Auditen
Home / Frameworks / DORA / Oversight of critical ICT third-party providers
DORA · Arts. 31–44

Oversight of critical ICT third-party providers

The Oversight Framework allows European Supervisory Authorities (ESAs) to designate specific ICT third-party providers as "critical" based on their systemic importance to the EU financial sector. Once designated, these Critical ICT Third-Party Providers (CTPPs) are subject to direct supervision by a Lead Overseer who can request information, conduct inspections, and issue binding recommendations.

What it means

Unlike standard vendor management—where a financial entity manages its own risks—this framework creates a top-down regulatory layer. The intent is to prevent systemic failure; if a provider serves so many financial entities that its collapse would threaten the stability of the entire EU financial system, the regulators step in to oversee them directly.

For financial entities, this means your relationship with a CTPP is no longer just a private contract but a regulated arrangement. You must ensure that your agreements with these providers explicitly allow for and facilitate this regulatory oversight.

For ICT providers, it means submitting to the authority of an ESA (the Lead Overseer), providing transparency into their operational resilience, and potentially implementing mandatory changes to their infrastructure or governance based on overseer recommendations.

How to meet it

Evidence an auditor asks for

  • CTPP Inventory: A register of all third-party ICT providers with a clear flag identifying those designated as "critical" by the ESAs.
  • Contractual Addenda: Copies of signed contracts or amendments containing clauses that explicitly allow for regulatory oversight and inspections per DORA requirements.
  • Governance Records: Minutes from risk committees showing the review and assessment of risks associated specifically with CTPPs.
  • Compliance Mapping: Documentation mapping how the entity monitors whether a CTPP is following the recommendations issued by its Lead Overseer.

Common pitfalls

  • Confusing "Criticality": Mistaking an internally defined "critical vendor" (based on business impact) for a regulatory-designated "CTPP" (based on systemic EU risk).
  • Reliance on Standard Audit Rights: Assuming that standard "right to audit" clauses in existing contracts are sufficient; DORA requires specific cooperation with the Lead Overseer, not just the client.
  • Passive Monitoring: Failing to track whether a CTPP has been designated or removed from the critical list by the ESAs, leading to outdated contractual terms.