Question ID: DORA 261 - 3416
Regulation Reference: (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Article: 3(5)
Status: Under Review
Date of submission: 09 Sep 2025
Question
Paragraph 5 of article 3 states that "financial entities, other than microenterprises, shall establish a role in order to monitor the arrangements concluded with ICT third-party service providers on the use of ICT services, or shall designate a member of senior management as responsible for overseeing the related risk exposure and relevant documentation". Given the Article 3, paragraph 5, of Delegated Regulation 2024/1773, what are the roles and responsabilities that are expected to be covered by the role/member of senior management?