Templates

DORA third-party risk: Article 30 clauses, register and exit strategies

Articles 28–44. Article 30 clause library with sample wording, Register of Information build guide, provider scoring matrix, exit playbooks by service type, hyperscaler negotiation playbook.

€69 excl. VAT
PDF · 20 pages · one-time · instant download
Buy & download →

What this solves

Pillar 4 is the pillar that reaches outside your organisation, which is why it is the one that takes longest. Article 30 lists the clauses every ICT contract supporting a critical or important function must contain — and most existing contracts do not contain them, including the ones with providers who have no intention of renegotiating.

Alongside that sits the Register of Information, the exit strategy nobody has written, and the uncomfortable question of what you would actually do if a hyperscaler were unavailable for a week.

What is inside

  • Article 30 12-clause library with sample wording
  • Register of Information build guide + data-quality framework
  • Provider scoring & criticality classification matrix
  • Exit playbooks by service type (SaaS / IaaS / outsourcing)
  • Negotiation playbook for hyperscalers
  • 15 KRIs for third-party portfolio monitoring
  • CTPP impact assessment template

What it covers in the regulation

  • Articles 28–30 — managing ICT third-party risk
  • Article 28(3) — the Register of Information
  • Article 30 — key contractual provisions
  • Articles 31–44 — oversight of critical ICT third-party providers
  • ITS (EU) 2024/2956 — Register of Information templates

Who uses it, and when

Vendor management, procurement and legal teams, plus the ICT risk function that owns the concentration picture. Used during contract remediation — typically the longest workstream in a DORA programme.

How to work through it

  1. Classify which contracts support a critical or important function; only those carry the full Article 30 set.
  2. Use the clause library to draft the amendments, starting with the providers most likely to agree.
  3. Build the Register from the ITS templates as you go, not as a separate project afterwards.
  4. Score providers with the matrix so concentration is visible rather than anecdotal.
  5. Write the exit playbook for each service type — the plan is the deliverable, not the intention.

Questions

Does it include actual clause wording?

Yes — an Article 30 clause library with sample wording you can adapt, not a checklist of clause topics.

Does it help with the Register of Information?

It includes the build guide. To fill and validate the register itself, the Register of Information Builder does that interactively.

Does it deal with hyperscalers?

There is a dedicated negotiation playbook for providers that will not accept bespoke terms.

What do I receive?

A PDF by personal download link, right after checkout.

How Compliant Is Your Institution?

Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.

Get Your Free DORA Score Join Free Monthly Webinar