Rekvira

Jobs / ICT risk or security lead

DORA third-party contract review

“A new or renewing ICT contract has landed and it has to meet DORA before anyone signs.”

2.1 min55 tool calls34 sources read32 citations verified

Recorded 23 September 2026 on the live service with Claude Code 2.1.280 (headless: claude -p), model claude-opus-5-5.

Today Financial institutions hold an average of 147 ICT third-party arrangements, each of which must now meet DORA's requirements (EBA 2024 survey, as reported by Legiscope). Survey: Legiscope, reporting a 2024 EBA survey

The run

Each step is a Rekvira playbook your assistant reads and follows. Open a step to see every call it made and what came back.

  1. Connected and read what the corpus holds today

    2 tool calls · under 1 s
    Show the 2 calls
    RekviraConnected, no accountconnect0.1 s
    connect({})
    RekviraRead what the corpus holds todaystart_here0.1 s
    start_here({})
  2. Read DORA's rules for ICT contracts and the register, then searched the other acts the contract touches

    21 tool calls · 24 s
    Show the 21 calls
    RekviraOpened the playbook dora-ict-third-partyget_workflow0.0 s
    get_workflow({"workflow_id": "dora-ict-third-party"})
    RekviraOpened the playbook cross-reg-compliance-scanget_workflow0.0 s
    get_workflow({"workflow_id": "cross-reg-compliance-scan"})
    RekviraChecked which acts are loaded and their dateslist_regulations0.0 s
    list_regulations({})
    • eu-ai-act EU AI Act
    • dora DORA (Digital Operational Resilience Act)
    • gdpr GDPR (General Data Protection Regulation)
    RekviraSearched dora for “ICT third-party risk contractual arrangements”search_regulation1.0 s
    search_regulation({"regulation": "dora", "query": "ICT third-party risk contractual arrangements"})
    • Article 1(1)
    • Article 28(1)
    • Article 28(2)
    RekviraArticle 28, full textread_unit0.5 s
    read_unit({"regulation": "dora", "kind": "article", "number": 28})
    • Article 28 Financial entities shall manage ICT third-party risk as an integral component of ICT risk within their ICT risk management framework as referred to in Article 6(1), and in accordance with the following principles: (a) financial entities that have in place cont
    RekviraArticle 30, full textread_unit0.1 s
    read_unit({"regulation": "dora", "kind": "article", "number": 30})
    • Article 30 The rights and obligations of the financial entity and of the ICT third-party service provider shall be clearly allocated and set out in writing. The full contract shall include the service level agreements and be documented in one written document which shall
    RekviraArticle 29, full textread_unit0.0 s
    read_unit({"regulation": "dora", "kind": "article", "number": 29})
    • Article 29 When performing the identification and assessment of risks referred to in Article 28(4), point (c), financial entities shall also take into account whether the envisaged conclusion of a contractual arrangement in relation to ICT services supporting critical or
    RekviraSearched dora for “critical or important function means”search_regulation0.1 s
    search_regulation({"regulation": "dora", "query": "critical or important function means", "kinds": ["paragraph"]})
    • Article 3, amendment (10)
    • Article 3, amendment (22)
    • Article 3, amendment (29)
    RekviraSearched every loaded act for “processor contract sub-processor audit personal data”search_regulations0.3 s
    search_regulations({"query": "processor contract sub-processor audit personal data", "regulations": ["gdpr", "eu-ai-act", "nis2"]})
    RekviraArticle 28, full textread_unit0.1 s
    read_unit({"regulation": "gdpr", "kind": "article", "number": 28})
    • Article 28 Where processing is to be carried out on behalf of a controller, the controller shall use only processors providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that processing will meet the requirements
    RekviraSearched eu-ai-act for “creditworthiness credit score natural persons”search_regulation0.1 s
    search_regulation({"regulation": "eu-ai-act", "query": "creditworthiness credit score natural persons"})
    • ANNEX III(5)
    • Article 5(1)
    • Article 2(10)
    RekviraANNEX III, full textread_unit0.0 s
    read_unit({"regulation": "eu-ai-act", "kind": "annex", "number": "III"})
    • ANNEX III Biometrics, in so far as their use is permitted under relevant Union or national law: (a) (a) remote biometric identification systems. This shall not include AI systems intended to be u
    RekviraArticle 26, full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "article", "number": 26})
    • Article 26 Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systems, pursuant to paragraphs 3 and 6. Deployers shall assign human o
    RekviraArticle 3, amendment (22), full textread_unit0.0 s
    read_unit({"regulation": "dora", "pinpoint": "Article 3(22)"})
    • Article 3, amendment (22) ‘critical or important function’ means a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities, or the discontinued, defective or failed performa
    RekviraSearched nis2 for “sector-specific Union legal act equivalent Regulation (EU) 2022/2554”search_regulation0.0 s
    search_regulation({"regulation": "nis2", "query": "sector-specific Union legal act equivalent Regulation (EU) 2022/2554"})
    • Article 13(4)
    • Article 7(1)
    • Article 4(1)
    RekviraArticle 4(1), full textread_unit0.0 s
    read_unit({"regulation": "nis2", "kind": "paragraph", "number": 1, "article": 4})
    • Article 4(1) Where sector-specific Union legal acts require essential or important entities to adopt cybersecurity risk-management measures or to notify significant incidents and where those requirements are at least equivalent in effect to the obligations laid down in thi
    RekviraArticle 6(2), full textread_unit0.0 s
    read_unit({"regulation": "eu-ai-act", "kind": "paragraph", "number": 2, "article": 6})
    • Article 6(2) In addition to the high-risk AI systems referred to in paragraph 1, AI systems referred to in Annex III shall be considered to be high-risk.
    RekviraArticle 27(1), full textread_unit0.1 s
    read_unit({"regulation": "eu-ai-act", "kind": "paragraph", "number": 1, "article": 27})
    • Article 27(1) Prior to deploying a high-risk AI system referred to in Article 6(2), with the exception of high-risk AI systems intended to be used in the area listed in point 2 of Annex III, deployers that are bodies governed by public law, or are private entities providing
    RekviraArticle 32(1), full textread_unit0.1 s
    read_unit({"regulation": "gdpr", "kind": "paragraph", "number": 1, "article": 32})
    • Article 32(1) Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the proces
    RekviraArticle 35(1), full textread_unit0.1 s
    read_unit({"regulation": "gdpr", "kind": "paragraph", "number": 1, "article": 35})
    • Article 35(1) Where a type of processing in particular using new technologies, and taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, prior to
    RekviraArticle 22(1), full textread_unit0.1 s
    read_unit({"regulation": "gdpr", "kind": "paragraph", "number": 1, "article": 22})
    • Article 22(1) The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
  3. You confirm. Confirm whether the service supports a critical or important function, which adds contract provisions.

    In this run: Checkpoint: I treated this service as supporting a critical or important function. That brings in Article 30(3), Article 28(8) and Article 29 on top of Article 30(2). The test in Article 3(22) is a function *"the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities"*. Core banking and loan origination appear to meet it. Article 28(4)(a) requires the bank to make this assessment formally before signing.

