Skip to main content
DORA Article 28-30 | Now Enforceable

Your ICT Vendors Are a Regulatory Time Bomb

DORA requires full visibility into your ICT supply chain — not just direct vendors, but their sub-contractors too. You need a platform that maps, monitors, and reports on the entire chain. In real time.

Regulatory Penalties

Up to 1% of average daily worldwide turnover for each day of non-compliance. Regulators can impose periodic penalty payments.

Personal Liability

Board members and senior management are directly responsible under Article 28(2). Individual accountability cannot be delegated.

ESA Reporting Deadline

Your Register of Information must be available to competent authorities on demand. Incomplete or inaccurate registers trigger immediate scrutiny.

Concentration Risk

Over-reliance on a single ICT provider is a systemic risk. Regulators can force you to diversify or limit new contracts with critical providers.

The Supply Chain Visibility Gap

Most financial institutions have hundreds of ICT providers — but almost no visibility beyond their direct vendors. DORA requires transparency over the entire chain, including sub-outsourcing arrangements. Spreadsheets and ad-hoc reviews can't map what you can't see. You need a tool that gives you real-time visibility into every layer of your ICT supply chain.

What Regulators Will Check

Complete ICT third-party provider register
Documented vendor tiering and criticality assessment
DORA-compliant contractual clauses in all ICT contracts
Exit strategies for every critical ICT provider
Concentration risk assessment and mitigation plan
Pre-contractual due diligence process
Ongoing monitoring and performance review program
Register of Information ready for ESA submission

DORA Third-Party Requirements: Article by Article

ICT Third-Party Register

Art. 28(3)

Maintain a complete, accurate register of all ICT third-party service arrangements at entity, sub-consolidated, and consolidated levels.

Pre-Contractual Due Diligence

Art. 28(4)

Conduct thorough risk assessment before entering ICT service arrangements, including ability to comply with DORA requirements.

Contractual Requirements

Art. 30

All ICT contracts must include specific clauses on security, audit rights, data location, incident notification, and exit provisions.

Concentration Risk

Art. 29

Assess and mitigate risks from over-reliance on single ICT providers. Consider substitutability and systemic impact.

Exit Strategy Planning

Art. 28(8)

Develop and maintain exit strategies for all critical ICT providers, ensuring business continuity during transition.

Ongoing Monitoring

Art. 28(2)

Implement continuous monitoring of ICT third-party performance, security, and compliance throughout the contract lifecycle.

Incident Management

Art. 31

Coordinate incident response with ICT third-party providers. Ensure timely notification and joint resolution processes.

Register of Information

Art. 28(3)

Prepare and maintain Register of Information (ROI) for submission to ESAs, covering all ICT third-party arrangements.

Sub-Outsourcing Transparency

Art. 28(7)/(8)

Ensure visibility into the full chain of ICT sub-outsourcing arrangements. Financial entities must identify and monitor sub-contractors of their direct providers.

The Auditbahn DORA Supply Chain Platform

Supply Chain Mapping

Core Module
  • Visualize the full ICT provider chain including sub-outsourcing layers
  • Auto-discover and map vendor-to-sub-contractor relationships
  • ICT provider tiering and criticality classification
  • Interactive dependency graph with drill-down capability
  • Import from existing registers, contracts, and vendor databases

Compliance Dashboard

Real-Time Monitoring
  • Track DORA Article 28-30 compliance status per provider
  • Concentration risk scoring with automated alerts
  • Contract clause compliance monitoring (Art. 30)
  • Exit strategy readiness tracking for critical providers
  • Board-level compliance overview and risk heatmaps

Reporting & Alerts

Automated Output
  • ESA-ready Register of Information generation
  • Automated alerts for risk threshold breaches
  • Regulatory submission-ready export formats
  • Periodic risk reassessment scheduling and tracking
  • Audit trail for all compliance activities

Who Needs DORA Supply Chain Compliance?

Banks & Credit Institutions

Commercial banks, savings banks, and cooperative banks with complex ICT vendor ecosystems.

Insurance & Reinsurance

Insurers and reinsurers managing third-party claims systems, underwriting platforms, and data providers.

Investment Firms & Asset Managers

Fund managers, trading venues, and investment firms dependent on market data and trading infrastructure.

Payment Service Providers

Payment processors, e-money institutions, and account information service providers with critical ICT dependencies.

Central Securities Depositories

CSDs and clearing houses managing settlement infrastructure and post-trade processing systems.

Crypto-Asset Service Providers

Exchanges, custody providers, and crypto platforms authorized under MiCA with ICT third-party exposure.

How It Works

1

Connect & Import

Import your existing ICT provider data from registers, contracts, and internal systems. No manual data entry required.

2

Map & Visualize

Auto-map the full supply chain including sub-outsourcing relationships. See your ICT dependencies in an interactive graph.

3

Assess & Monitor

Continuous concentration risk scoring, compliance gap tracking, and automated alerts when risk thresholds change.

4

Report & Export

Generate ESA-ready Register of Information, board dashboards, and regulatory submissions with one click.

Why the Auditbahn Platform

Built for DORA

Purpose-built for Articles 28-30. Every feature maps directly to a regulatory requirement — no generic GRC overhead.

Full Chain Visibility

Map sub-outsourcing relationships automatically. See beyond your direct vendors to the providers behind them.

Always Current

Real-time ESA-ready reporting, not one-off documents. Your Register of Information is always current and export-ready.

Financial Sector Focus

Designed specifically for EU financial institutions. Pre-configured for banking, insurance, and investment firm requirements.

DORA Enforcement Is Not Coming. It Is Here.

Every day without full visibility into your ICT supply chain increases your regulatory exposure. See how the Auditbahn platform maps your entire vendor ecosystem — including the sub-contractors you don't know about yet.

Hand Off Compliance. Keep Building.

Your compliance system is ready. Hand off vendor management, questionnaire responses, and regulatory compliance — and get back to building the product your customers are paying for.

Contact Us

Prefer to pick a time directly? Book a free intro call
100%
Audit Pass Rate
48hr
Vendor approval SLA
100%
Client retention