Resources

Practical writing on DORA third-party risk.

What the regulation asks for, what supervisors send back, and how teams keep a Register that matches reality. Written for compliance, ICT risk and procurement teams in European financial organisations.

Articles

On the Register, contracts, assessments and evidence.

Regulation5 min read

Critical ICT third-party providers: what designation changes

The ESAs designate a small number of providers as critical and supervise them directly. What that means for the entities using them, and what it does not mean.

Read
DORA Register6 min read

What the EBA taxonomy actually rejects

We put a generated Register of Information through the EBA's own 4.0 taxonomy. It failed with eighty-eight errors. Here is every cause, and what each one teaches about building a register that loads.

Read
Third-Party Risk5 min read

The Register columns only your provider can answer

Nineteen of the hundred and twenty columns describe the provider and its subcontractors, and six more describe where a service physically runs. None of them are facts you hold.

Read
DORA Register2 min read

The DORA Register of Information: what supervisors actually expect

The Register is not a spreadsheet exercise. A look at the structure, the reference data behind it and the errors that get registers sent back.

Read
Third-Party Risk2 min read

Classifying critical or important functions without guesswork

Criticality drives almost every DORA obligation. A repeatable method for classifying functions and the ICT services behind them.

Read
Contracts2 min read

Article 30 contract clauses: a practical review checklist

What every ICT contract needs, what critical-function contracts need on top, and how to review a portfolio you inherited.

Read
Assessments1 min read

Designing vendor assessments that vendors actually complete

Response rates collapse when questionnaires are long, repetitive and unclear. What to change in the questionnaire and the process around it.

Read
Evidence1 min read

Evidence expiry: the quiet failure mode of third-party programs

Certificates and reports have end dates. Without tracking, a compliant vendor file silently becomes an out-of-date one.

Read
Third-Party Risk1 min read

Concentration risk: seeing the providers behind your providers

Four vendors, one underlying cloud region. How to map ICT supply chains and spot concentration you did not contract for.

Read
AI Review1 min read

Where AI belongs in third-party risk, and where it does not

Assisted review saves real time on reading and extraction. It should never own a risk decision. A working boundary.

Read
Operations1 min read

Building a DORA-ready vendor onboarding process

Most register gaps are created at onboarding. A sequence that captures the right data before the contract is signed.

Read
Reporting1 min read

Reporting ICT third-party risk to the board without noise

Boards do not need a vendor list. Four views that answer the questions the management body is accountable for.

Read

Prefer to see it in the product?

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.

DORA Resources and Guides | Relynt