DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554)
Reaches every ICT service agreement with a financial entity in the EU or EEA (banks, credit unions, insurers, reinsurers, pension funds, asset managers, payments and investment firms): the register of information and pre-contract assessment of Art. 28, the key contractual provisions of Art. 30 (service description, data locations, security, incident assistance, audit and access, termination and exit), and the major-incident reporting of Art. 19 that drives the customer's clock.
On the register, tick "DORA" (every regime is ticked by default) and these rows attach where the customer's sector and country reach it. Source framework: DORA (Regulation (EU) 2022/2554).
What it expects, term by term
| DORA terms | Art. 28 · Art. 30On an ICT service arrangement |
|---|---|
| audit right | Art. 30On an ICT service arrangement, or where processor terms are expected |
| breach clock | Art. 19On an ICT service arrangement with a financial entity |
| exit and return of data | Art. 30On an ICT service arrangement, or where processor terms are expected |
The Art. 30 terms and the clock
An ICT service to a financial entity in the EU or EEA opens two boxes beyond the privacy ones: DORA terms (a DORA schedule, the Art. 30 provisions or an ICT addendum named on the row) and the audit right Art. 30 lists among them. Art. 19 is why the customer asks for a breach clock in hours: it reports major ICT-related incidents to its authority within prescribed timelines. A row with no DORA terms named raises the finding "financial-entity customer with no DORA or CPS 230 terms shown".
The clauses, quoted
3Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.
DORA Art. 19 Reporting of major ICT-related incidentsFinancial entities shall report major ICT-related incidents to the relevant competent authority within the prescribed timelines using initial, intermediate and final notifications, and may notify significant cyber threats on a voluntary basis.
Where it usually falls short: Late or missing major-incident reporting
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library
DORA Art. 28 ICT third-party risk: general principlesFinancial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangements (including concentration and subcontracting), and adopt an ICT third-party risk strategy.
Where it usually falls short: No Register of Information
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library
DORA Art. 30 Key contractual provisionsContractual arrangements for the use of ICT services shall include the mandatory key contractual provisions (e.g. clear service descriptions, locations of data processing, data protection, accessibility/availability/integrity/security, assistance on incidents, audit and access rights, termination rights and exit strategies), with enhanced provisions for services supporting critical or important functions.
Where it usually falls short: Contracts missing audit/access, termination or exit provisions
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library
See what it expects of your list
Paste the list of customer agreements and every row this regime reaches carries these terms, ticked or open. Eight agreements free, no account.
Check my contract list