Skip to main content
Category: Regulatory Frameworks

Chapter V DORA

Also known as: DORA Chapter V, Managing of ICT Third-Party Risk (DORA), DORA ICT third-party risk pillar
Simply put

Chapter V of the EU Digital Operational Resilience Act (DORA) is the part of the regulation that deals with how financial organisations manage the risks arising from their information and communication technology (ICT) third-party service providers. It sets out principles for managing these relationships and also establishes an oversight framework for providers deemed critical to the financial sector. It is one of the pillars of DORA and focuses specifically on ICT-related third-party dependencies rather than all supplier risk.

Formal definition

Chapter V of DORA, titled 'Managing of ICT Third-Party Risk,' is organised into two sections. Section I sets out principle-based rules for the sound management of ICT third-party risk within a financial entity's ICT risk management framework, beginning with the general principles in Article 28. A subsequent section addresses the oversight framework for ICT third-party service providers designated as critical, introducing regulatory oversight practices for those providers. The Chapter's scope is confined to ICT-related third-party arrangements and does not, by its terms, govern non-ICT supplier, financial, or broader supply chain risk. As a direct third-party (TPRM) provision, its principle-based obligations attach to a financial entity's contractual ICT relationships; the extent to which subcontracting and Nth-party dependencies are addressed depends on the specific requirements elaborated within the Chapter and related DORA provisions. Applicability is jurisdiction-specific to the EU financial sector entities within DORA's scope.

Why it matters

For EU financial entities within DORA's scope, ICT third-party dependencies have become a defining source of operational risk. When core banking, payments, trading, or data-processing functions rely on external ICT service providers, a disruption at the provider can propagate directly into the financial entity's own operations. Chapter V matters because it moves management of these dependencies from a discretionary, contract-by-contract practice into a set of principle-based regulatory obligations embedded within a financial entity's ICT risk management framework, beginning with the general principles set out in Article 28.

Chapter V is also significant because it introduces an oversight framework for ICT third-party service providers designated as critical to the financial sector. This reflects a recognition that concentration among a limited number of large ICT providers can create systemic exposure that individual firms cannot fully manage through their own contracts alone. By establishing regulatory oversight practices for these designated providers, the Chapter addresses risk at a level above the bilateral relationship, though the designation and oversight mechanism apply specifically to those providers deemed critical, not to the full population of ICT vendors a firm uses.

It is important to keep the Chapter's scope in view. Chapter V is confined to ICT-related third-party arrangements; it does not, by its terms, govern non-ICT supplier relationships, financial or credit risk arising from third parties, or broader physical supply chain risk. Firms treating Chapter V compliance as equivalent to comprehensive third-party or supply chain risk management would be conflating a specific ICT-focused pillar with a much wider discipline.

Who it's relevant to

ICT third-party risk and vendor management teams at financial entities
These teams are directly responsible for implementing Section I's principle-based obligations, embedding ICT third-party arrangements within the firm's ICT risk management framework. Their work covers the firm's direct contractual ICT relationships; visibility into subcontracting and lower-tier dependencies depends on the specific requirements elaborated within the Chapter and related DORA provisions.
Compliance and regulatory affairs functions in EU financial firms
Because applicability is jurisdiction-specific to EU financial sector entities within DORA's scope, compliance teams must map Chapter V obligations against existing third-party governance and avoid treating this ICT-focused pillar as a substitute for wider supplier, financial, or supply chain risk programmes that fall outside the Chapter's terms.
Critical ICT third-party service providers
Providers designated as critical to the financial sector become subject to the oversight framework established in Chapter V, which introduces regulatory oversight practices at a level above individual bilateral contracts. This designation applies specifically to those deemed critical rather than to every ICT provider serving in-scope firms.
Board members and senior management of in-scope financial entities
The principle-based nature of Section I places accountability for governing ICT third-party dependencies within the firm's overall ICT risk management framework, making senior oversight of these arrangements a governance concern rather than a purely operational or procurement matter.

Inside Chapter V DORA

ICT third-party risk management framework
Chapter V of the Digital Operational Resilience Act (DORA) addresses the sound management of ICT third-party risk by in-scope financial entities. It sets expectations for identifying, assessing, and monitoring risks arising from reliance on ICT service providers, situating this within the broader operational resilience obligations of the regulation rather than treating it as a standalone security exercise.
Pre-contractual assessment and due diligence
The chapter contemplates due diligence and risk assessment before entering into contractual arrangements for the use of ICT services, including consideration of whether a service supports a critical or important function. This covers the onboarding stage and does not by itself substitute for ongoing monitoring throughout the relationship.
Contractual arrangement requirements
Chapter V sets out elements that are expected to be reflected in contractual arrangements between financial entities and ICT service providers, with more extensive expectations where the service supports a critical or important function. These provisions govern the direct (third-party) relationship and its documentation rather than guaranteeing performance.
Register of information
Financial entities are expected to maintain a register of information on their contractual arrangements for the use of ICT services, which supports internal oversight and can be made available to competent authorities. The register documents relationships but is not itself a risk assessment or a control.
Oversight framework for critical ICT third-party service providers
The chapter establishes an oversight framework under which certain ICT third-party service providers may be designated as critical and subjected to oversight by a Lead Overseer at the Union level. This designation and oversight operate at the provider level and are distinct from the financial entity's own third-party risk management obligations.
Concentration and exit considerations
Chapter V reflects attention to ICT concentration risk and to arrangements for exiting or terminating contracts, including transition and continuity considerations. These address dependency and portability concerns rather than eliminating the underlying reliance on external providers.

