In the traditional logic of industrial organization, scale is the ultimate prize, offering economies that drive down marginal costs. However, under the European Union’s [Digital Operational Resilience Act (DORA)](https://eur-lex.europa.eu/eli/reg/2022/2554/oj), an Independent ATM Deployer (IAD) that successfully scales may find itself caught in a "regulatory death zone." Here, the reward for market leadership is not higher profits, but a designation as a **Critical ICT Third-Party Provider (CTPP)**, subjecting the firm to direct, intrusive oversight that can functionally invert the benefits of growth.
## The Regulatory Ceiling: Article 31 and Systemic Risk
DORA shifts the focus of financial regulation from entities (banks) to the underlying infrastructure (ICT providers). Under **Article 31**, the European Supervisory Authorities (ESAs), such as the [European Banking Authority (EBA)](https://www.eba.europa.eu/), can designate a provider as "critical" based on the systemic impact of a failure. For an IAD, which provides the ICT-heavy services of cash dispensing and transaction processing, crossing a threshold of market penetration triggers this designation.
> "The designation of critical ICT third-party providers should reflect the size and nature of the financial sector’s reliance on those providers... [and] the systemic impact that a failure or operational outage of such a provider could have on the financial stability of the Union." — [DORA Preamble, Recital 78](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554)
## The Economic Friction of Oversight
Once designated, an IAD faces a regime designed for global cloud giants like AWS or Microsoft, not margin-thin cash operators. This includes:
1. **Oversight Fees:** Under Article 43, the Lead Overseer charges the CTPP fees to cover all expenses related to oversight tasks. For an IAD, these non-negotiable costs can exceed the annual profit generated by the very machines that triggered the designation.
2. **Recommendations with Teeth:** The Lead Overseer can issue "recommendations" on security, audits, and hardware. While technically recommendations, failure to comply can lead to daily penalty payments of up to 1% of the average daily worldwide turnover.
## Strategic Fragmentation: A New "Lucas Critique"
Faced with this "regulatory ceiling," smart IADs may engage in a form of **regulatory arbitrage** by intentionally fragmenting their operations. Instead of a single large entity, an operator might split into multiple independent subsidiaries or limit its expansion in a specific Member State to stay below the ESAs' radar.
This creates a paradox of resilience. While DORA aims to secure the financial system, it may inadvertently incentivize a **less efficient, more decentralized, and technologically stagnant** cash infrastructure. As the [Bank for International Settlements (BIS)](https://www.bis.org/publ/bcbs_nl25.htm) has noted in discussions on operational resilience, systemic risk often migrates rather than disappears. By forcing IADs to stay small, the regulator might prevent "too big to fail" providers but simultaneously create a "too fragmented to secure" landscape, where no single operator has the capital to invest in high-level cybersecurity.
Does the pursuit of institutional resilience fundamentally threaten the economic viability of the very services being protected? This remains the central tension for the future of European cash access.