If you need to prepare for a DORA ICT outsourcing review in Romania, three questions should drive every decision you make today: Is each of your ICT vendors classified correctly, and could any qualify as a critical third-party provider (CTPP)? Do your existing contracts contain the audit rights, exit clauses, and incident-reporting obligations that Regulation (EU) 2022/2554 demands? And can you produce, within hours of a supervisory request, the documented evidence that proves all of the above? At Olawru, we advise Romanian financial entities and their technology partners on precisely these operational resilience challenges, and the pattern I see repeatedly is that organisations underestimate the depth of contract-level and governance-level work DORA requires.
This guide walks you through every step of a practical DORA ICT outsourcing review, from building your register of information and scoring vendor criticality, through to drafting exit plans and assembling the evidence package a Romanian regulator will expect on inspection. I have structured it as a phased playbook you can hand directly to your compliance, legal, and procurement teams.
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied across the EU since 17 January 2025. It imposes uniform requirements on financial entities in four interconnected pillars: ICT risk management, ICT-related incident reporting, digital operational resilience testing, and the management of ICT third-party risk (which is where outsourcing review sits). The regulation is complemented by delegated acts and regulatory technical standards (RTS) developed jointly by the European Supervisory Authorities, the EBA, ESMA, and EIOPA.
For Romanian institutions, the enforcement window is not approaching, it is here. National supervisors are now conducting thematic reviews, and the register of information that entities submitted in early 2025 is being used as a baseline for targeted inspections. The ESAs published their first report on major ICT-related incidents in mid-2026, signalling that supervisory scrutiny is intensifying across the Union.
DORA applies to virtually every regulated financial entity. In Romania, the relevant national competent authorities that enforce DORA requirements are determined by entity type. Understanding which supervisor oversees your institution is essential, because inspection methodologies, language requirements, and escalation channels differ.
| Entity Type | Core DORA Obligations (Summary) | Romanian Supervisory Note / Practical Implication |
|---|---|---|
| Banks (credit institutions) | ICT risk management, incident reporting, resilience testing, outsourcing oversight including CTPP oversight. | Supervised by Banca Naţională a României (BNR), expect targeted inspections, records in Romanian and English, evidence of business continuity. |
| Insurance / pensions | Same DORA pillars; heightened outsourcing controls for critical services. | ASF (Romanian Financial Supervisory Authority) coordinates with EIOPA, require insurer-specific register of information, testing evidence, and governance records. |
| Investment firms / asset managers | DORA requirements on ICT risk and third-party oversight; incident reporting to relevant authority (ESMA for EU-level guidance). | Local regulator oversight varies, ensure documentation maps to both DORA and local licensing conditions; prepare cross-jurisdictional incident escalation. |
Romanian entities should establish a clear internal protocol for notifying BNR or ASF. In my experience, regulators expect proactive engagement, not reactive disclosure. If a vendor you classify as critical experiences a material service disruption, or if you identify a significant gap in your ICT risk management framework, the supervisory expectation is that you escalate promptly and with documented analysis, not wait for the next scheduled report.
The register of information is the foundation of every DORA ICT outsourcing review. Article 28(3) of the regulation requires financial entities to maintain a complete, up-to-date register of all contractual arrangements with ICT third-party service providers. In practice, this means every outsourcing, cloud, managed-services, and co-location agreement must be captured, classified, and kept current.
To prepare your DORA ICT outsourcing review in Romania effectively, I recommend the following step-by-step approach to contract mapping:
The register should include, at minimum, the following data fields:
| Field | Description | Owner (typical) |
|---|---|---|
| Vendor name & LEI | Legal name and entity identifier | Procurement / Legal |
| Service type | Category of ICT service provided (cloud, network, application management, etc.) | IT / Architecture |
| Criticality classification | Whether the service supports a critical or important function | Risk / Compliance |
| Sub-processors | Names and locations of any sub-outsourcing chain | Procurement / Vendor mgmt |
| Data flows & storage location | Where data is processed, stored, and transferred | IT Security / DPO |
| SLA targets & RTO/RPO | Service-level commitments, recovery time and recovery point objectives | IT Operations |
| Exit & termination terms | Notice periods, data return, transition assistance, escrow | Legal |
| Audit rights | Right to audit, frequency, access to subcontractors | Internal Audit / Legal |
| Contract start/end date | Effective and expiry dates, renewal mechanism | Procurement |
| Primary contact | Operational and escalation contacts at the vendor | Vendor Management |
Not every vendor warrants the same level of scrutiny. I advise clients to score each arrangement against four dimensions: impact on business continuity if the service fails, sensitivity of data accessed, degree of substitutability (can you switch vendors within your RTO?), and concentration risk (do multiple business lines depend on the same provider?). Assign each dimension a score from 1 to 5, sum the results, and tier your vendors into critical, important, and standard categories. Critical-tier vendors receive full due diligence and enhanced contractual protections; standard-tier vendors receive baseline monitoring.
