DORA's Third-Party Requirements Are More Demanding Than Most Compliance Teams Expected
The Digital Operational Resilience Act entered full application in January 2025. One year on, the requirements that financial entities are most struggling to operationalise are not the incident reporting timelines or the TLPT (Threat-Led Penetration Testing) requirements - they are the ICT third-party risk management provisions under Chapter V.
Article 28 requires financial entities to maintain a comprehensive register of all ICT third-party service providers, categorise them by risk, and conduct due diligence proportionate to that risk. Article 30 requires contractual protections, including provisions for monitoring, audit rights, and incident notification by the provider.
But the requirement that creates the most operational complexity is Article 29's mandate for a documented, ongoing 'ICT concentration risk' assessment - understanding and managing the systemic risk that arises when multiple critical functions depend on the same third-party provider.
For the institutions we work with, building a defensible, auditable third-party risk programme under DORA requires more than a register and some contracts. It requires verifiable evidence.
The ICT Third-Party Register: What It Must Contain
Article 28(3) requires financial entities to maintain a register of all contractual arrangements with ICT third-party service providers. The register must include:
- Service classification. Whether the provider supports critical or important functions (higher risk category) or non-critical functions.
- Due diligence documentation. Pre-contractual and ongoing due diligence performed, including security assessments, certifications reviewed, and findings.





