ICT Providers
1. Roles & responsibilities
Appoint or introduce the role of compliance or regulatory officer to ensure that someone is managing this area for your business.
2. Know yourself
Undertake a preliminary self-assessment of your current clients to understand if your organisation is a critical provider.
3. Size the impact
Review the draft regulations to understand both the requirements from the DORA provisions (direct impact), and the requirements to be fulfilled under contractual arrangements with a financial entity (indirect impact).
4. Identify
Assess the “critical or important functions” with your product and technology leaders. Highlight areas that qualify as “vulnerabilities” and “ICT third-party risk” under the regulations. Match and prioritise them with your customer base.
5. Collaboration
Plan how you will communicate to your clients how you intend to align with them, to prepare a shared approach to DORA (also a relationship building opportunity).