ICT Vendor Assessment Checklist
The question areas a DORA-aligned vendor assessment should cover, with the additions that matter for cloud, payment and core banking providers.
Baseline for every provider
The baseline exists to confirm the provider has a functioning security and resilience posture and that your own records about them are accurate. Keep it short enough to be answered properly.
- Governance, certifications and audit history
- Access control, authentication and privileged access
- Incident management and notification timelines
- Business continuity and tested recovery objectives
- Data locations, transfers and retention
- Subcontractors used to deliver the service
Additions for cloud providers
For cloud services the interesting ground is the shared responsibility boundary, the tenancy and encryption model, regional failover behaviour and the concrete mechanics of exiting without a rebuild.
Additions for payment providers
Payment providers bring scheme obligations, settlement dependencies and their own downstream processors. Ask about transaction continuity, fallback routing and the notification path when settlement is delayed.
Additions for core banking
Core platforms are rarely substitutable at short notice. Focus on release and change management, data extraction rights, environment segregation and the realistic timeline for a supervised migration.
Scoring and follow-up
Score each area, mark the gaps and convert every material gap into a finding with an owner. An assessment that ends in a stored PDF has not reduced any risk.
Checklist
Work through it.
Print this, or use it as the acceptance criteria for your own programme.
Before sending
- Questionnaire tier matches provider criticality
- Contact and deadline confirmed with the vendor
- Prior evidence attached so nothing is re-requested
After response
- Every answer has supporting evidence where required
- Evidence is in date and in scope
- Gaps converted to findings with owners and dates
- Criticality reviewed against what the answers revealed
More
Other guides and checklists.
DORA ICT Third-Party Risk Guide
How ICT third-party oversight works in practice: inventory, criticality, assessments and continuous review.
Read GuideDORA Register of Information Guide
The structure of the Register, common data quality issues and how to keep it aligned with operations.
Read ChecklistDORA Contract Requirements Checklist
Clause topics to verify in ICT contracts, including audit rights, subcontracting and exit strategy.
ReadSee how this works in the product.
See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.