Chapter V: Managing of ICT third-party risk (Articles 28-44)
How DORAedge enables compliance with DORA
Article 28.1: General Principles for Managing ICT Third-Party Risk
Article 28.2: ICT Third-Party Risk Strategy
Article 28.3: Register of ICT Third-Party Contracts
Article 28.4: Pre-Contractual Assessment
Article 28.5: Information Security Standards
Article 28.6 : Audit Rights
Article 28.7: Termination of ICT Contracts
Article 28.8: Exit Strategies
Article 29: Preliminary Assessment of ICT Concentration Risk
Article 30: Key Contractual Provisions
Article 31–44: Oversight of Critical ICT Third-Party Providers
Article 31: Designation of Critical ICT Third-Party Providers (Relevant to ESAs)
Article 32: Structure of the Oversight Framework (Relevant to ESAs)
Article 33–35: Powers and Tasks of the Lead Overseer (Relevant to ESAs)
Article 36–37: Oversight and Inspections (Relevant to ESAs)
Article 38–40: General Investigations, Inspections, and Ongoing Oversight (Relevant to ESAs)
Article 41: Harmonization of Oversight Conditions (Relevant to ESAs)
Article 42–43: Follow-Up and Fees for Oversight (Relevant to ESAs)
Article 44: International Cooperation (Relevant to ESAs)
PreviousChapter IV: Digital Operational Resilience Testing (Articles 24-27)NextChapter VI: Information-sharing Arrangements (Article 45)
Last updated