{
  "attribution": {
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/api/public/v1/compliance",
    "cite_as": "NovaCopilot, legal.exploreworldai.com (https://legal.exploreworldai.com/api/public/v1/compliance)",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-10-05",
    "fingerprint": "ewai:eu:dded38",
    "proof": "sha256:92666ddaec7901afdae30601243fd1bb2148c1227f894a299dab96ef945b0d8d",
    "jurisdiction": "eu",
    "lang": "en",
    "publisher": "NovaCopilot by ExploreWorld Legal",
    "terms": "https://legal.exploreworldai.com/om"
  },
  "brand_source": "Source: NovaCopilot",
  "brand": {
    "product": "NovaCopilot",
    "platform": "ExploreWorldAI",
    "infrastructure": "ExploreWorld Legal",
    "infrastructure_url": "legal.exploreworldai.com",
    "legal_entity": "Valkiv Ventures AB",
    "permanent_url": "https://legal.exploreworldai.com/novacopilot",
    "source": "Source: NovaCopilot",
    "powered_by": "Powered by NovaCopilot",
    "license": "https://legal.exploreworldai.com/licensvillkor",
    "contact": "stig@valkiv.com"
  },
  "item": {
    "schema_version": "1.0.0",
    "id": "compliance:dora:financial-entity",
    "act": {
      "id": "dora",
      "slug": "dora-2022-2554",
      "celex": "32022R2554",
      "name": "DORA: Regulation (EU) 2022/2554",
      "official_source": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj",
      "consolidated": null,
      "in_force": "2023-01-16",
      "applies": "2025-01-17",
      "applies_kind": "application"
    },
    "role": "financial-entity",
    "obligations": [
      {
        "article": "5",
        "title": "Governance and organisation",
        "duty": "The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for it.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/dora-2022-2554/artikel-5",
        "obligation_id": "obligation:eu:dora-art-5-financial-entity",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-5-financial-entity",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 5",
          "title": "Governance and organisation",
          "paragraphs": [
            "1. Financial entities shall have in place an internal governance and control framework that ensures an effective and prudent management of ICT risk, in accordance with Article 6(4), in order to achieve a high level of digital operational resilience.",
            "2. The management body of the financial entity shall define, approve, oversee and be responsible for the implementation of all arrangements related to the ICT risk management framework referred to in Article 6(1).",
            "For the purposes of the first subparagraph, the management body shall:",
            "(a) bear the ultimate responsibility for managing the financial entity’s ICT risk;",
            "(b) put in place policies that aim to ensure the maintenance of high standards of availability, authenticity, integrity and confidentiality, of data;",
            "(c) set clear roles and responsibilities for all ICT-related functions and establish appropriate governance arrangements to ensure effective and timely communication, cooperation and coordination among those functions;",
            "(d) bear the overall responsibility for setting and approving the digital operational resilience strategy as referred to in Article 6(8), including the determination of the appropriate risk tolerance level of ICT risk of the financial entity, as referred to in Article 6(8), point (b);",
            "(e) approve, oversee and periodically review the implementation of the financial entity’s ICT business continuity policy and ICT response and recovery plans, referred to, respectively, in Article 11(1) and (3), which may be adopted as a dedicated specific policy forming an integral part of the financial entity’s overall business continuity policy and response and recovery plan;",
            "(f)"
          ],
          "truncated": true,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022R2554#art_5",
          "read_at": "2026-08-18",
          "sha256": "21b8b12dacc5ac51dca15e6963c14fc00ded6b379fe51adfb5be060083ec35a0",
          "complete": false,
          "completeness_note": "Utdraget omfattar artikelns första stycken, ordagrant. Resten av artikeln finns på official_url. Citera aldrig utdraget som hela artikeln."
