Question ID: DORA123 - 3163
Regulation Reference: (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Topic: ICT risk management (DORA)
Article: 3(22)
Status: Rejected
Date of submission: 03 Oct 2024
Question
Do you have examples of critical or important functions in the insurance sector from a DORA perspective ? We are currently reviewing the business impact analyses and trying to identify the critical functions based on the criteria "[...] or the discontinued, defective or failed performance of that function would materially impair the continuing compliance of a financial entity with the conditions and obligations of its authorisation, or with its other obligations under applicable financial services law". Do you have a list of functions ? Would functions of the second line of defense like CISO / DPO / BCM be also considered as critical functions, as should normally be CCO / CRO / Actuarial function ? If we considered the criteria of continuity of activity at entity-level to identify critical activities, would the members of the crisis management be considered as critical as their presence is potentially required during a disaster, based on the scenario, or should we consider their business role only, in which case they can rely on their teams for the continuity of activity?
Background of the question
Difficulty to interpret the regulatory criteria to identify a critical activity under Dora based on Art. 3(22)
EIOPA answer
This question has been rejected because the issue it deals with is clear from the regulation. Additional information on the matter can be found in the answer to Q&A DORA019.