Preliminary assessment of ICT concentration risk at entity level
Summary
When assessing ICT third-party risk, financial entities must also consider whether a contractual arrangement would create dependence on a non-substitutable provider or overlapping arrangements with closely connected providers, weighing costs and risks of alternative solutions and subcontracting.
concentration risksubstitutabilitysubcontractingthird country
Read the full official text: https://www.digital-operational-resilience-act.com/Article_29.html
Track DORA article 29 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial