Skip to main content
Category: Regulatory Frameworks

National Competent Authority

Also known as: NCA, Competent Authority, Regulatory Authority
Simply put

A National Competent Authority (NCA) is a government-designated body within a State responsible for tasks such as certification, authorisation, oversight, and enforcement in a particular regulated domain. The specific role of an NCA varies by sector, for example, it may authorise and monitor medicines in one context or oversee financial services in another. The term identifies a State-appointed authority rather than a single fixed function.

Formal definition

A National Competent Authority is an entity designated by a State to perform sector-specific regulatory functions, which may include certification, authorisation, oversight, monitoring, and enforcement within its territory. The precise mandate is jurisdiction- and domain-dependent: in the pharmaceutical sector an NCA typically evaluates, authorises, and monitors medicinal products and grants marketing authorisations, while in other contexts, such as EU medical device regulation, a Competent Authority belongs to a Member State's government and is responsible for transposing and applying applicable European requirements. In further domains such as Open Banking, NCA designations may be referenced through standardised codes (for example, by Trust Service Providers issuing identity certificates). Because the term denotes a designated regulatory role rather than a uniform institution, its scope, powers, and sectoral remit differ across jurisdictions and should be interpreted against the relevant legal framework; the evidence here does not establish a single global definition applicable to all sectors.

Why it matters

For third-party and supply chain risk professionals, the National Competent Authority is the State-designated body whose certification, authorisation, oversight, and enforcement decisions can directly shape whether a supplier is permitted to operate, sell, or continue supplying regulated goods and services. Because an NCA may authorise and monitor medicines in one context, or, under EU medical device rules, belong to a Member State's government responsible for transposing and applying European requirements in another, the authority sitting behind a vendor's regulatory standing varies by sector and jurisdiction. Understanding which NCA governs a given supplier helps assessors interpret the meaning and limits of the approvals that supplier relies on.

The term matters precisely because it does not denote a single institution or a uniform function. An NCA is a designated regulatory role, and its scope, powers, and sectoral remit differ across jurisdictions and must be read against the relevant legal framework. Treating an NCA reference as a globally consistent stamp of approval risks overstating what it confers. In pharmaceutical supply, for example, a marketing authorisation granted by one NCA applies within that authority's territory; in Open Banking, NCA designations may appear only as standardised codes referenced by Trust Service Providers issuing identity certificates, which is a very different function from product authorisation.

For risk teams, the practical significance lies in mapping the correct NCA to the correct control. A supplier's regulatory authorisation, and any oversight or enforcement action tied to it, is only as meaningful as the sectoral mandate and jurisdiction of the authority behind it. Conflating NCAs across sectors, or assuming powers not established by the applicable legal framework, can lead to misjudged assurance in third-party and supply chain assessments.

Who it's relevant to

Compliance and regulatory affairs teams
These teams need to identify the correct NCA for each regulated supplier and interpret its mandate against the applicable legal framework. Because an NCA's functions, certification, authorisation, oversight, monitoring, enforcement, vary by sector and jurisdiction, compliance staff should avoid treating an authorisation from one NCA as globally applicable or as conferring powers not established by the relevant framework.
Procurement and vendor onboarding functions
When onboarding suppliers of regulated goods or services, procurement teams may rely on NCA-granted authorisations as part of due diligence. It is important to recognise that a marketing authorisation or similar approval applies within the granting authority's territory, and that NCA references in some domains, such as standardised codes in Open Banking, reflect a different function than product authorisation.
Third-party and supply chain risk assessors
Risk assessors map suppliers' regulatory standing to the specific NCA and jurisdiction behind it. Since the term denotes a designated role rather than a fixed institution, assessors should confirm which sectoral mandate applies before drawing assurance from an NCA reference, and should not assume a single global definition covers all sectors.
Legal and contracts teams
Legal teams interpret the scope and powers of an NCA against the governing legal framework when structuring supplier obligations. Given that EU Member State Competent Authorities are responsible for transposing and applying European requirements, contract terms may need to account for jurisdiction- and domain-specific variation in NCA authority.

Inside NCA

Designated Supervisory Body
An NCA is a national authority formally designated by a jurisdiction to supervise, monitor, or enforce compliance with a specific regulatory regime. The designation is regime-specific, meaning an authority may be an NCA for one framework but not for others.
Sectoral or Regime Scope
The mandate of an NCA is typically bounded to a defined sector (for example financial services, critical infrastructure, or data protection) or a particular legislative instrument. Its authority does not automatically extend to matters outside that assigned scope.
Supervisory and Enforcement Powers
Depending on the regime, an NCA may hold powers such as receiving notifications, requesting information, conducting inspections, issuing guidance, and imposing corrective measures or penalties. The exact powers vary by the enabling legislation and jurisdiction.
Jurisdictional Boundary
An NCA operates within the territory of a single member state or country. Cross-border matters are often addressed through cooperation mechanisms or coordination with authorities in other jurisdictions rather than by unilateral extraterritorial action.
Relevance to Third-Party and Supply Chain Oversight
For TPRM and SCRM programs, an NCA may be the point of contact for regulatory expectations affecting an organization's suppliers or the organization itself, including any obligations that flow down to third parties operating within the same regulated regime.

