Managing Third-Party Cloud Risks Under DORA Mandates

Cloud computing has become a critical part of the operating model for banks, insurers, investment firms, payment institutions and other financial entities across Europe. Cloud platforms can host applications, process financial data, provide infrastructure and support functions that are essential to daily operations. This reliance also creates exposure to service outages, cyber incidents, data risks, subcontracting chains, concentration risk and difficulties when changing providers.
The Digital Operational Resilience Act, commonly known as DORA, establishes requirements for managing these ICT-related risks across the EU financial sector. DORA has applied since 17 January 2025 and places ICT third-party risk management within the broader ICT risk management framework of financial entities. Financial entities remain responsible for meeting their DORA obligations even when ICT services are provided by external organizations.
For organizations using cloud infrastructure or cloud-based services, DORA third-party cloud risk management therefore requires more than selecting a reputable provider. Financial entities need visibility into their ICT dependencies, contractual arrangements, service criticality, subcontracting structures, data locations, security expectations, monitoring arrangements and exit strategies.
Explore DORA Compliance Services. Strengthen digital operational resilience and address key ICT risk requirements under the EU Digital Operational Resilience Act.
Understanding DORA Third-Party Cloud Risk Management
DORA third-party cloud risk management focuses on how financial entities identify, evaluate, monitor and control risks arising from their dependence on ICT third-party service providers. Cloud service providers fall within this wider ICT third-party ecosystem when they provide ICT services to financial entities.
Article 28 of DORA requires financial entities to manage ICT third-party risk as an integral part of their ICT risk management framework. The regulation also establishes proportionality, meaning the approach should reflect the nature, scale, complexity and importance of ICT dependencies and the risks associated with the relevant contractual arrangements.
For cloud environments, this means organizations should understand which business processes depend on cloud services, whether those services support critical or important functions, how data is processed and stored, what happens during a provider disruption, and whether another provider or alternative arrangement could reasonably replace the service.
DORA Third-Party Risk Management
DORA third-party risk management covers contractual relationships with ICT third-party service providers and places responsibility for the associated risks with the financial entity. Organizations cannot transfer their regulatory responsibility simply because an ICT service has been outsourced.
A robust third-party risk approach should therefore connect procurement, ICT risk management, information security, business continuity, legal oversight and senior management governance. The risk profile of a cloud provider should be considered in relation to the service it provides and the effect that disruption could have on financial services.
DORA also requires financial entities to maintain and update a register of information concerning contractual arrangements for ICT services provided by ICT third-party service providers. The register is maintained at entity level and, where relevant, at sub-consolidated and consolidated levels.
DORA ICT Third-Party Risk Management
DORA ICT third-party risk management extends beyond basic vendor selection. Financial entities need an ongoing view of their ICT dependencies and the risks associated with external providers.
This becomes particularly important where cloud services are embedded across multiple business functions. A single provider may host applications, store sensitive information, provide computing resources and connect several internal systems. A disruption at that provider can therefore affect multiple services at the same time.
DORA also places importance on concentration and dependency risks. Organizations should consider whether excessive reliance on one ICT provider, technology platform or service ecosystem could create a significant operational resilience concern.
DORA Cloud Outsourcing Requirements
DORA cloud outsourcing requirements are primarily addressed through its broader rules for ICT third-party risk. The regulation does not treat outsourcing as a transfer of responsibility. Financial entities remain responsible for their obligations under DORA and applicable financial services legislation.
Before entering into an arrangement involving ICT services, organizations should consider the nature and importance of the service, the associated ICT risks, the provider's capabilities, the location of service delivery and data processing, subcontracting arrangements, concentration risk and the ability to monitor the relationship.
For services supporting critical or important functions, these considerations become particularly significant. DORA establishes specific contractual provisions and additional expectations concerning access, audit rights, security, continuity, subcontracting and termination.
DORA ICT Outsourcing Requirements
DORA ICT outsourcing requirements include clear allocation of rights and obligations between the financial entity and the ICT third-party service provider. Contracts must include the relevant service level arrangements and be maintained in a durable and accessible written format.
