DORA treats dependence on ICT providers as a core risk. Firms must keep a register of information of their ICT contractual arrangements (Article 28), include prescribed clauses in contracts supporting critical or important functions (Article 30), and manage concentration and sub-outsourcing risk. Providers designated as critical are supervised directly at EU level.
Modern financial services run on third parties. DORA makes managing that dependency an explicit, documented obligation.
The register of information (Article 28)
Every financial entity must maintain a structured register of information of all contractual arrangements with ICT third-party providers, distinguishing those that support critical or important functions. It must be available to the competent authority on request. See The DORA register of information.
Contractual requirements (Article 30)
Contracts for ICT services supporting critical or important functions must contain specific clauses, covering:
Service levels and performance
Security and incident cooperation
Audit and access rights
Sub-outsourcing conditions
Exit strategies and termination
Cooperation with testing, where relevant
Many firms implement these through contractual addenda to existing agreements.
Critical ICT third-party providers
The European Supervisory Authorities designate certain providers as critical, bringing them under a direct EU oversight framework. Where a designated provider fails to comply with oversight measures, its Lead Overseer may impose a daily periodic penalty of up to 1% of average daily worldwide turnover, for up to six months.
Concentration and sub-outsourcing
Firms must consider concentration risk (over-reliance on one provider) and understand sub-outsourcing chains beneath their direct suppliers.
Need help with your register or contract clauses? Book a readiness assessment.