DORA ICT Supplier Requirements: a practical overview for financial entities

The register, the mandatory contract clauses, concentration risk, and what an exit strategy actually contains.

Regulatory Frameworks 9 min read

What is it?

DORA — the Digital Operational Resilience Act — is EU regulation that applies to financial entities and their ICT third-party service providers. It codifies expectations for how financial firms manage the operational risk arising from ICT suppliers, and it establishes direct oversight of the most critical ICT third-party providers.

Why does it matter?

DORA raises the bar for ICT supplier oversight in financial services in three ways:

  1. Register of ICT providers — every in-scope firm must maintain a detailed, standardised register.
  2. Contractual requirements — specific clauses are mandatory in ICT service contracts.
  3. Concentration risk — firms must actively manage dependence on individual providers.

Failure is a regulated matter. This is not "recommended practice"; it is enforceable law within the EU financial sector.

Common challenges

  • Existing supplier registers do not capture the fields DORA requires.
  • Contracts pre-DORA lack the mandatory clauses; renegotiation is time-consuming and often contested.
  • Critical ICT providers may push back on audit rights, exit assistance and sub-outsourcing controls.
  • Threat-led penetration testing (TLPT) requirements need coordinated planning with providers.

Best practice

For each ICT third-party arrangement, in-scope firms should:

  1. Classify the arrangement — is it supporting a critical or important function?
  2. Record it in the DORA register in the mandated format.
  3. Verify the contract contains the required provisions (service description, data location, exit strategy, audit rights, sub-outsourcing controls, security levels).
  4. Assess the provider's operational resilience with evidence — not just questionnaires.
  5. Plan for exit — a documented, tested strategy for moving away if the arrangement fails.
  6. Review at defined intervals; reclassify when the function or the provider changes.

How Governly supports this area

The evidence-based assessment workflow supports the verification step — checking provider capability against a defined requirement set. DORA-specific requirement sets can be added to a customer's workspace; the resulting assessment is versioned and auditable, which matches DORA's expectations for defensible records.

Put this into practice

Governly applies the Requirements-to-Evidence Mapping methodology to your own vendors. Start from the Recommended Enterprise Baseline, upload your own requirements, or build from scratch — then add the vendor documents and receive a traceable due diligence report.