Loading…
Loading…
DORA Art. 29–35 grants the ESAs direct supervisory authority over CTPPs supplying ICT services to EU financial entities. Before any CTPPs could be formally designated (which happened in November 2025), the ESAs needed to publish the operational framework that would govern that oversight. JC 2025 29 is that framework.
Joint Oversight Venture (JOV): The ESAs established a cross-sectoral Joint Oversight Venture that became operational in October 2024. The JOV coordinates across banking, insurance, and securities sectors so that a single CTPP supplying all three faces consistent examination rather than three separate regimes. The guide is the JOV's primary procedural instrument.
Joint Examination Teams (JETs): One JET per CTPP, composed of staff from the lead overseer plus seconded experts from the other two ESAs. The lead overseer is determined by the financial sector in which the CTPP has the largest footprint:
Examination lifecycle: 1. Planning — annual oversight programme per CTPP based on risk assessment 2. On-site inspections and information requests — JET may enter CTPP premises globally 3. Risk assessment — standardised concentration-risk and operational-resilience scoring 4. Binding recommendations — ESAs may issue mandatory remediation requirements; CTPPs must implement or face daily penalties 5. Follow-up — ESAs verify implementation; persistent non-compliance escalates to daily fines under Art. 35(6) DORA (up to 1% of average daily worldwide turnover per breach day)
Penalty process: Penalties flow from Art. 35(6) DORA — the ESAs can impose fines directly on CTPPs (not just on the financial entities that use them). The guide details the investigation procedure, rights of defence, and publication of penalty decisions. For hyperscale cloud providers (AWS, Microsoft, Google Cloud), whose daily global revenues run to hundreds of millions of dollars, a 1%-per-day penalty regime is a material enforcement tool — not symbolic.
Operations, Google Cloud EMEA, Bloomberg Finance, SAP SE, Oracle Corporation, IBM, and 12 others are now operating under JET supervision pursuant to the governance this guide establishes. JET examinations commenced in 2026.
concentration-risk scrutiny from their own competent authority, triggered by the ICT third-party risk management obligations in DORA Art. 28–30 and operationalised through the register of information each FI must maintain per Art. 28(3).
concentration in supervisory practice. The IPTM platform's DORA-FI axis maps FI concentration exposure onto the 19 designated CTPPs; this guide defines EXACTLY what the ESAs will scrutinise in JET examinations — making it the primary regulatory reference for interpreting concentration-risk ratings on the platform.
ESA guidance carries quasi-binding force under the "comply or explain" mechanism of EU supervisory practice; supervisors treat non-compliance as presumptive non-compliance with the underlying regulation.
describes a publication process for penalty decisions but is ambiguous on whether routine examination reports are disclosed.
conflicting national law on data access (e.g., a Swiss affiliate of a US provider)?
risk prioritisation across the 19 CTPPs? (Would feed directly into IPTM scoring cadence.)