Skip to main content
Logo
European Insurance and Occupational Pensions Authority
 

DORA 261 - 3416

Q&A

Question ID: DORA 261 - 3416

Regulation Reference: (EU) 2022/2554 - Digital Operational Resilience Act (DORA)

Article: 3(5)

Status: Under Review

Date of submission: 09 Sep 2025

Question

Paragraph 5 of article 3 states that "financial entities, other than microenterprises, shall establish a role in order to monitor the arrangements concluded with ICT third-party service providers on the use of ICT services, or shall designate a member of senior management as responsible for overseeing the related risk exposure and relevant documentation". Given the Article 3, paragraph 5, of Delegated Regulation 2024/1773, what are the roles and responsabilities that are expected to be covered by the role/member of senior management?