Cybersecurity & resilience

ICT third-party risk

Published Reviewed

ICT third-party risk is the risk a financial entity takes on by relying on external providers of information and communication technology — cloud platforms, software vendors, data services. DORA makes managing it a regulated discipline: contracts must contain mandated provisions, critical providers must be identified, exit strategies must exist, and the whole picture must be recorded in a register of information available to the supervisor.

Läs definitionen på svenska: IKT-tredjepartsrisk

Also known as: ICT services · Critical ICT third-party provider

Where this term does its work

This definition is general information, not legal advice. Always verify the current official source.