Skip to main content
DORA Auditor

Critical or Important Function

Last updated: 1 authoritative sourceDORA Auditor Editorial Team

A critical or important function is any activity, service, or process whose failure would seriously impair a financial entity's performance, its financial soundness, or the continuity of its regulated activities. DORA Article 3(22) defines the term, and it is the trigger that decides how strictly many of the regulation's obligations apply.

Detailed explanation

DORA does not treat every activity or contract equally. Instead, it repeatedly scales obligations to whether a service, process, or ICT arrangement supports a critical or important function (CIF). Contracts with ICT third-party providers that support a CIF must contain the fuller set of contractual provisions listed in Article 30, including audit rights, exit strategies, and subcontracting conditions, while support for non-critical functions can rely on lighter terms. The register of information required by Article 28 must flag which arrangements support a CIF, since these entries draw closer supervisory scrutiny. Whether a function is critical is a judgement call the financial entity itself must make and document, weighing factors such as the impact of disruption on clients, market functioning, and financial stability, and regulators expect that assessment to be revisited whenever the entity's operating model changes. Because the designation cascades into contract terms, incident-classification thresholds, and resilience-testing scope, getting the CIF assessment wrong, in either direction, either under-scopes obligations or wastes compliance effort on low-risk arrangements.

In context

This term relates to the ICT Third-Party Risk pillar and is grounded in DORA Article 3.

Related terms

Sources

  1. DORA Article 3(22) and Article 30, EUR-Lex