Critical or Important Function
A critical or important function is an activity within a financial firm that is so essential that, if it were disrupted, it could seriously harm the firm's ability to operate, meet its legal duties, or provide services to customers. Under the EU's Digital Operational Resilience Act (DORA), each financial entity is expected to identify which of its own functions fall into this category. This classification then shapes how closely the firm must manage and oversee the technology and third-party providers that support those functions.
Under the EU Digital Operational Resilience Act (DORA), a "critical or important function" is a term defined in Article 3(22) and applied through an internal classification that each financial entity makes for its own functions. Per the evidence, a function is generally treated as critical or important where its disruption could significantly impair the financial entity's financial performance, the soundness or continuity of its services and activities, or its ability to fulfil applicable legal and regulatory obligations. The classification is entity-specific and drives downstream obligations, including identifying the ICT systems and third-party service providers that underpin such functions and applying heightened resilience, oversight, and contractual requirements to them. The precise scope, boundary conditions (for example, how this term relates to similar concepts under other EU financial regulations), and detailed application criteria should be verified against the DORA text and relevant regulatory guidance, as these can involve legal interpretation and vary by entity and supervisory expectation; matters of legal interpretation fall outside this definition and may require professional advice.
Why it matters
The classification of critical or important functions sits at the heart of DORA's approach to operational resilience because it determines the intensity of the obligations that follow. A financial entity that identifies a function as critical or important must, per the evidence, apply heightened resilience, oversight, and contractual requirements to the ICT systems and third-party service providers that underpin it. Getting the classification right therefore matters directly: under-classifying a function may leave genuinely essential activities without the enhanced controls DORA expects, while over-classifying may divert resources toward activities that do not warrant that level of scrutiny.
The concept also reflects a supervisory concern that disruption to certain functions could significantly impair a firm's financial performance, the soundness or continuity of its services, or its ability to meet applicable legal and regulatory obligations. By requiring firms to make this determination for their own functions, DORA places the burden of judgement on the entity itself, which in turn exposes that judgement to supervisory review. Because the classification is entity-specific rather than prescribed by a fixed list, firms bear responsibility for documenting and defending their reasoning.
It is worth noting that the precise boundary of this term, including how it relates to similar concepts under other EU financial regulations, can involve legal interpretation and may vary by entity and supervisory expectation. Firms should verify scope and application criteria against the DORA text and relevant regulatory guidance rather than relying on a generic reading, and treat matters of legal interpretation as requiring professional advice.
Who it's relevant to
Inside CIF
Common questions
Answers to the questions practitioners most commonly ask about CIF.

