Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Third-Party Risk Management

ICT Third-Party Service Provider

Also known as: ICT TPSP, ICT provider, ICT third-party service provider, third-party ICT provider
Simply put

An ICT third-party service provider is a company that supplies information and communication technology (ICT) services, such as digital and data services, to another organization. Under the EU's Digital Operational Resilience Act (DORA), financial entities that rely on these external providers must manage the risks arising from that dependence. Some providers may be further designated as 'critical' where they are considered systemically important to the EU financial sector.

Formal definition

Within the EU Digital Operational Resilience Act (DORA) framework, an ICT third-party service provider (ICT TPSP) is defined as an undertaking that provides ICT services (per Article 3 point 19 DORA), where ICT services are generally understood to encompass digital and data services provided to one or more internal or external users. The use of such providers gives rise to 'ICT third-party risk', the ICT-related risk that may arise for a financial entity in connection with its use of externally provided ICT services. A subset of ICT TPSPs may be designated as 'critical ICT third-party service providers' (CTPPs) by the European Supervisory Authorities under Article 31, a designation that in the reviewed sources is described as applying where a provider is systemically important to the EU financial sector and cumulatively meets the applicable quantitative sub-criteria of the designation assessment. Note that a regulated financial entity may itself additionally qualify as an ICT TPSP where it provides ICT services to others. Precise definitional wording, criteria thresholds, effective dates, and scope of application should be verified against the primary DORA text and its implementing measures, and applicability is specific to entities within DORA's scope.

Why it matters

The concept of the ICT third-party service provider sits at the heart of DORA's approach to operational resilience in the EU financial sector. Financial entities increasingly depend on externally provided digital and data services, and that dependence introduces ICT third-party risk, the ICT-related risk that may arise for a financial entity in connection with its use of these external services. Because a disruption, failure, or security weakness at a provider can propagate into the financial entities that rely on it, DORA requires those entities to actively identify, assess, and manage the risks flowing from these relationships rather than treating outsourcing as a transfer of responsibility.

The stakes rise further where a provider is designated as a 'critical ICT third-party service provider' (CTPP). Under Article 31, the European Supervisory Authorities may designate a provider as systemically important to the EU financial sector where it cumulatively meets the applicable quantitative sub-criteria of the designation assessment. Such a designation reflects the recognition that concentration of critical services in a small number of providers can create sector-wide exposure, so certain providers warrant heightened attention. For financial entities, understanding whether a provider falls within scope, and potentially within the critical designation, shapes contractual, monitoring, and governance obligations.

A further nuance that matters in practice is that a regulated financial entity may itself additionally qualify as an ICT third-party service provider where it provides ICT services to others. This means an organization can occupy both sides of the relationship, adding complexity to how it maps and manages its obligations. Because the precise definitional wording, criteria thresholds, effective dates, and scope depend on the primary DORA text and its implementing measures, entities should verify specifics against those sources and assess applicability to their own circumstances.

Who it's relevant to

Compliance officers at financial entities
Those responsible for DORA compliance need to determine which of their suppliers meet the ICT third-party service provider definition and whether any relationships involve providers that could be designated as critical. This classification informs the scope of contractual, monitoring, and risk-management obligations, and should be validated against the primary DORA text and implementing measures.
Risk managers and operational resilience teams
Because ICT third-party risk is the ICT-related risk arising from the use of externally provided ICT services, risk teams must identify, assess, and treat this exposure as part of managing dependence on external providers. Concentration in systemically important providers is a particular focus, given the potential for sector-wide impact.
ICT service providers to the financial sector
Undertakings that supply digital and data services to financial entities may fall within DORA's scope as ICT third-party service providers, and a subset may be designated as critical under Article 31 where they are systemically important and meet the applicable quantitative sub-criteria. Providers should assess whether and how the framework applies to them.
Regulated entities that also provide ICT services
A regulated financial entity may itself additionally qualify as an ICT third-party service provider where it provides ICT services to others. Such organizations may hold obligations on both sides of the relationship and should map their status carefully against the primary sources.
Legal counsel and contract teams
Because definitional wording, criteria thresholds, effective dates, and scope of application depend on the primary DORA text and its implementing measures, legal and contracting professionals play a key role in confirming classification and reflecting the resulting obligations in provider arrangements. Matters of interpretation may require professional legal advice.

Inside ICT TPSP

Provision of ICT Services
The defining characteristic of an ICT third-party service provider is that it supplies information and communication technology services to an organization, such as cloud computing, data processing, software provision, network services, or related technology-enabled functions. The precise scope of what qualifies as an 'ICT service' can vary by framework and regulatory regime and should be verified against the applicable source.
External Party Relationship
The provider is a distinct legal entity outside the organization consuming the service, engaged typically through a contractual arrangement. This external status is what brings the relationship within the ambit of third-party risk management and outsourcing oversight considerations.
Contractual Arrangement
The relationship is generally governed by a contract or agreement setting out the services, obligations, and terms. In many regulatory contexts, certain provisions relating to security, audit rights, subcontracting, and termination are emphasized, though specific mandatory clauses vary by jurisdiction and sector and should be checked against primary sources.
Subcontracting Chains
An ICT third-party service provider may itself rely on further providers (often described as fourth parties or subcontractors), creating a chain of dependencies. Many frameworks highlight the need to consider these downstream arrangements when assessing concentration and dependency, though the depth of required visibility is context-dependent.
Criticality and Materiality Considerations
Frameworks often distinguish between providers supporting critical or important functions and those that do not, as the intensity of oversight typically scales with the potential impact of a disruption or failure. What counts as 'critical' or 'important' is usually defined by the applicable framework or by the organization's own assessment.

