Chapter V — Managing of ICT third-party risk
Section II — Oversight framework for critical ICT third-party service providers
Structure of the Oversight Framework
Summary
Defines the institutional structure for overseeing critical ICT third-party providers, including the role of the Lead Overseer, the Joint Examination Team, and cooperation with national competent authorities.
Key Requirements
- 1
Lead Overseer designated from ESAs for each critical provider
- 2
Joint Examination Team supports oversight activities
- 3
Cooperation framework between Lead Overseer and national authorities
- 4
Oversight activities funded through fees from designated providers
Detailed Analysis
Article 32 establishes the institutional architecture for overseeing critical ICT third-party service providers. The Lead Overseer model ensures that each designated provider has a single primary supervisory counterpart, avoiding the fragmentation that would result from multiple national authorities independently overseeing the same global provider.
The Lead Overseer is supported by a Joint Examination Team comprising experts from the relevant ESAs and national competent authorities. This team provides the technical expertise and capacity needed for effective oversight of large, complex technology providers whose operations span multiple jurisdictions and serve diverse financial sectors.
The framework includes detailed cooperation arrangements between the Lead Overseer and national competent authorities, ensuring that local supervisory knowledge and concerns are incorporated into the oversight approach while maintaining the benefits of centralized coordination.
Importantly, the oversight framework is funded through fees charged to designated critical providers, ensuring that the cost of oversight falls on the entities creating the systemic risk rather than on public budgets or the financial entities that depend on these providers.
Ready to automate compliance with Article 32?
Valendir maps every DORA requirement to actionable controls, evidence, and workflows.