Take control of DORA third-party risk.
Manage ICT providers, automate vendor assessments, review contracts, collect evidence and maintain your DORA Register of Information from one platform.
Built for European financial organizations.
DORA Third-Party Risk Overview
Northstar Financial Europe · updated 9 August 2026
DORA Readiness
84%
ICT Providers
142
Critical Providers
18
High Risks
7
Missing Evidence
23
Register Complete
91%
DORA Readiness
- ICT Provider Inventory96%
- Assessments82%
- Contract Coverage74%
- Evidence88%
- Register of Information91%
Attention Required
View allAWS assessment expires soon
Annual ICT Risk Assessment 2026 · due 18 Aug
Microsoft contract needs review
Exit strategy clause not documented
Stripe evidence expires next month
SOC 2 Type II report valid until 14 Sep
The problem
DORA third-party risk is still managed with spreadsheets, emails and fragmented tools.
Vendor information scattered across teams
Procurement, security and compliance each keep their own list of ICT providers and services.
Assessments managed manually
Questionnaires travel by email and spreadsheet, and progress is impossible to track.
Contracts difficult to review consistently
Article 30 requirements are checked differently by each reviewer, with no shared record.
DORA Register difficult to maintain
The Register is rebuilt from scratch each reporting cycle and drifts from operational reality.
The problem is not collecting more documents. It is keeping providers, services, evidence, contracts and risks continuously connected and up to date.
Platform
One system for the entire ICT third-party risk lifecycle.
Every object is connected, so a change in one place updates the record everywhere it matters.
ICT Provider
Criticality
Assessment
Evidence
Contract Review
Risk
Remediation
DORA Register
Provider → service → assessment → evidence → contract clause → risk → remediation → Register field. Each link is preserved as an auditable record.
ICT Providers
Know every ICT provider and what they support.
- Centralize ICT providers in one inventory
- Map ICT services to each provider
- Identify critical and important providers
- Track countries and data locations
- Link providers to critical or important functions
- Assign internal owners
ICT Providers
142 providers · 18 critical
| Provider | ICT Service | Criticality | Country | Risk |
|---|---|---|---|---|
| Amazon Web Services | Cloud Infrastructure | Critical | Ireland | High |
| Microsoft Ireland | Cloud & Productivity | Critical | Ireland | Medium |
| Stripe Payments Europe | Payment Processing | Critical | Ireland | High |
| Snowflake Netherlands | Data Platform | Important | Netherlands | Medium |
| Cloudflare Germany | Network & Security | Important | Germany | Low |
| Temenos | Core Banking | Critical | Switzerland | Medium |
Vendor Assessments
Run vendor assessments without chasing spreadsheets.
- Send structured DORA questionnaires
- Give vendors a self-service portal
- Track progress section by section
- Request evidence inside the questionnaire
- Review responses in a single workspace
- Identify potential gaps before sign-off
ASM-2041 · AWS Annual ICT Assessment
Under Review117 questions · 12 sections · vendor submitted 4 August 2026
Section progress
- Governance & Oversight100%
- Information Security92%
- Business Continuity64%
- Incident Management88%
- Subcontracting45%
Q 4.3 · Business Continuity
Describe the frequency and scope of your disaster recovery testing.
“DR testing is performed periodically across production regions.”
AI Finding
Confidence 94%Disaster recovery testing evidence is missing.
The response describes testing but no test report was attached for the current period. Requires human review before any compliance decision.
Reviewed by Sarah Martin · AI suggestions never change compliance status automatically.
AI Review
Let AI do the first review. Keep humans in control.
AI can review assessment responses, detect missing evidence, extract information from documents, analyze contracts and suggest potential risks. Every compliance decision stays with your team.
- Suggestions are always labelled and reviewable
- Findings carry a confidence score and a source reference
- Nothing changes compliance status without human approval
- AI features can be disabled per workspace
AI Finding
Confidence 94%Disaster recovery testing evidence is missing.
The response describes testing but no test report was attached for the current period. Requires human review before any compliance decision.
Reviewed by Sarah Martin · AI suggestions never change compliance status automatically.
Contract Review
Find DORA contract gaps faster.
Contract Coverage: 78% · 3 clauses need review.
- Audit rights
- Incident notification
- Regulatory access
- Subcontracting
- Business continuity
- Data location
- Termination
- Exit strategy
CTR-1002 · Microsoft Ireland Operations Ltd
3 clauses need reviewDORA Article 30 clause coverage · analysed 7 August 2026
Contract Coverage
78%
- Audit rightsCovered
- Incident notificationCovered
- Regulatory accessCovered
- SubcontractingNeeds Review
- Business continuityCovered
- Data locationNeeds Review
- TerminationCovered
- Exit strategyMissing
DORA Register of Information
Build and maintain your DORA Register continuously.
Connect providers, ICT services, contracts, critical functions and subcontractors so the Register stays aligned with your operational data.
Register of Information
Reporting entity: Northstar Financial Europe · LEI 549300XKZ9Q2P1F4T083
Register Completeness
91%
Errors
3
Warnings
9
Validation issues
- AWSMissing contractual arrangement reference.Error
- StripeSubcontractor country incomplete.Error
- MicrosoftExit strategy not documented.Error
- SnowflakeData location not confirmed by evidence.Warning
- TemenosFunction criticality pending sign-off.Warning
AWS
Missing contractual arrangement reference.
Stripe
Subcontractor country incomplete.
Microsoft
Exit strategy not documented.
Data lineage
Every regulatory field has a source.
Compliance teams can trace each regulatory value back to the operational record and the evidence it came from, with the person and date behind the last change.
- Trace Register fields to providers, services and contracts
- See which evidence document supports a value
- Know who changed a field and when
- Answer regulator questions without rebuilding the trail
Register field · lineage
Traceable- Field
- Data Location
- Value
- Germany
- Source
- Microsoft Azure Production Service
- Evidence
- Microsoft DPA
- Last Updated
- 12 July 2026
- Updated By
- Sarah Martin
Risk management
Turn findings into action.
- Create a risk directly from an assessment, evidence or contract finding
- Assign an owner and set severity
- Add a mitigation plan and due date
- Accept a risk with documented rationale
- Resolve risks and keep the full history
Risk Register
7 high risks · 18 open · linked to assessments, evidence and contracts
| ID | Risk | Provider | Severity | Status | Owner |
|---|---|---|---|---|---|
| RSK-311 | DR testing evidence not provided | AWS | High | Mitigation Planned | S. Martin |
| RSK-318 | Exit strategy absent from contract | Microsoft | High | Open | T. Weber |
| RSK-324 | Subcontractor countries incomplete | Stripe | Medium | In Review | L. Dubois |
| RSK-327 | Pen test older than 12 months | Snowflake | Medium | Open | S. Martin |
| RSK-330 | No documented incident SLA | Temenos | Low | Accepted | M. Rossi |
Evidence
Stop chasing expired compliance documents.
SOC 2, ISO 27001, penetration tests, business continuity plans and disaster recovery tests tracked as Valid, Expiring, Expired or Missing.
- Automated evidence requests to vendors
- Expiry tracking with early warnings
- Documents linked to providers, services and risks
- Review queue for newly submitted evidence
Evidence Library
418 documents · 23 missing · 11 expiring within 60 days
- Expires 30 Nov 2026Valid
SOC 2 Type II
Amazon Web Services
- Expires 21 Mar 2027Valid
ISO 27001
Microsoft Ireland
- Expires 14 Sep 2026Expiring
Penetration Test
Stripe Payments Europe
- Expired 2 Jun 2026Expired
Business Continuity Plan
Snowflake Netherlands
- Requested 4 Aug 2026Missing
Disaster Recovery Test
Amazon Web Services
Supply chain
See beyond your direct ICT providers.
Capture subcontractors, countries, data locations and dependencies associated with each ICT service.
- Record subcontractors declared during assessments
- Track country and data location per dependency
- Flag incomplete supply-chain records for the Register
- Understand concentration across shared providers
Your Organization
Northstar Financial Europe · Netherlands
AWS
ICT Provider · Ireland · Critical
ICT Service
Core hosting for payments platform
Subcontractor
Regional CDN partner · Germany
Executive visibility
See what needs attention today.
An operational view of provider risk, assessments, evidence gaps, contract gaps, outstanding risks and Register completeness — not static documentation.
DORA Third-Party Risk Overview
Northstar Financial Europe · updated 9 August 2026
DORA Readiness
84%
ICT Providers
142
Critical Providers
18
High Risks
7
Missing Evidence
23
Register Complete
91%
DORA Readiness
- ICT Provider Inventory96%
- Assessments82%
- Contract Coverage74%
- Evidence88%
- Register of Information91%
Attention Required
View allAWS assessment expires soon
Annual ICT Risk Assessment 2026 · due 18 Aug
Microsoft contract needs review
Exit strategy clause not documented
Stripe evidence expires next month
SOC 2 Type II report valid until 14 Sep
How it works
From vendor inventory to DORA-ready reporting.
- 1
Import ICT providers
- 2
Classify critical services
- 3
Launch assessments
- 4
Collect evidence
- 5
Review contracts
- 6
Track risks and remediation
- 7
Maintain the DORA Register
Who it is for
Built for regulated financial organizations.
Typically used by compliance, ICT risk, procurement and operational resilience teams. Whether a specific entity falls within DORA scope depends on its own regulatory analysis.
Why it is different
DORA workflows, not another generic GRC platform.
Security
Built for sensitive compliance data.
We label what is available today and what is planned. We do not claim certifications we do not hold.
Encryption in transit and at rest
AvailableRole-based access control
AvailableAudit logs
AvailableTenant isolation
AvailableEU data hosting
AvailableMulti-factor authentication
AvailableSSO / SAML
EnterpriseData retention controls
PlannedPricing
Plans that scale with your ICT provider portfolio.
Essential
€299/month
For smaller regulated organizations.
- Up to 50 ICT providers · 5 users
- Vendor Qualification Register
- Assessments, evidence and risk register
- Basic Article 30 Gap Register
- DORA Register and Management Body Report
- Basic resilience testing programme
Growth
Most Popular€799/month
For established compliance and ICT risk teams.
- Up to 250 ICT providers · 25 users
- Everything in Essential
- AI assessment, evidence and contract review
- Advanced Article 30 Gap Register
- Testing coverage analytics
- Priority support
Enterprise
Custom
For groups with multiple legal entities.
- Custom provider and user limits
- SSO / SAML sign-in
- SLA and dedicated support
- Multi-entity Register, SCIM, API — planned
Get your ICT third-party risk under control.
See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.