DORA Contract Requirements Checklist
The contractual provisions DORA Article 30 expects in ICT arrangements, split between the baseline set and the additional requirements for services supporting critical or important functions.
Baseline provisions for every ICT arrangement
These apply regardless of criticality. They are also the ones most often missing from older contracts signed before DORA applied.
- Clear description of the ICT services supplied
- Locations where services are provided and data is processed
- Data protection, availability, integrity and confidentiality provisions
- Assistance on ICT incidents at no additional cost or at agreed cost
- Cooperation with competent authorities
- Termination rights and notice periods
Additional provisions for critical or important functions
Where the service supports a critical or important function, the arrangement needs more: service levels with precise quantitative targets, full audit and inspection rights, participation in your testing programme, and exit arrangements that are genuinely executable.
- Quantitative performance targets and remedies
- Unrestricted audit, access and inspection rights
- Cooperation with threat-led penetration testing
- Notification obligations for material subcontracting changes
- Exit strategy with transition support and data return
Reviewing at portfolio scale
Reviewing every contract manually against twenty clause topics is where legal teams lose months. Automated clause mapping narrows the work to the gaps: which arrangements lack audit rights, which have no exit provisions, which are silent on subcontracting.
Keep a lawyer in the loop on every conclusion. The value of automation here is triage, not judgement.
Remediating gaps
Gaps rarely close at once. Prioritise by criticality and renewal date: arrangements supporting critical functions that renew this year get addenda now; low-criticality gaps go into the renewal cycle.
Checklist
Work through it.
Print this, or use it as the acceptance criteria for your own programme.
Every arrangement
- Service description and locations are specified
- Data protection provisions are present
- Incident assistance obligations are defined
- Authority cooperation clause is present
- Termination rights are workable
Critical or important functions
- Quantitative service levels with remedies
- Unrestricted audit and inspection rights
- Testing cooperation clause
- Subcontracting notification and objection rights
- Documented, executable exit strategy
More
Other guides and checklists.
DORA ICT Third-Party Risk Guide
How ICT third-party oversight works in practice: inventory, criticality, assessments and continuous review.
Read GuideDORA Register of Information Guide
The structure of the Register, common data quality issues and how to keep it aligned with operations.
Read ChecklistICT Vendor Assessment Checklist
Question areas to cover for cloud, payment and core banking providers.
ReadSee how this works in the product.
See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.