Skip to main content

The EU’s Digital Operational Resilience Act (DORA) third-party risk management is the set of rules that requires financial entities to identify, assess, monitor, and manage the risks that come from their ICT (information and communications technology) third-party service providers. Under DORA ICT third-party risk management guidelines, organizations must oversee every stage of their relationships with third-party providers, including due diligence, contract negotiation, ongoing monitoring, and exit planning. This allows them to proactively manage third-party risks.

Role of third-party risk in the context of DORA

DORA applies to financial entities as of January 17, 2025, meaning affected organizations must already have the required controls in place. These entities include banks, insurance companies, investment firms, payment institutions, and crypto-asset service providers, among others. This regulation also extends to ICT third-party service providers, such as cloud platforms and data analytics vendors, recognizing that the operational resilience of a financial institution is only as strong as the vendors it relies on. This means that if a critical vendor goes down or suffers a security breach the financial entity is still responsible for the resulting impact. Therefore, DORA encourages organizations to treat that exposure with the same level of seriousness as any other internal risk.

What are critical ICT third-party providers?

Not all ICT vendors carry the same level of risk. Some technology providers are deemed so deeply embedded in the European financial system that their failure could ripple across multiple companies. DORA refers to these providers as critical ICT third-party providers (CTPPs) and treats them differently from ordinary vendors. As described in Articles 31 to 44 of Regulation (EU) 2022/2554 such providers are supervised directly by the European Supervisory Authorities, in addition to the oversight that each financial entity applies through its own contractual arrangements. In short, CTPPs usually include cloud platforms, data centers, or specialist tech vendors.

As previously mentioned, this oversight authority sits with the 3 European Supervisory Authorities (ESAs)—the European Banking Authority (EBA), the European Insurance and Occupational Pensions Authority (EIOPA), and the European Securities and Markets Authority (ESMA). However, this doesn’t reduce each financial entity’s responsibility, as each organization should still be required to assess, monitor, and manage the risks tied to CTPPs in their supply chain.

DORA’s third-party risk management requirements

DORA lays out a clear framework for how financial entities should handle their ICT third-party relationships. These requirements cover the entire lifecycle of a vendor relationship, from the first risk assessment to day-to-day oversight.

Pre-contractual due diligence and risk assessment

Before signing with any ICT provider, financial entities must carry out a thorough risk assessment. This includes evaluating whether the provider’s security aligns with the entity’s information security standards and business continuity capabilities. It also includes identifying any concentration risk that could arise from relying on the provider.

Contractual provisions

DORA sets specific expectations in Article 30, particularly in Article 30(2) for all ICT contracts and Article 30(3) for those supporting critical or important functions. These requirements detail what must be included in contracts with ICT third-party providers. These agreements must cover service-level descriptions, data protection obligations, audit and access rights, incident reporting procedures, and clear exit strategies. For providers supporting critical or important functions, the contractual requirements are even more detailed, with provisions for subcontracting restrictions and termination rights built in.

Register of information

Financial entities must maintain a complete, up-to-date register of information that documents all contractual arrangements with ICT third-party providers. This register needs to distinguish between contracts that support critical or important functions and those that don’t. It’s not just an internal exercise, either. Entities must be able to provide this register to the competent authorities upon request, making it a live compliance tool rather than a static spreadsheet.

Ongoing monitoring and oversight

The work doesn’t stop once a contract is signed. Financial entities are required to continuously monitor the performance and risk profile of their ICT providers throughout their entire relationship. This means tracking service delivery against agreed-upon standards, staying alert to changes in the provider’s risk posture, and having processes in place to escalate issues quickly. For providers supporting critical or important functions, entities must also ensure they have tested exit plans ready if the relationship needs to end.

DORA’s third-party risk management process

DORA is specific about what financial entities need to have in place, but how you implement those requirements across your organization is up to you. Here’s a practical breakdown of the process from start to finish.

Visually depicted DORA's third-party risk management process

Map all ICT third-party providers

Start by creating a comprehensive list of all ICT providers your organization relies on. As mentioned throughout the article, this covers cloud services, software vendors, and any subcontractors they might use. In other words, anything that touches your ICT environment belongs on the list. This inventory will be directly important for the register of information.

Classify by criticality

Once you have the full picture, categorize each provider based on how critical their services are. This means that CTPPs should be separated from the ordinary providers and fall under a higher level of scrutiny, stricter contractual terms, and more intensive oversight. In turn, such classification drives every decision that follows.

Conduct risk assessments

Before entering into or renewing any arrangement, assess each provider based on a defined set of risk criteria. Look at their security controls, financial stability, geographic risk, exposure to concentration, and substitutability. The goal is to understand exactly what could go wrong and how much damage it would cause.

Negotiate DORA-compliant contracts

Translate your risk findings into contractual protections. Make sure agreements include audit rights, incident notification obligations, data location requirements, performance benchmarks, subcontracting controls, and clearly defined exit clauses.

Monitor continuously

Ongoing monitoring means tracking provider performance against contractual commitments, reviewing their security posture regularly, and watching for warning signs like financial instability, leadership changes, or regulatory actions. Don’t wait for the renewal cycle to catch problems.

Test exit strategies

For providers supporting critical or important functions, your contracts must include termination, exit, and transition conditions. A practical test is whether you can end or move a service without exceeding the recovery tolerance of the function that depends on it. An exit plan that’s never been tested against that standard is just a document.

Report and update the register

Keep your register of information current as relationships change, contracts are amended, or new providers come on board. Be ready to share it with regulators at any point, not just during scheduled reviews.

Conclusion

DORA’s requirements are already in effect, and the underlying principle is consistent throughout: if your business depends on a third-party technology, you are responsible for the associated risks. Build real visibility into your vendor ecosystem, keep your register of information current, make sure your contracts include the Article 30 terms, and pressure-test your exit plans before you actually need them.