All resources
Regulation5 min read

Critical ICT third-party providers: what designation changes

DORA does something unusual for financial regulation: it reaches past the regulated entity and takes direct supervisory power over some of its suppliers. A small number of ICT providers are designated as critical by the European Supervisory Authorities and become subject to an oversight framework of their own. The mechanism is widely misunderstood by the entities that use those providers, usually in the direction of assuming it transfers responsibility. It does not.

Relynt · Engineering

How a provider becomes critical

Designation is not a label a provider applies for or an entity assigns. The ESAs make it, using criteria set out in DORA: the systemic impact on the stability and continuity of financial services if the provider failed, the systemic importance of the entities relying on it, the degree of substitutability, and the number of member states in which it operates and financial entities it serves.

The raw material for that assessment is the Registers of Information. That is the connection most people miss. Every entity's register is an input to a mapping exercise across the union, and the designation follows from what those registers collectively show about concentration. A register that understates a dependency is not only a filing problem; it is a distortion of the picture the ESAs are assembling.

Once designated, a provider is supervised by a lead overseer, one of the three ESAs, with powers to request information, conduct investigations and inspections, issue recommendations and, ultimately, to charge periodic penalty payments.

  • Designation is made by the ESAs, not requested by the provider or assigned by the entity
  • The Registers of Information are the raw material for the assessment
  • A designated provider gets a lead overseer with direct investigatory powers

What it does not change for you

The most important point is the one that is easiest to get wrong. Using a designated critical provider does not reduce your obligations. You still perform the risk assessment, still hold the Article 30 provisions in your contract, still gather evidence, still maintain your exit strategy, still report the arrangement in your register.

Oversight of the provider and supervision of the entity are separate regimes running in parallel. Your competent authority still holds you responsible for your ICT third-party risk. A recommendation the lead overseer issues to the provider is not a control you can point to in place of your own.

There is one genuine consequence. If a lead overseer issues a recommendation and the provider does not follow it, your competent authority may require you to suspend or terminate the arrangement. That is a real risk to plan for, and it is the strongest practical argument for having an exit strategy that has been tested rather than written.

What to do about it

Know which of your providers are likely candidates. The pattern is the obvious one: the large cloud infrastructure providers, the major core banking platforms, the payment and market infrastructure that many entities share. If a provider supports a critical or important function and would be difficult to replace, assume the question will arise.

For those, the practical preparation is substitutability. DORA asks you to record how substitutable each arrangement is and why, and to identify alternative providers where they exist. Entities tend to fill that in optimistically. The test is whether anybody has costed the migration, and whether the answer is measured in weeks or in years.

The second preparation is the exit plan itself. Not the clause in the contract saying one exists, but the document describing what happens: who does what, over what period, what the data comes back as, and what the business runs on in the meantime. A plan that has never been reviewed is a clause, not a plan.

  • Identify which providers would plausibly be designated, and treat their exit planning as the priority
  • Record substitutability honestly, including where the answer is that there is no real alternative
  • An exit strategy that has not been costed is a statement of intent rather than a control

The register is how the picture gets built

It is worth closing on the reason all of this depends on the Register of Information being accurate rather than merely submitted. The concentration the ESAs are looking for is not visible from any single register. It emerges from the overlap between them: the same underlying provider appearing beneath many entities, often at rank two or three of a subcontracting chain rather than as a direct arrangement.

That is the part of the register entities are least motivated to complete and least able to, because it depends on their providers disclosing their own suppliers. It is also the part that carries the most supervisory value. A register that describes direct arrangements precisely and the chain beneath them vaguely tells the ESAs very little about the risk DORA was written to address.

See how this works in the product.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.

Critical ICT third-party providers: what designation changes