIAS Information System shall keep records of all data processing operations carried out for assessments under this Article by the ETIAS National Unit of the Member State responsible or by the ETIAS National Units of the Member States consulted in accordance with Article 28. Those records shall be created and entered automatically in the application file. They shall show the date and time of each operation, the data used for consultation of other EU information systems, the data linked to the hit received and the staff member having performed the risk assessment.
The results of the assessment of the security, illegal immigration or high epidemic risk and the justification behind the decision to issue or refuse a travel authorisation shall be recorded in the application file by the staff member having performed the risk assessment.