Skip to content

Sectors · Finance & insurance

For financial entities and their providers

DORA requires you to keep a register of third-party providers. It says who you work with; it does not say what has already leaked at their end, or when.

The register, and what it lacks

One more column

The register lists. Anteriority qualifies. Crossing the two is what stops third-party risk monitoring from being merely declarative.

Your third-party providers, in DORA's sense

  • Core banking
  • Payments
  • Hosting
  • Asset management
  • Broking and distribution

03/2024a distributor's data in circulation, to be matched against your provider register

DORA requires keeping a register of third-party providers and tracking their risk. The register says who you work with; it does not say what has already leaked at their end, or when. That second column is the one usually missing.

Regulation (EU) 2022/2554. The diagram is illustrative.

The uses

Three moments of the regulation

  • The provider register

    Match your register against what has actually circulated, to rank critical providers.

  • Information sharing

    Dated, sourced elements, exportable in the formats your sector exchanges already use.

  • Cyber underwriting

    For carriers and brokers, a risk's exposure anteriority before it is written.

Two readings

The same index, on both sides of the contract

A bank looks at its providers; an insurer looks at its insureds. In both cases the question is the same: was this counterparty already exposed, and for how long.

The Insurance & broking page covers the second use in detail, from underwriting to the white-label report.

Cross your register with the archive

A list of critical providers is enough to measure what anteriority adds.

Book a demo