Vendor Register
Standards ยท DORA

DORA (Regulation (EU) 2022/2554)

Rendered when the buyer ticks "DORA financial entity". The register cites 4 of its 26 clauses, behind 7 findings: single-source vendors with no fallback named, concentration at or above the threshold, contracts ending inside 90 days with no re-tender noted, critical vendors with no contract end recorded, dora register-of-information fields missing, cloud services with no exit plan, sub-outsourcing chains longer than one hop, and on the obligation rows of every vendor it reaches.

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Framework page. What it attaches to a vendor: the DORA regime page.

Clauses cited

4 of 26
DORA Art. 28 ICT third-party risk: general principles

Financial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangements (including concentration and subcontracting), and adopt an ICT third-party risk strategy.

Evidence an auditor accepts: A Register of Information of ICT third-party arrangements reported to the competent authority; Pre-contract risk assessment records
Common gap: No Register of Information
Source framework: DORA (Regulation (EU) 2022/2554)
DORA Art. 29 Preliminary assessment of ICT concentration risk at entity level

When assessing ICT third-party arrangements supporting critical or important functions, financial entities shall assess ICT concentration risk, including the risks of contracting providers that are not easily substitutable or of multiple arrangements with the same or closely connected providers, and the implications of subcontracting.

Evidence an auditor accepts: ICT concentration-risk assessment for critical/important-function arrangements
Common gap: Concentration risk not assessed
Source framework: DORA (Regulation (EU) 2022/2554)
DORA Art. 30 Key contractual provisions

Contractual arrangements for the use of ICT services shall include the mandatory key contractual provisions (e.g. clear service descriptions, locations of data processing, data protection, accessibility/availability/integrity/security, assistance on incidents, audit and access rights, termination rights and exit strategies), with enhanced provisions for services supporting critical or important functions.

Evidence an auditor accepts: ICT contracts containing the mandatory key provisions (audit/access, termination, exit, security); Enhanced provisions for critical/important-function services
Common gap: Contracts missing audit/access, termination or exit provisions
Source framework: DORA (Regulation (EU) 2022/2554)
DORA Art. 31 Designation of critical ICT third-party service providers

The European Supervisory Authorities designate critical ICT third-party service providers, which become subject to the Union Oversight Framework led by a Lead Overseer; financial entities shall account for the use of such providers in their third-party risk management.

Evidence an auditor accepts: Identification of any critical ICT third-party providers used and their oversight status
Common gap: No awareness of critical-TPP designations affecting the entity
Source framework: DORA (Regulation (EU) 2022/2554)

See which clauses your list engages

Paste the list and every vendor names the clauses behind it, filtered to the regimes that apply to you. Eight vendors free, no account.

Build my vendor register