Third-Party Risk Management: TPRM under DORA, EBA and MaRisk

ADVISORI implements third-party risk management that meets DORA, the EBA Outsourcing Guidelines and MaRisk. We build the governance, assessment and monitoring processes for your entire third-party portfolio — from due diligence and contractual requirements to the register of information — so every vendor relationship remains controlled and audit-ready.

  • TPRM framework aligned with DORA, EBA and MaRisk
  • Risk-based third-party classification and due diligence
  • Register of information under Art. 28 DORA
  • Continuous monitoring across the entire vendor lifecycle
  • Documented exit strategies for critical providers

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

  • Your strategic goals and objectives
  • Desired business outcomes and ROI
  • Steps already taken

Or contact us directly:

Certifications, Partners and more...

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

DORA and MaRisk-Compliant Third-Party Risk Management

ADVISORI in Numbers

11+

Years of Experience

120+

Employees

520+

Projects

Our approach to third-party management is comprehensive, practice-oriented, and individually tailored to your organization.

Our Approach:

Inventory and analysis of existing third-party relationships

Development of a tailored third-party governance framework

Definition of risk categories and assessment criteria

Implementation of onboarding, monitoring, and offboarding processes

Integration into existing GRC systems and continuous optimization

"Systematic third-party management is the key to secure and sustainable business relationships. Those who effectively manage and monitor their third parties minimize risks and create long-term value."
Sarah Richter

Sarah Richter

Head of Information Security, Cyber Security

Expertise & Experience:

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Our Services

We offer you tailored solutions for your digital transformation

Third-Party Governance

Development of a solid third-party governance structure with clear roles, responsibilities, and processes.

  • Policies and standards for third-party management
  • Risk management framework for third parties
  • Clear roles and responsibilities
  • Integration into compliance and audit processes

Third-Party Assessment

Systematic assessment and classification of third parties by risk and strategic importance.

  • Due diligence and background checks
  • Financial and operational assessment
  • Compliance and reputational review
  • Continuous monitoring and reassessment

Process Integration & Automation

Integration of third-party management into existing processes and systems with a focus on automation.

  • Automated risk assessment and monitoring
  • Integration into GRC and ERP systems
  • Workflow automation for onboarding and reviews
  • Real-time dashboards and reporting

Our Competencies

Choose the area that fits your requirements

Due Diligence

Thorough due diligence is the key to successful outsourcing. We support you in the systematic review of potential vendors to make informed decisions and fulfil regulatory requirements.

Frequently Asked Questions about Third-Party Management

How does DORA change third-party risk management compared to the EBA Outsourcing Guidelines and MaRisk?

DORA broadens the scope significantly. While the EBA Outsourcing Guidelines and MaRisk AT

9 focus on outsourcing arrangements, DORA Chapter V covers all contractual arrangements on the use of ICT services — regardless of whether they legally qualify as outsourcing. Financial entities must maintain a register of information on all ICT third-party arrangements, embed the mandatory contractual provisions of Art.

30 DORA, assess ICT concentration risk and define documented exit strategies for services supporting critical or important functions. The EBA Guidelines and MaRisk continue to apply to non-ICT outsourcing, so most institutions need an integrated framework that satisfies both regimes without duplicating work. We design this integration so that one classification logic, one contract standard and one monitoring process serve all applicable requirements.

What is the register of information under DORA and what must it contain?

The register of information under Art. 28(3) DORA is a structured inventory of all contractual arrangements on the use of ICT services provided by third-party providers. It must be maintained at entity, sub-consolidated and consolidated level and be made available to the competent authority, which collects it regularly.

🔍 Key content per the ESA templates:

Identification of the provider and its ultimate parent, including LEI
The ICT services provided and the functions they support
Classification of supported functions as critical or important
Material subcontracting chains
Contract data such as term, notice periods and governing law. In practice, data quality is the main challenge: provider identifiers, service taxonomies and function mappings must be consistent across source systems. We help you build and maintain a register that passes supervisory plausibility checks.

How should we classify our third parties and calibrate due diligence effort?

Effective third-party management is risk-based: not every vendor warrants the same scrutiny. We establish a tiering model that classifies each third party by the criticality of the function it supports, its access to data and systems, its substitutability and the potential concentration risk it creates. This classification then drives the depth of due diligence, the contractual clauses applied, the frequency of reassessments and the intensity of ongoing monitoring. Critical ICT providers under DORA receive full assessments including exit strategy and testing of contractual audit rights, while low-risk suppliers pass through a streamlined process. The result is a defensible allocation of effort: supervisors see a consistent methodology, and your teams spend their time where the risk actually sits.

How do we get subcontracting and fourth-party risk under control?

