Critical or Important Functions
A critical or important function is an activity within a financial institution whose failure or disruption could seriously harm the firm's operations, financial health, or ability to meet its regulatory obligations. Because these functions matter so much, firms are expected to identify them and pay closer attention to the third-party services, particularly ICT services, that support them. Note that a supporting service such as IT is not itself the function; rather, it may underpin a function that qualifies as critical or important.
Under the EU Digital Operational Resilience Act (DORA), a 'critical or important function' is generally defined as one whose disruption would materially impair a financial entity's financial performance, the soundness or continuity of its services and activities, or its ability to comply with the conditions and obligations of its authorization and other regulatory requirements. Firms typically assess this designation against defined criteria, which may be evaluated through both quantitative metrics and qualitative judgment depending on the function. It is important to distinguish the function itself from the ICT or third-party services supporting it: DORA's requirements around ICT third-party service providers attach to those services that support functions classified as critical or important, rather than treating the underlying IT provision as a CIF in its own right. The label 'critical or important function' is not unique to DORA, the same or closely related terminology appears in earlier EU financial legislation and outsourcing guidance, so its precise scope and criteria depend on the specific regulatory regime, sector, and jurisdiction in which it is applied.
Why it matters
Correctly identifying critical or important functions is the foundation on which much of a financial entity's operational resilience and ICT third-party risk work rests. Under regimes such as the EU Digital Operational Resilience Act (DORA), the more stringent requirements around ICT third-party service providers attach specifically to the services that support functions classified as critical or important. If a firm designates these functions too narrowly, it may leave materially significant dependencies outside the scope of enhanced due diligence, contractual safeguards, and monitoring; if it designates them too broadly, it risks diluting attention and resources across activities that do not warrant the same intensity. The designation therefore directly shapes where a firm concentrates its assessment and oversight effort.
A recurring point of confusion is the relationship between a function and the services that support it. IT provision is not itself a critical or important function; rather, it may underpin a function, such as processing customer payments or meeting a regulatory reporting obligation, that qualifies as critical or important. Conflating the two can lead firms to classify a supporting ICT service as a CIF in its own right, misdirecting how DORA's third-party requirements are applied. The distinction matters because the regulatory obligations flow from the criticality of the underlying business function, not from the technical nature of the service.
The designation also carries a compliance dimension that is easy to underweight. DORA's definition treats disruption as material not only where it would impair a firm's financial performance or the soundness and continuity of its services and activities, but also where it would impair the firm's ability to comply with the conditions and obligations of its authorization and other regulatory requirements. A function that appears operationally modest may still qualify if its failure would jeopardize regulatory compliance, so assessments that focus solely on financial or operational impact can understate a function's true significance.
Who it's relevant to
Inside CIF
Common questions
Answers to the questions practitioners most commonly ask about CIF.
