Compliance Library Blog Product Sign In
EU-DORA-28-05 Documentation 28 — General principles

Include policy on critical/important ICT services in third-party risk strategy

Description

The ICT third-party risk strategy must include a policy on the use of ICT services supporting critical or important functions provided by ICT third-party service providers and apply on individual,...

Full Analysis & Evidence Requirements

Sign in to view the full obligation text, AI-generated applicability analysis, evidence checklists, and compliance mapping.

Sign In to View

Map this obligation to your AI systems

ReguLume automatically maps regulatory obligations to your system inventory, identifies compliance gaps, and generates remediation plans.

Get Started

Start your compliance assessment

Map obligations to your AI systems, identify gaps, and generate board-ready reports. Plans start at $149/mo.

Get Started