Operationalize DORA third-party risk management.
DORA turns ICT third-party oversight into a continuous operational process. Relynt gives European financial organizations the system to run it: providers, assessments, contracts, evidence, risks and the Register of Information in one connected platform.
DORA Third-Party Risk Overview
Meridian Bank Europe · updated 9 August 2026
ICT Providers
96
Critical Providers
18
Register errors
3
Register warnings
9
High Risks
7
Missing Evidence
23
Outstanding
- Register errors blocking filing3
- Register warnings9
- Evidence documents missing23
- Article 30 clauses unresolved11
- Assessments overdue2
Attention Required
View allHalcyon assessment expires soon
Annual ICT Risk Assessment 2026 · due 18 Aug
Northwind Cloud contract needs review
Exit strategy clause not documented
Payflux evidence expires next month
SOC 2 Type II report valid until 14 Sep
Coverage
From inventory to reporting.
Each area maps to the operational work behind DORA ICT third-party risk requirements. Whether a specific obligation applies to your entity depends on your own regulatory analysis.
ICT provider inventory
One register of providers and the ICT services they deliver.
Criticality classification
Record which providers support a critical or important function, and why that function is critical.
Vendor assessments
DORA-focused questionnaires with a vendor self-service portal.
Contract requirements
Clause-by-clause coverage analysis against Article 30 topics.
Subcontractor visibility
Capture dependencies, countries and data locations.
Risk management
Findings become tracked risks with owners and remediation.
Register of Information
Maintained continuously from your operational records.
Reporting
Board packs, audit packs and readiness reporting.
Inventory
Start from a provider inventory you trust.
Everything downstream, assessments, contracts, evidence and the Register, depends on knowing which providers support which functions.
- Import existing provider lists
- Map ICT services and data processed
- Classify criticality with a documented method
- Assign internal owners for accountability
ICT Providers
96 providers · 18 critical
| Provider | ICT Service | Criticality | Country | Risk |
|---|---|---|---|---|
| Halcyon Cloud Services | Cloud Infrastructure | Critical | Ireland | High |
| Northwind Cloud Ireland | Cloud & Productivity | Critical | Ireland | Medium |
| Payflux Payments Europe | Payment Processing | Critical | Ireland | High |
| Lumendata Netherlands | Data Platform | Important | Netherlands | Medium |
| Edgeway Germany | Network & Security | Important | Germany | Low |
| Valtera | Core Banking | Critical | Switzerland | Medium |
Register of Information
Reporting output, generated from live data.
Validation highlights errors and warnings before submission, so the Register reflects the same records your teams work in daily.
- Register completeness tracked continuously
- Errors and warnings surfaced per provider
- Lineage from every Register row to the records behind it
- Structured export when reporting is required
Register of Information
Reporting entity: Meridian Bank Europe · LEI 549300XKZ9Q2P1F4T083
Templates with rows
12 of 15
Errors
3
Warnings
9
Validation issues
- B_02.02Function identifier is empty. Every key column has to resolve.Error
- B_05.02Identification code of the recipient of sub-contracted ICT services is empty.Error
- B_02.01Holds "Payment Services", which is not one of the nineteen permitted service types.Error
- B_01.01Competent Authority is empty. A supervisor will ask about this.Warning
- B_02.02Location of the data at rest is empty.Warning
Workflow
A repeatable DORA operating rhythm.
Make DORA third-party risk operational.
See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.