For ICT services supporting critical or important functions, contractual arrangements need to address matters such as the services being provided, permitted subcontracting, service locations, data processing locations, security requirements, availability and continuity arrangements, access and audit rights, cooperation with competent authorities and termination conditions.
Organizations should also consider how subcontracting could affect oversight. Long or complex subcontracting chains can make it harder for a financial entity to monitor an outsourced function and can affect the ability of competent authorities to exercise effective supervision.
The European Commission adopted Commission Delegated Regulation (EU) 2025/532 concerning the elements financial entities must determine and assess when subcontracting ICT services supporting critical or important functions. This adds further regulatory detail to the DORA third-party risk framework.
DORA Cloud Service Provider Requirements
DORA cloud service provider requirements need to be understood in the context of DORA's distinction between financial entities and critical ICT third-party service providers. Financial entities have direct obligations to manage their ICT third-party risks. Certain ICT providers can also become subject to the EU-level oversight framework when designated as critical by the European Supervisory Authorities.
The ESAs published the first list of designated critical ICT third-party providers in November 2025. The designation process considers information from financial entities' Registers of Information and evaluates factors such as systemic importance, the role of the provider in supporting critical or important functions and substitutability.
Being designated as a critical ICT third-party provider does not remove the financial entity's own responsibilities. The DORA oversight framework complements the responsibilities of financial entities and the supervision performed by competent authorities.
Cloud providers serving financial entities should therefore understand the contractual, security, resilience, access and oversight expectations that can arise from DORA relationships. Financial entities, meanwhile, need sufficient visibility into their cloud arrangements to evaluate the risks associated with those relationships.
Managing Cloud Provider Risks Under DORA
Cloud provider risk management under DORA should begin with understanding the business importance of each cloud-dependent service. A cloud service supporting a non-critical administrative activity presents a different risk profile from a service that directly supports payment processing, trading, customer access or another important financial function.
Organizations should map important ICT dependencies and determine where cloud providers sit within those dependencies. This mapping should consider direct providers as well as relevant subcontracting relationships. It should also account for the possibility that several business services depend on the same provider or underlying technology.
The objective is not simply to maintain a list of suppliers. The organization needs a meaningful view of how cloud dependencies could affect operational resilience and whether contractual and technical arrangements provide sufficient visibility and control.
DORA Cloud Provider Risk Management
DORA cloud provider risk management should address security, availability, resilience, data processing, service continuity and provider dependency. These areas should be evaluated throughout the relationship rather than only when a cloud provider is selected.
Monitoring should consider whether the provider continues to meet agreed contractual conditions, whether material changes have occurred in the service arrangement, whether subcontracting structures have changed and whether emerging risks could affect the financial entity's operations.
Contractual provisions are especially important. DORA Article 30 requires clear allocation of rights and obligations and specifies contractual elements relating to ICT services. For relevant arrangements, organizations need appropriate provisions covering service descriptions, locations, data processing, security, access, audit and termination.
DORA Third-Party Cloud Risk Management
DORA third-party cloud risk management should also consider the possibility of provider failure or service disruption. A financial entity should understand how it would maintain important services if a cloud provider became unavailable.
Exit strategies are therefore an important consideration in cloud risk management. The organization should determine whether data and workloads can be transferred, whether alternative providers are technically and commercially viable, what dependencies could prevent migration and how service continuity would be maintained during a transition.
This is particularly relevant when cloud services become deeply embedded within business operations. A theoretical alternative provider may not represent a practical exit option if applications, data structures, interfaces or security controls are heavily dependent on the existing environment.
DORA Third-Party Risk Requirements
DORA third-party risk requirements create a structured framework for managing ICT dependencies within EU financial entities. The requirements cover governance, risk management, contractual arrangements, provider monitoring, registers of information, subcontracting and oversight of critical ICT third-party providers.
Financial entities should consider these requirements alongside the actual risk created by each ICT relationship. A proportional approach allows organizations to focus greater attention on providers and services that could have a significant effect on operational resilience.
