The classic trap
Recital 64 locks in a principle that many Luxembourg financial entities underestimate: ICT outsourcing never transfers regulatory responsibility. The CSSF regularly sanctions banks and PFS firms that point to a hosting provider or SaaS vendor failure to justify an incident, whereas DORA requires active and proportionate monitoring. The secondary trap is uniformity: applying the same control level to a messaging vendor as to a core banking provider reveals a lack of criticality analysis, and this is exactly what comes up during on-site inspections.
The proportionality test required by recital 64
This recital imposes a documented gradation of vendor monitoring along four cumulative criteria. The financial entity must be able to demonstrate, during a CSSF inspection, how each ICT relationship is classified and supervised:
- Nature and scale of the ICT dependency (volume, business criticality, substitutability).
- Complexity of the subcontracting chain (sub-processors, location, transfers outside the EU).
- Criticality or importance of the supported functions (CIF under DORA article 28).
- Potential impact on the continuity and quality of financial services, at individual and group level.
Concretely, a flat vendor register (Excel with one line per contract) is no longer enough: you need a dynamic scoring that reassesses each third party along these four axes and triggers a tailored monitoring level (audits, KPIs, inspection rights, exit strategy).
How Luxgap automates this risk
Our Luxgap ICT Dependency Radar turns the proportionality obligation of recital 64 into a living criticality score, continuously recalculated for each ICT provider and defensible before the CSSF. The tool aggregates your Odoo or SAP contracts, financial flows, Microsoft Defender for Cloud Apps logs, Azure / AWS / GCP inventories and ServiceNow CMDB to rebuild the real map of your ICT dependencies, without relying on a form filled in by the business.
- Automatically classifies each provider against the DORA article 28 grid (CIF / non-CIF) by cross-referencing contract volume, declared business criticality and observed data flows.
- Computes a four-axis proportionality score (nature, scale, complexity, impact) that dictates the required monitoring level: light, standard or enhanced.
- Detects hidden sub-processors by analysing DPAs, privacy policies and public certifications (ISO 27001, SOC 2, cloud certifications).
- Alerts in real time on risk changes: certification expiry, HIBP breach, financial downgrade of the vendor, change in data location.
- Produces a timestamped PDF report per provider, evidencing to the CSSF the due consideration required by recital 64 and article 28.
- Supports group oversight: consolidates dependencies at subsidiary and group level for entities subject to consolidated supervision.
Available as a complement to a Luxgap CISO mandate or as a dedicated SaaS module depending on your scope. Request a tailored quote and our teams will prepare a demonstration on your real vendor register, with a free 48h scan to measure your ICT exposure before any engagement.