DORA · ICT third-party risk management
Make DORA third-party oversight easier to evidence.
Assess suppliers, uncover shared dependencies and follow up security gaps. Bring the evidence behind your ICT third-party risk decisions into DORA reporting.
In this illustration, both providers rely on the same dependency. Its disruption could affect both routes. Your team assesses the business impact.
The regulatory context
Five pillars. A clear role for Risk Ledger.
DORA combines internal resilience obligations with ICT supplier oversight. Risk Ledger’s strongest fit is the supplier-assurance work within the fourth pillar, supported by trusted collaboration in the fifth.
1. ICT risk managementLimited supporting role
Articles 5–16 · Practical requirement
Management must oversee the internal ICT risk framework and its implementation.
How Risk Ledger fits
Supplier assessments can inform the third-party part of that framework. Risk Ledger does not operate your internal ICT governance or system inventory.
2. ICT-related incident reportingSupplier context
Articles 17–23 · Practical requirement
Classify incidents and notify major ICT-related incidents to the competent authority under the applicable rules.
How Risk Ledger fits
Supplier data, discussions and Emerging Threats provide context. They do not classify incidents under DORA or submit regulatory notifications.
3. Digital operational resilience testingSupplementary assurance
Articles 24–27 · Practical requirement
Operate the testing programme that applies to your entity. Designated entities must also undertake threat-led penetration testing (TLPT).
How Risk Ledger fits
External Monitoring adds outside-in supplier findings. It does not constitute your internal testing programme, TLPT or proof that Article 25 is satisfied.
4. ICT third-party risk managementPrimary fit
Articles 28–44 · Practical requirement
Assess ICT arrangements, maintain register information and manage supplier risk. Financial-entity requirements sit mainly in Articles 28–30; the wider chapter also establishes oversight of designated critical providers.
How Risk Ledger fits
Risk Ledger brings supplier assessments, policy-based review, dependency mapping and monitoring into your oversight. Contract terms, arrangement-level decisions and tested exit plans remain with your team.
5. Information sharingCollaboration support
Article 45 · Voluntary · Practical requirement
Share cyber threat information within trusted arrangements that protect sensitive information. Participation and departure trigger notification duties.
How Risk Ledger fits
Community features support peer exchange. Your organisation remains responsible for Article 45 safeguards and notifications; using a community does not by itself fulfil them.
Pillar 4 · ICT third-party risk
From regulatory obligation to practical oversight.
Build a clearer record of supplier risk, the action taken and the decisions that remain. This overview focuses on how the platform contributes to your process, rather than claiming complete coverage.
| DORA requirement | How Risk Ledger supports it | What your team still owns |
|---|---|---|
| Maintain a Register of InformationRecord ICT contractual arrangements using the prescribed ITS structure. | Filter and export supplier assessment data from the Supply Chain Data Table. CSV exports and the API can provide source data for your wider register workflow.Supply Chain Data Table | You still need contract, service and entity data, mapping to the required templates and validation. The supplier table is not a complete RoI. |
| Assess criticality and perform due diligenceDetermine whether an arrangement supports a critical or important function before contracting, then apply proportionate due diligence. | Use supplier-level criticality, confidentiality and PII labels with stacked policies to tailor security requirements and review assessment evidence.Supplier policies | Supplier labels help prioritise assurance. Your team makes and documents the DORA classification for the function and arrangement. |
| Investigate concentration and subcontracting riskAssess concentration, substitutability and relevant subcontracting exposure. | Use Network Visualisation and Concentration Risk tracking to investigate known fourth-, fifth- and sixth-party dependencies.Concentration Risk tracking | Network evidence informs your analysis; it does not prove complete chain coverage or replace service-impact and substitutability assessments. |
| Monitor supplier risk through the relationshipReview relevant ICT supplier risk and respond to changes, especially where critical or important functions are supported. | Combine reassessments and remediation tracking with the paid External Monitoring add-on for outside-in security findings alongside supplier answers.External Monitoring for Clients | Use findings and follow-up records in oversight reporting. Scanning covers observable exposure, not every supplier control. |
| Coordinate oversight across a groupMaintain appropriate individual and group-level oversight and register information where required. | Federated Network supports group visibility, central supplier management, shared assurance and standardised policies across sub-entities. | Your group retains the legal entity structure, responsibilities and completeness checks needed for DORA reporting. |
| Set contractual terms and plan exitInclude applicable security, service, audit and termination provisions; maintain and test exit strategies for relevant arrangements. | Use supplier findings and concentration-risk information to inform contract discussions and exit decisions. | Legal contract management and dedicated exit planning are outside this page’s platform scope. Those terms and plans must be created, maintained and tested separately. |
Platform compliance scores describe supplier responses against your policies. They are not legal determinations of DORA compliance. Capability availability and monitoring scope depend on your configuration and subscription.
