DORA
The EU regulation on digital operational resilience for the financial sector, which sets rules for managing ICT third-party risk (Regulation (EU) 2022/2554).
It applies from 17 January 2025 to banks, insurers, investment firms and other financial entities. Among other things, they must keep a register of information on all their contractual arrangements with ICT third-party service providers (Article 28(3)), assess providers before contracting, and include specific terms in those contracts (Article 30).
Source: Regulation (EU) 2022/2554 ↗
Related terms
ClauseTrail watches vendors' subprocessor lists, DPAs, privacy policies, terms and AI terms, and tells your team what changed and by when to object.