DORA and AI vendor outsourcing: what financial entities have to do
The Digital Operational Resilience Act, Regulation (EU) 2022/2554 (DORA), entered into application on 17 January 2025 and binds roughly 22,000 financial entities across the EU to a uniform ICT risk-management regime. AI systems supplied by third parties are squarely in scope as ICT services, which means model providers, hosting platforms and AI consultancies that touch in-scope financial workloads inherit DORA-grade due diligence, contract, exit and incident-reporting obligations [1].