Glossary term
Lead Overseer (DORA)
Also: DORA Art. 32, ESA Lead Overseer
One of the three European Supervisory Authorities (EBA, EIOPA, ESMA) responsible under DORA Art. 32 for direct supervision of an ICT third-party provider designated as critical. Assigned by the ESAs' Joint Committee.
The Lead Overseer takes over the continuous supervision of a CTPP: annual oversight plan, requests for information, on-site inspections, access to technical documents, staff interviews, recommendations for risk mitigation. Recommendations are not directly binding but are enforced by national supervisors towards financial entities.
Joint Examination Teams (JET) execute the operational reviews: staff from several national supervisors, coordinated by the Lead Overseer. Working language: English at ESA level, national languages for on-site audits.
Practical relevance: financial entities must expect Lead Overseer recommendations to be passed down indirectly via BaFin, BaFin equivalents or the ECB SSM. A critical provider without a cooperative Lead Overseer relationship becomes effectively unusable for regulated customers.
Related terms
DORA
EU regulation on digital operational resilience in the financial sector. Directly applicable since 1…
Critical ICT Third-Party Provider (CTPP)
ICT third-party provider designated critical by the European Commission under DORA Art. 31, falling …
ICT Third-Party Risk
Sammelbegriff für Risiken aus dem Einsatz externer ICT-Lieferanten: Cloud-Provider, SaaS-Anbieter, M…
AI Act Conformity Assessment
Procedure to demonstrate that a high-risk AI system complies with the EU AI Act before being placed …
AI Act Risk Categories
Four-tier classification under the EU AI Act: prohibited (Art. 5), high-risk (Annex I/III), limited …
Audit-ready decision
A decision whose record is structured, evidence-backed and stakeholder-signed to a level that a thir…
BAIT
BaFin circular that concretises IT requirements for credit institutions. Specifies MaRisk AT 7.2 for…
BCM
Discipline for maintaining critical business processes during disruptions. Standards: ISO 22301, BSI…
