Chapter V DORA
Chapter V of the EU Digital Operational Resilience Act (DORA) is the part of the regulation that deals with how financial organisations manage the risks arising from their information and communication technology (ICT) third-party service providers. It sets out principles for managing these relationships and also establishes an oversight framework for providers deemed critical to the financial sector. It is one of the pillars of DORA and focuses specifically on ICT-related third-party dependencies rather than all supplier risk.
Chapter V of DORA, titled 'Managing of ICT Third-Party Risk,' is organised into two sections. Section I sets out principle-based rules for the sound management of ICT third-party risk within a financial entity's ICT risk management framework, beginning with the general principles in Article 28. A subsequent section addresses the oversight framework for ICT third-party service providers designated as critical, introducing regulatory oversight practices for those providers. The Chapter's scope is confined to ICT-related third-party arrangements and does not, by its terms, govern non-ICT supplier, financial, or broader supply chain risk. As a direct third-party (TPRM) provision, its principle-based obligations attach to a financial entity's contractual ICT relationships; the extent to which subcontracting and Nth-party dependencies are addressed depends on the specific requirements elaborated within the Chapter and related DORA provisions. Applicability is jurisdiction-specific to the EU financial sector entities within DORA's scope.
Why it matters
For EU financial entities within DORA's scope, ICT third-party dependencies have become a defining source of operational risk. When core banking, payments, trading, or data-processing functions rely on external ICT service providers, a disruption at the provider can propagate directly into the financial entity's own operations. Chapter V matters because it moves management of these dependencies from a discretionary, contract-by-contract practice into a set of principle-based regulatory obligations embedded within a financial entity's ICT risk management framework, beginning with the general principles set out in Article 28.
Chapter V is also significant because it introduces an oversight framework for ICT third-party service providers designated as critical to the financial sector. This reflects a recognition that concentration among a limited number of large ICT providers can create systemic exposure that individual firms cannot fully manage through their own contracts alone. By establishing regulatory oversight practices for these designated providers, the Chapter addresses risk at a level above the bilateral relationship, though the designation and oversight mechanism apply specifically to those providers deemed critical, not to the full population of ICT vendors a firm uses.
It is important to keep the Chapter's scope in view. Chapter V is confined to ICT-related third-party arrangements; it does not, by its terms, govern non-ICT supplier relationships, financial or credit risk arising from third parties, or broader physical supply chain risk. Firms treating Chapter V compliance as equivalent to comprehensive third-party or supply chain risk management would be conflating a specific ICT-focused pillar with a much wider discipline.
Who it's relevant to
Inside Chapter V DORA
Common questions
Answers to the questions practitioners most commonly ask about Chapter V DORA.
