Effective Governance of Your ICT Supplier Relationships Under DORA

DORA ICT Third-Party Risk Management

ADVISORI helps banks and financial entities assess ICT providers, review contractual gaps and establish ongoing controls under DORA.

  • 01Assess DORA requirements systematically and prioritise implementation gaps
  • 02Identification and assessment of critical ICT service providers
  • 03Solid contractual frameworks and SLAs
  • 04Continuous monitoring and risk mitigation in the supply chain
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

DORA ICT Third-Party Risk Management

DORA establishes comprehensive requirements for managing ICT third-party providers. These are designed to strengthen the digital resilience of the financial sector by appropriately governing dependencies on external service providers. We support you in implementing an effective and DORA-compliant third-party risk management framework.

ADVISORI supports you in implementing a solid and DORA-compliant ICT third-party risk management framework. We accompany you from the initial gap analysis through conception to full implementation and integration into your existing processes.

2 service modules

What we take on for you

Bookable individually or as an end-to-end programme.

01

DORA TPRM Framework

Development and implementation of a comprehensive and DORA-compliant framework for managing ICT third-party risks.

  • Comprehensive Vendor Inventory: Systematic identification and categorization of all ICT service providers based on criticality and risk profile
  • Risk-Based Assessment Methodology: Development of standardized assessment frameworks for evaluating third-party security, resilience, and compliance capabilities
  • Governance Structure: Establishment of clear roles, responsibilities, and escalation paths for third-party risk management across the organization
  • Continuous Monitoring Framework: Implementation of ongoing oversight mechanisms including KPIs, dashboards, and automated risk indicators for critical vendors
02

DORA-Compliant Contract Design

Development of contract clauses and SLAs that meet DORA requirements and protect your interests vis-à-vis ICT service providers.

  • DORA-Specific Contract Clauses: Comprehensive templates for essential contractual provisions including audit rights, exit strategies, and incident management protocols
  • Resilience-Focused SLAs: Definition of service level agreements with specific metrics for availability, recovery times, and business continuity requirements
  • Exit and Transition Planning: Development of detailed exit strategies and transition procedures to ensure business continuity when changing providers
  • Concentration Risk Management: Strategies for identifying and mitigating concentration risks in your ICT supply chain, particularly for cloud services

5 phases

Our Approach

We support you in implementing DORA-compliant ICT third-party risk management with a structured and practice-oriented approach.

  1. Analysis of the current maturity level of your third-party risk management

  2. Identification and assessment of critical ICT third parties

  3. Design and implementation of DORA-compliant TPRM processes

  4. Development of templates for contract clauses and SLAs

  5. Establishment of a continuous monitoring framework for ICT service providers

Sarah Richter

Your contact

Sarah Richter

Head of Information Security, Cyber Security

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

DORA requirements for ICT third-party risk management present new challenges for many organizations. Our clients particularly value our pragmatic approach, which enables them to achieve compliance while effectively managing their business relationships with service providers.

Our Strengths

  • 01Deep expertise in regulatory requirements and best practices for Third-Party Risk Management
  • 02Experience implementing TPRM frameworks in financial institutions
  • 03Practice-oriented approaches that combine compliance with operational efficiency
  • 04Comprehensive templates and tools for efficient implementation

Expert Tip

Third-party risk management is one of the central elements of DORA. The integrated approach, encompassing contract design, risk assessment, and continuous monitoring, not only protects against compliance risks but also secures your company's operational stability.

6 QUESTIONS, BRIEFLY ANSWERED

Frequently asked questions about DORA ICT Third-Party Risk Management

What does Article 28 DORA specifically require for ICT third-party risk management?

Article 28 requires financial entities to treat ICT third-party risk as an integral part of their own ICT risk management: a risk assessment and due diligence before contract signing, ongoing monitoring throughout the contract term, and for critical providers, an additional concentration risk analysis. Responsibility for ICT risk stays fully with the financial entity regardless of what has been outsourced.

What contract clauses does DORA require for ICT service providers?

Required clauses include audit and access rights for the financial entity and its supervisor, clear service descriptions with defined service levels, provisions on subcontracting, and termination rights alongside a documented exit strategy for a provider switch. Existing contracts that lack these clauses need renegotiation, which in practice often affects older cloud and outsourcing agreements.

How is concentration risk with cloud providers assessed and managed?

Concentration risk arises when many critical functions depend on few or a single provider, which is often the practical reality with the leading hyperscalers. Assessment covers which critical business functions depend on which provider and how quickly a switch to an alternative provider could realistically happen in a failure scenario. Full avoidance is rarely realistic; the focus is a documented, deliberate risk acceptance backed by a contingency plan.

How is monitoring of critical ICT third-party providers operationalized without creating disproportionate overhead?

A risk-based tiering approach works well: not every provider needs the same monitoring depth. Non-critical standard vendors are usually fine with annual reviews, while critical providers with high failure impact need continuous monitoring, for example through SLA metrics and regular status reporting. This prioritization by criticality avoids spreading resources evenly across all providers instead of focusing on the ones that actually carry risk.

What belongs in the DORA information register for third-party providers?

The register captures, per contract, the provider name, the type of function performed, its criticality classification, the location of data processing, and details on subcontractors. It must be kept current and available on request from the supervisory authority; a register only updated ahead of an audit doesn't meet the ongoing maintenance obligation.

How are contingency plans for critical ICT third-party providers tested for DORA compliance?

Contingency plans for critical providers should be regularly tested through simulated failure scenarios rather than existing only on paper. This typically involves checking whether alternative sources or internal fallback solutions would actually be available within the defined recovery time. Test results feed into the ongoing assessment of the provider and can trigger a provider review if weaknesses recur.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance