ICT third-party risk and contractual provisions
DORA requires financial entities to manage risks arising from their reliance on ICT third-party service providers through a formal governance framework. It mandates rigorous pre-contractual due diligence, the maintenance of a detailed register of all ICT providers, and the inclusion of specific mandatory resilience clauses in all contracts.
What it means
The intent is to prevent systemic instability caused by failures in the supply chain. Rather than treating vendor management as a procurement task, DORA treats it as an operational resilience requirement. This means financial entities are held responsible for the security and availability of services provided by third parties.
The scope covers all ICT third-party providers, but higher standards apply to those supporting "critical or important functions." For these critical providers, the entity must ensure that the service can be transitioned or terminated without disrupting business operations.
In practice, this requires a shift from passive contract management to active lifecycle monitoring. Entities must prove they know exactly who their providers are, where data is stored, and how they can exit a relationship if the provider fails or becomes too risky.
How to meet it
- Establish an ICT Third-Party Risk Management (TPRM) framework approved by the board that defines strategies for selecting and monitoring vendors.
- Create and maintain a comprehensive "Register of Information" listing all contractual arrangements with ICT third-party providers, categorized by criticality.
- Conduct formal risk assessments before signing any contract to evaluate the provider's security posture and operational resilience.
- Update contract templates to include mandatory provisions: clear service level agreements (SLAs), detailed descriptions of services, data location specifications, and full access/audit rights for the entity and regulators.
- Implement a process for ongoing monitoring of third-party performance and risk, including periodic reviews of security certifications or audit reports.
- Develop documented exit strategies and transition plans for all ICT providers supporting critical or important functions to avoid vendor lock-in.
Evidence an auditor asks for
- The Register of Information (the inventory of all ICT third-party contracts).
- Due diligence records and risk assessment reports completed prior to the onboarding of key vendors.
- A sample of signed contracts demonstrating the inclusion of mandatory DORA clauses, specifically audit rights and termination terms.
- Evidence of ongoing monitoring, such as quarterly performance reviews or annual security assessments of providers.
- Documented exit plans for critical ICT services, including tested transition procedures.
Common pitfalls
- Relying on standard "take-it-or-leave-it" vendor contracts that lack the specific audit and access rights required by EU regulators.
- Failing to map dependencies (fourth-party risk), where a primary provider relies on another sub-contractor for critical infrastructure.
- Treating the Register of Information as a static spreadsheet rather than a live document integrated into the procurement lifecycle.
- Neglecting to define "critical or important functions" clearly, leading to inconsistent application of controls across different vendors.