Practical writing on DORA third-party risk.
What the regulation asks for, what supervisors send back, and how teams keep a Register that matches reality. Written for compliance, ICT risk and procurement teams in European financial organisations.
Articles
On the Register, contracts, assessments and evidence.
Critical ICT third-party providers: what designation changes
The ESAs designate a small number of providers as critical and supervise them directly. What that means for the entities using them, and what it does not mean.
ReadWhat the EBA taxonomy actually rejects
We put a generated Register of Information through the EBA's own 4.0 taxonomy. It failed with eighty-eight errors. Here is every cause, and what each one teaches about building a register that loads.
ReadThe Register columns only your provider can answer
Nineteen of the hundred and twenty columns describe the provider and its subcontractors, and six more describe where a service physically runs. None of them are facts you hold.
ReadThe DORA Register of Information: what supervisors actually expect
The Register is not a spreadsheet exercise. A look at the structure, the reference data behind it and the errors that get registers sent back.
ReadClassifying critical or important functions without guesswork
Criticality drives almost every DORA obligation. A repeatable method for classifying functions and the ICT services behind them.
ReadArticle 30 contract clauses: a practical review checklist
What every ICT contract needs, what critical-function contracts need on top, and how to review a portfolio you inherited.
ReadDesigning vendor assessments that vendors actually complete
Response rates collapse when questionnaires are long, repetitive and unclear. What to change in the questionnaire and the process around it.
ReadEvidence expiry: the quiet failure mode of third-party programs
Certificates and reports have end dates. Without tracking, a compliant vendor file silently becomes an out-of-date one.
ReadConcentration risk: seeing the providers behind your providers
Four vendors, one underlying cloud region. How to map ICT supply chains and spot concentration you did not contract for.
ReadWhere AI belongs in third-party risk, and where it does not
Assisted review saves real time on reading and extraction. It should never own a risk decision. A working boundary.
ReadBuilding a DORA-ready vendor onboarding process
Most register gaps are created at onboarding. A sequence that captures the right data before the contract is signed.
ReadReporting ICT third-party risk to the board without noise
Boards do not need a vendor list. Four views that answer the questions the management body is accountable for.
ReadGuides and checklists
Longer material you can work through.
Each one ends in a checklist you can use as acceptance criteria for your own programme.
DORA ICT Third-Party Risk Guide
How ICT third-party oversight works in practice: inventory, criticality, assessments and continuous review.
ReadDORA Register of Information Guide
The structure of the Register, common data quality issues and how to keep it aligned with operations.
ReadICT Vendor Assessment Checklist
Question areas to cover for cloud, payment and core banking providers.
ReadDORA Contract Requirements Checklist
Clause topics to verify in ICT contracts, including audit rights, subcontracting and exit strategy.
ReadThird-Party Risk Template
A starting structure for provider, service, risk and remediation records.
ReadDORA Readiness Checklist
A self-assessment across inventory, assessments, contracts, evidence, remediation and reporting.
ReadReference
What DORA asks, and how we answer for ourselves.
Everything linked here exists today.
DORA and ICT third-party risk
What the regulation asks of financial entities managing ICT providers, and which obligations fall where.
ReadThe Register of Information
What the Register contains, how it is assembled from operational records, and what supervisors do with it.
ReadArticle 30 contract requirements
The contractual provisions Article 30 requires, and how a gap register turns a missing clause into tracked remediation.
ReadOur incident response process
Severity classification, triage targets, containment, recovery and the windows in which we notify you.
ReadSub-processors
Every third party that processes customer data, what reaches them, and where they run it.
ReadSecurity and data protection
Encryption, tenant isolation, access control, auditability, retention, legal hold and restore testing.
ReadPrefer to see it in the product?
See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.