Third-Party Risk Template
A reference data structure for an ICT third-party risk programme: the records to keep, the fields on each, and the relationships that make DORA reporting possible.
Provider record
One record per legal entity you contract with, not per brand or per account manager.
- Legal name, LEI, registered country, group parent
- Relationship owner and business sponsor
- Overall criticality and the date it was last approved
- Status: onboarding, active, under review, exiting
Service record
The service is the governed unit. One provider can hold several with different criticality.
- Service description and type of ICT service
- Contractual arrangement it sits under
- Business function supported and whether it is critical or important
- Data categories, processing and storage locations
- Substitutability and estimated replacement time
Risk and finding records
Findings come from assessments, contract reviews, incidents and evidence gaps. Risks are what you actively manage.
- Source, description and affected service
- Likelihood, impact and resulting score
- Treatment decision: mitigate, accept, transfer, avoid
- Owner, due date, status and closure evidence
Relationships that matter
Provider to arrangement, arrangement to service, service to function, service to subcontractor, finding to risk, risk to remediation. Every DORA report you will ever produce is a query across these links.
Template
Work through it.
Print this, or use it as the acceptance criteria for your own programme.
Data hygiene
- One record per legal entity, deduplicated
- Every service linked to a function
- Every risk has an owner and a due date
- Closed risks carry closure evidence
More
Other guides and checklists.
DORA ICT Third-Party Risk Guide
How ICT third-party oversight works in practice: inventory, criticality, assessments and continuous review.
Read GuideDORA Register of Information Guide
The structure of the Register, common data quality issues and how to keep it aligned with operations.
Read ChecklistICT Vendor Assessment Checklist
Question areas to cover for cloud, payment and core banking providers.
ReadSee how this works in the product.
See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.