EU Regulation
DORA for ICT providers
DORA governs financial entities and strengthens their expectations of ICT providers.
Effect of this requirement
This rule cannot be read in isolation.
- Transfers
- Bilateral relationship
- Country sources reviewed on
Assumptions, limitations and sources of this reading
Reading point
The contract makes the dependency governable
The nature of the ICT service, its criticality and its subcontracting chain determine which topics need to be examined.
- Nature of the financial client
- ICT service provided and criticality
- Clauses, audit, continuity and subcontracting
- Expected operational evidence
Cascade of liability
Track the DORA requirement without assigning the supplier the role of the financial entity.
Financial entity
It remains responsible for its own IT-related risk.
ICT service contract
Rights, cooperation, localisation, continuity and exit are specified according to the service.
International supplier
It translates the clauses into capabilities, responsible parties, timelines and evidence.
Subcontracting
Significant dependencies and changes must remain visible.
Decision path
Qualify the ICT service before reading the clauses
DORA cannot be reduced to either the client's financial sector or a uniform list of clauses imposed on all its suppliers.
Specify the financial entity client, the activity served and the operational consequence of unavailability or compromise.
Define the systems, data, locations and dependencies that actually make up the ICT service under review.
Translate audit rights, assistance, notification, continuity, reversibility and exit into owners and deadlines the company can actually meet.
Make significant subcontractors, their changes, risk concentrations and client-usable evidence visible.
Operational reading of the ICT service
Requests to be linked to the contract, operations and subcontracting.
Questions to address
- Mandatory contractual clauses (audit, access, termination, subcontracting)
- Your entry in their information register
- Your continuity plans and test results
- Your ICT subcontracting chain and its locations
Elements that support the response
- Contracts and annexes aligned with the client's DORA requirements
- Dated continuity and restoration tests
- Subcontracting map with criticality
- Incident log and notification deadlines maintained
Confusions to avoid
- Reject audit clauses outright instead of negotiating their terms
- Discovering the information register at renewal time
- Underestimating the criticality assigned to your service
- Signing resilience commitments that have never been tested
Demonstration
Test the clause against how the ICT service actually operates.
The case sets a notification deadline against the arrangements available at weekends, exposing a structural impossibility before signature.
Understanding how evidence is qualified →Apply this reading
Present the ICT service and its role in the financial activity.
The proposed contract, the ICT service and its continuity arrangements make it possible to test rights, timeframes and obligations against actual capacity.

