All resources
Reporting6 min read

Reporting ICT third-party risk to the board without noise

Under DORA the management body holds final responsibility for ICT risk, including third-party arrangements. That makes board reporting a control, not a courtesy, and it changes what belongs on the page.

Tomas Lindqvist · Principal, ICT Risk

Answer four questions

A useful pack is short and repeats the same structure each quarter so trends are visible.

  • Are we ready: register completeness, assessment coverage, contract coverage
  • Where is the exposure: critical functions by risk level and concentration
  • What is moving: new, escalated and closed findings since the last meeting
  • What needs a decision: accepted risks, overdue remediation, exit readiness gaps

Show trend, not snapshots

A single completeness figure is uninformative. The same figure across four quarters, with the reason for movement, tells the board whether the program is improving or absorbing headcount without effect.

Keep the detail one click away

Every headline number should be traceable to the underlying records. Boards ask follow-up questions, and the credibility of the pack rests on being able to open the specific provider, finding or contract behind a figure.

See how this works in the product.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.