DORA · ICT providers

Critical by Designation by Kai London

DORA reaches beyond regulated firms to the providers they depend on. If you supply ICT services to financial entities, the contractual demands have already changed — and designation as critical brings direct oversight. This book explains the regime from the provider's side of the relationship.

Coming soonAll books

What the book covers

Designation and what follows

How a provider comes to be treated as critical, and the oversight relationship that results.

Contractual requirements

The provisions financial entities must obtain — service levels, access, audit, incident notification, termination — and how to negotiate them realistically.

Subcontracting chains

Disclosure, control and flow-down where material parts of the service are delivered by others.

Register of information

What customers must record, and the data a provider should be ready to supply consistently.

Resilience testing and evidence

Supporting customers' testing programmes without exposing the estate or duplicating effort endlessly.

Exit and substitutability

Credible exit plans, data portability and transition assistance obligations.

General guidance, not legal advice; take qualified advice on your own position. Independent, with no endorsement by or affiliation with any regulator, supervisory or oversight authority.

DORANIS2ISO 27001Operational resilience

Who it is for

Cloud, SaaS and managed-service providers to financial institutions, their legal, commercial and compliance teams, and the third-party risk functions at financial entities on the other side.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.