Back to blog

DORA ICT third-party provider: definition and impact on IT supplier oversight

Definition of an ICT third-party service provider under DORA, examples for an asset manager, and concrete impacts on the register, contracts and accountability.

By Arthur Chédeville··Read time : 4 min·For Compliance, CISO, CIO, Procurement
Office campus linked by walkways — ICT third-party provider chain

Under DORA, an ICT third-party service provider is an undertaking that provides digital and data services on a continuous basis through ICT systems. The notion extends oversight beyond suppliers labelled “IT” by Procurement. It has three main consequences: identify the services in scope, adapt the contracts, and retain accountability for their control.

What is an ICT third-party service provider

Article 3 of the DORA regulation gives a deliberately broad definition: an “ICT third-party service provider” is “an undertaking providing ICT services”. The supplier’s declared nature or sector is therefore not enough to decide whether it falls into this category.

The same article defines “ICT services” as digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis. The notion also covers hardware as a service and hardware services that include technical support through software or firmware updates — excluding traditional analogue telephone services.

The decisive criterion is therefore the service actually delivered. A supplier presented as a consulting firm can fall within this qualification if it continuously makes a digital platform available. Conversely, spend incurred with a technology company is not automatically an ICT service: the object and modalities of the engagement must be examined.

Concrete examples

For a portfolio management company, several common engagements match this definition:

  • cloud hosting of a business application or portfolio data;
  • a SaaS portfolio management, risk-control or compliance application;
  • an outsourced cybersecurity monitoring service, such as alert detection and handling;
  • an IT outsourcing engagement covering the operation, maintenance or support of ICT systems.

These services share one feature: they are delivered on an ongoing basis through ICT systems. The supplier is involved in the daily operation of the entity’s digital setup, even when it is not identified as an IT provider in internal taxonomies.

In practice, this is often where it breaks down: the category recorded in the procurement tool does not necessarily reflect the service delivered. A supplier registered under “advisory” may provide continuous SaaS access; an “assistance” contract may include infrastructure administration. The first inventory must therefore start from contracts, purchase orders and operational usage — not from the accounting or procurement category alone.

What this changes for you

Qualifying an engagement as an ICT service is not merely a wording question. It concretely changes oversight on three fronts.

  1. The register of information. The contractual arrangement must be recorded in the DORA register with the expected information on the provider, the service provided and its use by the entity. The register therefore cannot be built solely from a historical list of IT suppliers.

  2. Contractual arrangements. The contract must be reviewed against the DORA requirements applicable to ICT services. The aim is to verify that rights, obligations and control modalities for the service are sufficiently formalised — without assuming that a standard SaaS or outsourcing contract is already fit for purpose.

  3. The financial entity’s accountability. Using a third-party provider does not transfer regulatory responsibility. The financial entity remains fully accountable for meeting its DORA obligations, including where technical operation, hosting or monitoring have been outsourced.

A business SaaS solution is a simple example: it must be identified in the register, covered by an adapted contract, and overseen by the asset manager that uses it. Delegating technical execution is not delegating accountability.

Going further

Once ICT third-party service providers have been identified, the next step is to review their contracts and related oversight arrangements. See the mandatory DORA contractual clauses under Article 30 for that strand. The official ESMA page on DORA is also useful to follow the European framework and related texts.