An independent reading of your ICT third-party risk management against what DORA Articles 28-30 actually require, in writing, by someone with no implementation work to sell.
DORA is in active enforcement. You have vendor contracts, a register of some kind, and a general sense of where your critical dependencies sit. What you don’t have is independent confirmation that the register, the contractual provisions, and the concentration risk analysis would actually satisfy a supervisor testing them against Articles 28 through 30 specifically — not just against general good practice.
That is what this engagement is.
€15,000. Three to four weeks. Delivered in writing, with a presentation to whoever needs to hear it.
Fixed fee. No implementation work. No commissions. No product recommendations influenced by suppliers.
Why clients commission this review
- The board wants confirmation the ICT third-party register genuinely meets Article 28’s specific field and structure requirements, not a generic vendor list relabelled.
- A supervisory review or self-assessment cycle is approaching and the concentration risk analysis has never been independently tested.
- Existing vendor contracts predate DORA and haven’t been checked against the mandatory contractual provisions Article 30 requires.
- A critical vendor relationship has no documented exit strategy, and the board wants that gap closed before it becomes a finding.
- The firm has grown through acquisition and now has several parallel, inconsistent vendor registers that need reconciling against a single DORA-compliant structure.
Who this is for
Boards and risk functions at DORA in-scope financial entities who want independent confirmation their ICT third-party risk management would hold up under supervisory scrutiny.
Technology and procurement leaders responsible for the register who want a gap analysis before the next internal or external review.
Who this is not for
Firms wanting contracts renegotiated or the register rebuilt. We identify and recommend; we do not implement or negotiate on your behalf.
Firms wanting the full DORA operational resilience framework reviewed end to end, including ICT risk management and incident response — that’s a broader Technology Control Review scope.
What you receive
The Review tells you three things in writing: where your third-party risk management stands against Articles 28-30 specifically, where the concentration exposure sits, and what to fix before your next supervisory touchpoint. Five artefacts, delivered together, in plain language.
A register gap analysis. Your current ICT third-party register checked field by field against Article 28’s specific structural requirements, with every gap named.
A contractual provisions review. Key vendor contracts checked against the mandatory provisions Article 30 requires — audit rights, exit assistance, sub-outsourcing notification, service-level commitments — with what’s missing named specifically.
A concentration risk analysis. Where dependency is genuinely concentrated — cloud, payments, core platform providers — assessed with evidence, not assumption.
A prioritised remediation roadmap. What to close first, second, third, sequenced against your supervisory calendar and the severity of each gap.
A board presentation. A one-hour session with your board or risk committee, findings presented, challenged, and discussed in the room.
How the Review runs
Three to four weeks, in four phases.
Week one — scoping and inventory. Gathering the current register, key contracts, and stakeholder mapping across procurement, technology, and risk.
Week two — interviews and evidence gathering. Interviews across procurement, technology, and risk functions. Contract-by-contract review against Article 30’s specific requirements.
Week three — synthesis and writing. Findings written up into the artefacts above, concentration analysis calibrated against your actual vendor landscape.
Week four — presentation and revisions. The board or committee session, scheduled around your existing rhythm.
Everything is written before it is said. Nothing is presented to your board that you have not read first.
What this is not
Contract renegotiation or legal drafting. The Review identifies the gaps; your legal function or outside counsel closes them.
A remediation engagement. We identify and recommend; we do not implement.
A full DORA operational resilience audit. For ICT risk management and incident response beyond third-party risk specifically, see the Technology Control Review.
Proof
References available on request. Anonymised excerpts from prior reviews available on request.
What happens next
Start a ConversationThirty minutes. We confirm fit, scope, and timing against your supervisory calendar. No proposal is sent unless you ask for one.
Need broader vendor risk coverage, not just DORA-specific? See the Supplier & Dependency Review.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.