Common questions

Answers to the questions practitioners most commonly ask about ICT TPSP.

Is every vendor an organization uses considered an ICT third-party service provider?
No. The term typically refers specifically to entities that provide information and communication technology services, such as cloud computing, software, data processing, or related digital infrastructure, rather than to all vendors or suppliers generally. Providers of non-ICT goods or services (for example, catering, physical facilities maintenance, or general professional advisory services unrelated to technology) generally fall outside this classification. That said, the precise scope depends on the applicable framework or regulatory regime, and some definitions extend to arrangements where ICT is a component of a broader service. Organizations should assess each relationship against the definitions used in the standards or regulations that apply to them, since applicability varies by jurisdiction, sector, and the specific regime in question.
Does using an ICT third-party service provider transfer the organization's regulatory responsibility to that provider?
Not typically. In many regulatory regimes and governance frameworks, an organization that outsources an ICT service generally retains accountability for the associated risks and for compliance with its obligations, even though operational performance is delegated to the provider. Outsourcing often shifts the execution of an activity but not the ultimate responsibility for it. The specific allocation of duties depends on contractual terms, the applicable legal framework, and the nature of the arrangement, and questions of legal liability in a given case are matters requiring professional advice. The distinction between delegating an activity and delegating accountability is a recurring point of confusion in this area.
How should an organization identify and classify its ICT third-party service providers?
A common approach is to maintain an inventory or register of ICT service arrangements and to classify each according to factors such as the criticality of the supported function, the sensitivity of data involved, and the potential effect of disruption on the organization's objectives. Many frameworks distinguish arrangements that support critical or important functions from those that do not, since this often determines the depth of due diligence, oversight, and contractual protection expected. The specific classification criteria and any regulatory thresholds vary by regime and sector, so organizations should map their approach to the definitions and requirements that apply to them and verify particulars against the relevant primary sources.
What role does due diligence play before engaging an ICT third-party service provider?
Due diligence is typically the assessment conducted before entering an arrangement to understand the provider's capabilities, security posture, financial condition, operational resilience, and ability to meet the organization's requirements. It commonly informs the risk assessment for the relationship and helps identify controls or contractual safeguards that may be warranted. Due diligence generally supports, rather than replaces, ongoing monitoring throughout the relationship. The scope and rigor expected often scale with the criticality of the service and may be shaped by applicable regulatory expectations, which differ across jurisdictions and sectors.
What contractual provisions are commonly considered when engaging an ICT third-party service provider?
Contracts in this area often address matters such as service levels, security and data protection obligations, audit and access rights, incident reporting, business continuity and resilience, subcontracting (including so-called fourth-party arrangements), and termination and exit provisions. The aim is generally to define responsibilities clearly and to preserve the organization's ability to oversee and, where necessary, exit the arrangement. Specific required clauses can be mandated by particular regulatory regimes for certain arrangements, so organizations should confirm applicable requirements against the relevant primary sources and obtain legal advice on drafting and enforceability.
How can an organization maintain ongoing oversight of an ICT third-party service provider after engagement?
Ongoing oversight typically involves monitoring the provider's performance and risk profile over the life of the relationship rather than treating assessment as a one-time exercise. Common practices include periodic reviews, monitoring against agreed service levels, tracking incidents and remediation, reassessing risk when circumstances change, and maintaining awareness of subcontracting or concentration risks. The intensity of oversight often reflects the criticality of the service. The appropriate frequency and methods depend on the organization's risk profile and any applicable regulatory expectations, which vary by jurisdiction and sector.

Common misconceptions

Outsourcing an ICT service transfers the associated risk and accountability to the provider.
In many regulatory and governance frameworks, the engaging organization typically retains accountability for the outsourced function and its associated risks, even where operational delivery is performed externally. Contractual allocation of responsibilities does not generally remove the organization's own oversight and compliance obligations, and specifics depend on jurisdiction and the applicable regime.
Any external technology vendor automatically falls within the scope of ICT third-party service provider requirements.
Scope and applicability vary by framework, sector, and jurisdiction. Some regimes focus on providers supporting critical or important functions, or apply thresholds based on materiality. Whether a particular vendor is in scope should be assessed against the definitions in the relevant framework rather than assumed.
Managing the direct provider is sufficient to manage third-party ICT risk.
Because providers may rely on their own subcontractors, dependency and concentration risk can extend beyond the immediate contractual counterparty. Many frameworks encourage consideration of these onward arrangements, though the required extent of visibility into subcontracting chains is context-dependent.

Best practices

Maintain an inventory of ICT third-party service providers and map each to the business functions it supports, flagging those tied to critical or important functions for heightened oversight.
Ensure contractual arrangements address key areas such as security expectations, audit or access rights, subcontracting notification, and termination or exit, verifying required provisions against the applicable regulatory regime.
Assess and periodically reassess provider risk in proportion to the criticality of the service, distinguishing the organization's retained accountability from responsibilities delegated to the provider.
Seek visibility into material subcontracting chains to identify dependency and concentration risk that extends beyond the direct provider.
Confirm the applicable definition of an 'ICT service' and scope thresholds against the relevant framework or regulation, since applicability varies by jurisdiction, sector, and organization size.
Engage legal and compliance advisors where the classification, contractual terms, or cross-border implications of a provider relationship require interpretation of specific legal requirements.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide