CyberFinance
ICT Third-Party Risk & Register of Information
The DORA register regulators actually ask for, and the contract terms behind it.
The situation
What the client receives
Schedule of deliverables
- Complete ICT third-party inventory and critical-or-important function mapping
- Register of Information built to the ITS reporting template
- Article 30 contractual gap analysis and remediation clauses
- Subcontracting chain mapping (fourth-party risk)
- Concentration risk analysis and exit strategy per critical provider
- Annual register submission support
Frameworks and standards
Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.
- DORA Ch. V
- Commission ITS on the Register of Information
- EBA outsourcing guidelines
- ISO/IEC 27036
Related services
Discuss this engagement
Tell us about the state of your register and the contracts behind it and we will set out the scope, the method and the reporting format.