DORA also extends responsibility for digital resilience to relationships with ICT suppliers – and, crucially, does not allow this responsibility to be delegated. Even if a service is provided by an external cloud provider, SaaS provider or software house, the financial institution remains fully responsible for compliance. The fourth pillar of DORA (Articles 28–30) requires, amongst other things, a register of information on all contracts with ICT suppliers, an in-depth pre-contractual analysis, mandatory contractual clauses and an exit strategy. Below, we outline how to audit suppliers in practice in order to pass the supervisory review.
Why is this the most difficult pillar of DORA?
Third-party risk management is, according to the 2025–2026 supervisory assessments, the area with the highest proportion of compliance gaps and accounts for the lion’s share of the effort expended on DORA programmes. The reason is structural: over 60 per cent of the financial sector’s critical functions rely on external providers. Furthermore, DORA is clear on the issue of liability – the fact that a service is provided by a supplier does not diminish the institution’s obligations. The supplier’s conduct does not substitute for the financial institution’s compliance.
The information register – the cornerstone of the entire pillar
The starting point is the Register of Information, which is a structured list of all contracts with ICT suppliers. It contains the supplier’s identity, the services provided, the functions supported along with their criticality, data locations and the subcontracting chain. The template for the register is set out in the implementing standards, and the first submission of the register to the supervisory authorities was required as early as April 2025.
At the heart of the register lies the correct classification of critical or essential functions. It is this classification that determines which contracts require stricter clauses, fall under the subcontracting regulations, and are included in the scope of stress tests. An incorrect classification of critical functions means that the entire register is flawed – which is why this is where you must start.
Pre-contract analysis
DORA requires a documented risk analysis to be carried out before the contract is signed. Article 28 stipulates that an assessment must be made of, amongst other things, the substitutability of the supplier, the risk of its insolvency, compliance with data protection requirements, and the risks arising from the subcontractor chain. The risk of concentration must be assessed separately – namely, whether entering into a contract with a particular supplier makes the institution overly dependent on a single entity. The entire decision-making process must be documented, as this is what the supervisory authority or auditor will look for first.
Contractual clauses and subcontracting
Article 30 sets out mandatory contractual provisions, which are stricter for contracts supporting critical or essential functions. These relate, amongst other things, to access and audit rights, supervisory rights, service levels, the location of data processing, rules on subcontracting, and exit conditions. The rules on further subcontracting of services supporting critical functions are set out in more detail in a separate technical standard (RTS 2025/532). In practice, this means that contracts concluded prior to DORA often require amendments to comply with the requirements of Article 30 at all.
Critical suppliers and an exit strategy
The largest, systemically important ICT providers may be designated as critical (CTPP) and subject to direct supervision by European supervisory authorities. The first wave of such designations, in November 2025, covered a small group of providers, centred on the largest cloud infrastructure providers. Regardless of whether your provider is designated as critical, your institution must manage concentration risk and have a viable, tested contingency strategy – a plan for what will happen if you need to switch providers.
How to audit suppliers in practice
A proper supplier audit starts with a map, not a questionnaire. First, you need to classify critical functions and draw up a dependency map. Without this, the information register will be inaccurate.
The foundation is process inventory and the reconstruction of system documentation (S*. doc). These identify the external services that support key functions.
The next step is to review the agreements in light of Article 30. It is also necessary to assess the risk of concentration and test the exit plans. We bring it all together as part of DORA consulting. This ensures that the documentation is consistent and ready for an audit. doradztwa DORA. Dzięki temu dokumentacja jest spójna i gotowa na kontrolę.