ESMA · ESMA_QA_2457 Question Rejected
Clarification on DORA Audits for Non-European ICT Service Providers
- Regulation
- Regulation (EU) 2022/2554 - The Digital Operational Resilience Act (DORA)
- Topic
- Other DORA topics
- Submitted
- 2025-03-07
Question
The DORA law states that ICT third-party service providers must fully cooperate during onsite inspections and audits conducted by competent authorities, the Lead Overseer, the financial entity, or an appointed third party. Will these audits be conducted the same way if the provider is located outside Europe,
No answer published yet.
This Q&A is published by European Securities and Markets Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
ICT third-party risk management (DORA)
Answered 2025-11-20
Application of DORA for outsourced critical services that are not ICT
Answered 2024-02-12
Audit frequency limitations
Answered 2025-09-18
ICT third-party risk management (DORA)
Answered 2025-11-21
ICT third-party risk management (DORA)
Answered 2024-03-14
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.