Classify functions first, then services
A common mistake is to classify providers. Providers are not critical; functions are. A provider becomes significant because it supports a function whose disruption would materially impair financial performance, the soundness or continuity of services, or compliance with authorization conditions.
Start with a short list of business functions, classify those, then map each ICT service to the functions it supports. Criticality flows upward from the function to the service and finally to the provider.
Use a scored method, and write it down
A defensible classification uses a small number of weighted criteria applied identically to every function. Scoring is less about mathematical precision than about consistency and auditability: two analysts should reach the same answer.
- Impact on customers and the market if the function stops
- Maximum tolerable downtime and recovery expectations
- Sensitivity and volume of data processed
- Substitutability of the provider and switching time
- Regulatory and reporting dependencies
Review classifications on a cycle and on change
Criticality is not static. A payments provider that handled a pilot last year may now sit in the main flow. Tie reclassification to contract renewal, material change in the service, and an annual review so the Register does not drift away from operational reality.