General principles for ICT third-party risk management
Summary
Financial entities shall manage ICT third-party risk as an integral element of their ICT risk management framework.
third partyrisk managementcontractsmonitoringregister
Read the full official text: https://eur-lex.europa.eu/eli/reg/2022/2554/oj
← Article 23
ICT-related incident management process
Article 29 →
Key ICT third-party service providers
Track DORA article 28 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial