DORA, the Digital Operational Resilience Act
Attaches to contractual arrangements for ICT services: cloud, software, network, managed services and data feeds. A supply of hardware, a bank or a courier is recorded in the register only where a service element sits in the contract.
On the register, tick "DORA financial entity" and these rows appear on every vendor the regime reaches. Framework page.
Which vendors it reaches
| Families | Cloud and hosting, Software and SaaS, Network and connectivity, Managed and professional services, Data and content |
|---|---|
| On every vendor | DORA Art. 28, DORA Art. 30 |
| Cloud and hosting | the clauses on every vendor only |
| Software and SaaS | the clauses on every vendor only |
| Network and connectivity | the clauses on every vendor only |
| Managed and professional services | the clauses on every vendor only |
| Data and content | the clauses on every vendor only |
| Supports a critical or important function (rated critical or important on the register) | DORA Art. 29 |
| Informational, cloud and hosting, managed and professional services | DORA Art. 31: the ESAs designate critical ICT third-party providers; the entity accounts for their use, it owes them no clause |
DORA Article 30, key contractual provisions
The clauses the register expects in every vendor agreement the regime reaches, and the further clauses for a vendor rated critical.
- A clear and complete description of the functions and ICT services provided
- The locations, by region or country, where the service is provided and the data processed, with notice before a change
- Availability, authenticity, integrity and confidentiality of data, including personal data
- Access, recovery and return of data on the provider's insolvency, resolution or the termination of the arrangement
- Service level descriptions, with quantitative and qualitative targets
- Assistance on an ICT incident affecting the service, at no or pre-set cost
- Cooperation with the competent and resolution authorities
- Termination rights and the minimum notice period, in line with the supervisors' expectations
- Participation of the provider's staff in the entity's ICT security awareness and training
Where the vendor supports a critical or important function (rated critical or important on the register)
- Full service level agreements with performance targets and the remedies when they are missed
- Notice periods and reporting obligations, including notice of developments that could affect the service
- Business continuity plans and ICT security measures, tested, with results shared
- Participation in threat-led penetration testing where the entity runs it
- Unrestricted rights of access, inspection and audit, for the entity and for the competent authority
- Exit strategies, with a transition period long enough to migrate without disruption
The register of information
Article 28(3) asks every financial entity to keep a register of information on its contractual arrangements for ICT services and to report it to the competent authority. Vendor Register exports one row per vendor with these fields, as Vendor Register names them, following what the supervisory template asks for:
- Vendor
- Identification (LEI or registration, if held)
- Type of ICT service
- Category (register)
- Function supported (systems)
- Criticality
- Country of the provider
- Country of provision
- Annual spend
- Share of spend
- Substitutability
- Single source
- Sub-outsourcing chain
- Contract end
- Exit plan
- ICT service in DORA scope
A column the paste cannot fill is exported blank and raised as the finding "DORA register-of-information fields missing".
The clauses, quoted
4 of 26 in the frameworkRequirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.
DORA Art. 28 ICT third-party risk: general principlesFinancial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangements (including concentration and subcontracting), and adopt an ICT third-party risk strategy.
Common gap: No Register of Information
Source framework: DORA (Regulation (EU) 2022/2554)
DORA Art. 30 Key contractual provisionsContractual arrangements for the use of ICT services shall include the mandatory key contractual provisions (e.g. clear service descriptions, locations of data processing, data protection, accessibility/availability/integrity/security, assistance on incidents, audit and access rights, termination rights and exit strategies), with enhanced provisions for services supporting critical or important functions.
Common gap: Contracts missing audit/access, termination or exit provisions
Source framework: DORA (Regulation (EU) 2022/2554)
DORA Art. 29 Preliminary assessment of ICT concentration risk at entity levelWhen assessing ICT third-party arrangements supporting critical or important functions, financial entities shall assess ICT concentration risk, including the risks of contracting providers that are not easily substitutable or of multiple arrangements with the same or closely connected providers, and the implications of subcontracting.
Common gap: Concentration risk not assessed
Source framework: DORA (Regulation (EU) 2022/2554)
DORA Art. 31 Designation of critical ICT third-party service providersThe European Supervisory Authorities designate critical ICT third-party service providers, which become subject to the Union Oversight Framework led by a Lead Overseer; financial entities shall account for the use of such providers in their third-party risk management.
Common gap: No awareness of critical-TPP designations affecting the entity
Source framework: DORA (Regulation (EU) 2022/2554)
See what it attaches to your list
Paste the vendor list, tick the regime, and every vendor it reaches carries these rows. Eight vendors free, no account.
Build my vendor register