Compliance · Europe

DORA-ready AI: less third-party risk, a real exit plan.

Since 17 January 2025, EU financial entities must manage ICT third-party risk, keep a register of ICT arrangements and plan exits. Self-hosted AI with code you own makes that simpler.

Applies since
17 January 2025
Who
EU financial entities
Focus
ICT risk, incidents, testing, third parties
Our approach
You run it; we can hand over

In short

The Digital Operational Resilience Act (DORA) requires EU financial entities to manage ICT risk, report major incidents, test resilience and control ICT third-party risk, including contract terms, a register of information and exit strategies. AI that runs on your own infrastructure, with source code and runbooks you own, reduces dependence on any single provider.

What it asks

Requirements, and how we meet them.

RequirementHow DeepVox addresses it
ICT third-party risk managementThe AI runs on your infrastructure; we are not a critical runtime dependency unless you choose managed support.
Register of informationComponents, owners and contracts documented for your register.
Contract terms (exit, audit, access)Source code, runbooks and an exit package written into the engagement.
Incident managementLogs and monitoring feed your incident process.
Resilience testingDeployed with your standard testing and recovery tooling.

FAQ

Questions, answered.

Are you a critical ICT third-party provider?

Critical-provider designation applies at EU level to providers serving the sector at scale. Either way, because you own the code and can run it yourself, your exit plan is concrete.

Can you support our DORA documentation?

Yes. We document architecture, dependencies and exit procedures for your register and risk assessment.