ICT Third Party Risk Management Under DORA

Financial entities rely on cloud platforms, software providers, managed services and data vendors. DORA establishes requirements for managing the risks arising from ICT third-party arrangements and creates EU oversight for providers designated as critical. The financial entity remains responsible for its own obligations.

Published 2026-09-09 | Updated 2026-09-09 | GoalTech Ltd

Outsourcing does not transfer accountability

The control lifecycle

The register of information should reflect this lifecycle, but it does not replace the underlying risk decisions.

  • Identify the business function, information and dependencies supported by the provider.
  • Assess risk and criticality before contracting.
  • Perform proportionate due diligence on security, resilience and subcontracting.
  • Include the required rights, obligations, access, audit, incident and exit provisions in contracts.
  • Monitor performance, incidents, changes and concentration throughout the relationship.
  • Maintain tested exit and transition arrangements for critical or important functions.

How GoalTech supports the process

GoalTech can review the third-party framework, develop assessment templates, map contracts, support register preparation and help control owners design monitoring and exit evidence. Legal advice may be needed for contractual interpretation or negotiation, and technical specialists may be needed for detailed security testing.

Request a consulting discussion

Request a consultation with GoalTech