        }
      },
      {
        "article": "6",
        "title": "ICT risk management framework",
        "duty": "Maintain a sound, comprehensive and documented ICT risk management framework.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/dora-2022-2554/artikel-6",
        "obligation_id": "obligation:eu:dora-art-6-financial-entity",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-6-financial-entity",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 6",
          "title": "ICT risk management framework",
          "paragraphs": [
            "1. Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system, which enables them to address ICT risk quickly, efficiently and comprehensively and to ensure a high level of digital operational resilience.",
            "2. The ICT risk management framework shall include at least strategies, policies, procedures, ICT protocols and tools that are necessary to duly and adequately protect all information assets and ICT assets, including computer software, hardware, servers, as well as to protect all relevant physical components and infrastructures, such as premises, data centres and sensitive designated areas, to ensure that all information assets and ICT assets are adequately protected from risks including damage and unauthorised access or usage.",
            "3. In accordance with their ICT risk management framework, financial entities shall minimise the impact of ICT risk by deploying appropriate strategies, policies, procedures, ICT protocols and tools. They shall provide complete and updated information on ICT risk and on their ICT risk management framework to the competent authorities upon their request.",
            "4. Financial entities, other than microenterprises, shall assign the responsibility for managing and overseeing ICT risk to a control function and ensure an appropriate level of independence of such control function in order to avoid conflicts of interest. Financial entities shall ensure appropriate segregation and independence of ICT risk management functions, control functions, and internal audit functions, according to the three lines of defence model, or an internal risk management and control model.",
            "5. The ICT risk management framework shall be documented and reviewed at least once a year, or periodically in the case of microenterprises, as well as upon the occurrence of major ICT-related incidents, and following supervisory instructions or conclusions derived from relevant digital operational resilience testing or audit processes. It shall be continuously improved on the basis of lessons derived from implementation and monitoring. A report on the review of the ICT risk management framework shall be submitted to the competent authority upon its request.",
            "6. The ICT risk management framework of financial entities, other than microenterprises, shall be subject to internal audit by auditors on a regular basis in line with the financial entities’ audit plan. Those auditors shall possess sufficient knowledge, skills and expertise in ICT risk, as well as appropriate independence. The frequency and focus of ICT audits shall be commensurate to the ICT risk of the financial entity.",
            "7. Based on the conclusions from the internal audit review, financial entities shall establish a formal follow-up process, including rules for the timely verification and remediation of critical ICT audit findings.",
            "8. The ICT risk management framework shall include a digital operational resilience strategy setting out how the framework shall be implemented. To that end, the digital operational resilience strategy shall include methods to address ICT risk and attain specific ICT objectives, by:",
            "(a) explaining how the ICT risk management framework supports the financial entity’s business strategy and objectives;",
            "(b) establishing the risk tolerance level for ICT risk, in accordance with the risk appetite of the financial entity, and analysing the impact tolerance for ICT disruptions;",
            "(c) setting out clear information security objectives, including key performance indicators and key risk metrics;"
          ],
          "truncated": true,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022R2554#art_6",
          "read_at": "2026-08-18",
          "sha256": "aefb30c475edc5a56addedbbc6e1f475aca570f00c53c7d93b2ef25467b9fced",
          "complete": false,
          "completeness_note": "Utdraget omfattar artikelns första stycken, ordagrant. Resten av artikeln finns på official_url. Citera aldrig utdraget som hela artikeln."