Key DORA Third-Party Risk Requirements
One of the central DORA third-party risk requirements is the establishment of an ICT third-party risk strategy. This strategy should address the organization's approach to ICT services provided by third parties and should be reviewed regularly.
Another important requirement is the Register of Information. Financial entities must maintain and update information about contractual arrangements for ICT services provided by ICT third-party service providers. The register provides visibility into the organization's external ICT dependencies and is also used by competent authorities and the ESAs within the DORA supervisory framework.
Contractual controls are another major area. Contracts should clearly establish the responsibilities of the parties and address relevant matters such as service descriptions, service levels, security, access rights, audit rights, data processing locations, subcontracting and termination.
Organizations should also evaluate concentration risk. Heavy dependence on a small number of cloud providers can create broader operational resilience concerns if an outage, cyber incident or systemic issue affects multiple services simultaneously. DORA's oversight framework specifically addresses systemic and concentration risks associated with reliance on ICT providers.
DORA Requirements for Third-Party Cloud Providers
DORA requirements for third-party cloud providers should be considered from two perspectives. First, financial entities must manage their relationships with cloud providers as part of their ICT third-party risk framework. Second, cloud providers that meet the relevant criteria can be designated as critical ICT third-party providers and become subject to EU-level oversight.
The ESAs' oversight framework applies to ICT third-party providers designated as critical. The designation considers factors including systemic impact, interconnectedness, criticality of services, substitutability and the number and type of financial entities served.
For financial entities, this reinforces the importance of understanding which cloud services are relied upon, how critical those services are and how dependencies are structured. For cloud providers, it demonstrates why operational resilience, transparency and effective risk controls are increasingly important within the European financial sector.
Prepare for DORA Requirements. Assess your organization’s approach to ICT risk, resilience, incident management, security testing, and third-party ICT risk.
DORA ICT Third-Party Risk Management
DORA ICT third-party risk management is most effective when it is integrated into the organization's wider operational resilience framework rather than treated as a procurement exercise.
The board and senior management have important responsibilities under DORA, while operational teams need reliable information about ICT services, providers, dependencies and risks. A clear governance structure allows organizations to connect third-party risk decisions with business continuity, information security and ICT risk management.
The EBA states that the DORA technical standards for ICT third-party risk are designed to ensure financial entities remain in control of operational risks, information security and business continuity throughout the lifecycle of contractual arrangements with ICT third-party service providers.
Managing ICT Third-Party Risks
Managing ICT third-party risks under DORA requires visibility across the provider lifecycle. Organizations should consider risk before entering into a contract, monitor the relationship during service delivery and maintain appropriate arrangements for termination or transition.
Key considerations include the importance of the service, security risks, provider resilience, data processing locations, subcontracting, service continuity, concentration risk and contractual rights. These factors should be reviewed in proportion to the organization's risk profile and the criticality of the relevant ICT service.
A Register of Information should remain accurate as contractual arrangements change. The EBA confirms that financial entities subject to DORA are required to maintain such a register and apply a third-party risk management framework proportionate to the risks associated with their activities.
Managing Risks from Cloud Service Providers
Managing risks from cloud service providers requires financial entities to look beyond the primary provider relationship. Cloud platforms can rely on subcontractors, shared infrastructure, geographically distributed processing environments and interconnected technology services.
DORA requires financial entities to consider subcontracting arrangements and evaluate whether potentially long or complex subcontracting chains could affect oversight of services supporting critical or important functions.
Data location is another important consideration. DORA contractual provisions require arrangements to identify locations where contracted or subcontracted ICT functions and services are provided and where data is processed, including storage locations. Providers are also expected to notify the financial entity in advance when they envisage changing relevant locations under the applicable contractual arrangements.
For cloud-dependent financial services, effective third-party risk management therefore means maintaining visibility into the provider relationship, understanding critical dependencies and ensuring that contractual and operational arrangements remain consistent with DORA requirements.
Read More:
How to Achieve DORA Compliance for Cloud Infrastructure
Why the DORA Regulation Matters Beyond the EU?