PuReAIpureAi
Free scan

Glossary

ICT Third-Party Risk

The DORA term for risk arising from an organization's information and communication technology suppliers, requiring an ongoing register and continuous oversight.

Definition

ICT third-party risk is the term used under the EU Digital Operational Resilience Act (DORA) to describe risk arising from an organization's reliance on information and communication technology providers, including cloud platforms, software vendors, data centers and managed service providers. DORA treats this as a distinct, regulated risk category because financial entities increasingly depend on a small number of critical technology providers whose failure or compromise could ripple across the entire financial system.

Under DORA, financial entities are required to maintain a register of information covering all contractual arrangements with ICT third-party providers, including details on the services provided, the criticality of each provider, and sub-outsourcing chains. Providers deemed critical to the financial sector as a whole can be designated for direct oversight by European supervisory authorities, a level of regulatory attention that did not previously exist for pure technology vendors.

Managing ICT third-party risk in practice requires ongoing visibility rather than a one-time vendor questionnaire. Traditional vendor risk assessments, completed once at contract signing and refreshed annually at best, cannot keep pace with how quickly a vendor's own security posture can change. A vendor that passed a security review in January can have a newly exposed admin panel, an expired certificate, or a vulnerability under active exploitation by March, and none of that would surface again until the next scheduled review.

Continuous, outside-in monitoring of vendors' external attack surface has become a common way to close that gap. Because this kind of monitoring does not require the vendor's cooperation or access to their internal systems, it can be applied across an entire supplier register, including smaller vendors that would never agree to a full security audit, and it produces dated evidence of a vendor's posture over time rather than a single point-in-time attestation. This evidence trail is specifically useful for demonstrating DORA's requirement for continuous oversight of critical ICT providers, rather than periodic, static review.

ICT third-party risk overlaps closely with the broader discipline of Third-Party Risk Management (TPRM), but DORA gives it specific regulatory teeth for EU financial entities: the register of information, the criticality classification, and direct oversight powers over critical providers are all DORA-specific obligations that go beyond general vendor risk best practice.

Common questions

Who has to comply with DORA's ICT third-party risk requirements?

DORA applies to a broad range of EU financial entities, including banks, insurers, investment firms and payment institutions, as well as, indirectly, the critical ICT providers that serve them.

What is the register of information under DORA?

It is a mandated inventory financial entities must maintain of all their ICT third-party arrangements, including provider details, service descriptions, criticality and sub-outsourcing chains.

How can a company monitor ICT third-party risk continuously without vendor cooperation?

Outside-in, agentless monitoring of a vendor's public-facing assets and exposures does not require the vendor's involvement, which makes continuous coverage practical across an entire supplier base.