EIOPA · DORA123 - 3163
ICT risk management (DORA)
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- 3
- Topic
- ICT risk management (DORA)
- Submitted
- 2024-10-03
- Answered
- 2025-03-28
Question
Do you have examples of critical or important functions in the insurance sector from a DORA perspective ? We are currently reviewing the business impact analyses and trying to identify the critical functions based on the criteria "[...] or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law". Do you have a list of functions ? Would functions of the second line of defense like CISO / DPO / BCM be also considered as critical functions, as should normally be CCO / CRO / Actuarial function ? If we considered the criteria of continuity of activity at entity-level to identify critical activities, would the members of the crisis management be considered as critical as their presence is potentially required during a disaster, based on the scenario, or should we consider their business role only, in which case they can rely on their teams for the continuity of activity?
Background
Difficulty to interpret the regulatory criteria to identify a critical activity under Dora based on Art. 3(22)
Answer
This question has been rejected because the issue it deals with is clear from the regulation. Additional information on the matter can be found in the answer to Q&A DORA019.
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.