DORA: ICT Third-Party Risk Management and Operational Resilience

DORA gestione rischio fornitori ICT e resilienza operativa

The Digital Operational Resilience Act (DORA) extends the operational resilience management of financial entities beyond their internal infrastructure, including third-party ICT providers and the entire supply chain in the assessment, with a particular focus on operational continuity and third-party ICT services that support vital business functions.

DORA testing and external dependencies

DORA establishes that any disruptions at critical providers can generate systemic crises capable of threatening the stability of the financial sector. Financial entities retain ultimate responsibility for compliance and risk management, even for outsourced operations. Resilience testing programs are therefore extended to external dependencies to ensure the endurance and recovery of services, even in the event of incidents affecting technology partners.

Critical or important functions supported by third parties

ICT providers that support critical or important functions (CIFs) are subject to particularly rigorous monitoring and testing requirements. Financial entities are required to:

  • Explicitly identify in the register of information which assets and providers support critical or important functions.
  • Assess the potential impact of a provider failure on operational resilience and service continuity.
  • Include the “live” systems of providers supporting CIFs within the scope of advanced testing (TLPT).

Due diligence, contractual clauses, and vulnerability handling

DORA’s ICT third-party risk management is structured across the entire lifecycle of the relationship with the provider:

  • Due Diligence: Before contracting a provider for a critical or important function, it is necessary to evaluate their reputation, technical and financial resources, and information security standards.
  • Contractual Clauses: Contracts must detail the services, establish expected Service Level Agreements (SLAs), and provide for rights of access, inspection, and audit.
  • Vulnerability Handling: Providers are required to manage vulnerabilities related to the services provided, analyze their root causes, and promptly report critical risks to the financial entity.

Auditability and register of information

All financial entities must maintain an up-to-date Register of Information (RoI) that lists every contractual agreement with third-party ICT providers. This register:

  • Provides competent authorities with an overview of technological dependencies and concentration risks.
  • Enables traceability of the subcontracting chain, identifying material subcontractors involved in critical or important functions.
  • Allows the entity to exercise audit and testing rights along the entire technological value chain.

Common mistakes with cloud and MSPs

  • Low bargaining power: Entities often struggle to impose custom testing clauses on large Cloud Service Providers, but DORA requires that such clauses be present during the contracting phase.
  • Lack of visibility into subcontractors: Limiting monitoring to the direct provider is a mistake; it is necessary to obtain visibility into subcontractors and their actual participation in critical services.
  • Confusion over responsibilities: Outsourcing does not entail a total delegation of responsibility; the entity must ensure that the provider’s security measures are aligned with its own policies.

FAQ

  • Can we request VA/PT evidence from providers?
  • Yes. Financial entities hold the contractual right to request audit reports, third-party security certifications (such as ISO or SOC), or the results of tests conducted by the provider to validate system security.
  • Does DORA require audits for all providers?
  • All providers must be included in the risk strategy, but independent audits and in-depth verifications are mandatory exclusively for ICT services that support critical or important functions.
  • How should subcontractors be managed?
  • The contract with the direct provider must ensure that critical subcontractors grant the same rights of access, inspection, and audit, and participate in operational resilience testing where required.

Third-party testing readiness assessment

Do not leave blind spots in your resilience: request a Third-party testing readiness assessment today to map your critical providers and validate your audit and testing rights according to DORA.

Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.

Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.

Already know what you need? Explore our services:

And much more. Protect your company with the best cybersecurity experts!