  4. Checked every citation against the official text

    32 tool calls · 28 s
    Show the 32 calls
    RekviraArticle 3(22): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 3(22)", "regulation": "dora", "quote": "the disruption of which would materially impair the financial performance of a financial entity"})
    • Article 3, amendment (22) exists: held · quote: found
    RekviraArticle 28(1): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 28(1)", "regulation": "dora", "quote": "remain fully responsible for compliance with, and the discharge of, all obligations under this Regulation and applicable financial services law"})
    • Article 28(1) exists: held · quote: found
    RekviraArticle 28(3): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 28(3)", "regulation": "dora", "quote": "distinguishing between those that cover ICT services supporting critical or important functions and those that do not"})
    • Article 28(3) exists: held · quote: found
    RekviraArticle 28(4): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 28(4)", "regulation": "dora", "quote": "undertake all due diligence on prospective ICT third-party service providers"})
    • Article 28(4) exists: held · quote: found
    RekviraArticle 28(5): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 28(5)", "regulation": "dora", "quote": "most up-to-date and highest quality information security standards"})
    • Article 28(5) exists: held · quote: found
    RekviraArticle 28(6): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 28(6)", "regulation": "dora", "quote": "pre-determine the frequency of audits and inspections as well as the areas to be audited"})
    • Article 28(6) exists: held · quote: found
    RekviraArticle 28(7): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 28(7)", "regulation": "dora", "quote": "significant breach by the ICT third-party service provider of applicable laws, regulations or contractual terms"})
    • Article 28(7) exists: held · quote: found
    RekviraArticle 28(8): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 28(8)", "regulation": "dora", "quote": "Exit plans shall be comprehensive, documented and, in accordance with the criteria set out in Article 4(2), shall be sufficiently tested and reviewed periodically."})
    • Article 28(8) exists: held · quote: found
    RekviraArticle 28(9): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 28(9)", "regulation": "dora", "quote": "standard templates for the purposes of the register of information"})
    • Article 28(9) exists: held · quote: found
    RekviraArticle 29(1): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 29(1)", "regulation": "dora", "quote": "contracting an ICT third-party service provider that is not easily substitutable"})
    • Article 29(1) exists: held · quote: found
    RekviraArticle 29(2): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 29(2)", "regulation": "dora", "quote": "potentially long or complex chains of subcontracting"})
    • Article 29(2) exists: held · quote: found
    RekviraArticle 30(1): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 30(1)", "regulation": "dora", "quote": "The full contract shall include the service level agreements and be documented in one written document"})
    • Article 30(1) exists: held · quote: found
    RekviraArticle 30(2): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 30(2)", "regulation": "dora", "quote": "the requirement for the ICT third-party service provider to notify the financial entity in advance if it envisages changing such locations"})
    • Article 30(2) exists: held · quote: found
    RekviraArticle 30(3): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 30(3)", "regulation": "dora", "quote": "unrestricted rights of access, inspection and audit by the financial entity, or an appointed third party, and by the competent authority"})
    • Article 30(3) exists: held · quote: found
    RekviraArticle 30(4): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 30(4)", "regulation": "dora", "quote": "shall consider the use of standard contractual clauses developed by public authorities for specific services"})
    • Article 30(4) exists: held · quote: found
    RekviraArticle 30(5): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 30(5)", "regulation": "dora", "quote": "when subcontracting ICT services supporting critical or important functions"})
    • Article 30(5) exists: held · quote: found
    RekviraArticle 28(2): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 28(2)", "regulation": "gdpr", "quote": "The processor shall not engage another processor without prior specific or general written authorisation of the controller."})
    • Article 28(2) exists: held · quote: found
    RekviraArticle 28(3): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 28(3)", "regulation": "gdpr", "quote": "allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller"})
    • Article 28(3) exists: held · quote: found
    RekviraArticle 28(4): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 28(4)", "regulation": "gdpr", "quote": "the initial processor shall remain fully liable to the controller for the performance of that other processor's obligations"})
    • Article 28(4) exists: held · quote: found
    RekviraArticle 32(1): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 32(1)", "regulation": "gdpr", "quote": "the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident"})
    • Article 32(1) exists: held · quote: found
    RekviraArticle 35(1): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 35(1)", "regulation": "gdpr", "quote": "the controller shall, prior to the processing, carry out an assessment of the impact of the envisaged processing operations on the protection of personal data"})
    • Article 35(1) exists: held · quote: found
    RekviraArticle 22(1): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 22(1)", "regulation": "gdpr", "quote": "the right not to be subject to a decision based solely on automated processing, including profiling"})
    • Article 22(1) exists: held · quote: found
    RekviraArticle 6(2): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 6(2)", "regulation": "eu-ai-act", "quote": "AI systems referred to in Annex III shall be considered to be high-risk"})
    • Article 6(2) exists: held · quote: found
    RekviraAnnex III(5): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Annex III(5)", "regulation": "eu-ai-act", "quote": "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud"})
    • ANNEX III exists: held · quote: found
    RekviraArticle 26(1): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 26(1)", "regulation": "eu-ai-act", "quote": "use such systems in accordance with the instructions for use accompanying the systems"})
    • Article 26(1) exists: held · quote: found
    RekviraArticle 26(2): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 26(2)", "regulation": "eu-ai-act", "quote": "Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority"})
    • Article 26(2) exists: held · quote: found
    RekviraArticle 26(5): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 26(5)", "regulation": "eu-ai-act", "quote": "the monitoring obligation set out in the first subparagraph shall be deemed to be fulfilled by complying with the rules on internal governance arrangements"})
    • Article 26(5) exists: held · quote: found
    RekviraArticle 26(6): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 26(6)", "regulation": "eu-ai-act", "quote": "shall keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control"})
    • Article 26(6) exists: held · quote: found
    RekviraArticle 26(9): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 26(9)", "regulation": "eu-ai-act", "quote": "use the information provided under Article 13 of this Regulation to comply with their obligation to carry out a data protection impact assessment"})
    • Article 26(9) exists: held · quote: found
    RekviraArticle 26(11): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 26(11)", "regulation": "eu-ai-act", "quote": "shall inform the natural persons that they are subject to the use of the high-risk AI system"})
    • Article 26(11) exists: held · quote: found
    RekviraArticle 27(1): held, quoted words foundverify_citation0.0 s
    verify_citation({"citation": "Article 27(1)", "regulation": "eu-ai-act", "quote": "deployers of high-risk AI systems referred to in points 5 (b) and (c) of Annex III, shall perform an assessment of the impact on fundamental rights"})
    • Article 27(1) exists: held · quote: found
    RekviraArticle 4(1): held, quoted words foundverify_citation0.1 s
    verify_citation({"citation": "Article 4(1)", "regulation": "nis2", "quote": "the relevant provisions of this Directive, including the provisions on supervision and enforcement laid down in Chapter VII, shall not apply to such entities"})
    • Article 4(1) exists: held · quote: found

What it produced: the contract review pack

Word for word what the assistant wrote at the end of the run. The company in it is invented for this demonstration; the regulation text, pinpoints and checks are what Rekvira returned.

DORA third-party contract review: Lumen Bankas UAB and Debesis Cloud UAB

Illustrative case with invented companies. This pack gives sources, not legal advice. Whether to accept the vendor's risk is the ICT risk lead's decision.

RegulationCELEXdata_as_of
DORA, Regulation (EU) 2022/255432022R25542026-09-02T09:05:48Z
GDPR, Regulation (EU) 2016/67932016R06792026-09-02T09:05:48Z
EU AI Act, Regulation (EU) 2024/168932024R16892026-09-02T09:05:48Z
NIS2, Directive (EU) 2022/255532022L25552026-09-02T09:05:48Z

The corpus does not hold the DORA technical standards (RTS/ITS), including the register-of-information templates, or any national law (such as Lithuanian implementing acts or competent-authority guidance). The playbooks used were dora-ict-third-party and then cross-reg-compliance-scan.


1. The arrangement

  • Financial entity: Lumen Bankas UAB, a Lithuanian-licensed specialised bank with 140 staff. It is not a microenterprise, so the microenterprise exception in Article 30(3) does not apply.
  • Provider: Debesis Cloud UAB, an ICT third-party service provider.
  • Service: a hosted core-banking and loan-origination platform. It stores customer and loan data, including personal data, in two EU data centres and includes the vendor's AI credit-scoring module. The term is three years.
  • Draft contract terms:
  • a service description
  • a 99.5% availability target
  • the vendor may subcontract hosting without notice
  • termination only for material breach, with 12 months' notice
  • no audit right beyond an annual SOC 2 report
  • no exit plan

Checkpoint: I treated this service as supporting a critical or important function. That brings in Article 30(3), Article 28(8) and Article 29 on top of Article 30(2). The test in Article 3(22) is a function "the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities". Core banking and loan origination appear to meet it. Article 28(4)(a) requires the bank to make this assessment formally before signing.

2. Clause checklist against DORA

"Covers" means the draft addresses the provision. "Partial" means it touches the provision but falls short of the text. "Misses" means the draft conflicts with the provision. "Silent" means the draft does not mention it.

Article 30(1): form
#Requirement (official text)Draft
1"The full contract shall include the service level agreements and be documented in one written document"; rights and obligations "clearly allocated and set out in writing" (Art 30(1))Silent. It is unclear whether the SLA sits inside a single written document.
Article 30(2): minimum content of every ICT contract
#RequirementDraft
2"a clear and complete description of all functions and ICT services … indicating whether subcontracting of an ICT service supporting a critical or important function, or material parts thereof, is permitted and, when that is the case, the conditions applying to such subcontracting" (Art 30(2)(a))Partial / misses. The service description exists. Subcontracting is allowed, but with no conditions and no notice.
3"the locations, namely the regions or countries, where the contracted or subcontracted functions and ICT services are to be provided and where data is to be processed, including the storage location, and the requirement for the ICT third-party service provider to notify the financial entity in advance if it envisages changing such locations" (Art 30(2)(b))Partial. The draft says "two EU data centres" but names no countries or regions. It has no duty to give advance notice of a location change, and the free subcontracting clause could move processing.
4"provisions on availability, authenticity, integrity and confidentiality in relation to the protection of data, including personal data" (Art 30(2)(c))Silent.
5"provisions on ensuring access, recovery and return in an easily accessible format of personal and non-personal data … in the event of the insolvency, resolution or discontinuation of the business operations … or in the event of the termination" (Art 30(2)(d))Silent.
6"service level descriptions, including updates and revisions thereof" (Art 30(2)(e))Covers (minimally). There is a 99.5% availability target.
7"the obligation … to provide assistance to the financial entity at no additional cost, or at a cost that is determined ex-ante, when an ICT incident … occurs" (Art 30(2)(f))Silent.
8"the obligation … to fully cooperate with the competent authorities and the resolution authorities of the financial entity, including persons appointed by them" (Art 30(2)(g))Silent.
9"termination rights and related minimum notice periods … in accordance with the expectations of competent authorities and resolution authorities" (Art 30(2)(h))Partial. Termination exists only for material breach, with 12 months' notice. See line 10.
10The contract must be terminable for: "(a) significant breach … (b) circumstances identified throughout the monitoring of ICT third-party risk that are deemed capable of altering the performance of the functions … (c) … evidenced weaknesses pertaining to its overall ICT risk management … (d) where the competent authority can no longer effectively supervise the financial entity" (Art 28(7))Misses (b), (c) and (d). Only ground (a) is roughly covered, as "material breach".
11"the conditions for the participation of ICT third-party service providers in the financial entities' ICT security awareness programmes and digital operational resilience training in accordance with Article 13(6)" (Art 30(2)(i))Silent.
Article 30(3): additional content for critical or important functions
#RequirementDraft
12"full service level descriptions … with precise quantitative and qualitative performance targets … to allow effective monitoring … and enable appropriate corrective actions to be taken, without undue delay, when agreed service levels are not met" (Art 30(3)(a))Partial. There is one quantitative target. There are no qualitative targets and no corrective-action mechanism.
13"notice periods and reporting obligations … including notification of any development that might have a material impact on the ICT third-party service provider's ability to effectively provide the ICT services" (Art 30(3)(b))Silent. The "without notice" subcontracting clause points the other way.
14"requirements … to implement and test business contingency plans and to have in place ICT security measures, tools and policies that provide an appropriate level of security" (Art 30(3)(c))Silent. A SOC 2 report is evidence, not a contractual duty.
15"the obligation … to participate and fully cooperate in the financial entity's TLPT as referred to in Articles 26 and 27" (Art 30(3)(d))Silent.
16"unrestricted rights of access, inspection and audit by the financial entity, or an appointed third party, and by the competent authority, and the right to take copies of relevant documentation on-site … not impeded or limited by other contractual arrangements" (Art 30(3)(e)(i))Misses. The draft allows nothing beyond the annual SOC 2 report.
17"the right to agree on alternative assurance levels if other clients' rights are affected" (Art 30(3)(e)(ii))Silent.
18"the obligation … to fully cooperate during the onsite inspections and audits performed by the competent authorities, the Lead Overseer, financial entity or an appointed third party" (Art 30(3)(e)(iii))Misses.
19"the obligation to provide details on the scope, procedures to be followed and frequency of such inspections and audits" (Art 30(3)(e)(iv))Silent.
20"exit strategies, in particular the establishment of a mandatory adequate transition period" during which the provider "will continue providing the respective functions" and which allows "the financial entity to migrate to another ICT third-party service provider or change to in-house solutions" (Art 30(3)(f)(i)–(ii))Misses. There is no exit plan.
Related duties that sit on the bank, not in the contract
#ProvisionRelevance
21Art 28(1)(a): the bank must "at all times, remain fully responsible for compliance with, and the discharge of, all obligations under this Regulation"Outsourcing does not transfer responsibility.
22Art 28(4)(a)–(e): before signing, assess whether a critical or important function is supported, whether supervisory conditions are met, the risks including concentration, due diligence, and conflicts of interestThese are pre-signature steps.
23Art 28(5): the bank "may only enter into contractual arrangements with ICT third-party service providers that comply with appropriate information security standards"; for critical or important functions it must consider the "most up-to-date and highest quality information security standards"SOC 2 is one input to this.
24Art 28(6): the bank must "pre-determine the frequency of audits and inspections as well as the areas to be audited"The bank cannot do this without a contractual audit right (line 16).
25Art 28(8): the bank must have exit strategies and exit plans that are "comprehensive, documented and … sufficiently tested and reviewed periodically", plus transition plans to "securely and integrally transfer" the services and dataThe internal exit plan is also missing.
26Art 29(1): concentration risk, including "contracting an ICT third-party service provider that is not easily substitutable"This is relevant for a core-banking platform.
27Art 29(2): the bank must weigh the benefits and risks of subcontracting and assess "potentially long or complex chains of subcontracting"; it must also consider insolvency law for urgent data recoveryThis applies directly to the "subcontract without notice" clause.
28Art 30(4): the parties "shall consider the use of standard contractual clauses developed by public authorities"Consider during the negotiation.
29Art 30(5): the subcontracting conditions under Art 30(2)(a) are specified further in an RTSNot held.

3. Register of information entry (Article 28(3))

Under Article 28(3), the bank must:

  • Record the arrangement in the register, which must be kept "at entity level, and at sub-consolidated and consolidated levels", covering "all contractual arrangements on the use of ICT services provided by ICT third-party service providers".
  • Classify it as covering ICT services that support a critical or important function. Arrangements must be "appropriately documented, distinguishing between those that cover ICT services supporting critical or important functions and those that do not".
  • Report at least yearly "on the number of new arrangements on the use of ICT services, the categories of ICT third-party service providers, the type of contractual arrangements and the ICT services and functions which are being provided". For this entry that means:
  • provider: Debesis Cloud UAB
  • service: hosted core banking and loan origination, with an AI credit-scoring module
  • functions supported: core banking and lending
  • Give the register to the competent authority on request, either the "full register of information or, as requested, specified sections thereof".
  • Tell the competent authority in advance. The bank must "inform the competent authority in a timely manner about any planned contractual arrangement on the use of ICT services supporting critical or important functions". This must happen before signing.

