Resources Book a Demo
European Union · DORA

DORA ICT Third-Party Risk, Built Into Your Workflow.

RegAhead operationalises the Digital Operational Resilience Act's ICT third-party risk requirements — Articles 28 to 44 — turning the Register of Information, Article 30 contractual obligations, concentration risk, and sub-outsourcing controls into a live, audit-ready workflow inside PartnerHub.

2022/2554Regulation (EU)
17 Jan 25Fully applicable
Art 28–44ICT third-party risk
5Resilience pillars

Key takeaways

  • Operationalises DORA ICT third-party risk (Chapter V, Articles 28–44).
  • Maintains the Register of Information and maps Article 30 contractual provisions.
  • Analyses concentration risk and sub-outsourcing exposure.
  • DORA has been fully applicable since 17 January 2025.
The Mandate

What DORA Requires — and Where Third-Party Risk Sits

The Digital Operational Resilience Act — Regulation (EU) 2022/2554 — has been fully applicable across EU financial services since 17 January 2025. It harmonises digital operational resilience across five pillars: ICT risk management, ICT-related incident reporting, digital operational resilience testing, ICT third-party risk management, and information sharing.

It applies to more than 20 categories of financial entities — banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and more — and, critically, extends to their ICT third-party service providers.

ICT Third-Party Risk · Chapter V
  • Articles 28–30 (Section I): management of ICT third-party risk, the Register of Information, pre-contractual assessment, and mandatory contractual provisions (Article 30)
  • Articles 31–44 (Section II): EU oversight of Critical ICT Third-Party Providers (CTPPs) — designation, Lead Overseer, and supervisory powers
  • Concentration-risk analysis and sub-outsourcing controls
  • Supervisory access and resilience testing alignment
From Regulation to Monitored Control

How RegAhead Maps to DORA

DORA RequirementHow RegAhead Operationalises ItModule
Register of Information (Art. 28)Maintained ICT third-party register with provider, function, criticality and contractual metadata — examination-readyPartnerHub
Pre-contractual assessment & due diligence (Art. 28–29)AI-led due diligence, materiality tiering, and risk assessment before commercial commitmentPartnerHub
Contractual provisions (Art. 30)Contract-clause mapping and document analysis confirming SLA, security, data-protection, audit and exit termsPartnerHub
Concentration risk (Art. 29)Automated concentration-exposure analysis against thresholds across the ICT provider estatePartnerHub
Sub-outsourcing chainsFourth-party / sub-outsourcing tracking with dependency mapping and monitoringPartnerHub
Supervisory & oversight access (Art. 31–44)Auditor / supervisor read-only views and clause-traceable evidence for the Lead Overseer regimePartnerHub
Regulatory change (RTS / ITS)RegWatch ingests EBA/EC technical standards and flags affected controls automaticallyRegWatch
Group-level ICT governanceConsolidated DORA posture and concentration aggregation across the financial conglomerateReGroup

Primary sources: Regulation (EU) 2022/2554 on EUR-Lex and the European Supervisory Authorities (e.g. eba.europa.eu). This page is an implementation reference, not legal advice.

Frequently Asked Questions — DORA

DORA Compliance, Answered

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) is an EU regulation that has been fully applicable since 17 January 2025. It establishes a harmonised framework for the digital operational resilience of financial entities across five pillars: ICT risk management, ICT-related incident reporting, digital operational resilience testing, ICT third-party risk management, and information sharing. It applies to 20+ categories of financial entities and to their ICT third-party service providers.
Articles 28–44 (Chapter V) govern ICT third-party risk. Section I (Articles 28–30) covers management of ICT third-party risk — including maintaining a Register of Information of all ICT third-party arrangements and mandatory contractual provisions under Article 30. Section II (Articles 31–44) establishes the EU oversight framework for Critical ICT Third-Party Providers (CTPPs), including their designation and a Lead Overseer with supervisory powers.
The Register of Information (RoI) is a structured record of all of a financial entity's ICT third-party arrangements. It serves as an internal tool to monitor ICT third-party risk, as a source of information for competent authorities to supervise that risk, and as the basis for the European Supervisory Authorities to designate Critical ICT Third-Party Providers for oversight.
RegAhead's PartnerHub operationalises DORA's ICT third-party risk requirements (Articles 28–44): maintaining the ICT third-party register, mapping Article 30 contractual obligations, performing concentration-risk analysis, managing sub-outsourcing exposure, and supporting supervisory access. ReGroup extends DORA coverage to group-level ICT governance for financial conglomerates operating across EU jurisdictions.
Book a Regulator-Readiness Demo

Ready to Convert Regulatory Complexity into Competitive Advantage?

A 30-minute working session with a RegAhead risk-intelligence specialist — tailored to your jurisdiction and operating model. No obligation.

Your data stays in your perimeter — before, during, and after your RegAhead deployment.