The Digital Operational Resilience Act (DORA) became applicable on 17 January 2025. It requires every in-scope financial entity to manage ICT third-party risk end-to-end — before contracting, throughout the relationship, and on exit. This checklist focuses on the third-party pillar (Articles 28–30) and the register of information that supervisors will request.
1. Scope and governance
Confirm whether the entity is in scope (credit institutions, payment & e-money institutions, investment firms, insurers, crypto-asset service providers, etc.).
Assign board-level ownership of the ICT third-party risk strategy and document delegation to senior management.
Adopt and approve an ICT third-party risk policy that covers the full lifecycle (Art. 28(2)).
Establish a multi-vendor strategy to avoid concentration on a single ICT provider for critical or important functions.
2. Register of information (Article 28(3))
Maintain a register of all contractual arrangements with ICT third-party providers — at entity, sub-consolidated, and consolidated level.
Distinguish arrangements supporting "critical or important functions" from the rest.
Capture provider identification (LEI), corporate group, country of headquarters, country of service delivery, and chain of sub-contractors.
Record contract reference, start/end date, notice periods, governing law, and renewal terms.
Document the ICT services provided using the ESA harmonised taxonomy (S01–S19) and the function(s) they support.
Track data locations, data sensitivity, and whether personal data is processed.
Annually report the register to the competent authority in the EBA/ESMA/EIOPA ITS format.
3. Pre-contractual assessment
Perform a criticality assessment: would disruption materially impair regulated services, supervisory reporting, or operational continuity?
Assess concentration risk at entity and group level — including indirect concentration via sub-contractors.
Run due diligence on the provider's financial standing, reputation, security posture, business continuity, and audit history.
Verify the provider can meet appropriate information-security standards (ISO 27001, SOC 2 Type II, or equivalent).
Check sanctions, adverse media, beneficial ownership, and country risk on the provider and its group (KYB/KYS).
For critical or important functions, confirm the provider operates within the EU or that any third-country processing is legally workable.
4. Contractual requirements (Article 30)
Include a clear and complete description of all functions and ICT services to be provided.
Specify the locations where data is processed and stored, and require advance notice of change.
Define service levels, availability, performance targets, and reporting frequency.
For critical or important functions, add full audit, access, and inspection rights for the entity, its auditors, and the competent authority.
Mandate cooperation with supervisors and resolution authorities.
Require the provider to notify ICT-related incidents and participate in TLPT (threat-led penetration testing) where applicable.
Set unrestricted termination rights and an exit strategy with transition assistance.
Limit sub-contracting of critical or important functions and require prior notification.
5. Ongoing monitoring
Continuously monitor the provider's performance against contractual KPIs.
Re-assess vendor criticality and concentration at least annually.
Refresh sanctions, adverse media, beneficial ownership and financial-health screening on a defined cadence.
Track sub-contracting chains and material changes notified by the provider.
Log ICT-related incidents involving the provider and feed them into the major incident reporting workflow.
6. Exit and resolvability
Maintain a documented, tested exit plan for every critical or important function.
Identify alternative providers or in-house fallback paths.
Validate data portability — formats, encryption keys, and contractual return/deletion obligations.
Run periodic exit rehearsals as part of the digital operational resilience testing programme.
7. Supervisory readiness
Submit the annual register of information to the competent authority in the ESA format.
Be ready to provide the policy, due-diligence evidence, contracts, audit reports, and incident log on request.
Monitor designations of Critical ICT Third-Party Providers (CTPPs) and the EU oversight framework's recommendations.
How RisQo helps
RisQo automates the third-party pillar of DORA: continuous KYB/KYS, sanctions and adverse-media screening, financial-health signals, vendor criticality scoring, and an audit-ready register of information aligned with the ESA ITS taxonomy.
