The exposure that arrives through someone else, and the obligations that make it yours anyway. This is the busiest domain we cover and the one where regulators have moved fastest.
What we track
DORA third-party rules
EU financial entities. Contractual requirements, exit strategies, and the register of information submitted to competent authorities.
DORA subcontracting standard
EU. How far down the chain your obligations reach, and what a provider must tell you about subcontracting.
Critical ICT provider designations
EU. Which providers the ESAs have designated, and what direct oversight of them changes for their customers.
NIS2 supply chain duties
EU. Security in supplier relationships, and the member state guidance tying it to procurement clauses.
MAS third-party risk guidelines
Singapore. Expectations for regulated institutions, extended to technology suppliers serving them.
Concentration risk
EU, UK and Singapore. Supervisory concern about cloud and payments concentration, and where that concern is heading.
Who is in scope
Anyone with suppliers, which is everyone, but the heaviest obligations apply to regulated entities. DORA reaches EU financial entities and, through designation, their critical providers directly. NIS2 imposes supply chain security duties on essential and important entities. MAS expectations reach Singapore regulated institutions and now the technology suppliers serving them.
The interesting group is providers. A technology company that sells into regulated customers inherits contractual obligations from every one of them, and increasingly a supervisory relationship of its own.
Where the deadlines fall
Register submission cycles are the calendar item, and they repeat. Designation decisions arrive on the supervisors’ timetable, and change your obligations when they land. Contract remediation deadlines are set by your own renewal cycle, which is why firms that waited for a legal deadline usually ran out of time before their counterparties did.
Where organisations get caught
The register of information. It looks like an inventory exercise and turns out to be a data quality exercise. The fields must reconcile across contracts, entities and legal identifiers that were never maintained to that standard. The first submission is where firms find out how bad their supplier master data is.
Designation. When a provider you depend on is designated as critical, the supervisory relationship changes above your head, and your own obligations move without you having done anything.
Depth. Obligations reach subcontractors, and most organisations can see one tier. The provider who assures you is often not the party running the workload. An annual questionnaire and a certification used to be acceptable, and no longer answer the question a supervisor asks.
Questions worth asking now
- Can we produce a register of our ICT arrangements that reconciles to our contract repository?
- Which providers support a critical or important function, and who decided that mapping?
- How far into the chain can we see, and where does visibility stop?
- What would we do if our largest provider were designated as critical next quarter?
- Do our contracts contain the audit, exit and subcontracting terms our regulator expects?
- Have we ever exercised an exit plan, or only written one?
Related domains
Operational resilience covers the regime most of these duties belong to. Product security covers components you inherit inside what you ship. Cybersecurity regulation covers the NIS2 supplier duties.