For financial services procurement and risk teams, DORA has moved from a regulation to prepare for to one that is now firmly in force. But moving from awareness to actual operational readiness is where most organisations are still working.
DORA treats third-party risk as a lifecycle, not a one-time check. That means five distinct stages procurement needs to own or influence: pre-contract due diligence, contractual safeguards, ongoing monitoring, incident handling, and exit planning. Skipping any one of them leaves a gap that shows up exactly when you can least afford it, during an incident or an audit.
Article 28(3) is the requirement most teams recognise first: a maintained register of every ICT third-party arrangement, including the services provided, data classifications, and any subcontracting chains involved. What trips organisations up is not building the register once, it’s keeping it current as suppliers, contracts and subcontractors change.
Regulators have also introduced direct oversight of Critical Third-Party Providers, the vendors, often cloud and infrastructure providers, judged essential enough to the financial sector to warrant scrutiny beyond any single institution’s own due diligence. That doesn’t reduce what’s expected of procurement internally. If anything, it raises the bar: DORA is explicit that outsourcing a service never outsources accountability for its resilience.
A few practical starting points for teams still building this out:
Treat supplier criticality as a maintained attribute, not a one-off classification exercise. It should update when a relationship changes, not on a fixed annual cycle.
Build the due diligence gate into procurement itself. No ICT service should go live without a completed assessment and sign-off, and risk teams should be involved during onboarding, not brought in after the contract is signed.
Make exit planning a real, current document for your most critical suppliers, not a clause referenced in a contract nobody has revisited since signature.
Connect the register to contracts and risk data, so a question about a specific supplier’s exposure can be answered in minutes, not assembled from three separate systems under audit pressure.
At TSM, we implement Ivalua’s Source-to-Pay platform for financial services and other regulated organisations across the UK and Europe, bringing supplier information, sourcing, contracts and risk into one connected environment built for exactly this kind of ongoing scrutiny. If your DORA preparation still feels more manual than the regulation intends, we’d welcome a conversation.