Common questions

Answers to the questions practitioners most commonly ask about NCA.

Is a National Competent Authority the same as a single global regulator?
No. The term National Competent Authority refers to an authority designated within a specific jurisdiction to supervise or enforce a given regulatory regime, not to a single global body. Different countries, and often different sectors within a country, designate their own NCAs. Because designation and mandate vary by jurisdiction and sector, an NCA's authority typically applies only within its defined territorial and regulatory scope, and expectations may differ across regions.
Does designation as a National Competent Authority mean one authority handles all types of risk?
Not necessarily. An NCA's remit is usually defined by the specific regime under which it is designated, which may cover only a particular domain rather than the full range of financial, operational, information security, geopolitical, or ESG concerns. A single jurisdiction may designate multiple NCAs across different sectors or subject areas, so the scope of any one NCA should be confirmed against its designating instrument rather than assumed to be comprehensive.
How do I identify which NCA applies to a given third-party relationship?
Identification typically depends on the jurisdiction in which the activity or entity falls and the specific regulatory regime in question. Because designation varies by region and sector, in many programs teams map each relevant regime to its designated authority for the relevant jurisdiction, rather than assuming one authority applies across the board. Where an entity operates across multiple jurisdictions, more than one NCA may be relevant.
How should NCA expectations be reflected in third-party due diligence?
Where an NCA's regime is relevant to a third party's activities, its supervisory expectations may inform the scope of onboarding due diligence and, depending on the risk tier, ongoing monitoring. It is worth noting that due diligence aligned to one NCA's expectations does not necessarily satisfy those of another authority or another jurisdiction, so applicability should be confirmed for each relevant regime rather than generalized.
Can reliance on an NCA-supervised third party reduce the need for our own assessment?
Supervision by an NCA does not, on its own, substitute for an organization's own risk assessment of a third party. NCA oversight typically addresses the regime for which the authority is designated and may not cover all of the financial, operational, security, or resilience considerations relevant to a specific relationship. In many programs, NCA status is treated as one input rather than as independent verification of a third party's overall risk posture.
How should programs handle changes in NCA designation or expectations over time?
Because designations and supervisory expectations can change and vary by jurisdiction and sector, a point-in-time understanding can become stale. Depending on the risk tier, many programs periodically revisit which NCAs are relevant to their third-party relationships and monitor for changes in the applicable regimes, rather than relying on an assessment captured only at onboarding.

Common misconceptions

A National Competent Authority has a single, unified mandate that covers all regulatory matters within a country.
The term is regime-specific. A country typically has multiple NCAs, each designated for a particular sector or legislative instrument, and an authority competent for one regime holds no automatic authority over others.
Interacting with, or being supervised by, an NCA confers a compliance guarantee or certification for a supplier relationship.
Supervision by an NCA does not certify or guarantee that an organization or its third parties are compliant. It reflects a supervisory relationship, and residual regulatory and operational risk can remain regardless of that relationship.
An NCA's authority applies globally to an organization's entire supply chain.
An NCA operates within a defined jurisdiction and regime. Suppliers or entities outside that jurisdiction or scope fall outside its direct authority, and cross-border coverage typically depends on cooperation arrangements rather than a single global mandate.

Best practices

Identify which specific NCA (or NCAs) applies to each regulatory regime relevant to your organization and its in-scope suppliers, rather than assuming a single authority governs all obligations.
Map the jurisdictional and sectoral boundaries of each applicable NCA so that regulatory expectations are correctly scoped to the relevant entities and territories in your supply chain.
Confirm the specific powers and notification or reporting obligations of each NCA under its enabling regime, since these vary and may impose duties that flow down to third parties.
Where suppliers operate across multiple jurisdictions, account for the possibility that different NCAs apply and that coordination between them may be required, rather than presuming one authority's coverage extends everywhere.
Treat supervision by an NCA as one input to your risk view, not as evidence of compliance or certification for a third party, and maintain independent due diligence and monitoring accordingly.
Keep records of which regulatory obligations and NCA relationships are contractually flowed down to third parties, and review these as regimes and designations change over time.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps