DORA-Art32-P1

Article
32 (1)
Pillar
Third-Party ICT Risk Management
Regulation Ref
Regulation (EU) 2022/2554, Article 32(1)
Last Reviewed
2026-01-15

The ESAs shall, through the Joint Committee, develop common draft regulatory technical standards to further specify the criteria for the designation of ICT third-party service providers as critical for financial entities.

Evidence Profiles

Critical ICT Provider Designation Record RARE

JSON record documenting the designation of ICT third-party service providers as critical, including designation criteria, assessment results, and oversight implications.

Formats
JSON
Evidence Class
critical-provider-designation
Availability
RARE
Update Frequency
annual
Typical Author
CRO
Approval Chain
CRO → Board Risk Committee

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

JSON — Inline Preview
{
  "designationRecord": {
    "recordId": "CPD-2025-001",
    "institution": "Nordvik Bank AG",
    "assessmentDate": "2025-01-30",
    "assessedBy": "Elena Vasquez, Risk Manager — Third-Party ICT Risk",
    "approvedBy": "Board Risk Committee",
    "approvalDate": "2025-02-05",
    "regulatoryBasis": "DORA Article 31, ESA RTS on Criticality Designation Criteria",
    "nextReviewDate": "2026-01-30"
  },
  "designationCriteria": {
    "description": "Criteria for designating ICT third-party service providers as critical, based on DORA Article 31 and ESA Regulatory Technical Standards.",
    "criteria": [
      {
        "criterionId": "DC-01",
        "name": "Systemic importance",
        "description": "The provider serves a significant number of financial entities or supports functions whose disruption could affect financial stability.",
        "threshold": "Serves 10 or more financial entities in the EEA, or supports critical functions for 3 or more systemically important institutions."
      },
      {
        "criterionId": "DC-02",
        "name": "Substitutability",
        "description": "The degree to which the provider's services can be replaced by alternative providers.",
        "threshold": "Rated 'difficult_to_substitute' or 'not_substitutable' in the Bank's substitutability analysis."
      },
      {
        "criterionId": "DC-03",
        "name": "Impact on critical functions",
        "description": "The potential impact of the provider's failure on the Bank's critical or important functions.",
        "threshold": "Supports 3 or more critical business functions, or a single function whose disruption would cause severe financial or operational impact."
      },
      {
        "criterionId": "DC-04",
        "name": "Concentration risk",
        "description": "The degree to which the provider creates concentration risk at entity or sector level.",
        "threshold": "Single-provider dependency for any critical service, or provider represents more than 30% of critical ICT spend."
      }
    ]
  },
  "providerDesignations": [
    {
      "providerId": "PRV-001",
      "providerName": "Meridian Cloud Services GmbH",
      "designationDate": "2025-02-05",
      "isDesignatedCritical": true,
      "designationCriteriaMet": true,
      "criteriaAssessment": {
        "DC-01": {
          "met": true,
          "evidence": "Meridian serves 12 mid-size banks in the DACH region and 3 insurance companies. Designated as systemically important by BaFin preliminary assessment."
        },
        "DC-02": {
          "met": true,
          "evidence": "Rated 'difficult_to_substitute' — deep Temenos T24 integration, 18-month estimated transition period."
        },
        "DC-03": {
          "met": true,
          "evidence": "Supports 4 critical business functions: core banking, payment processing infrastructure, customer data storage, regulatory reporting."
        },
        "DC-04": {
          "met": true,
          "evidence": "Single-provider dependency for core banking hosting. Represents 26% of total critical ICT spend."
        }
      },
      "systemicImportanceScore": 82,
      "financialEntitiesServed": 15,
      "leadOverseerAssigned": true,
      "leadOverseerAuthority": "EBA (European Banking Authority)",
      "oversightImplications": [
        "Subject to annual oversight assessment by Lead Overseer",
        "Required to submit ICT risk management documentation to Lead Overseer",
        "Subject to on-site inspections under DORA Article 37",
        "Bank must include Meridian in its DORA Article 28(3) register with critical designation"
      ]
    },
    {
      "providerId": "PRV-003",
      "providerName": "SwiftPay Solutions B.V.",
      "designationDate": "2025-02-05",
      "isDesignatedCritical": true,
      "designationCriteriaMet": true,
      "criteriaAssessment": {
        "DC-01": {
          "met": true,
          "evidence": "SwiftPay processes payments for 28 financial entities across the EU. Under consideration for ESA-level critical designation."
        },
        "DC-02": {
          "met": true,
          "evidence": "Rated 'difficult_to_substitute' — PCI-DSS certification and card scheme connectivity required. 12-month transition estimate."
        },
        "DC-03": {
          "met": true,
          "evidence": "Supports 4 critical business functions: card acquiring, SEPA transfers, direct debits, instant payments."
        },
        "DC-04": {
          "met": true,
          "evidence": "Single-provider dependency for all payment processing. Represents 19% of total critical ICT spend."
        }
      },
      "systemicImportanceScore": 78,
      "financialEntitiesServed": 28,
      "leadOverseerAssigned": true,
      "leadOverseerAuthority": "EBA (European Banking Authority)",
      "oversightImplications": [
        "Subject to annual oversight assessment by Lead Overseer",
        "Required to demonstrate PCI-DSS compliance and card scheme certifications",
        "Subject to general investigations under DORA Article 36",
        "Bank must maintain documented exit strategy per DORA Article 44"
      ]
    },
    {
      "providerId": "PRV-002",
      "providerName": "Sentinel Cyber AG",
      "designationDate": "2025-02-05",
      "isDesignatedCritical": false,
      "designationCriteriaMet": false,
      "criteriaAssessment": {
        "DC-01": {
          "met": false,
          "evidence": "Sentinel serves 8 financial entities — below the 10-entity threshold."
        },
        "DC-02": {
          "met": false,
          "evidence": "Rated 'substitutable_with_effort' — multiple managed SOC providers available in EU market."
        },
        "DC-03": {
          "met": true,
          "evidence": "Supports 3 critical functions: security monitoring, incident detection, threat intelligence."
        },
        "DC-04": {
          "met": false,
          "evidence": "Not a single-provider dependency (alternatives identified). Represents 10% of critical ICT spend."
        }
      },
      "systemicImportanceScore": 41,
      "financialEntitiesServed": 8,
      "leadOverseerAssigned": false,
      "leadOverseerAuthority": null,
      "oversightImplications": [
        "Not subject to Lead Overseer oversight",
        "Standard third-party risk management applies",
        "Annual due diligence review required"
      ]
    }
  ]
}

