The Third-Party Risk Landscape Under DORA
No financial entity runs its own technology alone. Cloud platforms, software vendors, data centres, managed services — the modern entity is a web of dependencies. Pillar 4 governs that web.
Why third-party risk earns its own pillar
DORA dedicates Art. 28–44 — seventeen articles — to ICT third-party risk for two reasons. First, a provider failure can stop a financial entity as completely as an internal one: when the cloud goes down, so does the bank. Second, some providers are now so embedded across the EU financial system that their failure would be a systemic event, not a single-firm problem. No earlier EU regime supervised technology providers directly; DORA does.
The expert’s remit
Map
Know every ICT dependency and the critical functions each one supports.
Govern
Maintain the Register of Information, Article 30 contracts and pre-contract due diligence.
Monitor
Track performance, sub-outsourcing, concentration and exit-readiness across the contract life.
"ICT services" is deliberately broad
DORA does not use the narrow, traditional notion of "outsourcing". It regulates the use of ICT services in the round. A SaaS subscription, an API data feed, a cloud tenancy, a managed-security service — all are ICT third-party arrangements in scope, even those a lawyer would never have called outsourcing. The expert’s first instinct must be inclusive: if technology is being consumed from a third party, assume it is in scope until proven otherwise.
That was your free preview
Enrol to unlock all 23 lessons, every knowledge check, the dedicated certification exam, the downloadable toolkit and your verifiable certificate — lifetime access.
Secure payment via Stripe · 30-day money-back guarantee.