Dossier Secure
DORA & ICT Third-PartyGovernance Evidence Infrastructure
Governance Evidence Infrastructure

DORA & ICT Third-Party Evidence

2026 is the enforcement year. Documentation is what supervisors actually test.

DORA requires financial entities to map ICT third-party dependencies and maintain a Register of Information — a requirement nearly half of institutions report as their hardest to meet. Supervisors examine the underlying decision record: what was reviewed, who accepted the risk, and why a provider was deemed acceptable.

Register of InformationVendor Risk EvidenceBoard Sign-offResilience Testing Record
ICT dependency map and financial compliance documents on a dark conference table
What DORA tests

Not whether a vendor was used, but whether the risk acceptance and board sign-off can be shown.

The core problem

Regulation is an evidence reconstruction problem

DORA enforcement is active in 2026. The Register of Information has been named by 46% of financial institutions as their hardest requirement to meet — not because the concept is unclear, but because the underlying decision record was never structured to support it.

Supervisory expectation

"Document every decision — especially borderline cases. Supervisors will ask."

Personal accountability for senior management is part of the DORA regime, with penalties reaching up to €1 million for individuals in serious cases.

Nineteen Critical ICT Third-Party Providers have been designated at EU level — financial institutions must document their dependency on these and other providers.

What this requires

Four conditions for defensible ICT third-party evidence

1

ICT asset inventory

A documented inventory of ICT assets and their third-party dependencies, current and traceable.

2

Vendor risk assessment

A record of how each critical provider was assessed, including concentration risk across the dependency chain.

3

Board sign-off

Evidence that leadership reviewed and accepted the risk of relying on specific critical providers, recorded at the time.

4

Resilience testing record

Documentation showing operational resilience testing occurred and what its findings were, not just that a plan exists.

Where it goes wrong

How ICT third-party evidence fails in practice

Incomplete dependency mapping. A Register of Information exists, but does not reflect the true chain of subcontracted dependencies.
Risk acceptance without record. A critical provider was approved, but no documented rationale shows why the concentration risk was accepted.
Resilience testing undocumented. Testing occurred, but findings and remediation were not formally recorded.
Board awareness assumed. Leadership was briefed informally, but no record shows what was presented or approved.
How Dossier Secure addresses this today

A structured evidence foundation, built for today's pressure

Standard — Structured Dossier Foundation

Organizes ICT third-party facts, evidence, decisions and obligations into a defensible case structure. The documents are the output of that structure — not the product itself.

Pro — Governance & Integrity Layer

Adds governance and integrity controls around decision responsibility, evidence integrity and access-audit boundaries, strengthening the record of vendor risk oversight.

Enterprise — In Active Development

Dossier Secure Enterprise is being engineered to connect events, actors, policies, decisions, evidence bundles, outputs and audit trails into a defensible reconstruction chain — including ICT third-party risk and board sign-off evidence. This layer is in active development.

Frequently asked questions

DORA & ICT third-party evidence, explained

What does DORA mean for third-party service providers?

DORA requires financial entities to map and document their ICT third-party dependencies, including concentration risk across critical providers, and to maintain a Register of Information.

What is an ICT asset inventory and why is it required?

A documented inventory of ICT assets and their third-party dependencies, required so an organization can demonstrate it understands and manages its technology risk exposure.

How do regulators check decisions were properly documented?

Regulators request the underlying decision record — not just the outcome — including who approved it, what risks were considered, and what evidence supported the decision.

What records prove we are managing third-party ICT risk?

Vendor risk assessments, dependency mapping, board sign-off on critical providers, and incident records connected to specific third parties.

Is Dossier Secure Enterprise fully live for DORA evidence?

Dossier Secure Enterprise is in active development and is being engineered as forensic governance infrastructure. Current Dossier Secure layers provide a structured evidence foundation, while the full Enterprise reconstruction chain is being built step by step.

Next step

Test where your ICT third-party evidence is incomplete today

The 48-hour governance test shows exactly where the link between vendor risk and board-level evidence is missing — before scrutiny exposes it under pressure.