ICT third-party risk management under DORA
DORA changed ICT supplier management from a procurement exercise into a supervised risk discipline, with contract contents fixed by law, exit plans that have to be tested, and a concentration question the firm has to answer before it signs. The register of information is the document this discipline produces; the subject here is the discipline itself.
The strategy, and the process that never closes
Article 28 of DORA requires a financial entity to manage ICT third-party risk as an integral part of its ICT risk management framework, with a strategy on the use of ICT services that the management body reviews regularly. The same article requires the risk to be managed across the whole relationship, from pre-contractual assessment to exit.
Before signing, the firm assesses whether the service supports a critical or important function, whether supervisory and resolution conditions are met, and whether the provider's own risk posture is acceptable. Signing does not end it. The provider is monitored against the agreed service levels, the assessment is redone when the service changes, and the whole arrangement is reconsidered when the provider's circumstances change.
The contract clauses that are now mandatory
Article 30 of DORA fixes what has to be in the contract, in two tiers. Every ICT service contract carries a clear description of the service, the locations where data is processed and stored, data protection and availability provisions, assistance in the event of an ICT incident, cooperation with the authorities, and termination rights with notice periods.
A service supporting a critical or important function adds more: full service level descriptions with quantitative and qualitative performance targets, notice periods and reporting obligations on the provider, the obligation to participate in the firm's security awareness and resilience training, unrestricted access, inspection and audit rights, and an exit strategy. The two-tier split is why a firm's criticality assessment drives its contract templates, not the other way around.
The exit strategy, documented and tested
For a critical or important function the firm needs an exit strategy under Article 28(8), and it has to be documented, sufficiently tested and reviewed periodically. The test is what distinguishes it from a clause: a plan that has never been exercised does not establish that the firm could leave.
Three things decide whether an exit is real. The data has to come back in a usable format, which is a contractual and a technical question. A destination has to exist, either another provider or an in-house capability, which is why the register records whether alternatives were identified. And the transition period has to be long enough, which is negotiated before signing because it cannot be obtained later.
Concentration risk, at the firm and across the sector
Article 29 of DORA requires the firm, when considering a contract for a critical or important function, to assess whether the arrangement would lead to ICT concentration risk, including through subcontracting and through the provider being based in a third country. Substitutability is part of that question: a provider nobody can replace produces concentration whatever its market share.
The sector-level version is run by the supervisors on the registers of information. For the firm this means the analysis is not only internal; the answer about a given provider can change because other firms also use it. Outsourcing and cloud use in German banks covers the cloud-specific side and the German legal layer.
Subcontracting and the limits on it
Subcontracting is allowed and conditioned. Commission Delegated Regulation (EU) 2024/1773 specifies what a firm has to do when a provider subcontracts an ICT service supporting a critical or important function: assess the chain before signing, require the provider to notify material changes to it, and keep the right to object or terminate where a proposed subcontractor is unacceptable.
The practical limit is knowledge. A firm that cannot see past the first provider cannot assess the chain, so the contract has to oblige the provider to disclose the subcontractors supporting the function and the locations involved. This is the same data the register of information needs, which is why the two obligations are worked on together.
Oversight of the critical providers themselves
DORA added something new to EU financial regulation: supervision of the suppliers. The European Supervisory Authorities designate critical ICT third-party providers and oversee them directly, with a lead overseer per provider, the power to request information and conduct inspections, and the power to issue recommendations.
The authorities designated the first critical ICT third-party providers in a list of 19 names. For a bank, the designation of its cloud provider changes little about its own duties: the provider now has its own supervisor, and the financial entity remains fully responsible for its own compliance and its own resilience.
Pooled audits, and how several banks audit one provider
A large provider cannot host separate audits for every financial client, and Article 30(3) of DORA recognizes this by allowing the audit and inspection rights to be exercised through a pooled audit, where several financial entities audit the provider jointly, with an agreed scope and a shared report.
The firm stays responsible for the result. A pooled audit the firm did not help scope, whose report does not cover the services the firm actually uses, satisfies its own duty only to the extent of what was examined. Firms that use pooled audits therefore read the scoping document as carefully as the findings.
What is ICT third-party risk management?
ICT third-party risk management is the discipline of controlling the risk a financial entity takes on by having others run parts of its IT: assessing a provider and the criticality of the function before signing, putting the contract contents DORA requires into the agreement, monitoring performance and the subcontracting chain during the relationship, keeping a tested exit strategy, and answering the concentration question. The duties sit in Articles 28 to 30 of Regulation (EU) 2022/2554.
What is a critical or important function?
A function whose disruption would materially impair the firm's financial performance, the soundness or continuity of its services and activities, or its compliance with the conditions of its authorization. The firm assesses it, which makes the assessment a judgment it has to defend. Nearly everything else in the regime follows from the answer: the contract tier, the exit strategy, the subcontracting transparency and the depth of the register entry.
Does DORA replace the EBA outsourcing guidelines?
For ICT services, largely yes; for everything else, no. DORA is the regime for ICT third-party risk, and the EBA guidelines on outsourcing arrangements continue to apply to outsourcing that is not an ICT service, such as a business process handled by another firm. In Germany section 25b KWG and the MaRisk outsourcing module still sit underneath, so a bank applies both frames to the same supplier portfolio.
Who owns ICT third-party risk inside a bank?
DORA requires a function to monitor the arrangements, and in practice three units share the work: procurement and legal own the contracts, the business owns the service and its criticality, and ICT risk control challenges both. The management body carries the responsibility and cannot delegate it. The arrangement that fails is the one where procurement owns the supplier list and nobody owns the risk.
ICT third-party risk and Finance Loop
Finance Loop is the meeting place for the outsourcing officers, ICT risk controllers and procurement leads who manage these relationships in German finance. Finance Loop events put them in a room with the supervisors who read the registers and with the providers whose contracts are under discussion.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.