January 2025 marks the deadline for financial firms in the EU to comply with DORA requirements. Are you ready?
By January 2025, enterprises in the finance sector must strengthen their operational resilience in information and communication technology (ICT). This includes addressing the risks introduced by third-party providers that deliver digital services in your sourcing ecosystem. In just a few short weeks, the Digital Operational Resilience Act (DORA) will be law.
As we’ve been covering for more than a year, DORA is a standardized framework with broad-reaching regulations that apply across EU member states, including requirements for internal ICT risk management policies, incident reporting, third-party risk management, digital resilience testing and more. And for ICT services supporting critical functions, DORA specifies additional requirements, such as key provisions in contractual agreements with third-party service providers and stricter IT security.
What are the key contractual provisions for third parties in DORA? Financial services firms are increasingly outsourcing and integrating external partners into their ecosystems; DORA lays out contractual provisions precisely for managing this kind of risk.
Figure 1: Overview of Requirements for Contractual Arrangements on the Use of ICT Services
Financial entities need to approach DORA compliance in a structured way and assess the degree to which they are meeting or not meeting requirements in existing contracts. ISG leverages a three-step approach to support clients.
Please fill out this form to continue.