SkarpSkarp

Chapter 11 of 15

DORA Regulation (EU) 2022/2554 — Financial Entities' ICT Third-Party Risk Duties

Cloud and technology contracts become part of the regulated control environment under Articles 28–30. This chapter examines strategy, registers, due diligence, concentration analysis, mandatory clauses, audit rights, contingency planning, and viable exits.

24 min readen

1. Where ICT Third-Party Risk Fits in DORA

ICT third-party risk is ICT risk

Article 28(1) says financial entities shall manage ICT third-party risk as an integral component of ICT risk within the Article 6(1) ICT risk management framework.

Outsourcing does not transfer accountability

A provider may operate a service, but the entity remains accountable. Article 28(1)(a) says it shall, at all times, remain fully responsible for DORA and applicable financial-services-law obligations.

Apply proportionality

Risk management must reflect ICT dependency and the service's criticality or importance, including its possible effect on continuity and availability at individual and group level.

Legal status

As of 24 July 2026, DORA applies and remains in force. The proposed amendments supplied for this course do not change Articles 28-30.

2. Article 28(2): Strategy, Policy, and Management Body Review

Who must adopt the strategy?

Article 28(2) requires a strategy for financial entities other than Article 16(1), first-subparagraph entities and other than microenterprises. Preserve these exclusions.

Multi-vendor strategy

The strategy must take account of the Article 6(9) multi-vendor strategy where applicable. Article 28(2) does not itself impose a universal multi-provider requirement.

Required policy

The strategy shall include a policy on ICT services supporting critical or important functions. It applies individually and, where relevant, at sub-consolidated and consolidated levels.

Management body oversight

The management body shall regularly review identified risks in these contracts, based on the overall risk profile and the scale and complexity of business services.

3. Article 28(3): The Register, Reporting, and Notifications

A register of all arrangements

Article 28(3) requires a register of information for all contractual arrangements for ICT services, maintained and updated at entity, sub-consolidated, and consolidated levels.

Classify the arrangements

Contracts must be appropriately documented and distinguished between those supporting critical or important functions and those that do not.

At least yearly reporting

Report at least yearly: new-arrangement numbers, provider categories, contract types, and the ICT services and functions being provided.

Supervisory access and timely notice

Provide the full register or requested sections on request. Inform the competent authority in a timely manner about planned critical-or-important arrangements and functions that become critical or important.

4. Worked Example: Building a Defensible Provider Register

More than a vendor list

A procurement spreadsheet is not enough. The Article 28(3) register covers all ICT-service contractual arrangements and requires appropriate documentation.

The key classification

Northbank must distinguish transaction-processing cloud services that support a critical or important function from arrangements that do not.

Group-level visibility

Where a parent contracts and subsidiaries use the service, the register must be maintained and updated at the required entity, sub-consolidated, and consolidated levels.

Planned critical arrangements matter

A planned arrangement supporting a critical or important function requires timely information to the competent authority. So does a function becoming critical or important.

5. Article 28(4)-(6): Before Signing and While Auditing

Five pre-contract tasks

Article 28(4) requires criticality assessment, supervisory-condition assessment, risk and concentration analysis, due diligence and suitability, plus conflict-of-interest assessment.

Information-security gate

Entities may only contract with providers complying with appropriate information security standards. Critical-or-important arrangements require due consideration of the most up-to-date and highest quality standards.

Plan audits using risk

Pre-determine audit frequency and areas through a risk-based approach, adhering to commonly accepted audit standards and any relevant supervisory instruction.

Complex services need capable auditors

For high technical complexity, verify that internal or external auditors, or a pool of auditors, possess appropriate skills and knowledge for effective audit and assessment.

6. Article 29: Preliminary Assessment of ICT Concentration Risk

Two concentration indicators

For envisaged critical-or-important arrangements, consider whether the provider is not easily substitutable or whether multiple arrangements rely on the same or closely connected providers.

Alternatives must be weighed

The entity shall weigh benefits and costs of alternatives, such as different providers, against business needs and objectives in its digital resilience strategy.

Subcontracting and insolvency

Where relevant, weigh subcontracting benefits and risks; duly consider insolvency law and constraints on urgent recovery of the entity's data.

Third countries and chains

For third-country providers, additionally consider Union data-protection compliance and effective enforcement of law. Assess whether long or complex subcontracting chains impair monitoring or supervision.

7. Worked Example: Cloud Concentration and Subcontracting

Look across the ecosystem

Several contracts can create one dependency. Article 29 requires analysis of multiple critical-or-important-function arrangements with the same or closely connected providers.

No numeric substitutability test

Article 29 gives no numerical threshold. Meridian must consider whether a provider is not easily substitutable, then weigh alternatives' benefits and costs.

Subcontracting adds a layer

A third-country subcontractor requires weighing benefits and risks. Long or complex chains must be assessed for their effect on monitoring and effective supervision.

Data recovery matters

For critical or important functions, duly consider applicable insolvency law and any constraint on urgent data recovery; third-country providers add data-protection and enforcement considerations.

8. Article 28(7)-(8): Termination, Exit, Transition, and Continuity

Four termination circumstances

Termination must be possible for significant breach, performance-altering monitoring findings, evidenced ICT-risk-management weaknesses, or loss of effective supervisory ability.

Critical functions need exit strategies

For ICT services supporting critical or important functions, entities shall put in place exit strategies addressing failure, quality deterioration, disruption, deployment risk, and Article 28(7) termination.

The three protected outcomes

Exit must occur without disruption to business activities, limiting regulatory compliance, or detriment to the continuity and quality of client services.

Make exit viable

Plans shall be comprehensive, documented, tested, and periodically reviewed. Identify alternatives, create secure transition plans, and maintain appropriate continuity contingencies.

9. Article 30: What Every ICT Contract Must Contain

One accessible written contract

Article 30(1) requires clearly allocated written rights and obligations. The full contract, including service level agreements, must be in one written, downloadable, durable, and accessible format.

Scope, subcontracting, and location

State all functions and services, permitted subcontracting and conditions, provision and processing locations including storage, plus advance notice of intended location changes.

Data and service protections

Include data protection provisions, accessible-format access, recovery and return arrangements for stated events, and service-level descriptions including updates and revisions.

Incident and authority cooperation

Include incident assistance at no extra or ex-ante-determined cost, authority cooperation, termination rights and notice periods, and training-participation conditions.

10. Article 30(3)-(5): Extra Clauses for Critical or Important Functions

Measurable service levels

Critical-or-important-function contracts need precise quantitative and qualitative targets, enabling monitoring and corrective action without undue delay if service levels are missed.

Resilience and TLPT commitments

Include material-impact notices, tested contingency plans, appropriate security measures, tools and policies, plus provider participation and full cooperation in TLPT.

Unrestricted audit rights

Ongoing monitoring includes unrestricted access, inspection, and audit rights for the entity or appointee and the competent authority, not impeded or limited by other arrangements or policies.

Transition period and microenterprise derogation

Exit clauses need a mandatory adequate transition period. A limited microenterprise derogation permits delegation of audit rights to an independent provider-appointed third party.

Standard clauses and RTS deadline

Parties shall consider public-authority standard contractual clauses. Article 30(5) required ESAs to submit draft subcontracting RTS by 17 July 2024.

11. Quiz: Register and Pre-Contract Duties

Choose the best answer

A financial entity is considering a new ICT contract. Which option accurately combines Article 28 requirements?

Which statement is correct?

  1. The entity need only record contracts supporting critical or important functions, and it may notify the competent authority after signing.
  2. Before entering the contract, the entity shall assess criticality, supervisory conditions, relevant risks including possible ICT concentration risk, provider suitability through due diligence, and conflicts of interest.
  3. The provider becomes responsible for DORA compliance once the contract contains service level agreements.
  4. A yearly report must list every individual employee at each ICT third-party service provider.
Show Answer

Answer: B) Before entering the contract, the entity shall assess criticality, supervisory conditions, relevant risks including possible ICT concentration risk, provider suitability through due diligence, and conflicts of interest.

Article 28(4) lists those five pre-contract actions. Article 28(3) covers all ICT-service contractual arrangements in the register and requires timely information about planned arrangements supporting critical or important functions. Responsibility remains with the financial entity under Article 28(1)(a).

12. Flashcards: Recall the Control Architecture

Flip each card

Use these cards to test whether you can state the Article 28-30 rules with their conditions and qualifiers.

Who remains responsible after ICT outsourcing?
Under Article 28(1)(a), the financial entity shall, at all times, remain fully responsible for compliance with and discharge of DORA and applicable financial services law obligations.
What does the Article 28(3) register cover?
All contractual arrangements on the use of ICT services provided by ICT third-party service providers, maintained and updated at entity, sub-consolidated, and consolidated levels.
How often is Article 28(3) reporting required?
At least yearly, covering the number of new arrangements, provider categories, contract types, and ICT services and functions provided.
Name one Article 29 concentration-risk indicator.
An envisaged critical-or-important-function arrangement would use a provider that is not easily substitutable, or create multiple such arrangements with the same or closely connected providers.
What three outcomes must an Article 28(8) exit avoid?
Disruption to business activities, limiting compliance with regulatory requirements, and detriment to continuity and quality of services provided to clients.
What is the central Article 30(3) audit-rights phrase?
Unrestricted rights of access, inspection and audit by the financial entity, or an appointed third party, and by the competent authority.

Key Terms

TLPT
Threat-led penetration testing referred to in Articles 26 and 27. Article 30(3)(d) requires the provider's participation and full cooperation where the arrangement supports a critical or important function.
exit strategy
For ICT services supporting critical or important functions, a strategy required by Article 28(8) to support a viable departure from an arrangement while protecting business activity, regulatory compliance, and client-service continuity and quality.
subcontracting
Further provision of ICT services by another ICT third-party service provider. Articles 29 and 30 require specified assessment and contractual treatment where it concerns critical or important functions.
transition plan
A plan to remove contracted ICT services and relevant data from a provider and securely and integrally transfer them to an alternative provider or reincorporate them in-house.
ICT third-party risk
Risk arising from a financial entity's contractual arrangements for ICT services provided by ICT third-party service providers, managed by Article 28 as an integral component of ICT risk.
ICT concentration risk
The dependency risk examined in Article 29, including reliance on a provider that is not easily substitutable or multiple critical-or-important-function arrangements with the same or closely connected providers.
register of information
The Article 28(3) record maintained and updated for all ICT-service contractual arrangements at entity level and, where specified, sub-consolidated and consolidated levels.
service level agreement
Part of the full written contract under Article 30(1). For critical or important functions, Article 30(3) requires precise quantitative and qualitative performance targets.
microenterprise derogation
The Article 30(3) exception under which a provider and a financial entity that is a microenterprise may agree to delegate access, inspection, and audit rights to an independent third party appointed by the provider, subject to the stated assurance-access condition.
critical or important function
A function whose classification is central to Articles 28-30 because it triggers additional strategy, notification, concentration-risk, exit, and contractual duties. This module does not add a definition beyond the provisions supplied.

Finished reading?

Test your understanding with a custom practice exam on this chapter.

Test yourself