RatedWithAI

RatedWithAI

Accessibility scanner

EU Financial RegulationAugust 26, 2026

DORA Doesn't Regulate You. It Regulates the Customer Who Is About to Send You a 40-Question Addendum.

The Digital Operational Resilience Act binds EU financial entities, not their software suppliers. That distinction is worth exactly nothing at renewal, because a bank that cannot get the required clauses into your contract is a bank that has to stop using your product.

Article 30
The clause list every ICT contract must contain
Register
You are named in a filing to the regulator
Exit plan
Required for critical or important functions

The Transmission Mechanism

DORA is an EU regulation on digital operational resilience for the financial sector. It applies to a long list of regulated entities — credit institutions, insurers and reinsurers, investment firms, payment and e-money institutions, crypto-asset service providers, trading venues, fund managers — and it obliges each of them to manage ICT third-party risk as a supervised activity rather than as a procurement preference.

Nothing in that sentence mentions you. The mechanism that reaches you is that the regulated entity cannot satisfy its own obligations unless specific things are true about its contract with you. So the obligation arrives as a redline, an addendum, or a security questionnaire with a section nobody used to ask about — and the leverage behind it is not a fine you might pay, it is a renewal your customer is not permitted to sign.

Two Tiers, and Only One of Them Is Painful

The single most useful question to ask a financial customer early is whether your service is being classified as supporting a critical or important function. The answer determines which of these two lists you are negotiating against, and getting it settled in week one saves a quarter of contract cycles.

All ICT Contracts — Baseline
  • Clear description of the functions and services provided
  • The locations where services are provided and data is processed
  • Data protection, availability, integrity and confidentiality terms
  • Assistance during an ICT incident at no additional cost
  • Cooperation with the customer's competent authorities
  • Termination rights and notice periods
Critical or Important Functions — Additional
  • Quantitative service level targets, not best-effort language
  • Full audit, inspection and access rights, unrestricted
  • Participation in the customer's testing and awareness programmes
  • Incident reporting duties with defined timelines
  • Conditions and approval gates for subcontracting
  • A documented exit strategy with a transition period

Where AI Features Break the Template

Most of Article 30 is answerable by any competent SaaS vendor. The clauses that stall are the ones that assume you control your own stack — and an AI feature usually does not.

1

Your Subcontracting Chain Includes a Model Provider You Cannot Audit

DORA expects the financial entity to understand and record the chain of subcontractors supporting a critical or important function, and to retain rights when that chain changes. If your feature calls a third-party foundation model, that provider is in the chain. You will be asked to name the entity, the processing region, the retention posture, and what happens if that provider deprecates the model. 'We use a leading AI provider' is not an answer that fits in a register field.

2

Model Deprecation Is a Resilience Event, Not a Product Update

Upstream providers retire model versions on their own schedule. From the customer's side that is an unannounced change to a component supporting a regulated function, with different outputs and different failure modes. Vendors who commit to a pinned version, a deprecation notice period, and a documented revalidation path are answering a question their competitors are still treating as a roadmap detail.

3

Audit Rights Have to Survive Two Hops

For critical or important functions, the customer and its regulator need meaningful access. You cannot grant access to infrastructure you do not own, so the workable answer is a layered one: your own audit rights and reports, plus the upstream provider's independent assurance artefacts, plus a contractual commitment to pass through information requests. Say this explicitly. Silence reads as a refusal.

4

The Exit Strategy Has to Address the Data You Generated

Exit planning assumes the customer can move to another provider or bring the function in-house without disruption. For AI features the awkward part is derived data — embeddings, fine-tuning artefacts, evaluation histories, prompt libraries the customer's staff wrote inside your product. Decide in advance what is exportable and in what format, because the first time you think about it should not be during a termination.

The Register Entry Is the Real Deadline

Financial entities keep a register of information covering every ICT contractual arrangement and report it to their supervisor. Your company sits in that register as a named counterparty, with the function you support, its criticality classification, the countries where processing happens, and the subcontractors behind you.

