DORA

Operationalize DORA third-party risk management.

DORA turns ICT third-party oversight into a continuous operational process. Northstar gives European financial organizations the system to run it: providers, assessments, contracts, evidence, risks and the Register of Information in one connected platform.

app.northstar-dora.eu/dashboard

DORA Third-Party Risk Overview

Northstar Financial Europe · updated 9 August 2026

DORA Readiness

84%

ICT Providers

142

Critical Providers

18

High Risks

7

Missing Evidence

23

Register Complete

91%

DORA Readiness

  • ICT Provider Inventory96%
  • Assessments82%
  • Contract Coverage74%
  • Evidence88%
  • Register of Information91%

Attention Required

View all
  • AWS assessment expires soon

    Annual ICT Risk Assessment 2026 · due 18 Aug

  • Microsoft contract needs review

    Exit strategy clause not documented

  • Stripe evidence expires next month

    SOC 2 Type II report valid until 14 Sep

Coverage

From inventory to reporting.

Each area maps to the operational work behind DORA ICT third-party risk requirements. Whether a specific obligation applies to your entity depends on your own regulatory analysis.

ICT provider inventory

One register of providers and the ICT services they deliver.

Criticality classification

Structured scoring to identify critical or important functions supported.

Vendor assessments

DORA-focused questionnaires with a vendor self-service portal.

Contract requirements

Clause-by-clause coverage analysis against Article 30 topics.

Subcontractor visibility

Capture dependencies, countries and data locations.

Risk management

Findings become tracked risks with owners and remediation.

Register of Information

Maintained continuously from your operational records.

Reporting

Board packs, audit packs and readiness reporting.

Inventory

Start from a provider inventory you trust.

Everything downstream — assessments, contracts, evidence and the Register — depends on knowing which providers support which functions.

  • Import existing provider lists
  • Map ICT services and data processed
  • Classify criticality with a documented method
  • Assign internal owners for accountability
app.northstar-dora.eu/providers

ICT Providers

142 providers · 18 critical

Add ICT Provider
AllCriticalHigh RiskAssessment OverdueMissing Evidence
ProviderICT ServiceCriticalityCountryRisk
Amazon Web ServicesCloud InfrastructureCriticalIrelandHigh
Microsoft IrelandCloud & ProductivityCriticalIrelandMedium
Stripe Payments EuropePayment ProcessingCriticalIrelandHigh
Snowflake NetherlandsData PlatformImportantNetherlandsMedium
Cloudflare GermanyNetwork & SecurityImportantGermanyLow
TemenosCore BankingCriticalSwitzerlandMedium

Register of Information

Reporting output, generated from live data.

Validation highlights errors and warnings before submission, so the Register reflects the same records your teams work in daily.

  • Register completeness tracked continuously
  • Errors and warnings surfaced per provider
  • Field-level lineage to source and evidence
  • Structured export when reporting is required
app.northstar-dora.eu/dora-register

Register of Information

Reporting entity: Northstar Financial Europe · LEI 549300XKZ9Q2P1F4T083

Export

Register Completeness

91%

Errors

3

Warnings

9

Validation issues

  • AWSMissing contractual arrangement reference.Error
  • StripeSubcontractor country incomplete.Error
  • MicrosoftExit strategy not documented.Error
  • SnowflakeData location not confirmed by evidence.Warning
  • TemenosFunction criticality pending sign-off.Warning

Workflow

A repeatable DORA operating rhythm.

Inventory
Classify
Assess
Collect evidence
Review contracts
Remediate risks
Maintain Register

Make DORA third-party risk operational.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.