Regulated Customer Contract Checker
Regimes · DORA

DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554)

Reaches every ICT service agreement with a financial entity in the EU or EEA (banks, credit unions, insurers, reinsurers, pension funds, asset managers, payments and investment firms): the register of information and pre-contract assessment of Art. 28, the key contractual provisions of Art. 30 (service description, data locations, security, incident assistance, audit and access, termination and exit), and the major-incident reporting of Art. 19 that drives the customer's clock.

On the register, tick "DORA" (every regime is ticked by default) and these rows attach where the customer's sector and country reach it. Source framework: DORA (Regulation (EU) 2022/2554).

What it expects, term by term

DORA termsArt. 28 · Art. 30On an ICT service arrangement
audit rightArt. 30On an ICT service arrangement, or where processor terms are expected
breach clockArt. 19On an ICT service arrangement with a financial entity
exit and return of dataArt. 30On an ICT service arrangement, or where processor terms are expected

The Art. 30 terms and the clock

An ICT service to a financial entity in the EU or EEA opens two boxes beyond the privacy ones: DORA terms (a DORA schedule, the Art. 30 provisions or an ICT addendum named on the row) and the audit right Art. 30 lists among them. Art. 19 is why the customer asks for a breach clock in hours: it reports major ICT-related incidents to its authority within prescribed timelines. A row with no DORA terms named raises the finding "financial-entity customer with no DORA or CPS 230 terms shown".

The clauses, quoted

3

Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.

DORA Art. 19 Reporting of major ICT-related incidents

Financial entities shall report major ICT-related incidents to the relevant competent authority within the prescribed timelines using initial, intermediate and final notifications, and may notify significant cyber threats on a voluntary basis.

Evidence an auditor accepts: Major-incident reports (initial/intermediate/final) submitted to the competent authority within the deadlines
Where it usually falls short: Late or missing major-incident reporting
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library
DORA Art. 28 ICT third-party risk: general principles

Financial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangements (including concentration and subcontracting), and adopt an ICT third-party risk strategy.

Evidence an auditor accepts: A Register of Information of ICT third-party arrangements reported to the competent authority; Pre-contract risk assessment records
Where it usually falls short: No Register of Information
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library
DORA Art. 30 Key contractual provisions

Contractual arrangements for the use of ICT services shall include the mandatory key contractual provisions (e.g. clear service descriptions, locations of data processing, data protection, accessibility/availability/integrity/security, assistance on incidents, audit and access rights, termination rights and exit strategies), with enhanced provisions for services supporting critical or important functions.

Evidence an auditor accepts: ICT contracts containing the mandatory key provisions (audit/access, termination, exit, security); Enhanced provisions for critical/important-function services
Where it usually falls short: Contracts missing audit/access, termination or exit provisions
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library

See what it expects of your list

Paste the list of customer agreements and every row this regime reaches carries these terms, ticked or open. Eight agreements free, no account.

Check my contract list