DORA-Art32-P1

Article
32 (1)
Pillar
Third-Party ICT Risk Management
Regulation Ref
Regulation (EU) 2022/2554, Article 32(1)
Last Reviewed
2026-01-15

The ESAs shall, through the Joint Committee, develop common draft regulatory technical standards to further specify the criteria for the designation of ICT third-party service providers as critical for financial entities.

Evidence Profiles

Critical ICT Provider Designation Record RARE

JSON record documenting the designation of ICT third-party service providers as critical, including designation criteria, assessment results, and oversight implications.

Formats
JSON
Evidence Class
critical-provider-designation
Availability
RARE
Update Frequency
annual
Typical Author
CRO
Approval Chain
CRO → Board Risk Committee

Content Sections

Expected Fields

Common Quality Issues

Fact Schemas

critical_provider_designation_status

Schema ID
fs-critical-provider-designation
Control
DORA-Art32-P1

Valid Ranges

designation_date
within last 12 months
systemic_importance_score
above threshold defined by ESA RTS

Related Schemas

JSON Schema

{
  "properties": {
    "designation_criteria_met": {
      "type": "boolean"
    },
    "designation_date": {
      "format": "date",
      "type": "string"
    },
    "financial_entities_served": {
      "minimum": 0,
      "type": "integer"
    },
    "is_designated_critical": {
      "type": "boolean"
    },
    "lead_overseer_assigned": {
      "type": "boolean"
    },
    "provider_id": {
      "minLength": 1,
      "type": "string"
    },
    "systemic_importance_score": {
      "maximum": 100,
      "minimum": 0,
      "type": "number"
    }
  },
  "required": [
    "provider_id",
    "designation_date",
    "is_designated_critical",
    "designation_criteria_met"
  ],
  "type": "object"
}