DORA Explained: ICT Third-Party Risk Management Strategy (Part 3)

If you enjoy reading our articles and want to support our mission of sharing valuable insights on AML and investment funds, the easiest way to help is by subscribing to our Fundiligence newsletter.
For us it is very important, for you it is FREE.


Managing ICT Third-Party Risk under DORA

The strategy for managing ICT third-party risk under DORA includes a policy specifically designed for the use of ICT services that support critical or important functions. The Board of Directors is ultimately responsible for regularly reviewing and assessing the entity’s overall risk profile, considering the scale and complexity of its business operations. This evaluation includes assessing the risks associated with contractual arrangements for ICT services critical to the entity’s operations.

To ensure strong governance, the AIFM must implement a policy to identify, assess, and mitigate ICT risks tied to third-party service providers. This policy should clearly define what constitutes a critical or important function and emphasize the need for a thorough risk assessment before entering into contractual agreements. By systematically evaluating these risks, the management body can identify potential vulnerabilities and implement appropriate mitigation measures.

The identification phase involves analyzing third-party ICT service providers to determine their criticality to the organization’s operations. This assessment includes evaluating the provider’s cybersecurity posture, financial stability, and historical performance.

Subscribe to continue reading

Subscribe to get access to the rest of this post and other subscriber-only content.