Skip to main content
DORA Auditor

ICT Third-Party Risk under DORA

Last updated: 1 authoritative sourceDORA Auditor Editorial Team

DORA's ICT third-party risk pillar (Articles 28–30) requires financial entities to manage risk arising from ICT third-party providers throughout the contract lifecycle and to maintain a register of information on all ICT arrangements.

The register of information

Entities must keep a structured register of every ICT third-party arrangement, distinguishing those that support critical or important functions, and report it to competent authorities. Our TPP register generator produces a register in the EBA format, and our guide to building your first register walks through where to start and the most common mistakes.

Contractual requirements & oversight

Contracts must include specific provisions on access, audit, exit strategies, and sub-outsourcing. Critical ICT third-party providers are additionally subject to a new EU-level oversight framework led by the European Supervisory Authorities. The sub-outsourcing provisions are not left to negotiation: the RTS on subcontracting sets out exactly what must be assessed before a critical or important function is subcontracted, a notice-and-objection mechanism the ICT provider must follow before making material changes to its subcontracting chain, and mandatory contract termination rights if it does not. See our guide to the DORA subcontracting RTS for the checklist to apply before signing off.

Concentration risk (Article 29)

Before and during outsourcing, entities must also assess ICT concentration risk, whether contracting a provider creates a heavy dependency on one supplier, and how easily the service could be moved if needed. For a practical walkthrough of what Article 29 requires and how the November 2025 critical-provider designations changed the reference point, see our guide to DORA concentration risk.

Frequently asked questions

What is the DORA register of information?

Sources

  1. Regulation (EU) 2022/2554 (DORA), EUR-Lex