Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Third-Party Risk Management

Critical or Important Function

Also known as: CIF, Critical or Important Functions, CIFs
Simply put

A critical or important function is an activity within a financial firm that is so essential that, if it were disrupted, it could seriously harm the firm's ability to operate, meet its legal duties, or provide services to customers. Under the EU's Digital Operational Resilience Act (DORA), each financial entity is expected to identify which of its own functions fall into this category. This classification then shapes how closely the firm must manage and oversee the technology and third-party providers that support those functions.

Formal definition

Under the EU Digital Operational Resilience Act (DORA), a "critical or important function" is a term defined in Article 3(22) and applied through an internal classification that each financial entity makes for its own functions. Per the evidence, a function is generally treated as critical or important where its disruption could significantly impair the financial entity's financial performance, the soundness or continuity of its services and activities, or its ability to fulfil applicable legal and regulatory obligations. The classification is entity-specific and drives downstream obligations, including identifying the ICT systems and third-party service providers that underpin such functions and applying heightened resilience, oversight, and contractual requirements to them. The precise scope, boundary conditions (for example, how this term relates to similar concepts under other EU financial regulations), and detailed application criteria should be verified against the DORA text and relevant regulatory guidance, as these can involve legal interpretation and vary by entity and supervisory expectation; matters of legal interpretation fall outside this definition and may require professional advice.

Why it matters

The classification of critical or important functions sits at the heart of DORA's approach to operational resilience because it determines the intensity of the obligations that follow. A financial entity that identifies a function as critical or important must, per the evidence, apply heightened resilience, oversight, and contractual requirements to the ICT systems and third-party service providers that underpin it. Getting the classification right therefore matters directly: under-classifying a function may leave genuinely essential activities without the enhanced controls DORA expects, while over-classifying may divert resources toward activities that do not warrant that level of scrutiny.

The concept also reflects a supervisory concern that disruption to certain functions could significantly impair a firm's financial performance, the soundness or continuity of its services, or its ability to meet applicable legal and regulatory obligations. By requiring firms to make this determination for their own functions, DORA places the burden of judgement on the entity itself, which in turn exposes that judgement to supervisory review. Because the classification is entity-specific rather than prescribed by a fixed list, firms bear responsibility for documenting and defending their reasoning.

It is worth noting that the precise boundary of this term, including how it relates to similar concepts under other EU financial regulations, can involve legal interpretation and may vary by entity and supervisory expectation. Firms should verify scope and application criteria against the DORA text and relevant regulatory guidance rather than relying on a generic reading, and treat matters of legal interpretation as requiring professional advice.

Who it's relevant to

Compliance and operational resilience officers
Those responsible for DORA readiness must lead or coordinate the internal classification of functions and ensure the reasoning is documented and defensible to supervisors. Because the classification is entity-specific and drives the scope of downstream resilience and oversight obligations, its accuracy directly shapes the firm's compliance posture.
Third-party risk and procurement teams
Once functions are classified as critical or important, teams managing ICT third-party providers must identify the systems and providers that underpin those functions and apply the heightened contractual and oversight requirements DORA expects, including systems within a third party on which the entity relies for critical or important services.
Risk managers and internal auditors
These professionals assess whether the entity's classification methodology is sound, consistently applied, and aligned with the risk that disruption could impair financial performance, service continuity, or legal compliance. They also test whether the controls applied to underpinning systems and providers match the classification assigned.
General counsel and legal advisers
Because the precise scope of the term and its relationship to similar concepts under other EU financial regulations can involve legal interpretation, legal teams are relevant to confirming how the definition applies to the entity's specific circumstances and supervisory expectations. Matters of legal interpretation fall outside a general definition and may warrant tailored advice.

Inside CIF

Function
A discrete activity, service, or operation carried out by an organization, whether performed internally or supported by a third party. In the context of this concept, the assessment focuses on whether that activity meets criteria that elevate it to critical or important status.
Criticality assessment
The analysis used to determine whether a function is 'critical or important,' typically considering the impact its disruption would have on the organization's ability to continue providing services, to meet its objectives, or to comply with applicable obligations. Criteria and thresholds often vary by framework, sector, and jurisdiction.
Impact of disruption
A central element in classifying a function, generally referring to the consequences a failure or interruption would have, such as effects on continuity of operations, on customers or counterparties, or on regulatory obligations. The specific factors weighed depend on the governing regime and should be verified against the primary source.
Regulatory context
The concept appears in various supervisory and regulatory regimes, particularly those addressing operational resilience and outsourcing or third-party arrangements. The precise definition, applicable thresholds, and consequences of classification are set by the specific applicable rules and typically differ across jurisdictions and sectors.
Consequences of classification
Designating a function as critical or important often triggers heightened expectations, such as enhanced governance oversight, more rigorous risk management, contractual safeguards for outsourced arrangements, and continuity planning. The exact obligations attached to the designation depend on the governing framework and should be confirmed against the applicable source.

