EIOPA · 2673
ICT third-party risk management (DORA)
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- N/A
- Topic
- ICT third-party risk management (DORA)
- Submitted
- 2023-06-06
- Answered
- 2024-03-14
Question
If a firm is referring its staff to an online third-party ID verification provider and the third-party immediately passes its ratings to the firm via an API, but only stores the data for 30 days, could this be viewed as an outsourcing arrangement or not?
Background
Thinking of accepting a TPRM role.
Answer
This question has been rejected because it is an institution-specific question requiring bespoke advice.
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
ICT third-party risk management (DORA)
Answered 2025-08-08
ICT third-party risk management (DORA), Other DORA topics
Answered 2025-07-25
ICT third-party risk management (DORA)
Answered 2025-11-21
ICT third-party risk management (DORA)
Answered 2025-11-20
Application of DORA for outsourced critical services that are not ICT
Answered 2024-02-12
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.