Expertise Technical assistanceProject managementCustom solutions Industries BankingInsuranceFinance Approach Commitments Insights About Join Pronaxis
Contact us Français

DORA: what the regulation changes for your IT providers

Register of information, contractual clauses, critical functions: what DORA requires of your ICT provider relationships and what to ask them.

Pronaxis9 October 20265 min read

Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, known as DORA, has applied since 17 January 2025. It covers banks, insurance and reinsurance undertakings, investment firms, asset managers and many other financial entities.

DORA addresses five areas: information and communication technology (ICT) risk management, incident reporting, resilience testing, ICT third-party risk management and information sharing. This article focuses on the fourth area, the one that most directly changes the relationship between an IT department and its providers.

The principle: the financial entity remains responsible

The regulation sets a simple principle. A financial entity that uses an ICT service provider remains fully responsible for complying with its obligations. Outsourcing a service does not transfer the risk.

In practice, this leads to several requirements. The entity must define a strategy for third-party risk, assess that risk before contracting, monitor the relationship throughout its life and plan the conditions for exit.

The register of information

DORA requires every financial entity to maintain a register of information listing all contractual arrangements for ICT services provided by third parties. The register is kept at entity level and, where relevant, at sub-consolidated and consolidated levels.

The register identifies the arrangements that support critical or important functions. It must be made available to the competent authority on request. Standardised templates have been set at European level, which is why the information requested from providers is now more structured than before.

For a provider, this means its client will ask for precise details: identification of the company (a Legal Entity Identifier, or LEI, may be required), the nature of the service, where the service is provided and where data is processed, and any use of subcontractors.

Critical or important functions

The regulation defines a critical or important function as one whose disruption would materially impair the entity’s financial performance, the soundness or continuity of its services, or its compliance with regulatory obligations.

This qualification belongs to the financial entity. It has direct consequences for the contract: requirements are heavier when the ICT service supports such a function.

The qualification does not depend on the size of the provider. A service that is modest in volume can support a critical function, and a large contract can cover a function that is not critical.

The expected contractual clauses

Article 30 of the regulation lists the provisions every ICT services contract must contain. Among them:

  • a clear and complete description of the services;
  • the locations where services are provided and where data is processed;
  • provisions on the availability, authenticity, integrity and confidentiality of data;
  • access to, recovery and return of data if the contract ends or the provider fails;
  • assistance in the event of an ICT incident related to the service;
  • cooperation with competent authorities;
  • termination rights and notice periods;
  • the provider’s participation in the security awareness programmes defined by the entity.

When the service supports a critical or important function, the contract must also include detailed and measurable service levels, notification obligations, tested contingency plans, unrestricted rights of access, inspection and audit, and an exit strategy with a transition period.

Consulting and technical assistance

The question comes up often: does a technical assistance engagement, where a consultant works inside the IT department’s teams, fall under DORA?

The regulation targets ICT services, which it defines broadly. The answer depends on the actual nature of the service and on the financial entity’s own analysis. Many entities choose to record these engagements in their register and to apply the Article 30 clauses, at least in their basic form. For a provider, the sensible approach is to prepare for it.

What a buyer can now ask a consulting firm

In our engagements and in our supplier onboarding processes, we recommend that purchasing teams and IT departments ask precise questions. These are the ones we find useful.

Identity and organisation

  • Which legal entity is contracting, and does it have an LEI?
  • Does the provider use subcontractors or independent consultants? Which ones, and for which tasks?

Data and location

  • Where do the consultants work, and on which equipment?
  • Can client data leave the client’s environment? If so, where does it go and how is it protected?

Security and incidents

  • What security measures does the provider apply to its own tools?
  • How, and how quickly, does it inform the client of an incident?
  • Will the consultants follow the client’s security training?

Continuity and exit

  • How is knowledge documented and handed over during the engagement?
  • What happens if a consultant leaves or the contract ends early?
  • Does the provider accept the audit rights set out in the contract?

A serious provider should be able to answer these questions in writing, promptly and without generic wording.

What this changes in the relationship

DORA makes explicit what was often a matter of good practice: know your providers, document what they do, know where the data sits and prepare the exit from the start. For an IT department, this is additional work. It is also an opportunity to clarify relationships that are sometimes long-standing and loosely formalised.

For providers, transparency becomes a condition for working in the financial sector. Firms that can quickly supply reliable information and sign compliant clauses make their clients’ work easier.

This article sets out the general framework of the regulation. It does not replace the analysis of your legal and compliance teams, who remain best placed to qualify your contracts and functions.

All insights Français

A project, a team to reinforce, a question?

Tell us what you need. Our management team will reply.