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

critical_provider_designation_status — fs-critical-provider-designation
{
  "factId": "b7c8d9e0-f1a2-3456-bcde-678901234567",
  "evidenceId": "a6b7c8d9-e0f1-2345-6789-012345abcdef",
  "evidenceClassId": "critical-provider-designation",
  "factType": "critical_provider_designation_status",
  "data": {
    "provider_id": "PRV-001",
    "designation_date": "2025-02-05",
    "is_designated_critical": true,
    "designation_criteria_met": true,
    "systemic_importance_score": 82,
    "financial_entities_served": 15,
    "lead_overseer_assigned": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-02-06T09:00:00Z",
  "supersededBy": null
}

Fact Schemas

critical_provider_designation_status

Schema ID
fs-critical-provider-designation
Control
DORA-Art32-P1

Valid Ranges

designation_date
within last 12 months
systemic_importance_score
above threshold defined by ESA RTS

Related Schemas

JSON Schema

{
  "properties": {
    "designation_criteria_met": {
      "type": "boolean"
    },
    "designation_date": {
      "format": "date",
      "type": "string"
    },
    "financial_entities_served": {
      "minimum": 0,
      "type": "integer"
    },
    "is_designated_critical": {
      "type": "boolean"
    },
    "lead_overseer_assigned": {
      "type": "boolean"
    },
    "provider_id": {
      "minLength": 1,
      "type": "string"
    },
    "systemic_importance_score": {
      "maximum": 100,
      "minimum": 0,
      "type": "number"
    }
  },
  "required": [
    "provider_id",
    "designation_date",
    "is_designated_critical",
    "designation_criteria_met"
  ],
  "type": "object"
}