Vendor Register
Regimes ยท DORA

DORA, the Digital Operational Resilience Act

Attaches to contractual arrangements for ICT services: cloud, software, network, managed services and data feeds. A supply of hardware, a bank or a courier is recorded in the register only where a service element sits in the contract.

On the register, tick "DORA financial entity" and these rows appear on every vendor the regime reaches. Framework page.

Which vendors it reaches

FamiliesCloud and hosting, Software and SaaS, Network and connectivity, Managed and professional services, Data and content
On every vendorDORA Art. 28, DORA Art. 30
Cloud and hostingthe clauses on every vendor only
Software and SaaSthe clauses on every vendor only
Network and connectivitythe clauses on every vendor only
Managed and professional servicesthe clauses on every vendor only
Data and contentthe clauses on every vendor only
Supports a critical or important function (rated critical or important on the register)DORA Art. 29
Informational, cloud and hosting, managed and professional servicesDORA Art. 31: the ESAs designate critical ICT third-party providers; the entity accounts for their use, it owes them no clause

DORA Article 30, key contractual provisions

The clauses the register expects in every vendor agreement the regime reaches, and the further clauses for a vendor rated critical.

  1. A clear and complete description of the functions and ICT services provided
  2. The locations, by region or country, where the service is provided and the data processed, with notice before a change
  3. Availability, authenticity, integrity and confidentiality of data, including personal data
  4. Access, recovery and return of data on the provider's insolvency, resolution or the termination of the arrangement
  5. Service level descriptions, with quantitative and qualitative targets
  6. Assistance on an ICT incident affecting the service, at no or pre-set cost
  7. Cooperation with the competent and resolution authorities
  8. Termination rights and the minimum notice period, in line with the supervisors' expectations
  9. Participation of the provider's staff in the entity's ICT security awareness and training

Where the vendor supports a critical or important function (rated critical or important on the register)

  1. Full service level agreements with performance targets and the remedies when they are missed
  2. Notice periods and reporting obligations, including notice of developments that could affect the service
  3. Business continuity plans and ICT security measures, tested, with results shared
  4. Participation in threat-led penetration testing where the entity runs it
  5. Unrestricted rights of access, inspection and audit, for the entity and for the competent authority
  6. Exit strategies, with a transition period long enough to migrate without disruption

The register of information

Article 28(3) asks every financial entity to keep a register of information on its contractual arrangements for ICT services and to report it to the competent authority. Vendor Register exports one row per vendor with these fields, as Vendor Register names them, following what the supervisory template asks for:

  1. Vendor
  2. Identification (LEI or registration, if held)
  3. Type of ICT service
  4. Category (register)
  5. Function supported (systems)
  6. Criticality
  7. Country of the provider
  8. Country of provision
  9. Annual spend
  10. Share of spend
  11. Substitutability
  12. Single source
  13. Sub-outsourcing chain
  14. Contract end
  15. Exit plan
  16. ICT service in DORA scope

A column the paste cannot fill is exported blank and raised as the finding "DORA register-of-information fields missing".

The clauses, quoted

4 of 26 in the framework

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

DORA Art. 28 ICT third-party risk: general principles

Financial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangements (including concentration and subcontracting), and adopt an ICT third-party risk strategy.

Evidence an auditor accepts: A Register of Information of ICT third-party arrangements reported to the competent authority; Pre-contract risk assessment records
Common gap: No Register of Information
Source framework: DORA (Regulation (EU) 2022/2554)
DORA Art. 30 Key contractual provisions

Contractual arrangements for the use of ICT services shall include the mandatory key contractual provisions (e.g. clear service descriptions, locations of data processing, data protection, accessibility/availability/integrity/security, assistance on incidents, audit and access rights, termination rights and exit strategies), with enhanced provisions for services supporting critical or important functions.

Evidence an auditor accepts: ICT contracts containing the mandatory key provisions (audit/access, termination, exit, security); Enhanced provisions for critical/important-function services
Common gap: Contracts missing audit/access, termination or exit provisions
Source framework: DORA (Regulation (EU) 2022/2554)
DORA Art. 29 Preliminary assessment of ICT concentration risk at entity level

When assessing ICT third-party arrangements supporting critical or important functions, financial entities shall assess ICT concentration risk, including the risks of contracting providers that are not easily substitutable or of multiple arrangements with the same or closely connected providers, and the implications of subcontracting.

Evidence an auditor accepts: ICT concentration-risk assessment for critical/important-function arrangements
Common gap: Concentration risk not assessed
Source framework: DORA (Regulation (EU) 2022/2554)
DORA Art. 31 Designation of critical ICT third-party service providers

The European Supervisory Authorities designate critical ICT third-party service providers, which become subject to the Union Oversight Framework led by a Lead Overseer; financial entities shall account for the use of such providers in their third-party risk management.

Evidence an auditor accepts: Identification of any critical ICT third-party providers used and their oversight status
Common gap: No awareness of critical-TPP designations affecting the entity
Source framework: DORA (Regulation (EU) 2022/2554)

See what it attaches to your list

Paste the vendor list, tick the regime, and every vendor it reaches carries these rows. Eight vendors free, no account.

Build my vendor register