The ESAs shall, through the Joint Committee, develop common draft regulatory technical standards to further specify the criteria for the designation of ICT third-party service providers as critical for financial entities.
JSON record documenting the designation of ICT third-party service providers as critical, including designation criteria, assessment results, and oversight implications.
critical-provider-designationGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
{
"designationRecord": {
"recordId": "CPD-2025-001",
"institution": "Nordvik Bank AG",
"assessmentDate": "2025-01-30",
"assessedBy": "Elena Vasquez, Risk Manager — Third-Party ICT Risk",
"approvedBy": "Board Risk Committee",
"approvalDate": "2025-02-05",
"regulatoryBasis": "DORA Article 31, ESA RTS on Criticality Designation Criteria",
"nextReviewDate": "2026-01-30"
},
"designationCriteria": {
"description": "Criteria for designating ICT third-party service providers as critical, based on DORA Article 31 and ESA Regulatory Technical Standards.",
"criteria": [
{
"criterionId": "DC-01",
"name": "Systemic importance",
"description": "The provider serves a significant number of financial entities or supports functions whose disruption could affect financial stability.",
"threshold": "Serves 10 or more financial entities in the EEA, or supports critical functions for 3 or more systemically important institutions."
},
{
"criterionId": "DC-02",
"name": "Substitutability",
"description": "The degree to which the provider's services can be replaced by alternative providers.",
"threshold": "Rated 'difficult_to_substitute' or 'not_substitutable' in the Bank's substitutability analysis."
},
{
"criterionId": "DC-03",
"name": "Impact on critical functions",
"description": "The potential impact of the provider's failure on the Bank's critical or important functions.",
"threshold": "Supports 3 or more critical business functions, or a single function whose disruption would cause severe financial or operational impact."
},
{
"criterionId": "DC-04",
"name": "Concentration risk",
"description": "The degree to which the provider creates concentration risk at entity or sector level.",
"threshold": "Single-provider dependency for any critical service, or provider represents more than 30% of critical ICT spend."
}
]
},
"providerDesignations": [
{
"providerId": "PRV-001",
"providerName": "Meridian Cloud Services GmbH",
"designationDate": "2025-02-05",
"isDesignatedCritical": true,
"designationCriteriaMet": true,
"criteriaAssessment": {
"DC-01": {
"met": true,
"evidence": "Meridian serves 12 mid-size banks in the DACH region and 3 insurance companies. Designated as systemically important by BaFin preliminary assessment."
},
"DC-02": {
"met": true,
"evidence": "Rated 'difficult_to_substitute' — deep Temenos T24 integration, 18-month estimated transition period."
},
"DC-03": {
"met": true,
"evidence": "Supports 4 critical business functions: core banking, payment processing infrastructure, customer data storage, regulatory reporting."
},
"DC-04": {
"met": true,
"evidence": "Single-provider dependency for core banking hosting. Represents 26% of total critical ICT spend."
}
},
"systemicImportanceScore": 82,
"financialEntitiesServed": 15,
"leadOverseerAssigned": true,
"leadOverseerAuthority": "EBA (European Banking Authority)",
"oversightImplications": [
"Subject to annual oversight assessment by Lead Overseer",
"Required to submit ICT risk management documentation to Lead Overseer",
"Subject to on-site inspections under DORA Article 37",
"Bank must include Meridian in its DORA Article 28(3) register with critical designation"
]
},
{
"providerId": "PRV-003",
"providerName": "SwiftPay Solutions B.V.",
"designationDate": "2025-02-05",
"isDesignatedCritical": true,
"designationCriteriaMet": true,
"criteriaAssessment": {
"DC-01": {
"met": true,
"evidence": "SwiftPay processes payments for 28 financial entities across the EU. Under consideration for ESA-level critical designation."
},
"DC-02": {
"met": true,
"evidence": "Rated 'difficult_to_substitute' — PCI-DSS certification and card scheme connectivity required. 12-month transition estimate."
},
"DC-03": {
"met": true,
"evidence": "Supports 4 critical business functions: card acquiring, SEPA transfers, direct debits, instant payments."
},
"DC-04": {
"met": true,
"evidence": "Single-provider dependency for all payment processing. Represents 19% of total critical ICT spend."
}
},
"systemicImportanceScore": 78,
"financialEntitiesServed": 28,
"leadOverseerAssigned": true,
"leadOverseerAuthority": "EBA (European Banking Authority)",
"oversightImplications": [
"Subject to annual oversight assessment by Lead Overseer",
"Required to demonstrate PCI-DSS compliance and card scheme certifications",
"Subject to general investigations under DORA Article 36",
"Bank must maintain documented exit strategy per DORA Article 44"
]
},
{
"providerId": "PRV-002",
"providerName": "Sentinel Cyber AG",
"designationDate": "2025-02-05",
"isDesignatedCritical": false,
"designationCriteriaMet": false,
"criteriaAssessment": {
"DC-01": {
"met": false,
"evidence": "Sentinel serves 8 financial entities — below the 10-entity threshold."
},
"DC-02": {
"met": false,
"evidence": "Rated 'substitutable_with_effort' — multiple managed SOC providers available in EU market."
},
"DC-03": {
"met": true,
"evidence": "Supports 3 critical functions: security monitoring, incident detection, threat intelligence."
},
"DC-04": {
"met": false,
"evidence": "Not a single-provider dependency (alternatives identified). Represents 10% of critical ICT spend."
}
},
"systemicImportanceScore": 41,
"financialEntitiesServed": 8,
"leadOverseerAssigned": false,
"leadOverseerAuthority": null,
"oversightImplications": [
"Not subject to Lead Overseer oversight",
"Standard third-party risk management applies",
"Annual due diligence review required"
]
}
]
}
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
critical_provider_designation_status — fs-critical-provider-designation
{
"factId": "b7c8d9e0-f1a2-3456-bcde-678901234567",
"evidenceId": "a6b7c8d9-e0f1-2345-6789-012345abcdef",
"evidenceClassId": "critical-provider-designation",
"factType": "critical_provider_designation_status",
"data": {
"provider_id": "PRV-001",
"designation_date": "2025-02-05",
"is_designated_critical": true,
"designation_criteria_met": true,
"systemic_importance_score": 82,
"financial_entities_served": 15,
"lead_overseer_assigned": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-02-06T09:00:00Z",
"supersededBy": null
}
fs-critical-provider-designationDORA-Art32-P1designation_datesystemic_importance_score{
"properties": {
"designation_criteria_met": {
"type": "boolean"
},
"designation_date": {
"format": "date",
"type": "string"
},
"financial_entities_served": {
"minimum": 0,
"type": "integer"
},
"is_designated_critical": {
"type": "boolean"
},
"lead_overseer_assigned": {
"type": "boolean"
},
"provider_id": {
"minLength": 1,
"type": "string"
},
"systemic_importance_score": {
"maximum": 100,
"minimum": 0,
"type": "number"
}
},
"required": [
"provider_id",
"designation_date",
"is_designated_critical",
"designation_criteria_met"
],
"type": "object"
}