Common questions

Answers to the questions practitioners most commonly ask about Chapter V DORA.

Does Chapter V of DORA apply directly to third-party ICT providers, or does it regulate the financial entities that use them?
Chapter V is primarily addressed to the financial entities that fall within DORA's scope, setting out their obligations for managing ICT third-party risk. It is not accurate to characterize the chapter as directly regulating all ICT providers as a general matter. The exception is the oversight framework for those providers designated as critical ICT third-party service providers, which brings certain designated providers within direct supervisory reach. For non-designated providers, the obligations flow contractually and operationally through the financial entity rather than applying to the provider as a standalone regulated party.
Is meeting Chapter V's contractual requirements the same as achieving DORA compliance for third-party risk?
No. The contractual provisions in Chapter V are one component of the third-party risk requirements, not the whole of them. Chapter V also addresses matters such as maintaining a register of information on contractual arrangements, conducting pre-contractual assessment and due diligence, and considering concentration-related concerns, alongside the oversight regime for designated critical providers. Treating the mandatory contractual clauses as a complete compliance checklist conflates one obligation with the broader set of duties the chapter establishes.
What contractual arrangements does Chapter V expect financial entities to maintain with ICT third-party service providers?
Chapter V expects contractual arrangements to be documented and to include specified provisions covering the services concerned. Depending on the criticality or importance of the function supported, the expected content differs, with more extensive provisions typically required for arrangements supporting critical or important functions. Financial entities generally need to review existing contracts against these expectations and, where gaps exist, renegotiate or supplement terms. The specific clauses and their applicability should be confirmed against the text of DORA and any implementing measures rather than assumed.
How should a financial entity approach the register of information required under Chapter V?
Chapter V requires financial entities to maintain a register of information relating to their contractual arrangements for ICT services. In practice this typically means establishing a structured inventory that can be kept current and produced to competent authorities on request, and distinguishing arrangements that support critical or important functions from those that do not. Because the register underpins supervisory visibility and concentration analysis, it generally needs consistent data definitions across the organization and a process for keeping entries updated as contracts change, rather than being treated as a one-time compilation.
How does Chapter V's treatment of concentration risk affect provider selection and monitoring?
Chapter V directs financial entities to take account of concentration-related concerns when relying on ICT third-party providers. It is worth distinguishing concentration risk, single-source dependency, and single point of failure, as these are related but not identical. In implementation terms, this generally means assessing during selection whether reliance on a given provider or a small set of providers creates undue dependency, and monitoring that exposure over time rather than only at onboarding. The chapter frames this as a factor to consider; it does not prescribe a single quantitative threshold.
What does the oversight framework for critical ICT third-party service providers mean for a financial entity's own responsibilities?
The oversight framework brings designated critical ICT third-party service providers within direct supervisory attention, but it does not transfer the financial entity's own third-party risk management responsibilities to the supervisory authorities. Financial entities generally remain responsible for their due diligence, contractual arrangements, and ongoing monitoring regardless of whether a provider is designated. Depending on how the framework operates, the designation and any supervisory findings may inform an entity's risk assessment, but they do not substitute for the entity's own controls or serve as a compliance guarantee.

Common misconceptions

Being designated a 'critical ICT third-party service provider' under Chapter V is a form of certification or approval that assures financial entities the provider is secure.
Designation as critical triggers Union-level oversight of that provider; it is a supervisory mechanism, not an endorsement, certification, or attestation of security. Financial entities retain their own responsibility for managing the risk of the relationship, and oversight of a provider does not transfer or discharge that obligation.
Chapter V is essentially an information security or cybersecurity requirement.
Chapter V sits within DORA's operational resilience objectives and addresses ICT third-party dependency, contractual governance, concentration, and continuity of critical or important functions. It is broader than information security controls alone, though it also does not purport to cover every category of third-party risk such as financial or ESG risk in the same depth.
Completing pre-contractual due diligence and maintaining the register of information satisfies Chapter V.
Pre-contractual due diligence and the register document the onboarding stage and the inventory of arrangements, but Chapter V's expectations extend to ongoing monitoring, contractual content, and exit arrangements. Point-in-time onboarding checks and a static register can become stale and do not by themselves demonstrate continuous management of the relationship.

Best practices

Classify each ICT service by whether it supports a critical or important function early, since the depth of due diligence, contractual detail, and monitoring expected under Chapter V typically scales with that classification.
Maintain the register of information as a living record that is reconciled against actual contracts and reviewed on a defined cadence, rather than treating it as a one-time inventory produced for a regulator.
Ensure contractual arrangements capture the specific elements Chapter V contemplates for critical or important functions, and treat provider attestations as inputs to be validated rather than as independent verification.
Pair pre-contractual due diligence with an ongoing monitoring process, recognizing that a point-in-time assessment does not remain representative as the provider, service, or threat landscape changes.
Assess ICT concentration risk across your portfolio, distinguishing single-source dependency and single points of failure, and document tested exit and transition arrangements for critical or important functions.
Track which of your providers may fall within the Union-level oversight framework as critical, while recognizing that such oversight supplements, rather than replaces, your own third-party risk management responsibilities.
Promotional banner for the Pentest Readiness checklist download