DORA enforcement is live — national regulators are conducting readiness inspections now

DORA Compliance for Procurement Teams — Automated Supplier Risk Assessment That Your Regulator Will Accept

DORA Article 28 requires documented ICT third-party risk assessments with ongoing monitoring and a complete audit trail. FiorLab generates the exact evidence your national competent authority demands — in minutes, not months.

Start Your Assessment

No credit card · Live in 5 minutes · We score your first 20 suppliers free

Built for DORA, EU outsourcing and GxP compliance by people who ran regulated procurement

Irish-registered (CRO 813471)
Certified cloud infrastructure
EU-hosted · GDPR by design
DORA Article 28 mapped

What DORA Article 28 Actually Requires

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) entered into force on 17 January 2025. Article 28 sets mandatory obligations for managing ICT third-party risk. Here is what your regulator expects.

Article 28(1)(a)

Maintain a Register of All ICT Third-Party Providers

You must maintain an up-to-date, structured register of every ICT third-party service provider, including the nature of services, contract dates, and criticality classification. This register must be available to your national competent authority on request. A spreadsheet with inconsistent fields will not pass inspection.

Article 28(2)-(4)

Conduct Pre-Contractual Risk Assessments

Before entering into any ICT outsourcing arrangement, you must perform a documented risk assessment covering the provider's financial stability, operational resilience, compliance posture, and concentration risk. This assessment must be evidenced, not assumed. The regulator will ask for the methodology, the data sources, and the scoring rationale.

Article 28(5)-(7)

Implement Ongoing Monitoring and Exit Strategies

DORA requires continuous monitoring of ICT third-party providers, not annual reviews. You must track changes in financial health, compliance status, and operational performance throughout the contract lifecycle. Exit strategies and substitution plans must be documented and tested for critical providers.

Article 28(8) + Article 15

Maintain a Complete Audit Trail

Every risk assessment, scoring decision, document upload, and status change must be logged in an immutable, timestamped audit trail. When the CBI, BaFin, DNB, ACPR, AFM, AMF, or CSSF requests evidence of your ICT third-party risk management process, you must produce it — with full provenance — within the timeframe they specify. Typically 48 hours. Often less.

DORA sets no single EU-wide fine ceiling. Your exposure is set by your national competent authority under national law — and it is not capped by the Regulation.

Article 50(3) requires every Member State to lay down administrative penalties that are effective, proportionate and dissuasive. Article 50(4) obliges competent authorities (CBI, BaFin, AFM, AMF, FMA and others) to be able to order you to cease the conduct, to adopt measures including of a pecuniary nature, and to issue public statements naming your firm and the breach. Article 51(2) makes the gravity and duration of the breach an express weighting factor — which is precisely what a documented evidence trail speaks to. Separately, Article 35(6)–(8) lets the Lead Overseer fine a designated critical ICT third-party provider up to 1% of its average daily worldwide turnover, every day, for up to six months. The €10m / 2% figure widely quoted as the DORA fine is in fact the NIS2 ceiling for essential entities, Directive (EU) 2022/2555 Article 34(4). Enforcement is not theoretical — inspections are underway across the EU.

How FiorLab Maps to Every DORA Article 28 Requirement

FiorLab was purpose-built for regulated industries. Every feature exists because a specific regulatory requirement demands it.

DORA Requirement FiorLab Capability Evidence Produced
ICT provider register
Art. 28(1)(a)
Structured supplier registry with company details, service classification, contract metadata, and criticality tags. CSV import for bulk onboarding. Verified against CRO Ireland, Companies House, Handelsregister, VIES, and GLEIF. Exportable register
Registry verification timestamps
Provider classification
Pre-contractual risk assessment
Art. 28(2)-(4)
6-dimension scoring engine: financial health (Altman Z-Score, Piotroski F-Score, debt-to-equity), compliance, sustainability, delivery, quality, and innovation. Sub-metric evidence chain for every score. Assessment-type weights for DORA, EU Outsourcing (CBI / BaFin / DNB / ACPR / CSSF variants), GxP, and Hybrid frameworks. Scored assessment report (PDF)
Per-dimension breakdown
Scoring methodology reference
Ongoing monitoring
Art. 28(5)-(7)
Registry re-checks on a regular cadence. Document staleness decay as evidence ages. Anomaly detection with tiered severity. Financial early warning via real-time indicator tracking. Monitoring alerts log
Score change history
Staleness reports
Verification and cross-referencing
Art. 28(3), RTS
5-tier graduated verification: registry_verified, verified, partially_verified, unverified, self_declared. Cross-reference integrity checks (OCR name vs. registry name, status matching). Verification multiplier applied to raw scores. Trust tier classification
Verification source attribution
Cross-reference audit log
Immutable audit trail
Art. 28(8), Art. 15
Every action — assessment creation, score change, document upload, status update, user decision — recorded with timestamp, user identity, and before/after state. Tamper-resistant by design. Full-text search across audit history. Complete audit trail export
Per-action evidence chain
Regulatory inspection report
Concentration risk awareness
Art. 28(1)(b), Art. 29
Portfolio-level risk dashboard showing supplier distribution across risk tiers, industries, and geographies. Compliance gap identification with severity classification. RFP and contract lifecycle tracking per supplier. Portfolio risk overview
Risk distribution analysis
Gap remediation tracking

Built for DORA-Regulated Financial Entities

DORA applies to over 22,000 financial entities and ICT third-party providers across the EU. If your organisation holds a financial services licence and relies on external ICT providers, this is for you.

Banks and Credit Institutions

DORA applies to all credit institutions licensed under the CRD. Whether you are regulated by the CBI, BaFin, DNB, or ACPR, your ICT third-party risk register must meet Article 28 standards. FiorLab generates the evidence these supervisors require.

Insurance and Reinsurance

Solvency II entities are now also subject to DORA. Insurers relying on third-party claims platforms, underwriting engines, or data analytics providers must document their ICT risk assessments with the same rigour as banks. FiorLab provides the structured framework.

Payment and E-Money Institutions

PSD2 and EMD2-licensed firms fall squarely within DORA scope. If you process payments, issue e-money, or operate payment infrastructure, your ICT third-party risk management must be auditable. FiorLab automates the assessment and monitoring cycle.

Investment Firms and Fund Managers

MiFID II investment firms and AIFMD/UCITS fund managers are in scope. Portfolio management systems, trading platforms, and risk analytics providers must all be assessed under DORA. FiorLab scores them across six dimensions with full evidence chains.

EU-Wide Coverage

FiorLab serves regulated entities across Ireland, Germany, the Netherlands, France, Austria, and the broader EU. Registry verification covers CRO Ireland, UK Companies House, German Handelsregister, VIES, and GLEIF. One platform, every jurisdiction.

Heads of Procurement and Compliance

DORA compliance is not an IT project alone. It requires procurement, compliance, and risk teams to work from the same data. FiorLab provides a single source of truth that all three functions can rely on — with role-based access and an immutable audit trail.

The Cost of Waiting

1% / day
of average daily worldwide turnover — Art. 35(8) periodic penalty on a critical ICT provider, up to six months
On request
Art. 28(3): the register must be produced when the authority asks. DORA grants no preparation window
27
national penalty regimes — Art. 50(3) leaves the amounts to Member State law

Every month without a structured ICT third-party risk register is a month you are exposed to regulatory action. FiorLab starts at €0 for your first 20 suppliers. The question is not cost — it is whether you can produce evidence when the regulator asks.

