Two vendors cost the same, and one of them can bring the firm down. Telling them apart is not a question of price or size - but price and size are how most firms sort their vendors, and it is why the wrong ones get the scrutiny.
Under DORA a great deal turns on a single word, critical: whether a vendor needs deep due diligence, whether its subcontractors go in the register, how closely you monitor it, what your exit obligations are. Get the call right and the effort lands where it should; get it wrong and you either drown low-risk vendors in oversight or leave a genuinely critical one under-governed.
Yet the classification is often made on the wrong basis entirely - by how much the vendor costs, or how big the vendor is, rather than by what it actually does for you.
Criticality is a property of the function, not the vendor
Here is the shift that fixes most mis-classifications. Under DORA, the thing you classify is not the vendor and not the contract value. It is the business function the vendor supports, and whether that function is critical or important to the firm.
A vendor is critical because it supports a function you could not lose without serious harm - not because it sends a large invoice. A small, cheap tool can be critical if a function you cannot operate without runs through it; a large, expensive platform can be non-critical if nothing that matters depends on it.
Spend and size are proxies, and frequently wrong ones: the risk lives in the dependency, and the dependency does not correlate neatly with the price.
So the first question is never "how important is this vendor." It is "what function does this vendor support, and what happens to us if that function fails."
What "critical or important function" actually means
The test is about consequence. A function is critical or important, in DORA's sense, when its disruption would materially impair the firm's ability to deliver its services, meet its regulatory obligations, or maintain its financial soundness.
It is not a measure of how visible the function is, or how much attention it gets internally. It is a measure of what breaks if it stops.
That framing matters because it catches functions that do not feel critical day to day. The system that runs quietly in the background, that nobody thinks about precisely because it never fails, can be the one whose failure would stop the firm, and the vendor behind it inherits that criticality whether or not anyone has thought of it as a critical vendor.
How a vendor inherits criticality - including through AI
Once criticality is a property of the function, a vendor's classification follows from where it sits. A vendor supporting a critical function is treated as critical for that support; a vendor supporting only peripheral functions is not. Simple enough, until AI complicates where a vendor sits.
The complication is that a vendor's place in your function map can change without the vendor changing at all. A tool classified as non-critical when it was a passive record-store becomes critical the day an AI feature inside it starts making or shaping decisions within a function that matters. The vendor is the same; its relationship to a critical function is not.
Criticality classification, like everything else in third-party risk, is not a one-time label when AI is in the picture. A vendor can cross the line into critical without any of the usual signals that would prompt a re-look.
The common mis-classifications
Three patterns account for most of the classification errors worth avoiding.
The first is classifying by spend. The biggest contracts get the deepest scrutiny and the small ones get waved through - which inverts the actual risk when a cheap tool sits inside a critical function and an expensive one does not.
The second is classifying by vendor prominence. A well-known, heavily-marketed vendor feels important and gets treated as critical; a quiet utility that everything secretly depends on gets overlooked, because its importance is inversely related to how often anyone notices it.
The third is classifying once and never revisiting. A vendor mapped to a non-critical function at onboarding stays filed under non-critical, even after its role has grown or an AI feature has moved it into critical territory. The classification ages out of date silently, which is the same failure that undermines the register and the reassessment cycle.
Why getting it right is worth the effort
Criticality classification is not paperwork for its own sake. It is the dial that sets the intensity of everything downstream, and DORA expects that intensity to scale with criticality.
A vendor classified as critical warrants deeper due diligence, its subcontractors in the register, closer ongoing monitoring, and a real exit strategy. A vendor classified as non-critical warrants proportionately less.
This is what makes third-party risk affordable: you cannot apply maximum scrutiny to every vendor, so the classification tells you where maximum scrutiny belongs. A firm that classifies well spends its oversight where it counts; a firm that classifies by spend or reputation spends it where it is easiest to justify, which is not the same place.
I will be honest about the limit. Criticality is a judgement, not a calculation - there is no formula that reads a vendor and returns "critical," because it depends on how your specific firm depends on the function, which changes.
What discovery and function-mapping can do is make sure the judgement is made against a complete and current picture of what each vendor actually supports. The classification still takes a person who understands the business, but it cannot be a good classification if the map it is made against is missing the AI dependencies nobody recorded.
Frequently asked questions
How do you decide if a vendor is critical under DORA?
Montro's position is that you classify the function the vendor supports, not the vendor itself. A vendor is critical when it underpins a critical or important function - one whose disruption would materially impair the firm's service delivery, regulatory compliance, or financial soundness.
Contract value and vendor size are poor proxies: a small tool inside a critical function is critical, and a large one supporting nothing essential is not.
What is a critical or important function?
It is a function whose disruption would materially impair the firm's ability to deliver its services, meet its regulatory obligations, or remain financially sound.
The test is consequence, not visibility, a quiet background system that never fails can still be critical, because criticality is about what breaks if it stops, not how much attention it gets. Functions that do not feel critical day to day are exactly the ones this test is designed to catch.
Can an AI feature change a vendor's criticality?
Yes. Because criticality follows the function a vendor supports, a vendor can become critical without changing at all, if an AI feature inside its tool moves it deeper into a function that matters, for instance by starting to make or shape decisions within it. This is why criticality classification cannot be a one-time label: a vendor can cross into critical territory without any of the usual procurement signals, so the classification has to be revisited as the vendor's role changes.
Why does vendor criticality classification matter?
Because it sets the intensity of everything else DORA requires. Due-diligence depth, whether subcontractors go in the register, monitoring frequency, and exit-planning obligations all scale with criticality.
Classify well and oversight lands where the real risk is; classify by spend or vendor prominence and it lands where it is easiest to justify instead. The classification is what makes proportionate third-party risk management possible.




).jpeg)
