Chapter 13 of 15
DORA Regulation (EU) 2022/2554 — Oversight Procedures, Follow-Up, Fees, and Cooperation
Power must be exercised through defined procedures and followed by consequences. Articles 37–44 detail requests, investigations, inspections, examination teams, provider responses, possible service suspension, cost recovery, and international cooperation.
The Oversight Sequence in Articles 37-44
A connected oversight process
Articles 37-44 create a sequence: information gathering, investigations, inspections, recommendations, follow-up, fees, and international cooperation.
Different tools, different consequences
DORA distinguishes a simple request from a binding decision, an investigation from an inspection, and recommendations from last-resort suspension or termination measures.
Who acts?
The Lead Overseer acts alongside competent authorities, the JON, the Oversight Forum, and joint examination teams. Their roles are connected but not interchangeable.
Article 37 — Request for Information
The information scope
Article 37(1) reaches information necessary for oversight, including "all relevant business or operational documents, contracts, policies, documentation, ICT security audit reports, ICT-related incident reports".
Simple request
A simple request must identify its Article 37 basis, purpose, required information, and deadline. A representative is not obliged to reply, but any voluntary reply must not be incorrect or misleading.
Decision requiring information
A decision must also indicate Article 35(6) periodic penalty payments for incomplete or late information and indicate appeal and Court of Justice review rights.
Responsibility remains with the provider
Representatives or authorised lawyers may supply information, but the critical ICT third-party service provider remains fully responsible for incomplete, incorrect, or misleading information.
Article 38 — General Investigations
When an investigation may occur
Article 38(1) says the Lead Overseer, assisted by the Article 40(1) joint examination team, may, where necessary, investigate a critical ICT third-party service provider.
What may be examined
The Lead Overseer may "examine records, data, procedures and any other material relevant to the execution of its tasks, irrespective of the medium on which they are stored".
Additional investigatory tools
Article 38 also permits certified copies or extracts, explanations from representatives, consensual interviews of others, and requests for telephone and data-traffic records.
Authorisation and notification
Written authorisation must state the investigation's subject matter and purpose. Before it starts, competent authorities must be informed in good time, and the JON receives that transmitted information.
Article 39 — Inspections
Where inspection may occur
Article 39 permits the Lead Overseer to "enter in, and conduct all necessary onsite inspections on, any business premises, land or property of the ICT third-party service providers".
Powers at the site
Authorised persons may enter premises and may seal premises, books, or records, but only for the period of and to the extent necessary for the inspection.
Technical coverage
"Inspections shall cover the full range of relevant ICT systems, networks, devices, information and data" used for, or contributing to, ICT services provided to financial entities.
Notice is qualified
Reasonable notice is normally required. It need not be given where an emergency or crisis makes notice impossible, or where notice would make the inspection or audit ineffective.
Quiz — Selecting the Correct Tool
Check your understanding
A Lead Overseer wants a provider to produce records by a fixed deadline and wants the request to state periodic penalty payments if production is incomplete or late. Which Article 37 route fits this situation?
Which route should the Lead Overseer use?
- A simple request under Article 37(2)
- A decision requiring information under Article 37(3)
- An on-site inspection under Article 39(6)
- A non-binding opinion under Article 42(7)
Show Answer
Answer: B) A decision requiring information under Article 37(3)
Article 37(3) requires a decision to indicate the Article 35(6) periodic penalty payments where the required information is incomplete or is not provided within the stated time limit. A simple request instead informs the representative that he or she is not obliged to provide information.
Articles 40-41 — Ongoing Oversight and Harmonised Conditions
A team for each provider
Article 40(1) provides that "the Lead Overseer shall be assisted by a joint examination team established for each critical ICT third-party service provider".
Team composition and expertise
The team includes ESA and relevant competent-authority staff, with certain voluntary national-authority participation. Members shall have ICT and operational-risk expertise.
The three-month recommendation deadline
"Within 3 months of the completion of an investigation or inspection, the Lead Overseer, after consulting the Oversight Forum, shall adopt recommendations".
Article 41 currency note
Article 41 required draft RTS by 17 July 2024. In-force Commission Delegated Regulation (EU) 2025/420 supplements DORA on Article 41(1)(c) joint examination-team arrangements.
Article 42(1)-(5) — Provider Response, Disclosure, and Risk Follow-Up
Provider response
Within "60 calendar days of the receipt of the recommendations issued by the Lead Overseer", the provider shall state its intention to follow them or give a reasoned explanation for not doing so.
Disclosure is mandatory, but limited
"The Lead Overseer shall publicly disclose where a critical ICT third-party service provider fails to notify the Lead Overseer" or its explanation is not sufficient, subject to stated proportionality and stability limits.
Financial entities must take risks into account
Competent authorities shall inform financial entities about recommendation-identified risks. When managing ICT third-party risk, financial entities shall take those risks into account.
A warning before last-resort action
Where contractual arrangements do not appropriately address risks, the competent authority notifies the financial entity of the possibility of a paragraph 6 decision within 60 calendar days.
Article 42(6)-(11) — From Unaddressed Risk to Last-Resort Measures
Last resort means last resort
Article 42(6) permits action only as a measure of last resort, after the Article 42(4) notification and, if appropriate, the Article 42(5) consultation.
