Translations:Digital Operational Resilienec Act (DORA)/34/en
Aus RI Wiki
A key requirement is that financial entities must maintain an up-to-date information register containing details of all outsourced ICT processes. This register includes the respective contractual arrangements and classification of processes as critical or non-critical. These details must be made available to competent authorities upon request. Furthermore, financial entities must annually report the number of new agreements with ICT third-party providers, the services and functions provided, and the nature of the contractual arrangements. Entities must also promptly report to authorities any planned new arrangements involving critical functions or any change in the classification of a function as “critical.”