Lead Overseer
The Lead Overseer is a European Supervisory Authority designated under the EU's Digital Operational Resilience Act (DORA) to oversee a critical ICT third-party provider that supplies technology services to financial entities. Its purpose is to review and coordinate scrutiny of the ICT risk posed by these providers so that oversight is applied consistently. It focuses on ICT and digital operational resilience matters rather than on all categories of third-party risk.
Under DORA, the Lead Overseer (LO) is a European Supervisory Authority (ESA) appointed in accordance with Article 31(1), point (b) of the Regulation to conduct oversight activities in respect of the critical ICT third-party provider(s) (CTPP) allocated to it. Per Article 33, the LO is tasked with coordinating supervision of ICT risk with the objective of ensuring consistent and effective oversight across relevant authorities and providing conditions for a comprehensive review of the ICT risk arising from designated CTPPs. The role is scoped to the ICT third-party dimension of digital operational resilience within the EU financial-sector framework; it is not a general third-party or supply chain risk supervisor and does not, by itself, address financial, operational, geopolitical, or ESG risk categories outside its ICT oversight mandate. Note that the LO oversees designated CTPPs rather than exercising direct supervisory authority over the financial entities that rely on them, which remain subject to their respective competent authorities.
Why it matters
The Lead Overseer role addresses a structural gap in ICT third-party risk oversight: financial entities across the EU increasingly depend on a concentrated set of technology providers, yet each firm supervises its own contractual relationships in isolation. Under DORA, the Lead Overseer is designated to conduct oversight of a critical ICT third-party provider (CTPP) at the provider level, coordinating scrutiny so that a single systemically important supplier is reviewed comprehensively rather than through fragmented, firm-by-firm assessments. This matters because concentration risk, where many financial entities rely on the same provider, can create shared exposure that no individual firm's due diligence is positioned to see in full.
For risk and compliance professionals, the practical significance is that oversight of designated CTPPs is coordinated centrally, but this does not displace the obligations that individual financial entities owe to their own competent authorities. The Lead Overseer reviews the ICT risk arising from the provider; it does not supervise the financial entities that rely on that provider, nor does it certify a provider as safe to use. Firms should not treat a provider's designation as a CTPP, or the existence of Lead Overseer oversight, as a substitute for their own contractual controls, exit planning, or ongoing monitoring.
It is also important to recognize the scope boundary of the role. The Lead Overseer's mandate is confined to the ICT and digital operational resilience dimension of third-party risk within the EU financial-sector framework. It does not, by itself, address financial, operational, geopolitical, or ESG risks associated with a provider that fall outside its ICT oversight remit. Programs that read Lead Overseer activity as broad third-party assurance would overstate what the role delivers.
Who it's relevant to
Inside LO
Common questions
Answers to the questions practitioners most commonly ask about LO.
