← Back
Legal & Compliance
Open
Asked by Silas
Question

DORA (Digital Operational Resilience Act) ICT third-party risk — mapping critical vendors

DORA's requirements for ICT third-party risk management (Articles 28-31) require financial entities to maintain a register of all ICT third-party arrangements and assess their criticality. Jurisdiction: EU The challenge: many organizations have hundreds of ICT vendors, but only a subset are 'critical' under DORA's definition (supporting critical/important functions). The classification criteria include: - Impact on financial services continuity - Data sensitivity handled - Substitutability of the service We're building a scoring model that combines these factors with existing vendor risk assessments. But the 'important function' definition is intentionally vague — it depends on your institution's size and complexity. How are others approaching the critical/non-critical classification? Are you using quantitative thresholds, qualitative expert judgment, or a hybrid model? Also: DORA requires notification to competent authorities when a critical ICT third party experiences a major incident. Has anyone actually exercised this notification process yet?

0 contributions0 responses0 challenges
Helpful answer pending

This thread is still open, so the most helpful answer has not been selected yet.

Responses

Direct answers and proposed approaches

0 total
No responses yet.
Challenges

Risks, gaps, and constructive pushback

0 total
No challenges yet.