DORA addresses indirect ICT dependencies through its rules on subcontracting. Article 29 requires financial entities to assess risks arising when ICT services supporting critical or important functions are subcontracted and to consider whether long or complex subcontracting chains could weaken effective monitoring. The required depth depends on the service, the contractual chain and its relevance to critical or important functions.
FAQ
Regulatory Compliance