Skip to main content
Category: Foundational Concepts

Critical or Important Functions

Also known as: CIF, Critical or Important Function, Critical or Important Business Function
Simply put

A critical or important function is an activity within a financial institution whose failure or disruption could seriously harm the firm's operations, financial health, or ability to meet its regulatory obligations. Because these functions matter so much, firms are expected to identify them and pay closer attention to the third-party services, particularly ICT services, that support them. Note that a supporting service such as IT is not itself the function; rather, it may underpin a function that qualifies as critical or important.

Formal definition

Under the EU Digital Operational Resilience Act (DORA), a 'critical or important function' is generally defined as one whose disruption would materially impair a financial entity's financial performance, the soundness or continuity of its services and activities, or its ability to comply with the conditions and obligations of its authorization and other regulatory requirements. Firms typically assess this designation against defined criteria, which may be evaluated through both quantitative metrics and qualitative judgment depending on the function. It is important to distinguish the function itself from the ICT or third-party services supporting it: DORA's requirements around ICT third-party service providers attach to those services that support functions classified as critical or important, rather than treating the underlying IT provision as a CIF in its own right. The label 'critical or important function' is not unique to DORA, the same or closely related terminology appears in earlier EU financial legislation and outsourcing guidance, so its precise scope and criteria depend on the specific regulatory regime, sector, and jurisdiction in which it is applied.

Why it matters

Correctly identifying critical or important functions is the foundation on which much of a financial entity's operational resilience and ICT third-party risk work rests. Under regimes such as the EU Digital Operational Resilience Act (DORA), the more stringent requirements around ICT third-party service providers attach specifically to the services that support functions classified as critical or important. If a firm designates these functions too narrowly, it may leave materially significant dependencies outside the scope of enhanced due diligence, contractual safeguards, and monitoring; if it designates them too broadly, it risks diluting attention and resources across activities that do not warrant the same intensity. The designation therefore directly shapes where a firm concentrates its assessment and oversight effort.

A recurring point of confusion is the relationship between a function and the services that support it. IT provision is not itself a critical or important function; rather, it may underpin a function, such as processing customer payments or meeting a regulatory reporting obligation, that qualifies as critical or important. Conflating the two can lead firms to classify a supporting ICT service as a CIF in its own right, misdirecting how DORA's third-party requirements are applied. The distinction matters because the regulatory obligations flow from the criticality of the underlying business function, not from the technical nature of the service.

The designation also carries a compliance dimension that is easy to underweight. DORA's definition treats disruption as material not only where it would impair a firm's financial performance or the soundness and continuity of its services and activities, but also where it would impair the firm's ability to comply with the conditions and obligations of its authorization and other regulatory requirements. A function that appears operationally modest may still qualify if its failure would jeopardize regulatory compliance, so assessments that focus solely on financial or operational impact can understate a function's true significance.

Who it's relevant to

Operational resilience teams at financial entities
Teams responsible for resilience under DORA use the critical-or-important classification to determine which functions, and therefore which supporting ICT services, warrant the most intensive continuity planning, monitoring, and third-party oversight. Getting the designation right is a prerequisite for scoping resilience obligations accurately, since over- or under-inclusion directly affects where effort is concentrated.
ICT third-party risk and vendor management functions
Because DORA's enhanced requirements attach to services supporting critical or important functions rather than to IT provision as such, third-party risk professionals need to trace each ICT service back to the business function it underpins. This informs which contracts, due diligence measures, and ongoing monitoring fall within the more stringent regime, and helps avoid mislabeling a supporting service as a CIF in its own right.
Compliance and regulatory reporting teams
The CIF definition explicitly captures functions whose disruption would impair the firm's ability to comply with the conditions and obligations of its authorization and other regulatory requirements. Compliance teams therefore have a role in assessments to ensure that functions significant to regulatory obligations are not overlooked when the focus tends toward financial or operational impact alone.
Professionals operating across multiple regulatory regimes
Because the same or related terminology appears in earlier EU financial legislation and outsourcing guidance as well as DORA, professionals working across regimes, sectors, or jurisdictions should not assume a single definition or set of criteria applies uniformly. They benefit from confirming the precise scope and thresholds that govern the classification in each applicable context.

Inside CIF

Function whose disruption materially impairs operations
A core element of the concept: a function is treated as critical or important when its disruption would materially impair the performance of the entity's activities. This operational impairment dimension focuses on whether the entity can continue delivering its services if the function fails.
Function whose disruption impairs financial standing or soundness
The concept also captures functions whose failure would materially impair the entity's financial performance, financial standing, or the soundness and continuity of its services and activities, extending the assessment beyond purely operational effects.
Function whose disruption impairs regulatory compliance
The designation additionally covers functions whose discontinuation, defect, or failure would materially impair the entity's continued compliance with the conditions and obligations of its authorization or with other applicable regulatory obligations. Omitting this compliance dimension understates the scope of the term.
Materiality and impairment threshold
Central to the term is a materiality judgment: not every function qualifies, only those where impairment would be material. Determining this threshold is a matter of assessment rather than a fixed, universal list, and typically varies by the entity's size, activities, and risk profile.
Application to outsourced and third-party arrangements
The concept is frequently applied to identify which outsourced services or third-party arrangements support critical or important functions, which in turn tends to trigger heightened due diligence, contractual, and oversight expectations. It does not by itself define those specific control requirements.

Common questions

Answers to the questions practitioners most commonly ask about CIF.

Did the concept of 'critical or important functions' originate with DORA?
No. While DORA gives the term prominence in the context of digital operational resilience and ICT risk, the phrase 'critical or important function' predates DORA and appears in earlier EU financial legislation and outsourcing guidance. It is best understood as an established regulatory concept that DORA applies to the ICT and third-party context, rather than one DORA created.
Is a function only 'critical or important' if its failure would harm the firm's operations or financial performance?
Not exactly. The classification is broader than operational or financial impact alone. Under DORA's definition, a function can qualify where a defect or failure in its performance would also materially impair the firm's continuing compliance with the conditions and obligations of its authorisation or its other regulatory obligations. Reducing the test to operational and financial harm omits this regulatory-compliance dimension.
How do we determine whether a given function meets the CIF threshold?
Assessment typically weighs the potential impact of a defect or failure on the firm's operations, financial soundness or resilience, and its ability to meet regulatory obligations, rather than relying on a single metric. Many programs apply defined criteria and thresholds so the determination is consistent and documented, but the specific criteria and how strictly they are applied vary by firm, sector, and jurisdiction.
Does classifying a function as critical or important change how we manage the related third-party arrangement?
In many programs it does. Arrangements supporting a CIF are commonly subject to heightened due diligence, contractual requirements, ongoing monitoring, and exit and contingency planning that may not apply to lower-tier arrangements. The classification is often the trigger that determines the depth of oversight applied, though the precise obligations depend on the applicable regime and the firm's internal policies.
How often should CIF classifications be reviewed?
Because the classification can change as business activities, dependencies, and regulatory obligations evolve, treating it as a one-time, point-in-time determination is a common weakness. Many programs review classifications periodically and upon significant change, such as onboarding a new provider, altering a service, or changing regulatory scope. Review frequency and triggers vary by program and are typically set in internal policy.
Does identifying critical or important functions give us full visibility into the associated risks?
No. Identifying CIFs establishes where heightened attention should focus, but it does not by itself reveal downstream dependencies. Visibility often extends only to the direct arrangement, and subcontracting or fourth-party and Nth-party dependencies supporting the same function may remain less visible without additional mapping. The classification defines what matters, not the full chain of parties involved in delivering it.

Common misconceptions

The term 'critical or important function' was introduced by the EU Digital Operational Resilience Act (DORA).
The same or closely related terminology has been used in earlier EU financial legislation and outsourcing guidance predating DORA, such as MiFID II delegated regulation and prior supervisory outsourcing expectations. DORA carries the concept forward and applies it within its own scope rather than originating it.
A function is critical or important only if its failure would harm operations or finances.
The concept also captures functions whose impairment would affect the entity's continued compliance with the conditions of its authorization or other regulatory obligations. Treating the term as covering only operational or financial impact omits the regulatory-compliance dimension of the definition.
Designating a function as critical or important is a one-time, fixed classification.
The designation rests on a materiality assessment that depends on the entity's activities, structure, and risk profile, and can change as those factors change. In many programs it is expected to be reviewed rather than set permanently.

Best practices

Assess candidate functions against all applicable impairment dimensions, operational, financial, and regulatory-compliance, rather than screening only for operational or financial impact.
Document the materiality rationale for each designation, including the criteria and thresholds applied, so classifications can be justified and reviewed consistently across the organization.
Map which outsourced services and third-party arrangements support functions designated as critical or important, and apply heightened due diligence and oversight to those relationships according to your program's risk tiering.
Review and update classifications periodically and after significant changes to activities, structure, or third-party dependencies, since the designation can shift as the entity's risk profile changes.
Recognize that the term identifies which functions warrant elevated attention but does not itself prescribe specific controls; pair each designation with defined oversight, contractual, and continuity expectations.
Account for jurisdictional and sector variation, as related terminology and expectations appear across multiple EU financial regimes and may differ in scope and application depending on the applicable regime.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.