Governance & GRC

The Oversight Framework for Critical ICT Third-Party Providers

DORA does something unprecedented: it gives European supervisors direct oversight powers over technology companies that are not financial institutions. Here is how designation and oversight work, and what it means downstream.

By Jonas Adam Mohamed Osman AbdelghafourPublished 11 August 2026

The most structurally novel thing DORA does is not the incident reporting regime or the testing requirements. It is the extension of European financial supervision to entities that are not financial firms at all.

The Problem It Solves

Financial supervision has always operated through the regulated entity. If a bank outsources to a technology provider, the supervisor regulates the bank's management of that relationship, not the provider. That works when providers are numerous and substitutable.

It stops working when a handful of cloud, data and core-platform providers underpin a large share of the union's financial system. At that point the supervisory lever — telling each bank to manage its provider better — cannot reach the actual concentration. Individually rational outsourcing decisions aggregate into a systemic dependency no single supervisor can address.

DORA's answer is a union-level oversight framework applying directly to designated critical ICT third-party providers.

Designation

The European Supervisory Authorities designate critical ICT third-party providers based on criteria including the systemic impact on the stability, continuity or quality of financial services should the provider face a large-scale operational failure; the systemic character or importance of the financial entities relying on it; the reliance of financial entities on the provider for critical or important functions; and the degree of substitutability, accounting for the availability of alternatives and the migration cost and complexity.

The data feeding designation comes substantially from the registers of information that every financial entity submits — which is why register data quality is a supervisory concern rather than an administrative one. Designation can also be requested voluntarily by a provider that expects to qualify.

Each designated provider is assigned a lead overseer from among the ESAs.

Oversight Powers

The lead overseer's powers are meaningful. It can request all relevant information and documentation, conduct general investigations and inspections including on-premises, request reports after inspections, and issue recommendations on a defined set of matters — ICT security and quality requirements, conditions for providing services, subcontracting practices, and testing arrangements.

Where a critical provider does not endorse a recommendation and the deficiency is not addressed, competent authorities may ultimately require financial entities to temporarily suspend, in part or entirely, the use of the service, or to terminate the relevant contractual arrangements.

That final power is the teeth. It does not fine the provider; it removes its customers. It is also, for exactly that reason, an instrument of last resort — the disruption of forcing a systemic institution off a systemic provider is precisely the outcome the framework exists to avoid. The practical effect is negotiating leverage rather than frequent use.

Subcontracting and the Chain

Oversight reaches subcontracting. Where a critical provider subcontracts elements of a service supporting a critical or important function, the arrangements and their risks fall within the overseer's view. This addresses the fourth-party problem that individual financial entities cannot see: a provider's dependency on another provider's dependency.

Financial entities should not assume the oversight regime discharges their own obligation here. It does not. The entity remains fully responsible for compliance with DORA and for the risks arising from its outsourcing, regardless of the provider's designation status. Designation is an addition to firm-level duty, not a substitution for it.

What It Means for Financial Entities

Three practical consequences.

Register accuracy has systemic weight. Designation depends on aggregated register data. Misclassified or omitted arrangements distort the union-level view, and firms are increasingly asked to reconcile their submissions.

Provider designation changes the negotiating dynamic. A designated provider under oversight has a supervisory incentive to accept DORA-aligned contractual terms it previously resisted. Contract renewals with designated providers are a better negotiating moment than they were.

Suspension risk is a continuity scenario. If a supervisor can require termination of a provider relationship, that is a scenario a firm's exit planning should contemplate — a forced, externally-timed exit rather than a chosen one. Very few exit plans model this, and it is the version with the shortest timeline. The register and exit planning article sets out what a credible plan contains.

Key Takeaways

  • DORA extends direct EU supervisory oversight to non-financial technology providers, which is structurally unprecedented.
  • Designation rests on systemic impact, reliance for critical functions, and substitutability — fed by firms' registers of information.
  • The ultimate sanction is requiring financial entities to suspend or terminate use, not fining the provider.
  • Provider designation does not reduce the financial entity's own responsibility for third-party risk.
  • Exit planning should model a forced, externally-timed exit, not only a voluntary migration.

Frequently Asked Questions

Are non-EU providers in scope of designation? Yes, where they serve EU financial entities. A designated provider established outside the union is required to establish a subsidiary in the union so that oversight can be effectively conducted.

Does using a designated provider make a firm's own compliance easier? Marginally, in that terms and assurance artefacts become more standardised. It does not reduce the firm's obligations, and concentration risk in a designated provider is, if anything, more visible to supervisors.

How should a firm respond if its provider is designated? Review the contract against DORA's required provisions at the next renewal window, reassess concentration exposure across the group, and add forced-suspension to the exit scenario set.

About the author

Jonas Mohamed Osman Abdelghafour is a risk and compliance expert advising banks, insurers, payment institutions and asset managers on operational resilience, ICT and third-party risk, financial crime and enterprise governance across EU and UK regimes. He works at the point where digital operational resilience obligations meet the evidence a board and a supervisor actually ask for. See qualifications and services, or get in touch to discuss an engagement.

*This article discusses regulatory frameworks in general terms and is not legal advice. Jurisdictional interpretation should be confirmed with qualified counsel.*

Frequently asked questions

What should risk leaders know about the Problem It Solves?

Financial supervision has always operated through the regulated entity. If a bank outsources to a technology provider, the supervisor regulates the bank's management of that relationship, not the provider. That works when providers are numerous and substitutable.

What should risk leaders know about designation?

The European Supervisory Authorities designate critical ICT third-party providers based on criteria including the systemic impact on the stability, continuity or quality of financial services should the provider face a large-scale operational failure; the systemic character or importance of the financial entities relying on it; the reliance of financial entities on the provider for critical or important functions; and the degree of substitutability, accounting for the availability of alternat...

What should risk leaders know about oversight Powers?

The lead overseer's powers are meaningful. It can request all relevant information and documentation, conduct general investigations and inspections including on-premises, request reports after inspections, and issue recommendations on a defined set of matters — ICT security and quality requirements, conditions for providing services, subcontracting practices, and testing arrangements.

What should risk leaders know about subcontracting and the Chain?

Oversight reaches subcontracting. Where a critical provider subcontracts elements of a service supporting a critical or important function, the arrangements and their risks fall within the overseer's view. This addresses the fourth-party problem that individual financial entities cannot see: a provider's dependency on another provider's dependency.

What should risk leaders know about frequently Asked Questions?

**Are non-EU providers in scope of designation?** Yes, where they serve EU financial entities. A designated provider established outside the union is required to establish a subsidiary in the union so that oversight can be effectively conducted.