This changes the character of vendor diligence. A procurement questionnaire can be answered approximately and filed. A register entry cannot — it either has the field populated or it does not, and the person chasing you for it is being chased by their own compliance function against a reporting cycle. Vendors who can return a clean, structured answer inside a day become materially easier to buy than vendors who route the question to an account manager.

What to Prepare Before the Next Redline

Have This Written Down Already

  • Legal entity name, LEI if you have one, and country of incorporation
  • Every processing and storage location, by region and provider
  • Named subcontractors, including model and infrastructure providers
  • Quantitative availability and support-response commitments
  • Incident notification timelines and the channel you will use
  • Exit and data-export procedure with formats and timeframes

Decide Your Position on These

  • Whether you will pin model versions for regulated customers
  • Notice period before changing a subcontractor in the chain
  • Scope of audit and access rights you can actually grant
  • Whether incident assistance is genuinely at no extra cost
  • Which of your tiers can support critical-function commitments
  • Who signs off when a customer asks for a bespoke deviation

This Is a Commercial Advantage, Briefly

Right now most AI vendors selling into European financial services are answering these questions improvised, per-deal, by whoever picks up the thread. The requirements are public and finite, and the artefacts they need are a page of text each. A vendor who has them ready wins on cycle time against competitors with a better product and a worse answer — which is the kind of advantage that lasts until everyone else notices.

Frequently Asked Questions

Our EU customer says our tool is not a critical or important function. Are we done?

You still owe the baseline Article 30 terms, and the classification is the customer's to make and to revisit. Tools tend to drift upward in criticality as usage spreads — a reporting assistant that three analysts trialled becomes a dependency of a regulated process without anyone re-running the assessment. Ask to be told if the classification changes, and price the heavier commitments into a tier rather than granting them by accident.

Can we satisfy this with our SOC 2 report and a DPA?

They help and they are not sufficient. A SOC 2 report speaks to control design and operation; DORA's contract requirements are about specific rights and commitments that either appear in the agreement or do not — audit access, incident assistance at no cost, subcontracting conditions, exit assistance. A data processing addendum addresses personal data, not operational resilience. Expect to add a resilience addendum alongside both.

What if we refuse the unrestricted audit clause?

Then the customer cannot use you for a critical or important function, and the honest move is to say so early and scope the deal accordingly. Some vendors legitimately cannot grant physical inspection rights over infrastructure they rent. What loses deals is not the limitation itself but discovering it in month three of a negotiation, after the customer has already told its risk committee the vendor was compliant.

Does DORA overlap with the EU AI Act for our product?

They stack rather than substitute. DORA governs the operational resilience of the ICT service and the contractual relationship. The EU AI Act governs the AI system itself — its risk classification, documentation, transparency and oversight duties. A credit-decisioning feature sold to an EU bank plausibly sits inside both, and the financial regulator has separate expectations about model risk management on top. Map the three separately; the artefacts overlap more than the obligations do.

We are a small vendor. Will a bank actually enforce this on us?

The bank's supervisor enforces it on the bank, and the bank's only instrument against you is the contract. That instrument is decisive in practice: the register entry has to be completed, the clause list has to be present, and internal audit will eventually sample the arrangements. Small vendors do not get an exemption; they get less negotiating room, because the requirements are non-negotiable for the customer and the alternative is not using you.

The Answer Is a Document, Not a Meeting

Every question in this article resolves to a short written artefact: where you process, who is in your chain, what you commit to numerically, how a customer leaves. None of it requires a lawyer to draft the first version, and all of it is currently being reinvented per-deal by vendors who will answer it worse than you do.

Write it once. The next European financial prospect will ask for exactly this, and the speed of your answer is a signal they read as competence about everything else.

This article is general information about EU financial regulation, not legal advice. Classification of critical or important functions, contract terms, and supervisory expectations vary by entity and by national competent authority — confirm specifics with counsel before committing contractually.