Regulation · DORA · Critical Third Parties

DORA & critical third parties, explained

DORA and the UK's critical-third-parties regime both push the same point: when a financial firm depends on an outside ICT provider, that dependency — and the concentration it creates — is a risk the firm and its regulators have to manage.

What are DORA and the critical-third-parties regime?

DORA — the EU's Digital Operational Resilience Act — sets requirements for financial entities to manage ICT risk, including risk from ICT third-party providers, and creates an oversight framework for those designated as critical; it has applied since 17 January 2025. In the UK, a separate critical-third-parties regime (rules effective 1 January 2025) lets the regulators oversee third parties whose failure could threaten financial stability. That regime became operational on 13 July 2026, when the Treasury's first designations — the major cloud providers, such as AWS, Google Cloud, Microsoft and Oracle — took effect and joint oversight by the Bank of England, PRA and FCA began.

The two regimes are distinct in scope and mechanics. Firms should confirm which apply to them, and the current requirements, against the EU DORA texts and the UK regulators' published rules.

What they expect around ICT third parties

Across both regimes, the recurring themes for third-party and concentration risk are, in outline:

Third-party risk managementIdentify, assess and manage the ICT third parties a firm relies on, with due diligence, contractual safeguards and exit planning.
Concentration riskUnderstand where many firms — or one firm's critical functions — depend on the same provider or infrastructure, and the systemic exposure that creates.
Operational resilience & testingEnsure important business services can withstand and recover from ICT disruption, evidenced through resilience and, where relevant, threat-led testing.
Data & oversightMaintain oversight of where data and critical processing sit, with registers of arrangements and, for designated critical providers, direct regulatory oversight.

Where an analytics vendor sits in this — and where Abgalis sits

A cloud-hosted analytics vendor is, by construction, an ICT third party: send your exposures and positions out to a shared hyperscaler and you add exactly the concentration these regimes are written to surface. The point is no longer abstract — the first UK critical-third-party designations in July 2026 named the major cloud providers themselves — such as AWS, Google Cloud, Microsoft and Oracle — as systemic concentration points.

Abgalis is designed around the opposite premise — to operate inside a firm's own environment rather than as another external dependency, so third-party and data-egress exposure is minimised by design. Specific deployment, data-residency and resilience arrangements are agreed per engagement and confirmed contractually, not assumed. The concentration question itself is analysed in the Abgalis paper on critical third parties and cloud concentration; for how it lands in different books, see banks and market infrastructure.

DORA & critical third parties — questions firms ask

What is DORA?

DORA, the EU's Digital Operational Resilience Act, sets requirements for financial entities to manage ICT and cyber risk — including ICT third-party risk — and establishes oversight of ICT providers designated as critical. It has applied since 17 January 2025. Firms should confirm applicability and current requirements against the EU texts.

How is the UK critical-third-parties regime different?

The UK regime is separate from DORA. It gives the UK financial regulators powers to oversee third parties whose disruption could threaten financial stability or confidence — for example major cloud providers — rather than applying DORA's full framework. Its rules took effect on 1 January 2025 and became operational on 13 July 2026, when the Treasury's first designations — the major cloud providers, such as AWS, Google Cloud, Microsoft and Oracle — took effect. Scope and mechanics differ; confirm against the UK regulators' published rules.

What do these regimes expect around third-party risk?

In outline: managing the ICT third parties a firm relies on, understanding concentration where many firms depend on the same provider, ensuring important business services are operationally resilient and tested, and maintaining oversight of where data and critical processing sit — with direct oversight of designated critical providers.

Is a cloud analytics vendor a third-party concentration risk?

It can be. A cloud-hosted analytics service is an ICT third party, and sending exposures and positions to a shared hyperscaler adds to the concentration these regimes are written to surface. That is a factor firms weigh when choosing analytics providers.

How does Abgalis address third-party concentration?

Abgalis is designed to operate inside a firm's own environment rather than as another external cloud dependency, so third-party and data-egress exposure is minimised by design. The specific deployment, data-residency and resilience arrangements are agreed per engagement and confirmed contractually.

Does using Abgalis make us DORA-compliant?

No single vendor makes a firm compliant. DORA and the UK regime place obligations on the firm; a well-designed, in-estate analytics provider can reduce third-party and concentration exposure, but compliance is the firm's own responsibility, assessed against the applicable rules.

This page is a general explainer, not legal or regulatory advice. DORA and the UK critical-third-parties regime are distinct; firms should refer to the EU DORA texts and the UK regulators' published rules and take their own advice. Abgalis is a risk data and analytics provider and is not a regulated or authorised firm; deployment and data claims are confirmed contractually per engagement.

See everything.
Before it happens.

Discover how ABGALIS can unify your enterprise risk landscape into a single, living digital twin — with foresight across every domain.

Your data is handled in accordance with GDPR. We never share your information. Privacy Policy

Download Research Paper

Enter your details to access our peer-quality research from the Abgalis Risk Intelligence Lab.

Your data is handled in accordance with GDPR. We never share your information.