DORA ICT Third-Party Risk

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Articles 28-44 establish DORA's fourth pillar: management of ICT third-party risk. Comprehensive obligations on financial entities for managing TPP relationships, plus Union-level oversight of critical ICT third-party providers (CTPPs).

General principles (Articles 28-29)

Financial entity remains fully responsible for compliance with regulatory obligations regardless of outsourcing to ICT third-party providers. Cannot delegate ultimate accountability.

ICT third-party risk strategy (Article 28(2))

Strategy on the use of ICT services covering:

  • Concentration risk
  • Substitutability assessment
  • Exit strategies
  • Multi-vendor approach where appropriate

Register of information (Article 28(3))

Financial entity maintains register of all ICT TPP contractual arrangements:

  • Contractor identity
  • Service nature
  • Service criticality (supports critical or important functions vs not)
  • Location of data processing
  • Sub-processors
  • Risk assessment
  • Contract terms summary
  • Performance metrics

Register submitted to competent authority periodically. ITS standardizes the format.

Pre-contractual analysis (Article 28(7))

Before entering ICT service contracts:

  • Risk assessment
  • Due diligence on the TPP
  • Assessment of TPP's compliance with applicable regulation
  • Assessment of TPP's ability to meet entity's requirements

Concentration risk (Article 29)

Entity assesses and manages concentration risk:

  • Single-TPP dependencies
  • Multiple-TPP arrangements with same underlying provider
  • Geographical concentration
  • Substitutability constraints

Contractual provisions (Article 30)

Mandatory contract clauses with ICT TPPs supporting critical or important functions:

Article 30(2) general clauses

For all ICT TPP contracts:

  • Clear and complete description of services
  • Locations of service provision and data processing
  • Personal data handling provisions
  • Data accessibility, recovery, return in case of contract termination
  • Service level agreements with performance targets
  • Notification obligations
  • Cooperation with competent authorities
  • Termination rights
  • Service quality monitoring rights

Article 30(3) additional clauses for critical/important function support

Additional clauses:

  • Right to monitor TPP performance continuously
  • Right to inspect and audit (or accept third-party audits)
  • Right to access TPP premises
  • Cooperation with competent authority access
  • Exit strategy provisions
  • Service continuity during transition
  • Subcontracting restrictions and approval
  • Insurance coverage

Article 30(7) mandatory inclusion

Member States ensure contracts have these clauses. National competent authorities can require contract modifications.

Sub-outsourcing / subcontracting (Articles 30, 33)

TPP can sub-outsource only with controller authorization. Sub-processors:

  • Subject to flow-down requirements equivalent to original contract.
  • Identified in register of information.
  • Subject to entity's monitoring rights.

RTS specifies subcontracting conditions for critical / important functions.

Critical ICT third-party providers (Articles 31-44)

Subset of ICT TPPs designated as CTPP — subject to Union-level oversight.

CTPP designation criteria (Article 31)

ESAs designate based on:

  • Systemic impact: impact of CTPP failure on financial sector stability.
  • Substitutability: difficulty replacing CTPP.
  • Reliance: extent of financial entity reliance.
  • Number of financial entities using the CTPP.
  • Total value of services.

Likely CTPP designations: major cloud providers (AWS, Microsoft Azure, Google Cloud, IBM Cloud), major SaaS providers serving financial sector, specialized financial-services TPPs.

Joint Oversight Mechanism (Article 32)

For each CTPP:

  • Lead Overseer designated (one of ESAs).
  • Joint Oversight Network: ESAs cooperate on CTPP oversight.

Lead Overseer powers (Articles 35-39)

  • Information requests
  • General investigations
  • On-site inspections at CTPP premises
  • Requesting CTPP cooperation with financial entity audits
  • Issuing recommendations to CTPPs
  • Imposing periodic penalty payments

CTPP cooperation obligations

CTPPs must:

  • Cooperate with Lead Overseer.
  • Provide information.
  • Allow inspections.
  • Implement recommendations (or justify non-implementation).

Where CTPP non-cooperative

Lead Overseer can recommend financial entities terminate CTPP relationships or modify them. Significant business impact for non-cooperative CTPP.

Penalty payments

Lead Overseer can impose periodic penalty payments on non-cooperative CTPPs — daily fines up to 1% of average daily worldwide turnover.

Concentration risk at Union level (Article 44)

ESAs assess Union-level concentration risk in ICT third-party services. Can:

  • Issue guidelines.
  • Identify systemic concentration.
  • Recommend remediation.

Bridge to ISO 27001

ISO 27001 A.5.19-A.5.23 supplier relationships provide foundational discipline. DORA adds:

  • More prescriptive contract clauses.
  • Register of information format.
  • Substitutability and exit planning emphasis.
  • Union-level CTPP oversight (no ISO 27001 equivalent).

ISO 27001-implementing financial entities still need DORA-specific extensions.

SRE and AI-agent fit notes

Model providers as ICT TPPs

Anthropic, OpenAI, Google, Cohere, Mistral, others providing model APIs to financial entities are ICT third-party providers. Subject to:

  • Contract clauses (Art 30).
  • Register inclusion.
  • Risk assessment.
  • Potential CTPP designation (largest providers serving multiple financial entities).

Cloud providers as likely CTPPs

AWS, Azure, Google Cloud, IBM Cloud likely candidates for CTPP designation given:

  • Financial-sector penetration.
  • Substitutability challenges.
  • Systemic impact potential.

CTPP designation brings Lead Overseer oversight to vendor; affects vendor commercial terms with financial customers.

Contract negotiation for AI vendors

Financial-services AI vendor contracts must include Article 30(3) clauses for critical-function support:

  • Audit rights
  • Inspection rights
  • Exit provisions
  • Subcontracting controls

Standard model-vendor enterprise terms typically need DORA-specific addenda.

Stefan-context implementation sketch

  • For financial-services client engagements: support vendor due diligence on AI / cloud providers.
  • For consultancy positioning serving financial customers: ICT TPP status — expect contract clauses, register inclusion, audit cooperation.
  • Document own cybersecurity posture for financial entity register-of-information.

See also