General principles
Summary
Financial entities shall manage ICT third-party risk as an integral component of ICT risk, remain fully responsible for compliance regardless of outsourcing, adopt a strategy and register of ICT third-party arrangements, conduct due diligence, and put in place exit strategies for critical or important functions.
Read the full official text: https://www.digital-operational-resilience-act.com/Article_28.html
← Article 23
Operational or security payment-related incidents concerning credit institutions, payment institutions, account information service providers, and electronic money institutions
Article 29 →
Preliminary assessment of ICT concentration risk at entity level
Track DORA article 28 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial