DORA third-party risk: Article 30 clauses, register and exit strategies
Articles 28–44. Article 30 clause library with sample wording, Register of Information build guide, provider scoring matrix, exit playbooks by service type, hyperscaler negotiation playbook.
What this solves
Pillar 4 is the pillar that reaches outside your organisation, which is why it is the one that takes longest. Article 30 lists the clauses every ICT contract supporting a critical or important function must contain — and most existing contracts do not contain them, including the ones with providers who have no intention of renegotiating.
Alongside that sits the Register of Information, the exit strategy nobody has written, and the uncomfortable question of what you would actually do if a hyperscaler were unavailable for a week.
What is inside
- Article 30 12-clause library with sample wording
- Register of Information build guide + data-quality framework
- Provider scoring & criticality classification matrix
- Exit playbooks by service type (SaaS / IaaS / outsourcing)
- Negotiation playbook for hyperscalers
- 15 KRIs for third-party portfolio monitoring
- CTPP impact assessment template
What it covers in the regulation
- Articles 28–30 — managing ICT third-party risk
- Article 28(3) — the Register of Information
- Article 30 — key contractual provisions
- Articles 31–44 — oversight of critical ICT third-party providers
- ITS (EU) 2024/2956 — Register of Information templates
Who uses it, and when
Vendor management, procurement and legal teams, plus the ICT risk function that owns the concentration picture. Used during contract remediation — typically the longest workstream in a DORA programme.
How to work through it
- Classify which contracts support a critical or important function; only those carry the full Article 30 set.
- Use the clause library to draft the amendments, starting with the providers most likely to agree.
- Build the Register from the ITS templates as you go, not as a separate project afterwards.
- Score providers with the matrix so concentration is visible rather than anecdotal.
- Write the exit playbook for each service type — the plan is the deliverable, not the intention.