What is it?
DORA — the Digital Operational Resilience Act — is EU regulation that applies to financial entities and their ICT third-party service providers. It codifies expectations for how financial firms manage the operational risk arising from ICT suppliers, and it establishes direct oversight of the most critical ICT third-party providers.
Why does it matter?
DORA raises the bar for ICT supplier oversight in financial services in three ways:
- Register of ICT providers — every in-scope firm must maintain a detailed, standardised register.
- Contractual requirements — specific clauses are mandatory in ICT service contracts.
- Concentration risk — firms must actively manage dependence on individual providers.
Failure is a regulated matter. This is not "recommended practice"; it is enforceable law within the EU financial sector.
Common challenges
- Existing supplier registers do not capture the fields DORA requires.
- Contracts pre-DORA lack the mandatory clauses; renegotiation is time-consuming and often contested.
- Critical ICT providers may push back on audit rights, exit assistance and sub-outsourcing controls.
- Threat-led penetration testing (TLPT) requirements need coordinated planning with providers.
Best practice
For each ICT third-party arrangement, in-scope firms should:
- Classify the arrangement — is it supporting a critical or important function?
- Record it in the DORA register in the mandated format.
- Verify the contract contains the required provisions (service description, data location, exit strategy, audit rights, sub-outsourcing controls, security levels).
- Assess the provider's operational resilience with evidence — not just questionnaires.
- Plan for exit — a documented, tested strategy for moving away if the arrangement fails.
- Review at defined intervals; reclassify when the function or the provider changes.
How Governly supports this area
The evidence-based assessment workflow supports the verification step — checking provider capability against a defined requirement set. DORA-specific requirement sets can be added to a customer's workspace; the resulting assessment is versioned and auditable, which matches DORA's expectations for defensible records.