In a detailed article, Bird & Bird has provided advice for organizations on how to update information and communication technology contracts in the financial services (FS) sector to take into account changes that are needed due to the EU Digital Operational Resilience Regulation (DORA). Compliance with DORA must be in place by 17th January 2025.
In ‘DORA – what do in-house lawyers need to know when updating their contracts?’ Bird & Bird experts point out the onus is on financial services entities to incorporate DORA into their contracts with ICT third party service providers. ‘Except for critical ICT third party service providers, DORA doesn’t apply to ICT third party service providers directly’, says the article: but all providers will need to be ‘very familiar with its requirements’.
The article considers various key DORA Articles and addresses some key questions, looking at
Can I rely on the proportionality principle?
FS entities need to comply with DORA but there is a degree of flexibility afforded to FS entities when implementing the DORA requirements in accordance with the principle of proportionality. FS entities are to implement compliance with DORA taking into account their size and overall risk profile, and the nature, scale and complexity of their services, activities and operations.
How do I categorise which contracts to remediate given the definition of ICT services is so broad and ICT services are a part of most contracts?
Article 30 relates to contracts between the FS entity and the ICT third party service providers for the provision of ICT services. The definition of ICT services has been deliberately drafted broadly to cover all types of ICT services. It is likely that FS entities will need to go through each vendor contract and on a case-by-case basis.
Article 30(1) of DORA
One of the frequently missed new contractual requirements imposed by DORA is the requirement to document ICT arrangements in one written document available to the parties on paper, or in a document with another downloadable, durable, and accessible format.
Article 30(2) of DORA
Article 30(2) sets out nine requirements that need to be included in all contracts between FS entities and ICT third party service providers providing ICT services.
Article 30(3) of DORA
In addition to the Article 30(2) requirements where a FS entity enters into a contract with an ICT third party service provider for ICT services supporting a critical or important function then the FS entity needs to comply with Article 30(3). This sets out more onerous requirements some of which may prove challenging for FS entities to incorporate into their contracts.
Will there be model clauses / standard contractual clauses published that I can use to meet the DORA requirements ?
Article 30(4) of DORA anticipates that standard contractual clauses may be developed to help companies with compliance with the requirements of Article 30 but, as yet, none have been published.






