DORA turns vendor risk policy into a legal must-have

DORA

The Digital Operational Resilience Act has turned third party risk management from a best-practice exercise into a hard compliance requirement, with Article 28 setting out precisely how financial entities must classify, assess and monitor the vendors and ICT providers they rely on.

According to Copla, a policy alone is not enough. Applying it, tracking assessments, chasing evidence and keeping the vendor register current is separate, ongoing work, typically run through automated risk management tools rather than a shared drive or spreadsheet.

Under Article 28, the policy must define how vendors are classified as supporting a critical or important function, maintain a register of information structured to fixed regulatory templates, run pre-contractual due diligence on security and financial stability, assess concentration risk across providers, document a tested exit strategy for critical arrangements, and undergo at least an annual review by the management body.

Classifying vendors without a dedicated team is one of the harder practical challenges. Rather than the three-to-five tier models built for organisations with a risk committee and full security function, two tiers, critical/important and everything else, usually suffice for smaller entities managing 30 to 80 vendors.

Classification should be based on what a vendor can actually access and what would break if it failed, not on how the vendor describes its own service.

Article 30 sets out mandatory contract terms rather than leaving them to negotiation. These include audit and access rights, clarity on data location and any transfers outside the EU, quantitative service levels, advance notice of sub-outsourcing, a duty to cooperate with authorities during incidents, and defined termination and exit rights with a workable transition period.

Where third party risk most often slips through is in application rather than drafting. Treating vendor questionnaire answers as proof rather than a starting point, under-classifying vendors whose access footprint grows over time, and leaving policies unrevisited between scheduled reviews are recurring gaps.

A support tool given read access to transaction history 18 months after onboarding, without its classification being rerun, is a typical example of how exposure quietly expands.

A policy, a register entry and a signed contract describe a single point in time. None of them update automatically when a vendor’s access scope grows, a certification lapses, or a contract renewal approaches without a scheduled reassessment. Closing that gap requires keeping classification, contract and register connected and reviewed on a cadence tied to each vendor’s risk tier, not the calendar quarter.

Copla’s full post can be read here. 

Read the daily FinTech news

Copyright © 2026 FinTech Global

Enjoying the stories?

Subscribe to our daily FinTech newsletter and get the latest industry news & research

Investors

The following investor(s) were tagged in this article.