What DORA ICT Third-Party Risk Management and Oversight - Articles 28-44 (Regulation 2022/2554) requires
This regulation requires EU financial entities to manage risks associated with ICT third-party service providers by maintaining a register of information, conducting due diligence, and ensuring specific contractual provisions are in place (Article 30). It also establishes a Union Oversight Framework for critical ICT third-party service providers, granting Lead Overseers direct powers of investigation and enforcement (Article 31).
Pillar: Banking & Global Finance · Authority: European Parliament and the Council of the European Union · Version: 1.0.0 · Last updated:
Primary source: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554
SHA-256 integrity: 46e389f87ac81c38a4a575bced0134a7b3adee4cf8233bb72180766104bed883
Primary Citations — 7 traced to source
- Regulation (EU) 2022/2554, Article 28 - General principles
- Regulation (EU) 2022/2554, Article 29 - Preliminary assessment of ICT concentration risk and further sub-outsourcing arrangements
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/dora-third-party-risk-articles-28-44.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/dora-third-party-risk-articles-28-44.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/dora-third-party-risk-articles-28-44
- Back to registry: Browse all 10,090 compliance nodes