Back to glossaryLaw & regulation

European oversight of critical technology providers

Regime created by DORA placing certain technology providers, non-financial and until then outside the prudential perimeter, under direct oversight by the European supervisory authorities.

Definition

Prudential law addresses regulated entities, and a hosting provider is not one: the supervisor could reach it only indirectly, through the contract of the insurer using it, which assumes bargaining power the insurer does not have. DORA takes the step. The European supervisory authorities designate technology service providers deemed critical for the financial sector, in light of the systemic importance of the entities depending on them, the degree of substitutability, and the criticality of the functions served. A lead overseer is designated for each, able to request information, conduct investigations and inspections including on site, and issue recommendations on security, subcontracting and contractual terms. A provider that does not comply faces a periodic penalty payment, and financial entities may be required to suspend or terminate their use of its services. The regime does not turn the provider into a regulated entity, but it moves the supervisory frontier outside the financial sector, which is without precedent in European financial services law.

Example

Regulation (EU) 2022/2554, applicable since January 17, 2025, in the chapter devoted to the oversight framework. Designation relies on the registers of information filed by financial entities, which explains the ordering of deadlines: the dependency map had to be visible first, designation only afterward. The periodic penalty payment provided for is computed as a percentage of the provider's average daily worldwide turnover, a mechanism borrowed from competition law rather than prudential law.

Related terms
Also known as

oversight framework, superviseur principal, lead overseer, désignation de prestataire critique