All resources
Template9 min readICT risk, data owners

Third-Party Risk Template

A reference data structure for an ICT third-party risk programme: the records to keep, the fields on each, and the relationships that make DORA reporting possible.

Provider record

One record per legal entity you contract with, not per brand or per account manager.

  • Legal name, LEI, registered country, group parent
  • Relationship owner and business sponsor
  • Overall criticality and the date it was last approved
  • Status: onboarding, active, under review, exiting

Service record

The service is the governed unit. One provider can hold several with different criticality.

  • Service description and type of ICT service
  • Contractual arrangement it sits under
  • Business function supported and whether it is critical or important
  • Data categories, processing and storage locations
  • Substitutability and estimated replacement time

Risk and finding records

Findings come from assessments, contract reviews, incidents and evidence gaps. Risks are what you actively manage.

  • Source, description and affected service
  • Likelihood, impact and resulting score
  • Treatment decision: mitigate, accept, transfer, avoid
  • Owner, due date, status and closure evidence

Relationships that matter

Provider to arrangement, arrangement to service, service to function, service to subcontractor, finding to risk, risk to remediation. Every DORA report you will ever produce is a query across these links.

Template

Work through it.

Print this, or use it as the acceptance criteria for your own programme.

Data hygiene

  • One record per legal entity, deduplicated
  • Every service linked to a function
  • Every risk has an owner and a due date
  • Closed risks carry closure evidence

See how this works in the product.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.