What provider oversight covers
In the EU, one of the three European supervisory authorities acts as lead overseer for each designated provider and assesses whether it has adequate risk management and governance for the ICT risk it poses to financial firms. Oversight starts from a date notified to each provider, after which the overseer can request information, investigate, inspect and issue recommendations. The list is updated each year. Firms may continue to use a designated provider established outside the EU only if it sets up an EU subsidiary within 12 months of designation.
In the UK, the Bank of England, the PRA and the FCA jointly oversee the critical services the four providers supply to the UK financial sector, against rules covering governance, supply chain, cyber resilience, change management and incident management. Designation is neither an authorisation nor an endorsement of the provider. UK and EU regulators agreed in January 2026 to cooperate on this oversight.
Both regimes address the provider's risk to the financial sector as a whole. How a firm configures a service, how far it depends on it and how it could replace it remain for the firm to assess.
What stays with the firm
- Responsibility
- Under DORA, financial firms remain fully responsible for their obligations at all times. In the UK, designation leaves regulated firms responsible for managing their own third-party arrangements under existing operational resilience and outsourcing rules.
- Classification
- Designation reflects a provider's importance to the financial system. Whether a service supports a critical or important function is the firm's own classification, and suppliers outside the designation lists can support critical functions as well.
- Concentration
- Before contracting, firms assess whether a provider can be readily replaced, and whether several critical arrangements would sit with one provider or with closely connected providers. The assessment extends to long or complex chains of subcontractors.
- Board review
- The management body regularly reviews the risks in arrangements that support critical or important functions. That review should identify which dependencies exceed the firm's risk appetite and what action or investment needs approval.
- Exit
- Services that support critical or important functions need exit strategies. Each should set out a feasible alternative, what must be rebuilt or transferred, and how critical services continue during migration.
A scenario boards should test
Under DORA, if a designated provider does not address its overseer's recommendations and a firm has not managed the resulting risks, supervisors can, as a last resort and after notifying the firm, require it to suspend or end its use of the service, in part or in full. Firms are given time to adjust their contracts and carry out their exit plans.
An exit plan may therefore have to be used because of a supervisory decision, as well as after an outage or a commercial failure. The board should know how long an exit would take for each critical service, and what the firm would do in the meantime.
Questions for the board
These questions help the board establish whether the firm's own evidence supports its reliance on designated providers.
- Exposure
- Which critical or important functions depend on designated providers and other key suppliers, and how concentrated is that dependence?
- Assurance
- What does the firm take from the provider's oversight, and what does it assess for itself?
- Exit
- What did the latest exit test demonstrate, what remains unproven, and how long would transition take?
- Contracts
- Do the contracts give the firm the information, audit and exit rights it needs?