DORA and AI in Financial Services: ICT Third-Party Risk for Model Providers
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied directly since 17 January 2025, turning AI and LLM vendors into regulated ICT third-party service providers. Compliance leaders in banking and insurance must govern registers, contracts, exit strategies and concentration risk accordingly.
What DORA is and why it applies from 17 January 2025
DORA is Regulation (EU) 2022/2554 of 14 December 2022, establishing a single framework for managing information and communication technology (ICT) risk across the EU financial sector. As a regulation it applies directly in every Member State without national transposition, and it has been applicable since 17 January 2025.
The text rests on five pillars, each corresponding to a chapter: ICT risk management, ICT-related incident handling and reporting, digital operational resilience testing, ICT third-party risk management, and information-sharing arrangements. For AI deployment the fourth pillar matters most, because it governs external technology dependencies.
- ICT risk management (Arts 5–16): a governance-anchored, proportionate framework.
- Incident reporting (Arts 17–23): classifying and reporting major incidents.
- Resilience testing (Arts 24–27): including threat-led penetration testing.
- ICT third-party risk (Arts 28–30): contractual duties and lifecycle governance.
- Information sharing (Art. 45): voluntary exchange of cyber-threat intelligence.
How AI and LLM providers become ICT third-party providers
DORA defines ICT services broadly. An externally sourced language model, a model API, a vector database or a hosted inference platform will typically fall within the ICT-service concept once the financial entity relies on it. Outsourcing to an AI provider transfers no regulatory responsibility: the financial entity remains fully accountable at all times.
The decisive step is classifying by critical or important functions. Where an AI service supports a function whose failure would materially impair business continuity or regulatory compliance, the enhanced requirements of Articles 28 and 30 apply — regardless of whether the provider is established inside or outside the EU.
Register, subcontracting and exit strategies
Under Article 28, financial entities must document all ICT third-party service arrangements in a register of information. The standard template is set by Implementing Regulation (EU) 2024/2956; it captures providers, contract scope, service locations, subcontractors and criticality classification, and also serves the authorities as a basis for designating critical providers.
Article 30 sets the mandatory contractual clauses; for critical or important functions, enhanced duties apply, including full audit and access rights, subcontracting conditions and documented exit strategies. An exit strategy must realistically address data portability, transition timelines and contingency arrangements — the assessment framework for subcontracting is further specified by Delegated Regulation (EU) 2025/532.
Critical-provider oversight and practical steps
Article 31 establishes an EU-wide oversight framework for ICT third-party providers designated as critical (CTPPs), coordinated by the three European Supervisory Authorities — EBA, EIOPA and ESMA — through an appointed Lead Overseer. On 18 November 2025 the authorities published the first official list of 19 designated critical providers. Because large cloud and AI infrastructures often rest on the same few vendors, concentration risk becomes a governance concern in its own right.
In practice, banks and insurers should treat their AI dependencies like any other critical ICT service: inventory, classify, contract robustly and test the exit. A central, auditable view of models, data flows and provider chains — the kind an AI-governance platform can provide — shortens the path from inventory to demonstrable compliance.
- Record every AI/LLM service in the register of information (Art. 28) and classify by criticality.
- Test contracts against Article 30; make subcontracting chains transparent.
- Build and feasibility-test exit strategies for critical functions.
- Assess concentration risk where several functions rely on the same provider.
Treat every AI and LLM service as an ICT third-party arrangement — inventory it, classify its criticality, secure the contract, and back it with a tested exit strategy before the function goes live.