DORA123 - 3163 - EIOPA Skip to main content
European Insurance and Occupational Pensions Authority

DORA123 - 3163

Q&A

Question ID: DORA123 - 3163

Regulation Reference: (EU) 2022/2554 - Digital Operational Resilience Act (DORA)

Topic: ICT risk management (DORA)

Article: 3(22)

Status: Rejected

Date of submission: 03 Oct 2024

Question

Do you have examples of critical or important functions in the insurance sector from a DORA perspective ? We are currently reviewing the business impact analyses and trying to identify the critical functions based on the criteria "[...] or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law". Do you have a list of functions ? Would functions of the second line of defense like CISO / DPO / BCM be also considered as critical functions, as should normally be CCO / CRO / Actuarial function ? If we considered the criteria of continuity of activity at entity-level to identify critical activities, would the members of the crisis management be considered as critical as their presence is potentially required during a disaster, based on the scenario, or should we consider their business role only, in which case they can rely on their teams for the continuity of activity?

Background of the question

Difficulty to interpret the regulatory criteria to identify a critical activity under Dora based on Art. 3(22)

EIOPA answer

This question has been rejected because the issue it deals with is clear from the regulation. Additional information on the matter can be found in the answer to Q&A DORA019.