ICT Third-Party Risk under DORA
DORA's ICT third-party risk pillar (Articles 28–30) requires financial entities to manage risk arising from ICT third-party providers throughout the contract lifecycle and to maintain a register of information on all ICT arrangements.
The register of information
Entities must keep a structured register of every ICT third-party arrangement, distinguishing those that support critical or important functions, and report it to competent authorities. Our TPP register generator produces a register in the EBA format, and our guide to building your first register walks through where to start and the most common mistakes.
Contractual requirements & oversight
Contracts must include specific provisions on access, audit, exit strategies, and sub-outsourcing. Critical ICT third-party providers are additionally subject to a new EU-level oversight framework led by the European Supervisory Authorities. The sub-outsourcing provisions are not left to negotiation: the RTS on subcontracting sets out exactly what must be assessed before a critical or important function is subcontracted, a notice-and-objection mechanism the ICT provider must follow before making material changes to its subcontracting chain, and mandatory contract termination rights if it does not. See our guide to the DORA subcontracting RTS for the checklist to apply before signing off.
Concentration risk (Article 29)
Before and during outsourcing, entities must also assess ICT concentration risk, whether contracting a provider creates a heavy dependency on one supplier, and how easily the service could be moved if needed. For a practical walkthrough of what Article 29 requires and how the November 2025 critical-provider designations changed the reference point, see our guide to DORA concentration risk.
Frequently asked questions
What is the DORA register of information?
A structured record of all ICT third-party arrangements, maintained by the financial entity and reportable to competent authorities under Article 28.