The standard templates are in the implementing technical standards required by Art 28(9). The corpus does not hold those ITS, so this pack does not list the template fields. Which authority is competent, and any national reporting channel, is also outside the corpus.

4. Other regulations the contract touches

These are kept separate from the DORA conclusions above.

GDPR (32016R0679): Debesis appears to act as a processor for customer and loan data
  • Art 28(2): "The processor shall not engage another processor without prior specific or general written authorisation of the controller." Where authorisation is general, the processor must tell the controller about changes and give it "the opportunity to object". This conflicts with "subcontract hosting without notice".
  • Art 28(3): the contract must set out "the subject-matter and duration of the processing, the nature and purpose … the type of personal data and categories of data subjects". It must also contain clauses (a) to (h), including:
  • (g) delete or return data at the controller's choice
  • (h) "allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller"

The draft's SOC 2-only position falls short of (h).

  • Art 28(4): a sub-processor must carry the same obligations, and "the initial processor shall remain fully liable to the controller".
  • Art 32(1): security measures, including "the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident".
  • Art 35(1): a DPIA is required where processing "using new technologies … is likely to result in a high risk". AI credit scoring is a likely trigger, but that is Lumen's decision.
  • Art 22(1): data subjects have "the right not to be subject to a decision based solely on automated processing, including profiling". This bears on how the scoring module is used.
EU AI Act (32024R1689): the credit-scoring module
  • Annex III, point 5(b): "AI systems intended to be used to evaluate the creditworthiness of natural persons or establish their credit score, with the exception of AI systems used for the purpose of detecting financial fraud". Art 6(2) makes Annex III systems high-risk. This is subject to the Art 6(3) derogation, which I did not assess.
  • Lumen is the deployer. The contract should support these duties:
  • Art 26(1): use the system according to the instructions for use. The contract should require the provider to supply them.
  • Art 26(2): assign human oversight.
  • Art 26(5): monitor operation. For financial institutions this duty is "deemed to be fulfilled by complying with the rules on internal governance arrangements" under financial services law.
  • Art 26(6): keep logs "to the extent such logs are under their control", for at least six months. The contract should give Lumen access to the logs.
  • Art 26(9): use the provider's Art 13 information for the GDPR DPIA.
  • Art 26(11): inform the natural persons affected.
  • Art 27(1): deployers of point 5(b) systems "shall perform an assessment of the impact on fundamental rights" before deploying.
  • Debesis's duties as provider (Arts 16 onward) and the date the Annex III obligations apply were not read in this run.
NIS2 (32022L2555)
  • Art 4(1): where sector-specific Union acts impose requirements that are "at least equivalent in effect", the relevant NIS2 provisions "shall not apply to such entities". For Lumen's side, DORA is the operative text. Debesis may have its own NIS2 obligations as a cloud provider, but those are not a term of this contract. National transposition is not held.

Not covered: the Cyber Resilience Act was not scanned. Search pages were capped at 25 hits, so matches were left unshown:

  • DORA "ICT third-party" search: 25 of 339 shown
  • DORA critical-function search: 25 of 192 shown
  • AI Act credit-scoring search: 25 of 135 shown
  • NIS2 search: 25 of 266 shown
  • the cross-regulation search: capped at 25 per module

5. Gaps to negotiate

These are sources for the negotiation, not redrafted clauses.