Subcontracting chains are among the most common findings in supervisory reviews, and DORA explicitly addresses them: financial entities must know which material subcontractors underpin the ICT services supporting critical or important functions and reflect them in the register of information. We help you establish chain transparency in three steps: contractual flow-down clauses that oblige providers to disclose and seek approval for material subcontracting, a structured intake of subcontractor data during due diligence and contract renewal, and ongoing monitoring of changes in the chain. For critical services, we also assess whether subcontracting concentrations — for example on a single cloud provider — create risks that require mitigation or contractual safeguards.

How much effort does implementing a TPRM framework involve and what determines the timeline?

The effort depends primarily on three factors: the size and heterogeneity of your third-party portfolio, the maturity of existing processes and data, and the tooling landscape. A typical implementation follows a clear sequence: first, a complete inventory and gap analysis against DORA, EBA and MaRisk requirements; second, design of the governance framework, classification methodology and contract standards; third, remediation of priority gaps such as the register of information and contracts for critical providers; and finally, rollout of onboarding, monitoring and offboarding processes with supporting workflows. We deliberately prioritize the elements with supervisory deadlines or the highest risk exposure, so your institution reaches a defensible state early while the full framework is completed in manageable stages.

How does third-party risk management integrate with our existing GRC tools and processes?

TPRM should not become another silo. We integrate third-party management into your existing GRC architecture so that vendor risks feed the same risk taxonomy, control framework and reporting lines as your other operational risks.

🔍 Typical integration points:

Vendor master data synchronized with procurement and contract management systems
Assessment workflows and questionnaires in your GRC or dedicated TPRM tool
Findings and measures tracked in the central issue management process
Register of information generated from structured data rather than maintained manually
Aggregated third-party risk reporting into existing risk committees. Where automation adds value — continuous monitoring feeds, external ratings, expiry alerts — we implement it pragmatically, always ensuring the process remains explainable to auditors and supervisors.

Latest Insights on Third-Party Management

Discover our latest articles, expert knowledge and practical guides about Third-Party Management

The CRA Single Reporting Platform (SRP): status, registration and what to prepare
Informationssicherheit

The Single Reporting Platform (SRP) is how manufacturers report under the Cyber Resilience Act from 11 September 2026. Till now it is not live, there is no API, and cross-border sharing is manual. What you can prepare regardless.

ECB requires action plan on AI-enabled cyber threats by 31 October 2026
Informationssicherheit

ECB Banking Supervision requires all significant institutions to submit an action plan addressing AI-enabled cyber threats by 31 October 2026. What letter SSM-2026-0301 demands, and how the six focus areas map onto DORA.

Cyber Insurance: Requirements, Costs, and Selection Guide for Businesses 2026
Informationssicherheit

Cyber insurance covers financial losses from cyberattacks, data breaches, and IT outages. This guide explains what insurers require in 2026, coverage types, costs by company size, and how to choose the right policy — including how ISO 27001 certification reduces premiums.

Vulnerability Management: The Complete Lifecycle for Finding, Prioritizing, and Remediating Weaknesses
Informationssicherheit

Over 30,000 CVEs are published annually. Effective vulnerability management prioritizes what matters most to your organization and remediates before attackers exploit. This guide covers the full lifecycle: discovery, scanning, risk-based prioritization, remediation, and compliance.

Security Awareness Training: Building Effective Programs and Measuring Impact
Informationssicherheit

The human layer remains the weakest link in cybersecurity. This guide covers how to build an effective security awareness program, run phishing simulations, design role-based training, and measure whether your program actually reduces risk — with benchmarks and KPIs.

Penetration Testing: Methods, Process & Provider Selection Guide 2026
Informationssicherheit

Penetration testing reveals vulnerabilities before attackers exploit them. This comprehensive guide covers black box, grey box, and white box methods, the 5-phase pentest process, provider selection criteria, DORA TLPT requirements, and cost benchmarks for every test type.

Success Stories

Discover how we support companies in their digital transformation

Digitalization in Steel Trading

Steel trading company from Germany

Digital Transformation in Steel Trading

Case Study

Results

Over 2 billion euros in annual revenue through digital channels
More than half of revenue through online channels as a strategic goal
Improved customer satisfaction through automated processes

AI-Powered Manufacturing Optimization

Industrial group from Germany

Smart Manufacturing Solutions for Maximum Value Creation

Case Study

Results

Significant increase in production performance
Reduction of downtime and production costs
Improved sustainability through more efficient resource utilization

AI Automation in Production

Automation specialist from Germany

Intelligent Networking for Future-Proof Production Systems

Case Study

Results

Improved production speed and flexibility
Reduced manufacturing costs through more efficient resource utilization
Increased customer satisfaction through personalized products

Generative AI in Manufacturing

Technology group from Germany

AI Process Optimization for Improved Production Efficiency

Case Study

Results

Reduction of AI application implementation time to just a few weeks
Improvement in product quality through early defect detection
Increased manufacturing efficiency through reduced downtime

Let's

Work Together!

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance