Home › DORA › Third-Party Risk

DORA Compliance

DORA Third-Party Risk Management

Key takeaway

DORA treats dependence on ICT providers as a core risk. Firms must keep a register of information of their ICT contractual arrangements (Article 28), include prescribed clauses in contracts supporting critical or important functions (Article 30), and manage concentration and sub-outsourcing risk. Providers designated as critical are supervised directly at EU level.

Modern financial services run on third parties. DORA makes managing that dependency an explicit, documented obligation.

The register of information (Article 28)

Every financial entity must maintain a structured register of information of all contractual arrangements with ICT third-party providers, distinguishing those that support critical or important functions. It must be available to the competent authority on request. See The DORA register of information.

Contractual requirements (Article 30)

Contracts for ICT services supporting critical or important functions must contain specific clauses, covering:

  • Service levels and performance

  • Security and incident cooperation

  • Audit and access rights

  • Sub-outsourcing conditions

  • Exit strategies and termination

  • Cooperation with testing, where relevant

Many firms implement these through contractual addenda to existing agreements.

Critical ICT third-party providers

The European Supervisory Authorities designate certain providers as critical, bringing them under a direct EU oversight framework. Where a designated provider fails to comply with oversight measures, its Lead Overseer may impose a daily periodic penalty of up to 1% of average daily worldwide turnover, for up to six months.

Concentration and sub-outsourcing

Firms must consider concentration risk (over-reliance on one provider) and understand sub-outsourcing chains beneath their direct suppliers.

Next step

Need help with your register or contract clauses? Book a readiness assessment.