Chapter 11 of 15
DORA Regulation (EU) 2022/2554 — Financial Entities' ICT Third-Party Risk Duties
Cloud and technology contracts become part of the regulated control environment under Articles 28–30. This chapter examines strategy, registers, due diligence, concentration analysis, mandatory clauses, audit rights, contingency planning, and viable exits.
1. Where ICT Third-Party Risk Fits in DORA
ICT third-party risk is ICT risk
Article 28(1) says financial entities shall manage ICT third-party risk as an integral component of ICT risk within the Article 6(1) ICT risk management framework.
Outsourcing does not transfer accountability
A provider may operate a service, but the entity remains accountable. Article 28(1)(a) says it shall, at all times, remain fully responsible for DORA and applicable financial-services-law obligations.
Apply proportionality
Risk management must reflect ICT dependency and the service's criticality or importance, including its possible effect on continuity and availability at individual and group level.
Legal status
As of 24 July 2026, DORA applies and remains in force. The proposed amendments supplied for this course do not change Articles 28-30.
2. Article 28(2): Strategy, Policy, and Management Body Review
Who must adopt the strategy?
Article 28(2) requires a strategy for financial entities other than Article 16(1), first-subparagraph entities and other than microenterprises. Preserve these exclusions.
Multi-vendor strategy
The strategy must take account of the Article 6(9) multi-vendor strategy where applicable. Article 28(2) does not itself impose a universal multi-provider requirement.
Required policy
The strategy shall include a policy on ICT services supporting critical or important functions. It applies individually and, where relevant, at sub-consolidated and consolidated levels.
Management body oversight
The management body shall regularly review identified risks in these contracts, based on the overall risk profile and the scale and complexity of business services.
3. Article 28(3): The Register, Reporting, and Notifications
A register of all arrangements
Article 28(3) requires a register of information for all contractual arrangements for ICT services, maintained and updated at entity, sub-consolidated, and consolidated levels.
Classify the arrangements
Contracts must be appropriately documented and distinguished between those supporting critical or important functions and those that do not.
At least yearly reporting
Report at least yearly: new-arrangement numbers, provider categories, contract types, and the ICT services and functions being provided.
Supervisory access and timely notice
Provide the full register or requested sections on request. Inform the competent authority in a timely manner about planned critical-or-important arrangements and functions that become critical or important.
4. Worked Example: Building a Defensible Provider Register
More than a vendor list
A procurement spreadsheet is not enough. The Article 28(3) register covers all ICT-service contractual arrangements and requires appropriate documentation.
The key classification
Northbank must distinguish transaction-processing cloud services that support a critical or important function from arrangements that do not.
Group-level visibility
Where a parent contracts and subsidiaries use the service, the register must be maintained and updated at the required entity, sub-consolidated, and consolidated levels.
Planned critical arrangements matter
A planned arrangement supporting a critical or important function requires timely information to the competent authority. So does a function becoming critical or important.
5. Article 28(4)-(6): Before Signing and While Auditing
Five pre-contract tasks
Article 28(4) requires criticality assessment, supervisory-condition assessment, risk and concentration analysis, due diligence and suitability, plus conflict-of-interest assessment.
Information-security gate
Entities may only contract with providers complying with appropriate information security standards. Critical-or-important arrangements require due consideration of the most up-to-date and highest quality standards.
Plan audits using risk
Pre-determine audit frequency and areas through a risk-based approach, adhering to commonly accepted audit standards and any relevant supervisory instruction.
Complex services need capable auditors
For high technical complexity, verify that internal or external auditors, or a pool of auditors, possess appropriate skills and knowledge for effective audit and assessment.
6. Article 29: Preliminary Assessment of ICT Concentration Risk
Two concentration indicators
For envisaged critical-or-important arrangements, consider whether the provider is not easily substitutable or whether multiple arrangements rely on the same or closely connected providers.
Alternatives must be weighed
The entity shall weigh benefits and costs of alternatives, such as different providers, against business needs and objectives in its digital resilience strategy.
Subcontracting and insolvency
Where relevant, weigh subcontracting benefits and risks; duly consider insolvency law and constraints on urgent recovery of the entity's data.
Third countries and chains
For third-country providers, additionally consider Union data-protection compliance and effective enforcement of law. Assess whether long or complex subcontracting chains impair monitoring or supervision.
7. Worked Example: Cloud Concentration and Subcontracting
Look across the ecosystem
Several contracts can create one dependency. Article 29 requires analysis of multiple critical-or-important-function arrangements with the same or closely connected providers.
No numeric substitutability test
Article 29 gives no numerical threshold. Meridian must consider whether a provider is not easily substitutable, then weigh alternatives' benefits and costs.
Subcontracting adds a layer
A third-country subcontractor requires weighing benefits and risks. Long or complex chains must be assessed for their effect on monitoring and effective supervision.
Data recovery matters
For critical or important functions, duly consider applicable insolvency law and any constraint on urgent data recovery; third-country providers add data-protection and enforcement considerations.
8. Article 28(7)-(8): Termination, Exit, Transition, and Continuity
Four termination circumstances
Termination must be possible for significant breach, performance-altering monitoring findings, evidenced ICT-risk-management weaknesses, or loss of effective supervisory ability.
Critical functions need exit strategies
For ICT services supporting critical or important functions, entities shall put in place exit strategies addressing failure, quality deterioration, disruption, deployment risk, and Article 28(7) termination.
The three protected outcomes
Exit must occur without disruption to business activities, limiting regulatory compliance, or detriment to the continuity and quality of client services.
