All resources
Third-Party Risk8 min read

Classifying critical or important functions without guesswork

Whether a function is critical or important determines the depth of your assessments, the clauses your contracts must contain, the exit planning you need and what appears in the Register. Getting the classification wrong in either direction is expensive.

Tomas Lindqvist · Principal, ICT Risk

Classify functions first, then services

A common mistake is to classify providers. Providers are not critical; functions are. A provider becomes significant because it supports a function whose disruption would materially impair financial performance, the soundness or continuity of services, or compliance with authorization conditions.

Start with a short list of business functions, classify those, then map each ICT service to the functions it supports. Criticality flows upward from the function to the service and finally to the provider.

Use a scored method, and write it down

A defensible classification uses a small number of weighted criteria applied identically to every function. Scoring is less about mathematical precision than about consistency and auditability: two analysts should reach the same answer.

  • Impact on customers and the market if the function stops
  • Maximum tolerable downtime and recovery expectations
  • Sensitivity and volume of data processed
  • Substitutability of the provider and switching time
  • Regulatory and reporting dependencies

Review classifications on a cycle and on change

Criticality is not static. A payments provider that handled a pilot last year may now sit in the main flow. Tie reclassification to contract renewal, material change in the service, and an annual review so the Register does not drift away from operational reality.

See how this works in the product.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.