Glossary · DORA
Lead Overseer
The European Supervisory Authority appointed to directly oversee a critical ICT third-party provider under DORA.
Explained in depth: DORA overview
Each designated CTPP is assigned one of the three ESAs (EBA, ESMA, or EIOPA) as its Lead Overseer. The Lead Overseer assesses whether the provider has adequate rules, procedures, and controls to manage the ICT risk it poses to the financial system, and holds real powers: information requests, general investigations, on-site and off-site inspections, and recommendations the provider must address or explain. Non-cooperation has teeth. The Lead Overseer can impose periodic penalty payments of up to 1% of the provider's average daily worldwide turnover for up to six months, and competent authorities can ultimately require financial entities to suspend or terminate contracts with a non-compliant provider.
Why it matters
The Lead Overseer regime means cloud and software giants answer to an EU financial supervisor for the first time. Financial entities should track their critical vendors' oversight status; findings against a provider may require action on the customer side too.
