Sectors · Finance & insurance
For financial entities and their providers
DORA requires you to keep a register of third-party providers. It says who you work with; it does not say what has already leaked at their end, or when.
The register, and what it lacks
One more column
The register lists. Anteriority qualifies. Crossing the two is what stops third-party risk monitoring from being merely declarative.
Your third-party providers, in DORA's sense
- Core banking
- Payments
- Hosting
- Asset management
- Broking and distribution
03/2024a distributor's data in circulation, to be matched against your provider register
DORA requires keeping a register of third-party providers and tracking their risk. The register says who you work with; it does not say what has already leaked at their end, or when. That second column is the one usually missing.
Regulation (EU) 2022/2554. The diagram is illustrative.
The uses
Three moments of the regulation
The provider register
Match your register against what has actually circulated, to rank critical providers.
Information sharing
Dated, sourced elements, exportable in the formats your sector exchanges already use.
Cyber underwriting
For carriers and brokers, a risk's exposure anteriority before it is written.
Two readings
The same index, on both sides of the contract
A bank looks at its providers; an insurer looks at its insureds. In both cases the question is the same: was this counterparty already exposed, and for how long.
The Insurance & broking page covers the second use in detail, from underwriting to the white-label report.
Cross your register with the archive
A list of critical providers is enough to measure what anteriority adds.