DORA — Digital Operational Resilience Act (AI overlay)
Regulation (EU) 2022/2554 — Digital Operational Resilience Act, with the AI-specific overlay applied to ICT third-party risk management. In force since 17 January 2025. Targets EU financial entities (banks, insurers, investment firms, payment institutions) and the AI systems they consume from ICT third-party providers. The EU's first joint Critical Third-Party Providers (CTPPs) list was published in November 2025 — DORA's CTPP oversight directly reaches the hyperscalers that ship foundation-model AI to EU FS customers.
Direct ESA oversight reaches your AI suppliers — not just your bank.
DORA's Article 31 creates the EU's first cross-border oversight regime for Critical Third-Party Providers (CTPPs). The first CTPP list was published in November 2025 and reaches the hyperscalers that ship foundation-model AI to EU financial entities. This pack maps your AI vendor inventory to the CTPP register and produces the concentration-risk documentation your competent authority will expect at the next examination.
- Register of Information with AI-vendor sub-processor disclosure (Art. 28)
- Concentration-risk map across CTPP dependencies (Art. 31)
- Exit-strategy templates for AI-as-a-service contracts (Art. 30)
- TLPT-aligned testing programme covering AI use cases (Art. 24)
ICT risk management framework
Establish a sound, comprehensive, and well-documented ICT risk management framework covering AI systems used in critical or important functions.
Identification of ICT-related risks
Identify, classify, and document all ICT-supported business functions (including AI-driven ones), assets, and the information assets they handle. Maintain an inventory updated at least annually.
ICT-related incident management process
Establish and implement an ICT-related incident management process to detect, manage, and notify ICT-related incidents — including AI hallucination / bias incidents that disrupt critical functions.
Reporting of major ICT-related incidents
Report major incidents to competent authorities. Initial, intermediate, and final reports per the technical RTS. AI-system outages that breach the materiality thresholds are in scope.
Digital operational resilience testing
Test ICT systems regularly. For significant entities, threat-led penetration testing (TLPT) every three years. AI systems used in critical functions are scoped into the testing programme.
General principles — ICT third-party risk
Manage ICT third-party risk as an integral component of ICT risk. Maintain a Register of Information for all contractual arrangements, including AI-as-a-service vendors and foundation-model providers.
Key contractual provisions
Contracts with ICT third-party service providers must contain rights to audit, monitor, terminate, and ensure exit strategies. AI vendor contracts must include model versioning, data lineage attestations, and sub-processor disclosure.
Critical Third-Party Providers (CTPPs)
ICT services from designated CTPPs (the EU Joint Oversight Forum published the first list in November 2025) are subject to direct oversight by ESAs. Financial entities consuming AI from CTPPs must document those dependencies and implement concentration-risk controls.
Information-sharing arrangements
Financial entities may exchange information and intelligence on cyber threats, including AI-specific attack patterns (prompt-injection campaigns, jailbreak repositories, model poisoning).
Unlock the full DORA-AI pack
Get all 6 remaining requirements, generated reports, evidence-mapping templates, and the audit-chain export. Cancel anytime.
Not ready to buy? Run the free EU AI Act gap report.
12-question intake mapped to Articles 9-15. Branded PDF in your inbox in minutes. No card required.