AqtaAqta

DORA - Regulation (EU) 2022/2554

Article 28 - ICT third-party register

DORA Article 28 requires financial entities to maintain, as part of their ICT risk-management framework, a register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers, and to identify which provider supports which function.

What the clause asks for

A register kept up to date with information on each contractual arrangement, distinguishing those supporting critical or important functions, and traceable evidence of third-party involvement per function.

The field-by-field mapping

Which record fields answer this clause, one by one, comes with the procurement pack and with every pilot. Request the pack.

Receipts give the register row-level evidence. A regulator asking “which provider handled this decision” gets a signed answer, not a pointer to a vendor dashboard.

Read Article 28 on EUR-Lex or read the full open spec at github.com/Aqta-ai/attestation-spec.

← Back to the verifier