DORA Playbook - Part 1: Third Parties

Date
January 9, 2026
Industry
Payments

This playbook explores third-party oversight, critical ICT providers, lead overseers, information requests, investigations and practical compliance checklists

As DORA moves from implementation to active supervision, financial entities and ICT providers need to understand what direct regulatory oversight means in practice.

Part 1 of Vixio’s three-part DORA Playbook series focuses on third-party provisions, providing practical guidance to help compliance, risk, legal and senior management teams understand their responsibilities and prepare for regulatory scrutiny.

Inside, you’ll discover:

  • Critical ICT third-party providers: How criticality is assessed, including the quantitative and qualitative criteria used by the European Supervisory Authorities.
  • Direct regulatory oversight: What to expect from lead overseers, including information requests, reviews, investigations and inspections — and the potential consequences of non-compliance.
  • Practical compliance checklists: Key questions for corporate groups, compliance and risk teams, operations leaders, boards and senior management to assess their readiness.

This is Part 1 of a three-part series. Look out for Part 2: DORA Governance and Part 3: DORA Reporting, coming soon.

Master your next market

ake a closer look at how we track and simplify global regulatory shifts in real-time