Critical or important functions
Institutions and payment institutions should always consider a function as critical or important in the following situations:(34)
where a defect or failure in its performance would materially impair:
their continuing compliance with the conditions of their authorisation or its other obligations under Directive 2013/36/EU, Regulation (EU) No 575/2013, Directive 2014/65/EU (opens EUR-Lex in a new tab), Directive (EU) 2015/2366 (opens EUR-Lex in a new tab) and Directive 2009/110/EC (opens EUR-Lex in a new tab) and their regulatory obligations;
their financial performance; or
the soundness or continuity of their banking and payment services and activities;
when operational tasks of internal control functions are outsourced, unless the assessment establishes that a failure to provide the outsourced function or the inappropriate provision of the outsourced function would not have an adverse impact on the effectiveness of the internal control function;
when they intend to outsource functions of banking activities or payment services to an extent that would require authorisation(35) by a competent authority, as referred to in Section 12.1.
In the case of institutions, particular attention should be given to the assessment of the criticality or importance of functions if the outsourcing concerns functions related to core business lines and critical functions as defined in Article 2(1)(35) and 2(1)(36) of Directive 2014/59/EU(36) and identified by institutions using the criteria set out in Articles 6 and 7 of Commission Delegated Regulation (EU) 2016/778.(37) Functions that are necessary to perform activities of core business lines or critical functions should be considered as critical or important functions for the purpose of these guidelines, unless the institution’s assessment establishes that a failure to provide the outsourced function or the inappropriate provision of the outsourced function would not have an adverse impact on the operational continuity of the core business line or critical function.
When assessing whether an outsourcing arrangement relates to a function that is critical or important, institutions and payment institutions should take into account, together with the outcome of the risk assessment outlined in Section 12.2, at least the following factors:
the potential impact of any disruption to the outsourced function or failure of the service provider to provide the service at the agreed service levels on a continuous basis on their:
short- and long-term financial resilience and viability, including, if applicable, its assets, capital, costs, funding, liquidity, profits and losses;
business continuity and operational resilience;
operational risk, including conduct, information and communication technology (ICT) and legal risks;
reputational risks;
where applicable, recovery and resolution planning, resolvability and operational continuity in an early intervention, recovery or resolution situation;
the potential impact of the outsourcing arrangement on their ability to:
the potential impact on the services provided to its clients;
all outsourcing arrangements, the institution’s or payment institution’s aggregated exposure to the same service provider and the potential cumulative impact of outsourcing arrangements in the same business area;
the size and complexity of any business area affected;
the possibility that the proposed outsourcing arrangement might be scaled up without replacing or revising the underlying agreement;
the ability to transfer the proposed outsourcing arrangement to another service provider, if necessary or desirable, both contractually and in practice, including the estimated risks, impediments to business continuity, costs and time frame for doing so (‘substitutability’);
the ability to reintegrate the outsourced function into the institution or payment institution, if necessary or desirable;
the protection of data and the potential impact of a confidentiality breach or failure to ensure data availability and integrity on the institution or payment institution and its clients, including but not limited to compliance with Regulation (EU) 2016/679 (opens EUR-Lex in a new tab)(39) .