One of the biggest issues firms are grappling with is figuring out which suppliers truly matter under DORA. Some are narrowing their focus using their own definitions of Tier 1 and Tier 2 suppliers, while others are casting a wide net, mapping every technology provider.
Some firms are focusing on operational resilience frameworks, using the Important Business Services as a starter, then scoping DORA through identifying the 'critical' IT providers for those services.
Other firms are also factoring in their latest assessment of Critical or Important Functions (CIFs), adding another layer of complexity.
There was no single, consistent approach being used. With institutions struggling to align, this is likely to lead to mixed messages and inconsistent expectations of suppliers further down the chain. In turn, this may expose inconsistencies in the required Registers of Information.
We expect regulators to ask for copies of the Registers of Information in 2025 in order to understand the critical supplier landscape to a greater extent. Inconsistent scoping and definitions of critical ICT providers may set off alarm bells once their analysis is completed.