Temporary suspension
Authorities may "take a decision requiring financial entities to temporarily suspend, either in part or completely, the use or deployment of a service" until risks are addressed.
Termination where necessary
"Where necessary, they may require financial entities to terminate, in part or completely, the relevant contractual arrangements" with the critical ICT third-party service provider.
Continuity and transition matter
Authorities must consider continuity risk and shall give financial entities necessary time to adjust contracts, avoid detrimental resilience effects, and deploy exit strategies and transition plans.
Articles 43-44 — Fees and International Cooperation
Full cost recovery
Article 43 requires "fees that fully cover the Lead Overseer’s necessary expenditure in relation to the conduct of oversight tasks pursuant to this Regulation".
Fee proportionality
A provider's fee shall cover all costs derived from duties in this Section and shall be proportionate to its turnover.
Article 43 currency note
In-force Commission Delegated Regulation (EU) 2024/1505 supplements Article 43. It includes an annual-fee floor of EUR 50,000, subject to its calculation and transitional rules.
Five-year confidential reporting
"The ESAs shall, through the Joint Committee, submit every five years a joint confidential report" on discussions with third-country authorities and the implications of ICT third-party risk.
Quiz — Conditions for Suspension
Check your understanding
Which statement most accurately reflects Article 42(6) and Article 42(8)?
Choose the best answer.
- Competent authorities must immediately terminate all provider contracts whenever a provider does not follow a recommendation.
- Competent authorities may impose a temporary partial or complete suspension as a measure of last resort, and must consider listed risk, non-compliance, and continuity criteria.
- The Lead Overseer alone must impose suspension once a provider's explanation is deemed insufficient.
- A financial entity has no time to adjust contractual arrangements after a suspension or termination decision.
Show Answer
Answer: B) Competent authorities may impose a temporary partial or complete suspension as a measure of last resort, and must consider listed risk, non-compliance, and continuity criteria.
Article 42(6) describes suspension as a measure of last resort and permits partial or complete temporary suspension. Article 42(8) requires consideration of specified criteria, including continuity risk. It also requires competent authorities to grant financial entities the necessary period to adjust contracts and deploy exit strategies and transition plans.
Flashcards — Precision Review
Recall the legal sequence
Flip each card and test whether you can state the relevant Article, actor, condition, and deadline precisely.
- Article 37: What is the difference between a simple request and a decision?
- A simple request informs the representative that he or she is not obliged to provide information, although any voluntary reply must not be incorrect or misleading. A decision adds Article 35(6) periodic penalty-payment information and appeal and Court of Justice review rights.
- Article 38: What is the central examination power?
- The Lead Overseer may "examine records, data, procedures and any other material relevant to the execution of its tasks, irrespective of the medium on which they are stored".
- Article 39: What must inspections cover?
- "Inspections shall cover the full range of relevant ICT systems, networks, devices, information and data" used for, or contributing to, ICT services for financial entities.
- Article 40: What team supports oversight?
- The Lead Overseer shall be assisted by a joint examination team established for each critical ICT third-party service provider.
- Article 40: When are recommendations adopted?
- Within 3 months of completion of an investigation or inspection, after consulting the Oversight Forum.
- Article 42: How long does a provider have to respond to recommendations?
- Within 60 calendar days of receipt, it shall notify an intention to follow them or give a reasoned explanation for not following them.
- Article 42: What is the ultimate follow-up tool?
- As a measure of last resort, competent authorities may require temporary partial or complete suspension; where necessary, they may require partial or complete termination of relevant contractual arrangements.
- Article 44: What is the international reporting cycle?
- The ESAs, through the Joint Committee, shall submit every five years a joint confidential report to the European Parliament, Council, and Commission.
Key Terms
- JON
- The Joint Oversight Network, which receives specified information from the Lead Overseer under Articles 37, 38, and 42.
- Lead Overseer
- The authority exercising DORA's direct oversight powers over a critical ICT third-party service provider in the Articles covered by this module.
- Oversight Forum
- The body consulted by the Lead Overseer before recommendations under Article 40(3) and before the possible Article 42(7) opinions.
- recommendations
- Measures adopted by the Lead Overseer after an investigation or inspection under Article 40(3), which trigger the Article 42 provider-response and competent-authority follow-up process.
- on-site inspection
- An Article 39 inspection involving entry to premises, land, or property, subject to the powers, authorisation, notice, and decision requirements in that Article.
- competent authority
- A national authority with the follow-up functions described in Article 42 in relation to financial entities.
- joint examination team
- The team established for each critical ICT third-party service provider to assist the Lead Overseer in oversight activities, particularly investigations and inspections.
- periodic penalty payments
- Payments referred to in Article 35(6), which must be indicated in specified Article 37, 38, and 39 decisions or authorisations where information, materials, answers, or submission to inspection are missing or incomplete.
- exit strategies and transition plans
- Measures referred to in Article 28 that financial entities may need to deploy when adjusting contractual arrangements following Article 42 follow-up.
- critical ICT third-party service provider
- An ICT third-party service provider designated as critical under DORA and therefore subject to the oversight framework addressed in Articles 37-44.