SkarpSkarp

Chapter 12 of 15

DORA Regulation (EU) 2022/2554 — Critical Provider Designation and Lead Overseer Powers

DORA's oversight framework begins with designation and extends into intrusive supervisory powers. Articles 31–36 show how critical providers are selected, organised under a Lead Overseer, examined, directed toward remediation, and addressed across Union borders.

29 min readen

1. The Oversight Framework: From Designation to Intervention

A sequenced framework

Articles 31-36 move from designation to structure, assessment, coordination, powers, enforcement and third-country action.

Who is covered?

The framework concerns ICT third-party service providers designated as critical under Article 31, not every provider serving finance.

Currency check

Article 31(6)'s 17 July 2024 deadline has passed. Delegated Regulation (EU) 2024/1502 is in force and specifies designation criteria.

2. Article 31(1): Designation and Appointment of the Lead Overseer

Two actions

Under Article 31(1), the ESAs through the Joint Committee shall designate critical providers and shall appoint a Lead Overseer for each one.

Designation wording

The load-bearing obligation is to designate the ICT third-party service providers that are critical for financial entities.

Asset-based allocation

The Lead Overseer is the ESA responsible for users holding the largest combined share of total assets, evidenced by individual balance sheets.

3. Article 31(2): The Four Designation Criteria

Criterion (a)

Assess the systemic impact on the stability, continuity or quality of the provision of financial services if a large-scale operational failure occurs.

Criteria (b) and (c)

Consider systemic users, their interdependence, and reliance for critical or important functions, whether reliance is direct or through subcontracting.

Criterion (d)

Substitutability includes real alternatives and migration difficulty: cost, time, resources, increased ICT risk and other operational risks.

4. Worked Example: Applying the Designation Criteria

Failure impact

CloudCore EU's importance depends on the effect of a large-scale failure, including its users' number and total asset value.

Direct and indirect reliance

A provider can support a financial entity's critical function directly or indirectly through a subcontracting chain. Article 31(2)(c) covers both.

Real, not theoretical, alternatives

Alternatives may exist on paper but not be practically substitutable where migration is costly, slow, resource-intensive or risk-increasing.

5. Article 31(3)-(13): Groups, Process, Exclusions and the Union List

Groups and procedural rights

Group providers are assessed as a whole and need one legal-person coordination point. A provider has 6 weeks to submit a reasoned statement.

List, exclusions and opt-in

The ESAs shall establish, publish and update yearly the list of critical ICT third-party service providers at Union level. Article 31(8) contains exclusions.

Third-country providers

Financial entities shall use a designated critical third-country provider only if the latter has established a subsidiary in the Union within the 12 months following the designation.

Quiz 1: Designation Deadlines and Scope

Choose the answer that accurately applies Article 31.

After notification of the assessment outcome leading to designation, how long does an ICT third-party service provider have to submit its reasoned statement?

  1. 15 calendar days
  2. 30 calendar days
  3. 6 weeks
  4. 6 months
Show Answer

Answer: C) 6 weeks

Article 31(5) gives the ICT third-party service provider 6 weeks from the notification date to submit a reasoned statement. The 15-calendar-day period belongs to comments on a draft annual oversight plan under Article 33(4).

6. Article 32: The Oversight Forum

Supporting, not replacing

The Oversight Forum is a Joint Committee sub-committee. It supports the Joint Committee and Lead Overseer in ICT third-party risk across sectors.

Annual collective function

It annually assesses oversight findings across all critical providers, promotes resilience coordination, best practices and mitigants for cross-sector risk transfer.

Membership and independence

Article 32 specifies members and observers. Independent experts are selected transparently and must act independently, objectively and solely for the Union.

7. Article 33: What the Lead Overseer Assesses

Core task

The Lead Overseer assesses whether the provider has comprehensive, sound and effective arrangements to manage ICT risk posed to financial entities.

Main focus, qualified extension

The assessment mainly concerns services supporting critical or important functions, but extends to other functions where necessary to address all relevant risks.

Breadth of review

Article 33(3) spans technical resilience, facilities, governance, incidents, portability, testing, audits and applicable standards.

8. Article 33(4)-(5): The Individual Annual Oversight Plan

Required annual plan

The Lead Overseer shall adopt a clear, detailed and reasoned individual oversight plan with annual objectives and main planned actions.

Draft-plan response

The provider may respond within 15 calendar days, evidencing expected impact on customers outside DORA's scope and, where appropriate, mitigants.

Coordinated measures

After plans are adopted and notified, competent authorities may take measures concerning the provider only in agreement with the Lead Overseer.

9. Article 34: The Joint Oversight Network

Why the JON exists

The three Lead Overseers shall establish the JON for consistent oversight, coordinated strategies and cohesive operational approaches.

A living protocol

They shall draw up a common protocol for daily coordination and swift exchanges and reactions, revising it periodically for operational needs.

Optional technical support

On an ad-hoc basis, Lead Overseers may call on the ECB and ENISA for advice, hands-on experience or specific JON meetings.

10. Article 35(1)-(5): Information, Investigation, Inspection and Recommendations

The powers

Article 35(1) covers information and documentation, general investigations, inspections, remedial-action reports and recommendations.