Common questions

Answers to the questions practitioners most commonly ask about CIF.

Is a 'critical or important function' the same as any function an organization considers valuable or high-priority?
No. The term is typically used in a more specific, regulatory sense rather than as a general label for functions an organization happens to value. In many operational resilience and outsourcing frameworks, a function is treated as critical or important where its disruption could materially impair an organization's ability to meet regulatory obligations, continue in business, or provide essential services, rather than simply because it is commercially significant. Because the precise definition and its triggers vary by jurisdiction, sector, and the specific framework or regulation in question, organizations should confirm the applicable criteria against the relevant primary source rather than rely on an internal notion of importance.
Does classifying a function as critical or important mean it must never be outsourced or must be brought back in-house?
Not typically. The classification generally drives heightened governance, oversight, and continuity expectations rather than a prohibition on outsourcing. In many frameworks, functions identified as critical or important may still be outsourced, but doing so often attracts additional requirements, such as more rigorous due diligence, stronger contractual provisions, exit and continuity planning, and ongoing monitoring. Whether and how a specific function may be outsourced depends on the applicable regulation and jurisdiction, and legal or regulatory advice may be needed for specific arrangements.
How does an organization typically go about identifying which functions are critical or important?
Identification is often based on an assessment of the potential impact of disruption against defined criteria, commonly considering effects on the organization's ability to meet regulatory obligations, maintain financial soundness, or deliver essential services to clients and the market. Many organizations use a structured, documented methodology, frequently linked to business impact analysis, to apply consistent criteria across functions. Because applicable criteria vary by framework and jurisdiction, the specific thresholds and factors used should be verified against the relevant primary source.
Who is usually responsible for approving the designation of a function as critical or important?
In many governance arrangements, the designation is a matter for senior management or the board, or a delegated committee, given its implications for oversight, resourcing, and risk. This reflects the governance principle that decisions with significant impact on objectives and regulatory standing sit with an appropriate level of authority. The precise allocation of decision rights depends on the organization's structure and any applicable regulatory expectations, so responsibilities should be defined and documented internally.
How often should the list of critical or important functions be reviewed?
Periodic review is commonly expected, with many organizations reassessing on a regular cycle and also upon significant change, such as new products, restructuring, changes to outsourcing arrangements, or shifts in the regulatory environment. The aim is to keep the classification current so that oversight and continuity measures remain aligned with actual operations. Specific review frequencies, where mandated, vary by framework and should be confirmed against the applicable source.
What obligations typically follow once a function is classified as critical or important?
Consequences often include enhanced continuity and resilience planning, closer oversight and monitoring, stronger controls, and, where the function is outsourced, more stringent due diligence, contractual safeguards, and exit strategies. The classification frequently spans governance, risk management, and compliance, since it engages decision rights, treatment of disruption risk, and adherence to regulatory expectations. The exact obligations depend on the applicable framework, jurisdiction, and sector, and any specific legal requirements should be verified against the relevant primary source.

Common misconceptions

'Critical' and 'important' are two separate tiers with distinct, universally recognized meanings.
Many regulatory regimes treat 'critical or important function' as a single combined classification rather than two ranked tiers, and terminology varies across frameworks and jurisdictions. Practitioners should not assume a fixed hierarchy and should verify how the governing regime defines and uses the terms.
A function is critical or important only if it is outsourced to a third party.
The classification generally concerns the significance of the function itself, which may be performed internally or externally. While the concept is prominent in outsourcing and third-party risk contexts, an internally performed function can also meet the criteria depending on the applicable framework.
Once a function is classified as critical or important, the designation is permanent.
Criticality typically reflects the organization's circumstances and objectives at a point in time and can change as operations, dependencies, and the regulatory environment evolve. Classifications are usually expected to be reassessed periodically rather than treated as static.

Best practices

Establish documented criteria and thresholds for determining whether a function is critical or important, aligned with the specific applicable regulatory regime rather than a generic assumption.
Assess criticality based on the potential impact of disruption on continuity of operations, on affected stakeholders, and on the organization's regulatory obligations, considering functions performed both internally and by third parties.
Verify the precise definition, thresholds, and resulting obligations against the primary source governing your jurisdiction and sector, as these vary and evolve over time.
Reassess classifications periodically and upon material changes to operations, dependencies, or the regulatory environment, since criticality is context-dependent and not static.
Ensure that functions designated as critical or important receive commensurate governance oversight, risk management, and continuity planning, with clear ownership and decision rights.
Where classification affects outsourced or third-party arrangements, confirm that contractual and monitoring safeguards required by the applicable framework are in place, and seek professional advice on jurisdiction-specific interpretation where needed.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide