Regulated Customer Contract Checker
Standards ยท DORA

DORA (Regulation (EU) 2022/2554)

Rendered when "DORA" is ticked and the customer reaches it. The register cites 3 of its 26 clauses, behind 4 findings: breach-notice clocks that disagree, financial-entity customer with no dora or cps 230 terms shown, audit rights granted, duplicate agreement, and on the rows it reaches.

Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so. Source framework: DORA (Regulation (EU) 2022/2554). What it expects of an agreement: the DORA regime page.

Clauses cited

3 of 26
DORA Art. 19 Reporting of major ICT-related incidents

Financial entities shall report major ICT-related incidents to the relevant competent authority within the prescribed timelines using initial, intermediate and final notifications, and may notify significant cyber threats on a voluntary basis.

Evidence an auditor accepts: Major-incident reports (initial/intermediate/final) submitted to the competent authority within the deadlines
Where it usually falls short: Late or missing major-incident reporting
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library
DORA Art. 28 ICT third-party risk: general principles

Financial entities shall manage ICT third-party risk as an integral component of ICT risk, maintain a Register of Information on all contractual arrangements for the use of ICT services, report it to competent authorities, assess risk before entering arrangements (including concentration and subcontracting), and adopt an ICT third-party risk strategy.

Evidence an auditor accepts: A Register of Information of ICT third-party arrangements reported to the competent authority; Pre-contract risk assessment records
Where it usually falls short: No Register of Information
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library
DORA Art. 30 Key contractual provisions

Contractual arrangements for the use of ICT services shall include the mandatory key contractual provisions (e.g. clear service descriptions, locations of data processing, data protection, accessibility/availability/integrity/security, assistance on incidents, audit and access rights, termination rights and exit strategies), with enhanced provisions for services supporting critical or important functions.

Evidence an auditor accepts: ICT contracts containing the mandatory key provisions (audit/access, termination, exit, security); Enhanced provisions for critical/important-function services
Where it usually falls short: Contracts missing audit/access, termination or exit provisions
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library

See which clauses your list engages

Paste the list of customer agreements and every row names the clauses behind it. Eight agreements free, no account.

Check my contract list