Regulation · Europe

DORA and AI vendors: what banks must ask of an ICT provider

In short

Since 17 January 2025, DORA requires EU financial entities to manage ICT third-party risk: contracts with audit, access and exit terms, a register of information and tested exit strategies. Before adopting an AI service, ask where it runs, who operates it, what happens on exit and whether you could run it without the vendor.

Why AI is an ICT third-party question

Under the Digital Operational Resilience Act, an AI service that supports business functions is an ICT service. If a vendor runs it, that vendor becomes part of your ICT third-party risk: it enters your register of information, your contracts need specific terms, and your exit strategy has to be real.

Seven questions to ask an AI vendor

  1. Where does it run, and who operates it? Your infrastructure, the vendor's cloud, or the vendor operating inside your cloud?
  2. What data leaves your environment? Prompts, documents, embeddings, logs?
  3. Which sub-processors are involved? Model providers, hosting, monitoring?
  4. What are the audit and access rights? Can you and your supervisor inspect it?
  5. How are incidents reported to you? And how fast?
  6. What is the exit plan? What do you keep, and how long does migration take?
  7. Could you run it without the vendor? Code, models, runbooks?

How ownership changes the answers

If the AI system runs on your infrastructure and you own the code and runbooks, many of these questions shrink. The vendor is a build partner, not a runtime dependency, unless you choose managed support. Exit becomes a knowledge transfer you can rehearse, not a migration project.

What to document

  • The components and their owners for your register of information.
  • Contract terms covering audit, access, incident notice and exit.
  • A tested exit procedure, ideally walked through before go-live.

See also our DORA page and financial services page.

General information, not legal advice. Questions? Write to sales@deepvox.ai.