        }
      },
      {
        "article": "11",
        "title": "Response and recovery",
        "duty": "Put in place an ICT business continuity policy with response and recovery plans.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/dora-2022-2554/artikel-11",
        "obligation_id": "obligation:eu:dora-art-11-financial-entity",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-11-financial-entity",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 11",
          "title": "Response and recovery",
          "paragraphs": [
            "1. As part of the ICT risk management framework referred to in Article 6(1) and based on the identification requirements set out in Article 8, financial entities shall put in place a comprehensive ICT business continuity policy, which may be adopted as a dedicated specific policy, forming an integral part of the overall business continuity policy of the financial entity.",
            "2. Financial entities shall implement the ICT business continuity policy through dedicated, appropriate and documented arrangements, plans, procedures and mechanisms aiming to:",
            "(a) ensure the continuity of the financial entity’s critical or important functions;",
            "(b) quickly, appropriately and effectively respond to, and resolve, all ICT-related incidents in a way that limits damage and prioritises the resumption of activities and recovery actions;",
            "(c) activate, without delay, dedicated plans that enable containment measures, processes and technologies suited to each type of ICT-related incident and prevent further damage, as well as tailored response and recovery procedures established in accordance with Article 12;",
            "(d) estimate preliminary impacts, damages and losses;",
            "(e) set out communication and crisis management actions that ensure that updated information is transmitted to all relevant internal staff and external stakeholders in accordance with Article 14, and report to the competent authorities in accordance with Article 19.",
            "3. As part of the ICT risk management framework referred to in Article 6(1), financial entities shall implement associated ICT response and recovery plans which, in the case of financial entities other than microenterprises, shall be subject to independent internal audit reviews.",
            "4. Financial entities shall put in place, maintain and periodically test appropriate ICT business continuity plans, notably with regard to critical or important functions outsourced or contracted through arrangements with ICT third-party service providers."
          ],
          "truncated": true,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022R2554#art_11",
          "read_at": "2026-08-18",
          "sha256": "13975647dd66fb4a51c9a5dfde9a0cdb0dce3a17db74115259e3fea4133bc3e1",
          "complete": false,
          "completeness_note": "Utdraget omfattar artikelns första stycken, ordagrant. Resten av artikeln finns på official_url. Citera aldrig utdraget som hela artikeln."
        }
      },
      {
        "article": "17",
        "title": "ICT-related incident management process",
        "duty": "Define and implement an ICT-related incident management process.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/dora-2022-2554/artikel-17",
        "obligation_id": "obligation:eu:dora-art-17-financial-entity",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-17-financial-entity",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 17",
          "title": "ICT-related incident management process",
          "paragraphs": [
            "1. Financial entities shall define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents.",
            "2. Financial entities shall record all ICT-related incidents and significant cyber threats. Financial entities shall establish appropriate procedures and processes to ensure a consistent and integrated monitoring, handling and follow-up of ICT-related incidents, to ensure that root causes are identified, documented and addressed in order to prevent the occurrence of such incidents.",
            "3. The ICT-related incident management process referred to in paragraph 1 shall:",
            "(a) put in place early warning indicators;",
            "(b) establish procedures to identify, track, log, categorise and classify ICT-related incidents according to their priority and severity and according to the criticality of the services impacted, in accordance with the criteria set out in Article 18(1);",
            "(c) assign roles and responsibilities that need to be activated for different ICT-related incident types and scenarios;",
            "(d) set out plans for communication to staff, external stakeholders and media in accordance with Article 14 and for notification to clients, for internal escalation procedures, including ICT-related customer complaints, as well as for the provision of information to financial entities that act as counterparts, as appropriate;",
            "(e) ensure that at least major ICT-related incidents are reported to relevant senior management and inform the management body of at least major ICT-related incidents, explaining the impact, response and additional controls to be established as a result of such ICT-related incidents;",
            "(f)"
          ],
          "truncated": true,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022R2554#art_17",
          "read_at": "2026-08-18",
          "sha256": "b6b12b9d7cb74c43d9e5163a456353cab3002440b81b22eeac2b307cd7953597",
          "complete": false,
          "completeness_note": "Utdraget omfattar artikelns första stycken, ordagrant. Resten av artikeln finns på official_url. Citera aldrig utdraget som hela artikeln."
        }
      },
      {
        "article": "19",
        "title": "Reporting of major ICT-related incidents and voluntary notification of significant cyber threats",
        "duty": "Report major ICT-related incidents to the competent authority.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/dora-2022-2554/artikel-19",
        "obligation_id": "obligation:eu:dora-art-19-financial-entity",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-19-financial-entity",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 19",
          "title": "Reporting of major ICT-related incidents and voluntary notification of significant cyber threats",
          "paragraphs": [
            "1. Financial entities shall report major ICT-related incidents to the relevant competent authority as referred to in Article 46 in accordance with paragraph 4 of this Article.",
            "Where a financial entity is subject to supervision by more than one national competent authority referred to in Article 46, Member States shall designate a single competent authority as the relevant competent authority responsible for carrying out the functions and duties provided for in this Article.",
            "Credit institutions classified as significant, in accordance with Article 6(4) of Regulation (EU) No 1024/2013, shall report major ICT-related incidents to the relevant national competent authority designated in accordance with Article 4 of Directive 2013/36/EU, which shall immediately transmit that report to the ECB.",
            "For the purpose of the first subparagraph, financial entities shall produce, after collecting and analysing all relevant information, the initial notification and reports referred to in paragraph 4 of this Article using the templates referred to in Article 20 and submit them to the competent authority. In the event that a technical impossibility prevents the submission of the initial notification using the template, financial entities shall notify the competent authority about it via alternative means.",
            "The initial notification and reports referred to in paragraph 4 shall include all information necessary for the competent authority to determine the significance of the major ICT-related incident and assess possible cross-border impacts.",
            "Without prejudice to the reporting pursuant to the first subparagraph by the financial entity to the relevant competent authority, Member States may additionally determine that some or all financial entities shall also provide the initial notification and each report referred to in paragraph 4 of this Article using the templates referred to in Article 20 to the competent authorities or the computer security incident response teams (CSIRTs) designated or established in accordance with Directive (EU) 2022/2555.",
            "2. Financial entities may, on a voluntary basis, notify significant cyber threats to the relevant competent authority when they deem the threat to be of relevance to the financial system, service users or clients. The relevant competent authority may provide such information to other relevant authorities referred to in paragraph 6.",
            "Credit institutions classified as significant, in accordance with Article 6(4) of Regulation (EU) No 1024/2013, may, on a voluntary basis, notify significant cyber threats to relevant national competent authority, designated in accordance with Article 4 of Directive 2013/36/EU, which shall immediately transmit the notification to the ECB.",
            "Member States may determine that those financial entities that on a voluntary basis notify in accordance with the first subparagraph may also transmit that notification to the CSIRTs designated or established in accordance with Directive (EU) 2022/2555.",
            "3. Where a major ICT-related incident occurs and has an impact on the financial interests of clients, financial entities shall, without undue delay as soon as they become aware of it, inform their clients about the major ICT-related incident and about the measures that have been taken to mitigate the adverse effects of such incident.",
            "In the case of a significant cyber threat, financial entities shall, where applicable, inform their clients that are potentially affected of any appropriate protection measures which the latter may consider taking.",
            "4. Financial entities shall, within the time limits to be laid down in accordance with Article 20, first paragraph, point (a), point (ii), submit the following to the relevant competent authority:",
            "(a) an initial notification;"
          ],
          "truncated": true,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022R2554#art_19",
          "read_at": "2026-08-18",
          "sha256": "bec97cfc444361e56ed35b180bfa01d7726581f8dc0aaf19abca99c09d1a874d",
          "complete": false,
          "completeness_note": "Utdraget omfattar artikelns första stycken, ordagrant. Resten av artikeln finns på official_url. Citera aldrig utdraget som hela artikeln."
        }
      },
      {
        "article": "24",
        "title": "General requirements for the performance of digital operational resilience testing",
        "duty": "Establish a digital operational resilience testing programme.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/dora-2022-2554/artikel-24",
        "obligation_id": "obligation:eu:dora-art-24-financial-entity",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-24-financial-entity",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 24",
          "title": "General requirements for the performance of digital operational resilience testing",
          "paragraphs": [
            "1. For the purpose of assessing preparedness for handling ICT-related incidents, of identifying weaknesses, deficiencies and gaps in digital operational resilience, and of promptly implementing corrective measures, financial entities, other than microenterprises, shall, taking into account the criteria set out in Article 4(2), establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk-management framework referred to in Article 6.",
            "2. The digital operational resilience testing programme shall include a range of assessments, tests, methodologies, practices and tools to be applied in accordance with Articles 25 and 26.",
            "3. When conducting the digital operational resilience testing programme referred to in paragraph 1 of this Article, financial entities, other than microenterprises, shall follow a risk-based approach taking into account the criteria set out in Article 4(2) duly considering the evolving landscape of ICT risk, any specific risks to which the financial entity concerned is or might be exposed, the criticality of information assets and of services provided, as well as any other factor the financial entity deems appropriate.",
            "4. Financial entities, other than microenterprises, shall ensure that tests are undertaken by independent parties, whether internal or external. Where tests are undertaken by an internal tester, financial entities shall dedicate sufficient resources and ensure that conflicts of interest are avoided throughout the design and execution phases of the test.",
            "5. Financial entities, other than microenterprises, shall establish procedures and policies to prioritise, classify and remedy all issues revealed throughout the performance of the tests and shall establish internal validation methodologies to ascertain that all identified weaknesses, deficiencies or gaps are fully addressed.",
            "6. Financial entities, other than microenterprises, shall ensure, at least yearly, that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions."
          ],
          "truncated": false,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022R2554#art_24",
          "read_at": "2026-08-18",
          "sha256": "48c9a0da4180fb648d0a3426bb31d691f7ec3a87fd57ff45505e46f90239aacc",
          "complete": true,
          "completeness_note": "Hela artikeln, ordagrant."
        }
      },
      {
        "article": "26",
        "title": "Advanced testing of ICT tools, systems and processes based on TLPT",
        "duty": "Carry out threat-led penetration testing where identified by the competent authority.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/dora-2022-2554/artikel-26",
        "obligation_id": "obligation:eu:dora-art-26-financial-entity",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-26-financial-entity",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 26",
          "title": "Advanced testing of ICT tools, systems and processes based on TLPT",
          "paragraphs": [
            "1. Financial entities, other than entities referred to in Article 16(1), first subparagraph, and other than microenterprises, which are identified in accordance with paragraph 8, third subparagraph, of this Article, shall carry out at least every 3 years advanced testing by means of TLPT. Based on the risk profile of the financial entity and taking into account operational circumstances, the competent authority may, where necessary, request the financial entity to reduce or increase this frequency.",
            "2. Each threat-led penetration test shall cover several or all critical or important functions of a financial entity, and shall be performed on live production systems supporting such functions.",
            "Financial entities shall identify all relevant underlying ICT systems, processes and technologies supporting critical or important functions and ICT services, including those supporting the critical or important functions which have been outsourced or contracted to ICT third-party service providers.",
            "Financial entities shall assess which critical or important functions need to be covered by the TLPT. The result of this assessment shall determine the precise scope of TLPT and shall be validated by the competent authorities.",
            "3. Where ICT third-party service providers are included in the scope of TLPT, the financial entity shall take the necessary measures and safeguards to ensure the participation of such ICT third-party service providers in the TLPT and shall retain at all times full responsibility for ensuring compliance with this Regulation.",
            "4. Without prejudice to paragraph 2, first and second subparagraphs, where the participation of an ICT third-party service provider in the TLPT, referred to in paragraph 3, is reasonably expected to have an adverse impact on the quality or security of services delivered by the ICT third-party service provider to customers that are entities falling outside the scope of this Regulation, or on the confidentiality of the data related to such services, the financial entity and the ICT third-party service provider may agree in writing that the ICT third-party service provider directly enters into contractual arrangements with an external tester, for the purpose of conducting, under the direction of one designated financial entity, a pooled TLPT involving several financial entities (pooled testing) to which the ICT third-party service provider provides ICT services.",
            "That pooled testing shall cover the relevant range of ICT services supporting critical or important functions contracted to the respective ICT third-party service provider by the financial entities. The pooled testing shall be considered TLPT carried out by the financial entities participating in the pooled testing.",
            "The number of financial entities participating in the pooled testing shall be duly calibrated taking into account the complexity and types of services involved.",
            "5. Financial entities shall, with the cooperation of ICT third-party service providers and other parties involved, including the testers but excluding the competent authorities, apply effective risk management controls to mitigate the risks of any potential impact on data, damage to assets, and disruption to critical or important functions, services or operations at the financial entity itself, its counterparts or to the financial sector.",
            "6. At the end of the testing, after reports and remediation plans have been agreed, the financial entity and, where applicable, the external testers shall provide to the authority, designated in accordance with paragraph 9 or 10, a summary of the relevant findings, the remediation plans and the documentation demonstrating that the TLPT has been conducted in accordance with the requirements.",
            "7. Authorities shall provide financial entities with an attestation confirming that the test was performed in accordance with the requirements as evidenced in the documentation in order to allow for mutual recognition of threat led penetration tests between competent authorities. The financial entity shall notify the relevant competent authority of the attestation, the summary of the relevant findings and the remediation plans.",
            "Without prejudice to such attestation, financial entities shall remain at all times fully responsible for the impact of the tests referred to in paragraph 4.",
            "8. Financial entities shall contract testers for the purposes of undertaking TLPT in accordance with Article 27. When financial entities use internal testers for the purposes of undertaking TLPT, they shall contract external testers every three tests.",
            "Credit institutions that are classified as significant in accordance with Article 6(4) of Regulation (EU) No 1024/2013, shall only use external testers in accordance with Article 27(1), points (a) to (e)."
          ],
          "truncated": true,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022R2554#art_26",
          "read_at": "2026-08-18",
          "sha256": "f96eb3003ca5456226b9041ec5c3d9145de685ff1eb5f9e131b2f5ccdda873c6",
          "complete": false,
          "completeness_note": "Utdraget omfattar artikelns första stycken, ordagrant. Resten av artikeln finns på official_url. Citera aldrig utdraget som hela artikeln."
        }
      },
      {
        "article": "28",
        "title": "General principles",
        "duty": "Manage ICT third-party risk and keep a register of information on all ICT service contracts.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/dora-2022-2554/artikel-28",
        "obligation_id": "obligation:eu:dora-art-28-financial-entity",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-28-financial-entity",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 28",
          "title": "General principles",
          "paragraphs": [
            "1. Financial entities shall manage ICT third-party risk as an integral component of ICT risk within their ICT risk management framework as referred to in Article 6(1), and in accordance with the following principles:",
            "(a) financial entities that have in place contractual arrangements for the use of ICT services to run their business operations shall, at all times, remain fully responsible for compliance with, and the discharge of, all obligations under this Regulation and applicable financial services law;",
            "(b) financial entities’ management of ICT third-party risk shall be implemented in light of the principle of proportionality, taking into account:",
            "(i) the nature, scale, complexity and importance of ICT-related dependencies,",
            "(ii) the risks arising from contractual arrangements on the use of ICT services concluded with ICT third-party service providers, taking into account the criticality or importance of the respective service, process or function, and the potential impact on the continuity and availability of financial services and activities, at individual and at group level.",
            "2. As part of their ICT risk management framework, financial entities, other than entities referred to in Article 16(1), first subparagraph, and other than microenterprises, shall adopt, and regularly review, a strategy on ICT third-party risk, taking into account the multi-vendor strategy referred to in Article 6(9), where applicable. The strategy on ICT third-party risk shall include a policy on the use of ICT services supporting critical or important functions provided by ICT third-party service providers and shall apply on an individual basis and, where relevant, on a sub-consolidated and consolidated basis. The management body shall, on the basis of an assessment of the overall risk profile of the financial entity and the scale and complexity of the business services, regularly review the risks identified in respect to contractual arrangements on the use of ICT services supporting critical or important functions.",
            "3. As part of their ICT risk management framework, financial entities shall maintain and update at entity level, and at sub-consolidated and consolidated levels, a register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers.",
            "The contractual arrangements referred to in the first subparagraph shall be appropriately documented, distinguishing between those that cover ICT services supporting critical or important functions and those that do not.",
            "Financial entities shall report at least yearly to the competent authorities on the number of new arrangements on the use of ICT services, the categories of ICT third-party service providers, the type of contractual arrangements and the ICT services and functions which are being provided.",
            "Financial entities shall make available to the competent authority, upon its request, the full register of information or, as requested, specified sections thereof, along with any information deemed necessary to enable the effective supervision of the financial entity."
          ],
          "truncated": true,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022R2554#art_28",
          "read_at": "2026-08-18",
          "sha256": "9d15cdea2ce2f3ab26645fa8ad89b17dd33258ca4daddc5417d355e5bd3a4401",
          "complete": false,
          "completeness_note": "Utdraget omfattar artikelns första stycken, ordagrant. Resten av artikeln finns på official_url. Citera aldrig utdraget som hela artikeln."
        }
      },
      {
        "article": "30",
        "title": "Key contractual provisions",
        "duty": "Include the key contractual provisions in contracts with ICT third-party service providers.",
        "page": "https://legal.exploreworldai.com/eu/rattsakter/dora-2022-2554/artikel-30",
        "obligation_id": "obligation:eu:dora-art-30-financial-entity",
        "obligation_object": "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-30-financial-entity",
        "duty_kind": "summary",
        "source_text": {
          "content_kind": "official_text",
          "lang": "en",
          "label": "Article 30",
          "title": "Key contractual provisions",
          "paragraphs": [
            "1. The rights and obligations of the financial entity and of the ICT third-party service provider shall be clearly allocated and set out in writing. The full contract shall include the service level agreements and be documented in one written document which shall be available to the parties on paper, or in a document with another downloadable, durable and accessible format.",
            "2. The contractual arrangements on the use of ICT services shall include at least the following elements:",
            "(a) a clear and complete description of all functions and ICT services to be provided by the ICT third-party service provider, indicating whether subcontracting of an ICT service supporting a critical or important function, or material parts thereof, is permitted and, when that is the case, the conditions applying to such subcontracting;",
            "(b) the locations, namely the regions or countries, where the contracted or subcontracted functions and ICT services are to be provided and where data is to be processed, including the storage location, and the requirement for the ICT third-party service provider to notify the financial entity in advance if it envisages changing such locations;",
            "(c) provisions on availability, authenticity, integrity and confidentiality in relation to the protection of data, including personal data;",
            "(d) provisions on ensuring access, recovery and return in an easily accessible format of personal and non-personal data processed by the financial entity in the event of the insolvency, resolution or discontinuation of the business operations of the ICT third-party service provider, or in the event of the termination of the contractual arrangements;",
            "(e) service level descriptions, including updates and revisions thereof;",
            "(f) the obligation of the ICT third-party service provider to provide assistance to the financial entity at no additional cost, or at a cost that is determined ex-ante, when an ICT incident that is related to the ICT service provided to the financial entity occurs;"
          ],
          "truncated": true,
          "official_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX%3A32022R2554#art_30",
          "read_at": "2026-08-18",
          "sha256": "f579127bbe641e20e69cf693657391a4b5227fd7d71eba6e758b0b17d6694a15",
          "complete": false,
          "completeness_note": "Utdraget omfattar artikelns första stycken, ordagrant. Resten av artikeln finns på official_url. Citera aldrig utdraget som hela artikeln."
        }
      }
    ],
    "national_implementation": [],
    "read_at": "2026-08-31",
    "sha256": "7ed0b9e1124f0428407c197d599c4f80bcbf8055076f3d11531bae5259a8b940",
    "industries": [
      "banking",
      "insurance"
    ],
    "freshness": {
      "index": 61,
      "readAt": "2026-08-31",
      "ageDays": 35,
      "cadenceDays": 30,
      "nextCheck": "2026-09-30",
      "state": "due",
      "stateLabel": "Omläsning inplanerad"
    },
    "stay_current": {
      "cursor": "MjAyNi0wOS0xMH5zZX52aXNzZWxibGFzYXJsYWdlbg",
      "chain_hash": "b2e9562b24e7de637742b1660609c2d36eb107fbb6c5ca8041be4979b823290d",
      "changes": "https://legal.exploreworldai.com/api/public/v1/changes/cursor?after=MjAyNi0wOS0xMH5zZX52aXNzZWxibGFzYXJsYWdlbg",
      "verify": "https://legal.exploreworldai.com/api/public/v1/changes/verify?cursor=MjAyNi0wOS0xMH5zZX52aXNzZWxibGFzYXJsYWdlbg&chain_hash=b2e9562b24e7de637742b1660609c2d36eb107fbb6c5ca8041be4979b823290d",
      "poll_after_seconds": 3600
    },
    "permanent_url": "https://legal.exploreworldai.com/api/public/v1/compliance?act=dora-2022-2554&role=financial-entity",
    "method": "Skyldigheter ur registrets egna rader, artikel för artikel. Inget tolkas eller läggs till.",
    "official_text_coverage": {
      "quoted": 9,
      "total": 9
    },
    "content_kind_rule": "Endast source_text är lagens egen lydelse. duty är en kort sammanfattning, ej juristgranskad."
  },
  "explore": {
    "brand_source": "Source: NovaCopilot",
    "brand": {
      "product": "NovaCopilot",
      "platform": "ExploreWorldAI",
      "infrastructure": "ExploreWorld Legal",
      "infrastructure_url": "legal.exploreworldai.com",
      "legal_entity": "Valkiv Ventures AB",
      "permanent_url": "https://legal.exploreworldai.com/novacopilot",
      "source": "Source: NovaCopilot",
      "powered_by": "Powered by NovaCopilot",
      "license": "https://legal.exploreworldai.com/licensvillkor",
      "contact": "stig@valkiv.com"
    },
    "data_model": "https://legal.exploreworldai.com/api/public/v1/data-model",
    "relations": "https://legal.exploreworldai.com/api/public/v1/relations?id=compliance%3Adora-2022-2554%3Afinancial-entity",
    "risk": "https://legal.exploreworldai.com/api/public/v1/risk?id=compliance%3Adora-2022-2554%3Afinancial-entity",
    "changes": "https://legal.exploreworldai.com/api/public/v1/changes/cursor",
    "partner_entries": "https://legal.exploreworldai.com/api/public/v1/partner-entry",
    "source": "Source: NovaCopilot"
  },
  "hash": "sha256:92666ddaec7901afdae30601243fd1bb2148c1227f894a299dab96ef945b0d8d",
  "version": "legal-2026-10-05",
  "expires": "2026-10-07T00:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-10-05+legal-2026-10-05+2026-10-05T15:24:01",
    "content_hash": "sha256:92666ddaec7901afdae30601243fd1bb2148c1227f894a299dab96ef945b0d8d",
    "revalidate_after": "2026-10-05T16:35:17.133Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; attribution-preferred",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/api/public/v1/compliance",
  "disclaimer": "Source reference with official identifier. Not legal advice and not a compliance decision.",
  "content_notice": {
    "legal_advice": false,
    "nature": "Source register. Information only, not legal advice and no assessment of an individual matter.",
    "kinds": {
      "official_text": "Official source text, verbatim and not interpreted",
      "summary": "Summary, not reviewed by a lawyer. Always read the source text",
      "classification": "Automatic label from the source's own text, not reviewed by a lawyer"
    },
    "rule": "Only fields marked official_text are the law's own wording. Everything else points to it.",
    "report_error": "https://legal.exploreworldai.com/api/public/v1/corrections",
    "ai_act_declaration": "https://legal.exploreworldai.com/api/public/v1/ai-act-declaration"
  },
  "usageInfo": "https://legal.exploreworldai.com/citering"
}