Why static vendor policies fail under DORA rules

DORA

The EU’s Digital Operational Resilience Act has turned third party risk management from a best-practice exercise into a checkable legal requirement, and financial entities that treat their policy as a static document risk falling short of what regulators expect.

According to Copla, under Article 28, a financial entity’s ICT third-party risk strategy must define how vendors are classified, assessed before signature, and monitored on an ongoing basis. The policy itself is the operational layer, setting out how classification, due diligence and monitoring actually happen rather than simply stating that they should.

This includes maintaining a register of ICT third-party arrangements in a fixed structure, assessing concentration risk across providers, and building a tested exit strategy for any arrangement supporting a critical or important function. The management body must review the policy at least annually.

Classification does not need a five-tier framework to be defensible. Many financial entities run lean teams, and two tiers, those supporting a critical or important function and everything else, can suffice, provided the reasoning behind each decision is documented.

Classification should be driven by what a vendor can access and what would break if it failed, not by how the vendor markets itself; a low-risk marketing tool can still hold sensitive customer data.

Article 30 sets out contractual terms that must appear in writing rather than being left to due diligence conversations. These include audit and access rights, data location disclosures, quantifiable service levels, sub-outsourcing notification, cooperation obligations during ICT incidents, and clearly defined termination and exit rights.

Where risk tends to slip through is not the policy document itself but its application. Questionnaire responses are often treated as evidence rather than claims requiring verification. Vendors can be under-classified when their access footprint expands after onboarding without triggering a fresh review. And policies are frequently left unrevisited until a scheduled cycle, rather than being reassessed when a new regulation, peer incident, or vendor category emerges.

A policy, register entry and signed contract capture a single point in time. They do not automatically flag when a vendor’s access grows beyond what was approved, when a contractual audit right goes unexercised, or when a fourth-party subcontractor is added mid-relationship.

Closing that gap requires the register, contract and classification to stay linked and be reassessed on a cadence tied to each vendor’s tier, rather than relying on quarterly spreadsheet reviews.

Copla’s full post can be read here. 

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2026 RegTech Analyst

Investors

The following investor(s) were tagged in this article.