DORA

DORA Advanced

Complex DORA scenarios: Oversight Framework mechanics, cross-border ICT concentration risk, and TLPT programme design.

11 questions · 80% to pass · free

eurocompliant.com is not an accredited certification body. This is a self-paced educational assessment; the certificate confirms completion only, not a professional, statutory, or accredited qualification.

Your details

We'll email your certificate here if you pass. We may occasionally follow up about eurocompliant.com - you can unsubscribe any time.

Question 1 of 11

Under the DORA Oversight Framework, which body/bodies can be designated as Lead Overseer for a critical ICT third-party service provider?

Question 2 of 11

What power does a Lead Overseer generally have with respect to a designated critical ICT third-party provider under DORA?

Question 3 of 11

Which of the following are relevant when a financial entity assesses concentration risk arising from reliance on a small number of critical ICT third-party providers?

Select all that apply.

Question 4 of 11

Under Article 30's key contractual provisions, what exit strategy consideration must be addressed for critical/important functions?

Question 5 of 11

How does DORA's TLPT requirement relate to frameworks such as TIBER-EU?

Question 6 of 11

A financial entity relies on a single cloud provider for a function later classified as 'critical or important.' What DORA-driven risk should its board specifically evaluate?

Question 7 of 11

Which of the following are typical components of a mature ICT third-party risk management lifecycle under DORA?

Select all that apply.

Question 8 of 11

What is the general relationship between DORA and sector-specific EU financial regulation already addressing ICT/operational risk (e.g. existing EBA guidelines)?

Question 9 of 11

Under DORA, competent authorities can require a financial entity to temporarily suspend the use of an ICT service, in serious cases, where necessary to protect the integrity of the financial system.

Question 10 of 11

Why might 'sub-outsourcing' by an ICT third-party provider be a specific area of DORA-related contractual and oversight focus?

Question 11 of 11

How should a globally active financial group approach DORA compliance alongside similar operational resilience requirements in non-EU jurisdictions (e.g. UK operational resilience rules)?

0 of 11 answered