Technology service provider designated by the European supervisory authorities as systemic for the financial sector, and subject on that basis to a regime of direct oversight.
Designation requires four cumulative conditions to be met: the systemic impact of a large-scale operational failure, the systemic character or importance of the dependent financial entities, the fact that this dependence attaches to critical functions, and the degree of substitutability of the provider. The fourth criterion is the only one that actually measures systemic character, and it inverts the competition reflex: what makes a provider critical is not its market share but the impossibility of leaving it quickly. The method used to build the list interests insurance more than the list itself, since a supervisor obtained through a reporting obligation the map of shared technical dependencies the market had demanded for fifteen years without ever being able to produce it, for want of power to compel declaration.
Supervising governance reduces the probability of a failure, it does nothing to its consequence: a regulator can make a single point of failure more reliable, it cannot make it less single.
CTPP, critical ICT third-party provider, prestataire tiers critique, prestataire informatique critique