Oversight of critical ICT third-party providers
The Oversight Framework allows European Supervisory Authorities (ESAs) to designate specific ICT third-party providers as "critical" based on their systemic importance to the EU financial sector. Once designated, these Critical ICT Third-Party Providers (CTPPs) are subject to direct supervision by a Lead Overseer who can request information, conduct inspections, and issue binding recommendations.
What it means
Unlike standard vendor management—where a financial entity manages its own risks—this framework creates a top-down regulatory layer. The intent is to prevent systemic failure; if a provider serves so many financial entities that its collapse would threaten the stability of the entire EU financial system, the regulators step in to oversee them directly.
For financial entities, this means your relationship with a CTPP is no longer just a private contract but a regulated arrangement. You must ensure that your agreements with these providers explicitly allow for and facilitate this regulatory oversight.
For ICT providers, it means submitting to the authority of an ESA (the Lead Overseer), providing transparency into their operational resilience, and potentially implementing mandatory changes to their infrastructure or governance based on overseer recommendations.
How to meet it
- Identify CTPPs: Maintain a dynamic list of your ICT providers and cross-reference them against the official designations published by the ESAs.
- Update Contractual Clauses: Amend contracts with designated CTPPs to include specific language that permits the Lead Overseer to exercise their powers, including rights of inspection and information requests.
- Establish Communication Workflows: Create a formal process for handling inquiries from regulators regarding your critical providers and for receiving notifications about overseer recommendations.
- Review Exit Strategies: For any provider designated as "critical," verify that exit plans are realistic and account for the systemic nature of the service (e.g., avoiding concentration risk by not moving to another CTPP).
- Coordinate Reporting: Ensure your incident reporting pipeline includes a mechanism to notify regulators if an event involves a CTPP, as this may trigger overseer intervention.
Evidence an auditor asks for
- CTPP Inventory: A register of all third-party ICT providers with a clear flag identifying those designated as "critical" by the ESAs.
- Contractual Addenda: Copies of signed contracts or amendments containing clauses that explicitly allow for regulatory oversight and inspections per DORA requirements.
- Governance Records: Minutes from risk committees showing the review and assessment of risks associated specifically with CTPPs.
- Compliance Mapping: Documentation mapping how the entity monitors whether a CTPP is following the recommendations issued by its Lead Overseer.
Common pitfalls
- Confusing "Criticality": Mistaking an internally defined "critical vendor" (based on business impact) for a regulatory-designated "CTPP" (based on systemic EU risk).
- Reliance on Standard Audit Rights: Assuming that standard "right to audit" clauses in existing contracts are sufficient; DORA requires specific cooperation with the Lead Overseer, not just the client.
- Passive Monitoring: Failing to track whether a CTPP has been designated or removed from the critical list by the ESAs, leading to outdated contractual terms.