A bank hands its IT supplier a “DORA addendum” and treats it as boilerplate. Most of it is not. DORA fixes a floor of contractual terms; a great deal of what actually arrives sits well above that floor — and a supplier who signs as-is takes on duties the Regulation never imposed.
Facing this on a live addendum?
DORA — Regulation (EU) 2022/2554 — lists the contractual terms a financial entity must put in place with its ICT third-party providers (art. 30(2): a clear service description, locations and data-processing sites, access and audit rights, assistance on ICT incidents, subcontracting conditions, and exit). It sets termination grounds (art. 28(7)) and a duty to cooperate on security awareness (art. 13(6)). The crucial word is minimum: these are defined, and they are governed by proportionality and necessity. Beyond them, the supplier is negotiating from a strong position, not a weak one.
Sort every clause into three buckets
The fastest way through a bank’s draft is to triage it: each ask is either required by DORA, an over-reach to be trimmed to the minimum, or simply abusive and to be resisted.
Where the drafts overreach
Audit. DORA gives the bank and the authorities access and audit rights (art. 30) — not an unconditional run of the supplier’s systems. Tie audits to the contracted services, with reasonable notice, and carve out the supplier’s IP and other clients’ data.
Subcontracting. Art. 30(2) requires prior information and clear conditions, with notice of material change — it does not, as a rule, hand the bank a consent or veto, still less a right to rewrite the supplier’s contracts with its own subcontractors.
Termination. Art. 28(7) ties termination to objective grounds. A right to terminate immediately on subjective criteria (“deemed capable of affecting…”) is an imbalance to resist; unfounded termination should sound in damages for the supplier.
Two over-reaches that recur. Obligations DORA reserves for critical ICT providers (art. 31) do not bind a supplier that has not been designated — you are presumed non-critical. And bank recovery-and-resolution provisions belong in financial contracts; an ordinary ICT services contract is not one, and those powers should not be imported into it.
The move
General information on DORA (Regulation (EU) 2022/2554) from the ICT supplier’s perspective, not legal advice, and no lawyer–client relationship is created. DORA and its regulatory technical standards carry detailed conditions; any specific addendum needs advice on its own facts.
Handed a bank’s DORA addendum? Trim it to the DORA minimum before you sign.
Free brochure
The DORA addendum negotiation checklist
A one-page brief on this topic, sent straight to your inbox.
Facing this on a live document?
Book a 30-minute clinic
A quick read on your exact seam — by a lawyer qualified on both sides of it. No charge for the first look.
Your details go to Răzvan Alexandru Olaru (raz@olawru.com) and are held under a lawyer’s professional secrecy (Legea nr. 51/1995 & the Statutul profesiei de avocat) and the corresponding SRA confidentiality rules, processed in line with the GDPR. See our Privacy Policy and GDPR Statement.