Make exit viable
Plans shall be comprehensive, documented, tested, and periodically reviewed. Identify alternatives, create secure transition plans, and maintain appropriate continuity contingencies.
9. Article 30: What Every ICT Contract Must Contain
One accessible written contract
Article 30(1) requires clearly allocated written rights and obligations. The full contract, including service level agreements, must be in one written, downloadable, durable, and accessible format.
Scope, subcontracting, and location
State all functions and services, permitted subcontracting and conditions, provision and processing locations including storage, plus advance notice of intended location changes.
Data and service protections
Include data protection provisions, accessible-format access, recovery and return arrangements for stated events, and service-level descriptions including updates and revisions.
Incident and authority cooperation
Include incident assistance at no extra or ex-ante-determined cost, authority cooperation, termination rights and notice periods, and training-participation conditions.
10. Article 30(3)-(5): Extra Clauses for Critical or Important Functions
Measurable service levels
Critical-or-important-function contracts need precise quantitative and qualitative targets, enabling monitoring and corrective action without undue delay if service levels are missed.
Resilience and TLPT commitments
Include material-impact notices, tested contingency plans, appropriate security measures, tools and policies, plus provider participation and full cooperation in TLPT.
Unrestricted audit rights
Ongoing monitoring includes unrestricted access, inspection, and audit rights for the entity or appointee and the competent authority, not impeded or limited by other arrangements or policies.
Transition period and microenterprise derogation
Exit clauses need a mandatory adequate transition period. A limited microenterprise derogation permits delegation of audit rights to an independent provider-appointed third party.
Standard clauses and RTS deadline
Parties shall consider public-authority standard contractual clauses. Article 30(5) required ESAs to submit draft subcontracting RTS by 17 July 2024.
11. Quiz: Register and Pre-Contract Duties
Choose the best answer
A financial entity is considering a new ICT contract. Which option accurately combines Article 28 requirements?
Which statement is correct?
- The entity need only record contracts supporting critical or important functions, and it may notify the competent authority after signing.
- Before entering the contract, the entity shall assess criticality, supervisory conditions, relevant risks including possible ICT concentration risk, provider suitability through due diligence, and conflicts of interest.
- The provider becomes responsible for DORA compliance once the contract contains service level agreements.
- A yearly report must list every individual employee at each ICT third-party service provider.
Show Answer
Answer: B) Before entering the contract, the entity shall assess criticality, supervisory conditions, relevant risks including possible ICT concentration risk, provider suitability through due diligence, and conflicts of interest.
Article 28(4) lists those five pre-contract actions. Article 28(3) covers all ICT-service contractual arrangements in the register and requires timely information about planned arrangements supporting critical or important functions. Responsibility remains with the financial entity under Article 28(1)(a).
12. Flashcards: Recall the Control Architecture
Flip each card
Use these cards to test whether you can state the Article 28-30 rules with their conditions and qualifiers.
- Who remains responsible after ICT outsourcing?
- Under Article 28(1)(a), the financial entity shall, at all times, remain fully responsible for compliance with and discharge of DORA and applicable financial services law obligations.
- What does the Article 28(3) register cover?
- All contractual arrangements on the use of ICT services provided by ICT third-party service providers, maintained and updated at entity, sub-consolidated, and consolidated levels.
- How often is Article 28(3) reporting required?
- At least yearly, covering the number of new arrangements, provider categories, contract types, and ICT services and functions provided.
- Name one Article 29 concentration-risk indicator.
- An envisaged critical-or-important-function arrangement would use a provider that is not easily substitutable, or create multiple such arrangements with the same or closely connected providers.
- What three outcomes must an Article 28(8) exit avoid?
- Disruption to business activities, limiting compliance with regulatory requirements, and detriment to continuity and quality of services provided to clients.
- What is the central Article 30(3) audit-rights phrase?
- Unrestricted rights of access, inspection and audit by the financial entity, or an appointed third party, and by the competent authority.
Key Terms
- TLPT
- Threat-led penetration testing referred to in Articles 26 and 27. Article 30(3)(d) requires the provider's participation and full cooperation where the arrangement supports a critical or important function.
- exit strategy
- For ICT services supporting critical or important functions, a strategy required by Article 28(8) to support a viable departure from an arrangement while protecting business activity, regulatory compliance, and client-service continuity and quality.
- subcontracting
- Further provision of ICT services by another ICT third-party service provider. Articles 29 and 30 require specified assessment and contractual treatment where it concerns critical or important functions.
- transition plan
- A plan to remove contracted ICT services and relevant data from a provider and securely and integrally transfer them to an alternative provider or reincorporate them in-house.
- ICT third-party risk
- Risk arising from a financial entity's contractual arrangements for ICT services provided by ICT third-party service providers, managed by Article 28 as an integral component of ICT risk.
- ICT concentration risk
- The dependency risk examined in Article 29, including reliance on a provider that is not easily substitutable or multiple critical-or-important-function arrangements with the same or closely connected providers.
- register of information
- The Article 28(3) record maintained and updated for all ICT-service contractual arrangements at entity level and, where specified, sub-consolidated and consolidated levels.
- service level agreement
- Part of the full written contract under Article 30(1). For critical or important functions, Article 30(3) requires precise quantitative and qualitative performance targets.
- microenterprise derogation
- The Article 30(3) exception under which a provider and a financial entity that is a microenterprise may agree to delegate access, inspection, and audit rights to an independent third party appointed by the provider, subject to the stated assurance-access condition.
- critical or important function
- A function whose classification is central to Articles 28-30 because it triggers additional strategy, notification, concentration-risk, exit, and contractual duties. This module does not add a definition beyond the provisions supplied.