Skip to main content
DORA Auditor

Single Point of Failure

Last updated: 1 authoritative sourceDORA Auditor Editorial Team

A single point of failure is any component, system, or provider whose failure alone would disrupt a critical or important function with no alternative in place to keep it running. Under DORA it is a central concept in assessing ICT concentration risk (Article 29) and in the systemic reasoning behind the Oversight Framework for critical ICT third-party providers.

Detailed explanation

Single points of failure can sit inside an entity's own infrastructure (an unreplicated data centre, a single administrator credential, a system with no failover) or, more commonly in the DORA context, in its dependency chain: a critical or important function that relies on one cloud region, one software vendor, or one ICT third-party provider with no realistic substitute. Article 29 requires financial entities to assess this before and during outsourcing, weighing how difficult substitution would be and whether sub-outsourcing quietly reintroduces a dependency the entity thought it had diversified away. At the sector level, the same logic underpins why substitutability and the number of financial entities relying on a given provider are among the criteria used to designate a critical ICT third-party provider for direct EU oversight: a provider that is a single point of failure for many entities at once is a systemic risk, not just an individual one. Reducing single points of failure typically means multi-region or multi-provider architecture where proportionate, documented failover and backup arrangements, and exit strategies that are actually exercised rather than theoretical.

In context

This term relates to the ICT Third-Party Risk pillar and is grounded in DORA Article 29.

Related terms

Sources

  1. DORA Article 29, EUR-Lex