If you enjoy reading our articles and want to support our mission of sharing valuable insights on AML and investment funds, the easiest way to help is by subscribing to our Fundiligence newsletter.
For us it is very important, for you it is FREE.
Managing ICT Third-Party Risk under DORA
The strategy for managing ICT third-party risk under DORA includes a policy specifically designed for the use of ICT services that support critical or important functions. The Board of Directors is ultimately responsible for regularly reviewing and assessing the entity’s overall risk profile, considering the scale and complexity of its business operations. This evaluation includes assessing the risks associated with contractual arrangements for ICT services critical to the entity’s operations.
To ensure strong governance, the AIFM must implement a policy to identify, assess, and mitigate ICT risks tied to third-party service providers. This policy should clearly define what constitutes a critical or important function and emphasize the need for a thorough risk assessment before entering into contractual agreements. By systematically evaluating these risks, the management body can identify potential vulnerabilities and implement appropriate mitigation measures.
The identification phase involves analyzing third-party ICT service providers to determine their criticality to the organization’s operations. This assessment includes evaluating the provider’s cybersecurity posture, financial stability, and historical performance.
Subscribe to continue reading
Subscribe to get access to the rest of this post and other subscriber-only content.
I am Diego Ofano, a Compliance and Anti-Money Laundering professional based in Luxembourg. I serve as Conducting Officer and RC/MLRO for a financial institution, overseeing regulatory compliance for EU-domiciled funds. My responsibilities include AML/CFT frameworks, due diligence, regulatory advisory, and training. I regularly deal with complex regulatory and operational matters, with a focus on pragmatic and risk-based solutions in the investment funds industry.
I hold a Law Degree from the University of Bologna, a Master in European Business from ESCP, and certifications like CAMS, keeping me current in compliance and technology.