Third-Party Risk After DORA: The Controls Financial Institutions Should Review Now
DORA has rightly concentrated attention on ICT resilience. But a business can still be operationally fragile because of dependencies that sit outside the neat boundary of “ICT third party”. Finance and operations should use the same discipline to ask a broader question: what would actually stop us operating?
The Digital Operational Resilience Act has forced financial institutions to become much more explicit about ICT risk, critical providers, incident management and resilience. That is a positive development. It has also created a useful side effect: many firms are finally mapping the third parties on which important processes depend.
The danger is stopping the exercise too early.
A critical dependency does not become harmless simply because it is not an ICT service. A payment institution may depend on a safeguarding bank, payroll provider, local accountant, card scheme, external reconciliation process, specialist compliance provider, outsourced operations team or data supplier. A fast-growing fintech may have one person who knows how a recurring regulatory submission actually gets completed. None of those examples fits comfortably into a simplistic “technology vendor” box, yet failure can still interrupt operations, reporting, cash access or regulatory obligations.
Start with the process, not the supplier register
Supplier registers are useful, but they are usually organised around contracts and procurement. Operational resilience works better in the opposite direction. Start with a critical process and ask what has to work for that process to complete on time and correctly.
For finance, that might mean month-end close, daily client-money reconciliations, liquidity monitoring, payroll, regulatory reporting, settlement, treasury payments or access to bank accounts. The dependency map is often broader than expected once each process is followed end to end.
Five controls worth reviewing
Finance owns more of this than it sometimes realises
Third-party risk is often assigned to procurement, technology, compliance or operational resilience. But finance commonly owns or co-owns the business processes in which the consequences become visible: inaccessible cash, missing reconciliations, delayed reporting, incorrect payments, failed close activities or lack of evidence for an auditor or regulator.
That makes finance an important participant in resilience design, not merely a recipient of vendor questionnaires.
What good looks like
A strong framework does not require a huge governance industry. For a smaller regulated business, a concise process inventory, dependency map, owner matrix and periodic review can be more useful than an elaborate policy nobody uses.
The important point is that the organisation can explain which dependencies are genuinely critical, why they matter, who owns them, what is monitored and what happens if they fail.
DORA provides a strong reason to improve that discipline for ICT risk. The same thinking is worth applying to the rest of the operating model.
Could you name your five most critical non-ICT third parties without opening your supplier register?
Clarensys helps regulated and control-heavy businesses map finance dependencies, strengthen ownership and controls, and turn policy requirements into processes that can actually be operated and evidenced.
Book a 30-minute conversation →This article is operational finance commentary, not legal advice. Regulatory interpretation should be confirmed with the appropriate legal or compliance advisers. For background on DORA, see the European Commission’s digital operational resilience material and Regulation (EU) 2022/2554.