Continuous supplier assurance
Put external findings beside supplier answers.
External Monitoring is a paid add-on that complements self-reported assessment data with outside-in checks. Use the findings to inform questions, investigations and follow-up.
What External Monitoring checks
- Web security configuration, including TLS and security headers
- Email authentication, including SPF, DKIM and DMARC
- DNS configuration and exposed ports
Severity-rated findings appear alongside relevant supplier assessment answers.
Explore External MonitoringHow to use the evidence
Compare observed findings with supplier responses, investigate discrepancies and follow remediation progress. Bring the resulting evidence into your ongoing supplier-risk review.
Outside-in findings are one assurance input. They do not verify every control or replace DORA testing, independent audits or TLPT.
Reporting in practice
Show the evidence behind the decision.
Gather the supplier context
Use the Supply Chain Data Table to filter supplier information and export relevant assessment data for review.
Explain the action taken
Bring assessment findings, external observations and remediation records together with your own review decisions.
Feed the wider reporting process
Use CSV exports and the API as inputs to management reporting and your register workflow. Add the contractual and entity information that sits outside supplier assessments.
Pillar 5 · Voluntary information sharing
See what isolated supplier reviews can miss.
Risk Ledger’s Community features support peer discussions and shared signals. Organisations participating in Article 45 arrangements remain responsible for confidentiality safeguards and notifications to their competent authority.
Collaboration in financial services
The FS-ISAC collaboration study highlighted in Risk Ledger’s research shows the value of looking across institutions. The published findings describe a pilot involving six financial institutions and the dependencies visible through their combined supplier networks.
These findings demonstrate the value of collective visibility. They are not evidence that participants fulfilled Article 45 or achieved DORA compliance.
Questions
Understand the scope of support.
Can Risk Ledger produce the complete DORA Register of Information?
Use the Supply Chain Data Table and API as sources for your register process. Supplier information still needs to be combined with contractual and service data, transformed into the prescribed structure and checked for completeness. This is not a native, validated RoI submission workflow.
Are supplier criticality labels the same as DORA classification?
No. They help organise supplier assurance and apply policies. DORA’s critical-or-important-function assessment concerns the function and the ICT arrangement. Your team makes that decision. A supplier you label critical is also not automatically a regulator-designated critical ICT third-party provider (CTPP).
Does External Monitoring satisfy DORA testing requirements?
It adds outside-in assurance on monitored suppliers and can inform risk review. It does not replace a financial entity’s risk-based testing programme or TLPT. Its contribution depends on your scope, methods and evidence requirements.
Does Emerging Threats classify or report major incidents under DORA?
No. It uses Risk Ledger’s own threat-selection criteria. It can help your team understand supplier exposure and follow up with suppliers, while DORA classification and competent-authority notifications remain separate.
Does joining a community fulfil Article 45?
No. Information sharing is voluntary. If you participate in an Article 45 arrangement, you remain responsible for its conditions, protection of sensitive information and the required notifications about participation or cessation.
Bring clarity to your DORA supplier oversight.
Explore assessments, network visibility, External Monitoring and reporting with the Risk Ledger team.
Book a demoFramework and platform references
- DORA: Regulation (EU) 2022/2554
- EIOPA: DORA and implementing provisions
- Supply Chain Data Table
- Supplier policies
- Risk Ledger API
- Concentration Risk tracking
- External Monitoring for Clients
- Emerging Threats criteria
- Monitoring and reporting
- Financial-services collaboration study
- FS-ISAC community on Risk Ledger