Subcontracting safeguard

Refraining from entering into a further subcontracting arrangement applies only where all three listed Article 35(1)(d)(iv) conditions are met.

Procedural constraints

The Lead Overseer shall consult the Oversight Forum and, before recommendations, give 30 calendar days for relevant information and possible mitigants.

11. Article 35(6)-(11): Periodic Penalty Payments and Defence Rights

When a daily penalty can begin

There must be whole or partial non-compliance with measures under Article 35(1)(a)-(c), and at least 30 calendar days after notification.

Duration and ceiling

A payment is daily until compliance, for no more than six months after notification, and may be up to 1% of average daily worldwide turnover.

Fair process

Before a payment, the provider must be heard. A decision may rely only on findings it had an opportunity to comment on.

Quiz 2: Subcontracting and Penalties

Test your understanding of Article 35's limits and conditions.

Which statement is correct under Article 35?

  1. A Lead Overseer may prohibit any subcontracting whenever it prefers a different provider.
  2. A periodic penalty payment may be imposed immediately after a recommendation is issued.
  3. A recommendation to refrain from further subcontracting requires all three Article 35(1)(d)(iv) conditions to be met.
  4. A daily periodic penalty payment may continue indefinitely until the provider complies.
Show Answer

Answer: C) A recommendation to refrain from further subcontracting requires all three Article 35(1)(d)(iv) conditions to be met.

Article 35(1)(d)(iv) makes the three conditions cumulative. A periodic penalty requires defined non-compliance and at least 30 calendar days after notification of the measures; it may run for no more than six months following notification of the penalty decision.

12. Article 36: Oversight Powers Outside the Union

A last-resort setting

Third-country action may occur when objectives cannot be attained through the Article 31(12) subsidiary or oversight activities at Union premises.

Four cumulative conditions

The inspection must be necessary and directly Union-service-related; the provider must consent; and the notified third-country authority must raise no objection.

Cooperation arrangements

EBA, ESMA or EIOPA shall conclude administrative arrangements. They facilitate inspections but create no legal obligations for the Union or Member States.

13. Article 36(3): If External Oversight Cannot Be Conducted

Oversight does not disappear

If the Lead Overseer cannot conduct external activities, it shall exercise Article 35 powers using all facts and documents available.

Document the limitation

The Lead Overseer shall document and explain consequences of its inability to conduct the envisaged activities. Those consequences inform recommendations.

The complete chain

Designation selects critical providers; oversight assesses them; coordinated powers address risks; and Article 36 limits and documents external action.

Flashcards: Critical Provider Oversight

Flip each card and recall the exact Article 31-36 rule before checking the answer.

Who designates critical ICT third-party service providers?
The ESAs, through the Joint Committee and upon recommendation from the Oversight Forum, shall designate them under Article 31(1)(a).
What is the Article 31(2)(a) systemic-impact phrase?
The assessment considers "the systemic impact on the stability, continuity or quality of the provision of financial services".
How often is the Union list updated?
The ESAs, through the Joint Committee, shall establish, publish and update yearly the list of critical ICT third-party service providers at Union level.
What is the deadline for a reasoned statement after assessment notification?
Within 6 weeks from the date of notification under Article 31(5).
What is the third-country subsidiary condition?
Financial entities shall use the designated critical provider only if it has established a subsidiary in the Union within the 12 months following designation.
What does the Oversight Forum support?
It is established as a sub-committee for supporting the work of the Joint Committee and of the Lead Overseer.
What must an Article 33(4) oversight plan be?
A clear, detailed and reasoned individual oversight plan describing annual oversight objectives and the main oversight actions planned.
What is the maximum duration of a daily periodic penalty payment?
No more than a period of six months following notification of the decision to impose it.
What is the penalty-payment maximum amount?
Up to 1% of the average daily worldwide turnover of the critical ICT third-party service provider in the preceding business year.
Name two third-country inspection conditions.
The provider concerned consents to the inspection, and the relevant third-country authority has been officially notified and raised no objection. Necessity and direct relation to Union financial entities' ICT services are also required.

Key Terms

ESA
A European Supervisory Authority: EBA, ESMA or EIOPA in the DORA framework.
JON
The Joint Oversight Network set up by the three Lead Overseers under Article 34 for coordination.
G-SII
Global systemically important institution.
O-SII
Other systemically important institution.
Lead Overseer
The ESA appointed for a particular critical ICT third-party service provider under Article 31(1)(b); it conducts oversight and is the primary contact point.
Third-country
A country outside the Union.
Joint Committee
The mechanism through which the ESAs take the Article 31 designation and Lead Overseer appointment actions.
Oversight Forum
A Joint Committee sub-committee established under Article 32(1) to support the Joint Committee and Lead Overseer on ICT third-party risk.
Substitutability
The degree to which an ICT third-party service provider can realistically be replaced, considering alternatives and data or workload migration barriers.
ICT concentration risk
Risk associated with concentrated reliance on ICT third-party service providers, including potential single points of failure and systemic impact.
Periodic penalty payment
An administrative, daily payment imposed under Article 35(6)-(8) to compel compliance after the stated non-compliance and notification conditions are met.
Critical ICT third-party service provider
An ICT third-party service provider designated as critical under Article 31(1)(a) of DORA.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself