Your contextContext not defined
Country of the organisation assessedNot provided
What it providesNot provided
Relationship with the EUNot provided
Home / EU Regulation

EU Regulation

DORA for ICT providers

DORA governs financial entities and strengthens their expectations of ICT providers.

Effect of this requirement

This rule cannot be read in isolation.

Applicability to be qualified
Transfers
Bilateral relationship
Country sources reviewed on
Assumptions, limitations and sources of this reading

Reading point

The contract makes the dependency governable

The nature of the ICT service, its criticality and its subcontracting chain determine which topics need to be examined.

  • Nature of the financial client
  • ICT service provided and criticality
  • Clauses, audit, continuity and subcontracting
  • Expected operational evidence

Cascade of liability

Track the DORA requirement without assigning the supplier the role of the financial entity.

01

Financial entity

It remains responsible for its own IT-related risk.

02

ICT service contract

Rights, cooperation, localisation, continuity and exit are specified according to the service.

03

International supplier

It translates the clauses into capabilities, responsible parties, timelines and evidence.

04

Subcontracting

Significant dependencies and changes must remain visible.

Decision path

Qualify the ICT service before reading the clauses

DORA cannot be reduced to either the client's financial sector or a uniform list of clauses imposed on all its suppliers.

01Function supported

Specify the financial entity client, the activity served and the operational consequence of unavailability or compromise.

02Service and criticality

Define the systems, data, locations and dependencies that actually make up the ICT service under review.

03Contractual capabilities

Translate audit rights, assistance, notification, continuity, reversibility and exit into owners and deadlines the company can actually meet.

04Controlled chain

Make significant subcontractors, their changes, risk concentrations and client-usable evidence visible.

Operational reading of the ICT service

Requests to be linked to the contract, operations and subcontracting.

Questions to address

  • Mandatory contractual clauses (audit, access, termination, subcontracting)
  • Your entry in their information register
  • Your continuity plans and test results
  • Your ICT subcontracting chain and its locations

Elements that support the response

  • Contracts and annexes aligned with the client's DORA requirements
  • Dated continuity and restoration tests
  • Subcontracting map with criticality
  • Incident log and notification deadlines maintained

Confusions to avoid

  • Reject audit clauses outright instead of negotiating their terms
  • Discovering the information register at renewal time
  • Underestimating the criticality assigned to your service
  • Signing resilience commitments that have never been tested
Assurance file, IN-011Demonstration example
Contractual clauseIncident notification to the client within 24 hoursFinding
Internal processIncident qualification within 48 to 72 hoursFinding
Actual timelineDetection Saturday 03:10, qualification Monday morningFinding
Divergence observedThe clause is structurally untenable at weekendsGap
ImpactLikely contractual breach from the very first real incidentGap
ActionNegotiate a "notification of known facts" clause with a defined response deadlineDecision
Reading the coloursFactual observationGap or riskDecision or action

Demonstration

Test the clause against how the ICT service actually operates.

The case sets a notification deadline against the arrangements available at weekends, exposing a structural impossibility before signature.

Understanding how evidence is qualified →

Apply this reading

Present the ICT service and its role in the financial activity.

The proposed contract, the ICT service and its continuity arrangements make it possible to test rights, timeframes and obligations against actual capacity.