EIOPA · DORA 228 - 3317

ICT third-party risk management (DORA)

Regulation
(EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Article
28(6) 30(3)(e)(i)
Topic
ICT third-party risk management (DORA)
Submitted
2025-04-09
Answered
2025-11-21

Question

Does Article 28(6) requires financial entity to obtain access, inspection and audit rights in relation to any ICT third party service providers, regardless of whether their services supporto critical or important functions?

Background

Both Articles 28(6) and 30(3)(e)(i) rules access, inspection, and audit rights. However, the latter is referred to ICT third party service providers supporting COI functions, while the former generally refers to ICT third party service providers, without any further specification. It appears that the main difference between the two rules is that Article 30(3)(e)(i) requires "unrestricted" rights of access, inspection and audit. Does this mean that financial entities should obtain such access, inspection and audit rights in respect of all providers, ensuring that when the relevant services supports essential or important functions, these rights are "unrestricted"?

Answer

This question has been rejected because it is seeking confirmation of a requirement already clearly set out in the Regulation (Art. 28(6) and Art. 30(3)(i)).

This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.