Translations:Digital Operational Resilienec Act (DORA)/36/en
Aus RI Wiki
Before concluding a contract with an ICT third-party provider, financial entities must conduct a risk assessment taking into account the criteria in Article 28(4) and (5) DORA. During contract negotiations, they must ensure the definition of audit frequencies and the audit scope to maintain control over critical systems. Additionally, contractual termination rights and appropriate exit strategies must be defined, especially for critical or important functions.