Key ICT third-party service providers
Summary
Financial entities shall adopt a strategy on ICT third-party risk and exercise due diligence when assessing ICT third-party service providers.
strategydue diligencecritical servicesexit strategy
Read the full official text: https://eur-lex.europa.eu/eli/reg/2022/2554/oj
← Article 28
General principles for ICT third-party risk management
Article 30 →
Preliminary assessment of ICT concentration risk
Track DORA article 29 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial