DORA third-party contract review: Lumen Bankas UAB and Debesis Cloud UAB
Illustrative case with invented companies. This pack gives sources, not legal advice. Whether to accept the vendor's risk is the ICT risk lead's decision.
| Regulation | CELEX | data_as_of |
|---|---|---|
| DORA, Regulation (EU) 2022/2554 | 32022R2554 | 2026-09-02T09:05:48Z |
| GDPR, Regulation (EU) 2016/679 | 32016R0679 | 2026-09-02T09:05:48Z |
| EU AI Act, Regulation (EU) 2024/1689 | 32024R1689 | 2026-09-02T09:05:48Z |
| NIS2, Directive (EU) 2022/2555 | 32022L2555 | 2026-09-02T09:05:48Z |
The corpus does not hold the DORA technical standards (RTS/ITS), including the register-of-information templates, or any national law (such as Lithuanian implementing acts or competent-authority guidance). The playbooks used were dora-ict-third-party and then cross-reg-compliance-scan.
1. The arrangement
- Financial entity: Lumen Bankas UAB, a Lithuanian-licensed specialised bank with 140 staff. It is not a microenterprise, so the microenterprise exception in Article 30(3) does not apply.
- Provider: Debesis Cloud UAB, an ICT third-party service provider.
- Service: a hosted core-banking and loan-origination platform. It stores customer and loan data, including personal data, in two EU data centres and includes the vendor's AI credit-scoring module. The term is three years.
- Draft contract terms:
- a service description
- a 99.5% availability target
- the vendor may subcontract hosting without notice
- termination only for material breach, with 12 months' notice
- no audit right beyond an annual SOC 2 report
- no exit plan
Checkpoint: I treated this service as supporting a critical or important function. That brings in Article 30(3), Article 28(8) and Article 29 on top of Article 30(2). The test in Article 3(22) is a function "the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities". Core banking and loan origination appear to meet it. Article 28(4)(a) requires the bank to make this assessment formally before signing.
2. Clause checklist against DORA
"Covers" means the draft addresses the provision. "Partial" means it touches the provision but falls short of the text. "Misses" means the draft conflicts with the provision. "Silent" means the draft does not mention it.
Article 30(1): form
| # | Requirement (official text) | Draft |
|---|---|---|
| 1 | "The full contract shall include the service level agreements and be documented in one written document"; rights and obligations "clearly allocated and set out in writing" (Art 30(1)) | Silent. It is unclear whether the SLA sits inside a single written document. |
Article 30(2): minimum content of every ICT contract
| # | Requirement | Draft |
|---|---|---|
| 2 | "a clear and complete description of all functions and ICT services … indicating whether subcontracting of an ICT service supporting a critical or important function, or material parts thereof, is permitted and, when that is the case, the conditions applying to such subcontracting" (Art 30(2)(a)) | Partial / misses. The service description exists. Subcontracting is allowed, but with no conditions and no notice. |
| 3 | "the locations, namely the regions or countries, where the contracted or subcontracted functions and ICT services are to be provided and where data is to be processed, including the storage location, and the requirement for the ICT third-party service provider to notify the financial entity in advance if it envisages changing such locations" (Art 30(2)(b)) | Partial. The draft says "two EU data centres" but names no countries or regions. It has no duty to give advance notice of a location change, and the free subcontracting clause could move processing. |
| 4 | "provisions on availability, authenticity, integrity and confidentiality in relation to the protection of data, including personal data" (Art 30(2)(c)) | Silent. |
| 5 | "provisions on ensuring access, recovery and return in an easily accessible format of personal and non-personal data … in the event of the insolvency, resolution or discontinuation of the business operations … or in the event of the termination" (Art 30(2)(d)) | Silent. |
| 6 | "service level descriptions, including updates and revisions thereof" (Art 30(2)(e)) | Covers (minimally). There is a 99.5% availability target. |
| 7 | "the obligation … to provide assistance to the financial entity at no additional cost, or at a cost that is determined ex-ante, when an ICT incident … occurs" (Art 30(2)(f)) | Silent. |
| 8 | "the obligation … to fully cooperate with the competent authorities and the resolution authorities of the financial entity, including persons appointed by them" (Art 30(2)(g)) | Silent. |
| 9 | "termination rights and related minimum notice periods … in accordance with the expectations of competent authorities and resolution authorities" (Art 30(2)(h)) | Partial. Termination exists only for material breach, with 12 months' notice. See line 10. |
| 10 | The contract must be terminable for: "(a) significant breach … (b) circumstances identified throughout the monitoring of ICT third-party risk that are deemed capable of altering the performance of the functions … (c) … evidenced weaknesses pertaining to its overall ICT risk management … (d) where the competent authority can no longer effectively supervise the financial entity" (Art 28(7)) | Misses (b), (c) and (d). Only ground (a) is roughly covered, as "material breach". |
| 11 | "the conditions for the participation of ICT third-party service providers in the financial entities' ICT security awareness programmes and digital operational resilience training in accordance with Article 13(6)" (Art 30(2)(i)) | Silent. |
Article 30(3): additional content for critical or important functions
| # | Requirement | Draft |
|---|---|---|
| 12 | "full service level descriptions … with precise quantitative and qualitative performance targets … to allow effective monitoring … and enable appropriate corrective actions to be taken, without undue delay, when agreed service levels are not met" (Art 30(3)(a)) | Partial. There is one quantitative target. There are no qualitative targets and no corrective-action mechanism. |
| 13 | "notice periods and reporting obligations … including notification of any development that might have a material impact on the ICT third-party service provider's ability to effectively provide the ICT services" (Art 30(3)(b)) | Silent. The "without notice" subcontracting clause points the other way. |
| 14 | "requirements … to implement and test business contingency plans and to have in place ICT security measures, tools and policies that provide an appropriate level of security" (Art 30(3)(c)) | Silent. A SOC 2 report is evidence, not a contractual duty. |
| 15 | "the obligation … to participate and fully cooperate in the financial entity's TLPT as referred to in Articles 26 and 27" (Art 30(3)(d)) | Silent. |
| 16 | "unrestricted rights of access, inspection and audit by the financial entity, or an appointed third party, and by the competent authority, and the right to take copies of relevant documentation on-site … not impeded or limited by other contractual arrangements" (Art 30(3)(e)(i)) | Misses. The draft allows nothing beyond the annual SOC 2 report. |
| 17 | "the right to agree on alternative assurance levels if other clients' rights are affected" (Art 30(3)(e)(ii)) | Silent. |
| 18 | "the obligation … to fully cooperate during the onsite inspections and audits performed by the competent authorities, the Lead Overseer, financial entity or an appointed third party" (Art 30(3)(e)(iii)) | Misses. |
| 19 | "the obligation to provide details on the scope, procedures to be followed and frequency of such inspections and audits" (Art 30(3)(e)(iv)) | Silent. |
| 20 | "exit strategies, in particular the establishment of a mandatory adequate transition period" during which the provider "will continue providing the respective functions" and which allows "the financial entity to migrate to another ICT third-party service provider or change to in-house solutions" (Art 30(3)(f)(i)–(ii)) | Misses. There is no exit plan. |
Related duties that sit on the bank, not in the contract
| # | Provision | Relevance |
|---|---|---|
| 21 | Art 28(1)(a): the bank must "at all times, remain fully responsible for compliance with, and the discharge of, all obligations under this Regulation" | Outsourcing does not transfer responsibility. |
| 22 | Art 28(4)(a)–(e): before signing, assess whether a critical or important function is supported, whether supervisory conditions are met, the risks including concentration, due diligence, and conflicts of interest | These are pre-signature steps. |
| 23 | Art 28(5): the bank "may only enter into contractual arrangements with ICT third-party service providers that comply with appropriate information security standards"; for critical or important functions it must consider the "most up-to-date and highest quality information security standards" | SOC 2 is one input to this. |
| 24 | Art 28(6): the bank must "pre-determine the frequency of audits and inspections as well as the areas to be audited" | The bank cannot do this without a contractual audit right (line 16). |
| 25 | Art 28(8): the bank must have exit strategies and exit plans that are "comprehensive, documented and … sufficiently tested and reviewed periodically", plus transition plans to "securely and integrally transfer" the services and data | The internal exit plan is also missing. |
| 26 | Art 29(1): concentration risk, including "contracting an ICT third-party service provider that is not easily substitutable" | This is relevant for a core-banking platform. |
| 27 | Art 29(2): the bank must weigh the benefits and risks of subcontracting and assess "potentially long or complex chains of subcontracting"; it must also consider insolvency law for urgent data recovery | This applies directly to the "subcontract without notice" clause. |
| 28 | Art 30(4): the parties "shall consider the use of standard contractual clauses developed by public authorities" | Consider during the negotiation. |
| 29 | Art 30(5): the subcontracting conditions under Art 30(2)(a) are specified further in an RTS | Not held. |
3. Register of information entry (Article 28(3))
Under Article 28(3), the bank must:
- Record the arrangement in the register, which must be kept "at entity level, and at sub-consolidated and consolidated levels", covering "all contractual arrangements on the use of ICT services provided by ICT third-party service providers".
- Classify it as covering ICT services that support a critical or important function. Arrangements must be "appropriately documented, distinguishing between those that cover ICT services supporting critical or important functions and those that do not".
- Report at least yearly "on the number of new arrangements on the use of ICT services, the categories of ICT third-party service providers, the type of contractual arrangements and the ICT services and functions which are being provided". For this entry that means:
- provider: Debesis Cloud UAB
- service: hosted core banking and loan origination, with an AI credit-scoring module
- functions supported: core banking and lending
- Give the register to the competent authority on request, either the "full register of information or, as requested, specified sections thereof".
- Tell the competent authority in advance. The bank must "inform the competent authority in a timely manner about any planned contractual arrangement on the use of ICT services supporting critical or important functions". This must happen before signing.
The standard templates are in the implementing technical standards required by Art 28(9). The corpus does not hold those ITS, so this pack does not list the template fields. Which authority is competent, and any national reporting channel, is also outside the corpus.
4. Other regulations the contract touches
These are kept separate from the DORA conclusions above.
GDPR (32016R0679): Debesis appears to act as a processor for customer and loan data
- Art 28(2): "The processor shall not engage another processor without prior specific or general written authorisation of the controller." Where authorisation is general, the processor must tell the controller about changes and give it "the opportunity to object". This conflicts with "subcontract hosting without notice".
- Art 28(3): the contract must set out "the subject-matter and duration of the processing, the nature and purpose … the type of personal data and categories of data subjects". It must also contain clauses (a) to (h), including:
- (g) delete or return data at the controller's choice
- (h) "allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller"
The draft's SOC 2-only position falls short of (h).
- Art 28(4): a sub-processor must carry the same obligations, and "the initial processor shall remain fully liable to the controller".
- Art 32(1): security measures, including "the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident".
- Art 35(1): a DPIA is required where processing "using new technologies … is likely to result in a high risk". AI credit scoring is a likely trigger, but that is Lumen's decision.
- Art 22(1): data subjects have "the right not to be subject to a decision based solely on automated processing, including profiling". This bears on how the scoring module is used.
EU AI Act (32024R1689): the credit-scoring module
- Annex III, point 5(b): "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud". Art 6(2) makes Annex III systems high-risk. This is subject to the Art 6(3) derogation, which I did not assess.
- Lumen is the deployer. The contract should support these duties:
- Art 26(1): use the system according to the instructions for use. The contract should require the provider to supply them.
- Art 26(2): assign human oversight.
- Art 26(5): monitor operation. For financial institutions this duty is "deemed to be fulfilled by complying with the rules on internal governance arrangements" under financial services law.
- Art 26(6): keep logs "to the extent such logs are under their control", for at least six months. The contract should give Lumen access to the logs.
- Art 26(9): use the provider's Art 13 information for the GDPR DPIA.
- Art 26(11): inform the natural persons affected.
- Art 27(1): deployers of point 5(b) systems "shall perform an assessment of the impact on fundamental rights" before deploying.
- Debesis's duties as provider (Arts 16 onward) and the date the Annex III obligations apply were not read in this run.
NIS2 (32022L2555)
- Art 4(1): where sector-specific Union acts impose requirements that are "at least equivalent in effect", the relevant NIS2 provisions "shall not apply to such entities". For Lumen's side, DORA is the operative text. Debesis may have its own NIS2 obligations as a cloud provider, but those are not a term of this contract. National transposition is not held.
Not covered: the Cyber Resilience Act was not scanned. Search pages were capped at 25 hits, so matches were left unshown:
- DORA "ICT third-party" search: 25 of 339 shown
- DORA critical-function search: 25 of 192 shown
- AI Act credit-scoring search: 25 of 135 shown
- NIS2 search: 25 of 266 shown
- the cross-regulation search: capped at 25 per module
5. Gaps to negotiate
These are sources for the negotiation, not redrafted clauses.
- Audit and access (Art 30(3)(e)(i)–(iv), Art 28(6); GDPR Art 28(3)(h)). The draft allows only a SOC 2 report. The text requires unrestricted access, inspection and audit rights for the bank, a third party it appoints, and the competent authority, plus a duty to cooperate.
- Exit (Art 30(3)(f), Art 30(2)(d), Art 28(8); GDPR Art 28(3)(g)). There is no transition period and no provision for data return, recovery or access on insolvency or termination. The bank's own exit plan is also missing.
- Subcontracting (Art 30(2)(a), Art 29(2); GDPR Art 28(2) and 28(4)). The "without notice" clause conflicts with both acts. Conditions, notice, a right to object and flow-down of obligations are needed.
- Termination (Art 28(7)(b)–(d), Art 30(2)(h)). Only material breach is covered. The supervisory and risk-monitoring grounds are missing. Whether 12 months' notice is right is a question of what the competent authority expects, which the corpus does not hold.
- Locations (Art 30(2)(b)). The countries or regions must be named, with advance notice of any change.
- Service levels (Art 30(3)(a)–(b)). Qualitative targets, corrective actions, and notice or reporting of material developments are needed.
- Security, business continuity and TLPT (Art 30(2)(c), Art 30(3)(c)–(d)). Data-protection and security obligations, contingency-plan testing and TLPT participation are missing.
- Incident assistance and authority cooperation (Art 30(2)(f)–(g)).
- Training participation (Art 30(2)(i)).
- Single written document (Art 30(1)).
- AI module support for deployer duties (AI Act Arts 26(1), 26(6), 26(9) and 27(1)): instructions for use, access to logs, and the Art 13 information.
- Before signing: complete the Art 28(4) assessment and the Art 29 concentration check, notify the competent authority under Art 28(3), and create the register entry.
6. Citations checked
All pinpoints below were run through verify_citation with a quote from this pack. Every one returned exists: held, quote: found.
- DORA: Art 3(22), 28(1), 28(3), 28(4), 28(5), 28(6), 28(7), 28(8), 28(9), 29(1), 29(2), 30(1), 30(2), 30(3), 30(4), 30(5).
- GDPR: Art 22(1), 28(2), 28(3), 28(4), 32(1), 35(1).
- EU AI Act: Art 6(2), Annex III point 5(b), Art 26(1), 26(2), 26(5), 26(6), 26(9), 26(11), 27(1).
- The Annex III check was run as "Annex III(5)" but resolved at the annex level ("ANNEX III"). The quote from point 5(b) was found.
- NIS2: Art 4(1).
Sub-points such as 30(2)(a)–(i) and 30(3)(a)–(f) were checked through their parent paragraph and the full article text returned by read_unit.
I did not record any assessments with record_assessment. Applicability verdicts are for the ICT risk lead to state.