Assess your ICT vendor risks according to DORA. Profile a provider across criticality, security, jurisdiction and contract governance — and get an instant risk score with recommendations.
The score sums four risk dimensions. A higher total means higher risk. It is indicative and aligned with DORA Articles 28-30 and the RTS on subcontracting.
Basis: DORA Art. 28 (TPRM), Art. 29 (concentration), Art. 30 (contractual provisions).
Free tools that pick up where this one stops.
The Third-Party Risk Playbook: the Article 30 clause library, Register of Information build guide, provider scoring matrix and exit playbooks.
We will send your results and the 75-control DORA compliance checklist to your work inbox. Unsubscribe anytime.
Workbooks, playbooks and certifications built for EU financial entities. Add several to your cart: volume discounts apply automatically.
Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.