Skip to content
DIRECT OVERSIGHT

Critical ICT third-party provider

Cloud, hosting or ICT service provider designated as “critical” by the European Supervisory Authorities.

Download this sheet to share or keep it.

Download as PDF

Your obligations

  • 1

    Direct oversight by a European authority designated as Lead Overseer (Art. 31-44).

    Being designated a critical provider triggers an in-depth review conducted by one of the three European Supervisory Authorities (EBA, ESMA or EIOPA).

  • 2

    Access to the information, systems and premises needed for the oversight review.

    The provider must fully cooperate with the Joint Examination Teams set up by the Lead Overseer.

  • 3

    Implementation of the recommendations issued by the Lead Overseer.

    These recommendations may cover security, operational resilience, or the management of the provider's subcontractors.

  • 4

    Possible daily penalty payments for non-compliance, of up to 1% of average daily worldwide turnover (Art. 35).

    This penalty can be applied for up to six months, until the provider complies with the recommendations issued.