Start Your DORA Compliance Pilot

DORA Compliance: Common Questions

What does DORA Article 28 require for ICT third-party risk management?+

DORA Article 28 requires financial entities to maintain a documented register of all ICT third-party service providers, conduct risk assessments before entering outsourcing arrangements, implement ongoing monitoring with defined risk indicators, and maintain a complete audit trail of all third-party risk decisions. National competent authorities — including the CBI, BaFin, AFM, and AMF — can request this documentation at any time. DORA itself sets no fine ceiling for financial entities: Article 50(3) requires each Member State to lay down penalties that are effective, proportionate and dissuasive, and Article 50(4) requires authorities to be able to order cessation, impose measures of a pecuniary nature, and publicly name the firm and the breach. The €10 million / 2% figure often quoted as the DORA fine is in fact the NIS2 ceiling for essential entities, Directive (EU) 2022/2555 Article 34(4).

How does FiorLab help with DORA Article 28 compliance?+

FiorLab automates DORA Article 28 compliance by providing 6-dimension supplier risk scoring (financial health, compliance, sustainability, delivery, quality, and innovation), automated registry verification against CRO Ireland, UK Companies House, German Handelsregister, VIES, and GLEIF, document verification with staleness tracking, and an immutable audit trail that records every assessment, score change, and decision. Run a DORA-aligned EU outsourcing assessment scoped to your national variant (CBI Ireland, BaFin/MaRisk Germany, DNB Netherlands, ACPR France, CSSF Luxembourg) and FiorLab generates the exact evidence your national competent authority requires — exportable as audit-ready PDF reports.

Which national regulators enforce DORA?+

DORA is enforced by national competent authorities across all 27 EU member states. Key regulators include the Central Bank of Ireland (CBI), BaFin in Germany, the AFM (Autoriteit Financiele Markten) in the Netherlands, the AMF (Autorite des Marches Financiers) in France, and the FMA in Austria. FiorLab's assessment framework is designed to meet the requirements of all EU national competent authorities, as DORA sets a harmonised standard across jurisdictions. The European Supervisory Authorities (EBA, EIOPA, ESMA) provide Regulatory Technical Standards that FiorLab incorporates.

Can FiorLab replace our spreadsheet-based supplier risk register?+

Yes. A spreadsheet cannot provide the automated scoring, registry verification, document staleness tracking, or immutable audit trail that DORA demands. FiorLab replaces manual supplier risk registers with a structured, auditable system that scores suppliers across six dimensions, verifies data against live government registries, tracks document freshness with a 5-tier decay model, and generates PDF assessment reports on demand. Registration takes under 5 minutes, CSV import is supported, and your first 20 suppliers are scored free.

What types of financial institutions need DORA third-party risk management?+

DORA applies to all regulated financial entities in the EU: banks and credit institutions (CRD), insurance and reinsurance undertakings (Solvency II), investment firms (MiFID II), payment institutions (PSD2), e-money institutions (EMD2), fund managers (AIFMD/UCITS), crypto-asset service providers (MiCA), central securities depositories, trading venues, and credit rating agencies. Additionally, critical ICT third-party providers designated by the ESAs are directly subject to the oversight framework. If your organisation holds any EU financial services licence and uses external ICT providers, DORA Article 28 applies to you.

How quickly can we become DORA-compliant with FiorLab?+

Most procurement teams are generating their first DORA-ready supplier assessments within 24 hours of registration. The process: register (2 minutes), import your supplier list via CSV or manual entry (5 minutes), run a DORA-aligned EU outsourcing assessment for your jurisdiction (CBI Ireland, BaFin/MaRisk Germany, DNB Netherlands, ACPR France, CSSF Luxembourg, and others), and review the scores. FiorLab automatically scores each supplier across all six dimensions, verifies company data against government registries, applies document staleness decay, and generates audit-ready PDF reports. No IT integration, onboarding calls, or implementation project required. Your first 20 suppliers are scored free.

Your Regulator Will Not Wait. Neither Should You.

DORA enforcement is live across every EU member state. The CBI, BaFin, AFM, and AMF are conducting readiness inspections. Every week without a structured ICT third-party risk register is a week your organisation is exposed to regulatory action.

Start Your DORA Compliance Pilot

No credit card · Live in 5 minutes · We score your first 20 suppliers free