January 2025 marks the deadline for financial firms in the EU to comply with DORA requirements. Are you ready?
By January 2025, enterprises in the finance sector must strengthen their operational resilience in information and communication technology (ICT). This includes addressing the risks introduced by third-party providers that deliver digital services in your sourcing ecosystem. In just a few short weeks, the Digital Operational Resilience Act (DORA) will be law.
As we’ve been covering for more than a year, DORA is a standardized framework with broad-reaching regulations that apply across EU member states, including requirements for internal ICT risk management policies, incident reporting, third-party risk management, digital resilience testing and more. And for ICT services supporting critical functions, DORA specifies additional requirements, such as key provisions in contractual agreements with third-party service providers and stricter IT security.
What are the key contractual provisions for third parties in DORA? Financial services firms are increasingly outsourcing and integrating external partners into their ecosystems; DORA lays out contractual provisions precisely for managing this kind of risk.
Figure 1: Overview of Requirements for Contractual Arrangements on the Use of ICT Services
Financial entities need to approach DORA compliance in a structured way and assess the degree to which they are meeting or not meeting requirements in existing contracts. ISG leverages a three-step approach to support clients.
DORA Article 28.3 requires identification and documentation of all ICT services, as well as the definition of what it calls “critical and important functions.” This means mapping ICT services and suppliers to business functions. This is also required to meet the requirements specified in the draft Implementing Technical Standards (ITS) on the Register of Information.
Figure 2: Required Classifications to Determine DORA Compliance
There is not yet an official regulatory template or guideline for assessing the criticality of business functions. This means financial entities must define their own approach based on the definition of “critical and important function” provided in DORA article 3.22. The same applies to the process of identifying ICT services, which, according to DORA, are “digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services” (DORA article 3.21). Although the EU provides a list of types of ICT services in the draft ITS, it provides limited information about how to correctly classify services. As a starting point, financial entities may reference their implementations for similar existing regulations, i.e., the EBA guidelines on outsourcing arrangements. It is important to note that risk classification from previous regulations, i.e. the German MaRisk, cannot simply be translated to the DORA classification.
Assess outsourcing contracts based on ICT and criticality classification.
Once financial entities have classified their outsourced services, they can start to assess current compliance with DORA stipulations and identify required adaptations. This could involve potentially hundreds of contractual agreements with ICT third-party service providers, which requires significant planning and resources and typically results in a risk-based approach to focus on critical outsourcing arrangements first and dealing with the rest later.
ISG helps enterprises take the necessary steps toward DORA compliance. Our experienced advisors use proven methodologies and tools to:
Because becoming compliant with DORA requires a significant investment of time and effort, financial entities should think about how to generate additional value from the work. The goal should be an actionable risk framework rather than only a set of standard contract clauses. After all, IT operational resilience is the ultimate objective.
ISG recommends financial entities evaluate the following options for creating sustained value:
With the DORA compliance deadline approaching, it's crucial to act swiftly and methodically. ISG can help you prioritize your ICT contracts, develop comprehensive governance frameworks and ensure clear communication across your organization. For more detailed guidance on DORA compliance, get in touch with us