  1. Audit and access (Art 30(3)(e)(i)–(iv), Art 28(6); GDPR Art 28(3)(h)). The draft allows only a SOC 2 report. The text requires unrestricted access, inspection and audit rights for the bank, a third party it appoints, and the competent authority, plus a duty to cooperate.
  2. Exit (Art 30(3)(f), Art 30(2)(d), Art 28(8); GDPR Art 28(3)(g)). There is no transition period and no provision for data return, recovery or access on insolvency or termination. The bank's own exit plan is also missing.
  3. Subcontracting (Art 30(2)(a), Art 29(2); GDPR Art 28(2) and 28(4)). The "without notice" clause conflicts with both acts. Conditions, notice, a right to object and flow-down of obligations are needed.
  4. Termination (Art 28(7)(b)–(d), Art 30(2)(h)). Only material breach is covered. The supervisory and risk-monitoring grounds are missing. Whether 12 months' notice is right is a question of what the competent authority expects, which the corpus does not hold.
  5. Locations (Art 30(2)(b)). The countries or regions must be named, with advance notice of any change.
  6. Service levels (Art 30(3)(a)–(b)). Qualitative targets, corrective actions, and notice or reporting of material developments are needed.
  7. Security, business continuity and TLPT (Art 30(2)(c), Art 30(3)(c)–(d)). Data-protection and security obligations, contingency-plan testing and TLPT participation are missing.
  8. Incident assistance and authority cooperation (Art 30(2)(f)–(g)).
  9. Training participation (Art 30(2)(i)).
  10. Single written document (Art 30(1)).
  11. AI module support for deployer duties (AI Act Arts 26(1), 26(6), 26(9) and 27(1)): instructions for use, access to logs, and the Art 13 information.
  12. Before signing: complete the Art 28(4) assessment and the Art 29 concentration check, notify the competent authority under Art 28(3), and create the register entry.

6. Citations checked

All pinpoints below were run through verify_citation with a quote from this pack. Every one returned exists: held, quote: found.

  • DORA: Art 3(22), 28(1), 28(3), 28(4), 28(5), 28(6), 28(7), 28(8), 28(9), 29(1), 29(2), 30(1), 30(2), 30(3), 30(4), 30(5).
  • GDPR: Art 22(1), 28(2), 28(3), 28(4), 32(1), 35(1).
  • EU AI Act: Art 6(2), Annex III point 5(b), Art 26(1), 26(2), 26(5), 26(6), 26(9), 26(11), 27(1).
  • The Annex III check was run as "Annex III(5)" but resolved at the annex level ("ANNEX III"). The quote from point 5(b) was found.
  • NIS2: Art 4(1).

Sub-points such as 30(2)(a)–(i) and 30(3)(a)–(f) were checked through their parent paragraph and the full article text returned by read_unit.

I did not record any assessments with record_assessment. Applicability verdicts are for the ICT risk lead to state.

Start it yourself

Connect Rekvira to Claude, ChatGPT or Cursor (one step, no account), then paste this and add your facts:

Use Rekvira to review this ICT contract against DORA: a clause checklist, the register-of-information entry and the gaps. Quote the official text with pinpoints.

Where you decide

  • After dora-ict-third-party: Confirm whether the service supports a critical or important function, which adds contract provisions.

What comes back

  1. The arrangement
  2. Clause checklist against DORA
  3. Register of information entry
  4. Other regulations the contract touches
  5. Gaps to negotiate
  6. Citations checked

How it keeps it defensible

  • Each checklist line cites the DORA article and paragraph it comes from
  • Every pinpoint is checked with verify_citation
  • States the data_as_of date and what the corpus does not hold (technical standards, national law)

What it will not do

  • Accept or reject the vendor's risk: that decision is yours
  • Read the regulatory technical standards or the register templates, which the corpus does not hold
  • Redraft the contract

Recorded on the live Rekvira service on 23 September 2026 without an account, with the job's playbooks named in the prompt. The prompt, every tool call and the finished text are stored as recorded; tool results above are shortened. The scenario is illustrative.