DORA
In shortForces financial firms to plan and rehearse leaving an IT provider.
DORA has applied since 17 January 2025 to banks, insurers, payment providers, fund managers and some twenty further categories of financial entity. If you are not one of them, it is still worth knowing: it mandates what elsewhere is merely recommended.
The article that counts
Article 28 governs contracts with ICT third-party providers. For services supporting critical or important functions it requires, among other things, complete service descriptions, access and audit rights, termination rights, provisions on where processing happens — and exit strategies.
Those exit strategies must be documented, assessed for adequacy, and tested periodically. Not described. Tested.
Why this is interesting beyond finance
Because it answers the question that otherwise stays open: how do you know an exit capability is real? DORA's answer is uncomfortable and useful — because somebody has run it once and written down what did not work.
Firms outside DORA's scope can hold themselves to the same bar without adopting the reporting duties and the registers. See Exit strategy.
The register of information
DORA also requires a complete register of all ICT providers, including subcontracting chains and which entity supports which function. That list is also the basis of any sovereignty assessment — and the reason regulated institutions can now answer the dependency question better than many manufacturers can.
The oversight framework
Also new: providers designated as critical — the large cloud vendors fall in here — can be supervised directly by the European supervisory authorities. That changes nothing about the parent company's jurisdiction, but it gives the EU its first direct handle on providers previously reachable only through their customers.