Third-Party ICT Risk Under DORA: How to Build a Register That Survives a Supervisory Review
Key takeaways A supervisory review of DORA compliance does not start with the register. It starts with a question: can your organization explain, with documentation, why a specific service is classified the way it is, what has been monitored since the last review, and what happened when something went wrong? Most financial institutions that have […]