DORA establishes the most comprehensive ICT third-party risk management framework in EU financial regulation. Articles 28–44 require financial entities to evaluate whether any of their providers qualify as critical third-party providers (CTPPs), a designation that triggers EU-level oversight by a lead overseer appointed from among the ESAs.
Indicators that a vendor may warrant CTPP treatment include: a significant market share in a particular ICT service category, systemic importance (where multiple financial entities rely on the same provider), the provider’s access to sensitive or personal data at scale, and the difficulty of migrating away from the provider within an acceptable timeframe. In Romania, major cloud infrastructure providers, core banking platform vendors, and telecommunications operators are the most common candidates.
When regulators, whether BNR, ASF, or an ESA lead overseer, conduct an inspection, they will ask for evidence that your monitoring and logging arrangements are operational, not merely documented. DORA requires financial entities to implement mechanisms to promptly detect anomalous activities, including ICT-related incidents and significant cyber threats.
From a practical standpoint, this means your outsourcing contracts must include obligations for the vendor to maintain comprehensive logs, grant you (or your auditors) access to those logs, and cooperate during incident investigations. I recommend requiring vendors to retain logs for a minimum period aligned with your supervisory expectations, in practice, at least 12 months for operational logs and longer for security event logs.
Under DORA, an ICT-related incident is defined as a single event or a series of linked events, unplanned by the financial entity, that compromises the security of network and information systems and has an adverse impact on the availability, authenticity, integrity, or confidentiality of data or services. Major incidents must be reported to the relevant national competent authority within prescribed timelines, using the templates developed by the ESAs.
A regulator-ready incident report should include:
In my view, exit planning is the most commonly under-developed area in DORA outsourcing reviews across Romania. Many contracts I review contain a vague commitment to “assist with transition” but lack enforceable specifics: defined data formats, migration runbooks, transition-period service levels, or escrow arrangements. DORA demands substantially more.
A compliant exit plan must address: the format and mechanism for data extraction (including cryptographic keys and configuration files), a tested runbook for migrating to an alternative provider or bringing the service in-house, service transfer testing conducted at least annually, escrow arrangements where the vendor holds proprietary code or configurations critical to the entity’s operations, and clear SLA commitments during the transition period.
Below are three clause templates I regularly use when drafting or amending ICT outsourcing agreements to meet DORA standards:
For each critical vendor, maintain documented evidence that exit plans have been reviewed by the board, tested against realistic scenarios, and updated following any material change to the outsourcing arrangement.
DORA places explicit responsibility on the management body, the board of directors or equivalent, for setting, approving, overseeing, and being accountable for the implementation of the ICT risk management framework. In Romania, this translates into a requirement for board-level awareness, documented risk appetite statements, and a governance structure that assigns clear ownership over ICT third-party risk.
I advise clients to establish a dedicated third-party governance committee (or sub-committee of the risk committee) with a mandate that covers vendor onboarding approvals, ongoing monitoring, escalation procedures, and periodic reporting to the board. The committee should meet at least quarterly and maintain formal minutes.
When a BNR or ASF inspection team arrives, they will request specific documentation. Based on the engagements I have conducted at Olawru, the following evidence package represents the minimum expectation:
Below is a consolidated, phased checklist that compliance teams can use as an operational playbook. I have structured it around realistic milestones, with clear ownership assignments.
Red flags requiring immediate escalation: discovery of an undisclosed sub-outsourcing arrangement, a critical vendor’s refusal to grant audit rights, evidence that a vendor’s data-processing location has changed without notification, or identification of a vendor with no viable exit path within your RTO requirements.
The institutions that will navigate DORA inspections successfully are those that treat this regulation not as a one-time compliance exercise but as an ongoing operational discipline. If you are looking to prepare for a DORA ICT outsourcing review in Romania, my advice is to start with two immediate actions: map your critical vendors using a documented scoring methodology, and run a contract gap analysis against DORA’s minimum requirements. Everything else, governance structures, incident workflows, exit plans, and evidence files, builds from that foundation. For Romanian entities navigating these requirements, the Technology practice area and our directory of Romania, Technology lawyers are valuable starting points for specialist guidance.
For specialist advice on this topic, contact Razvan Alexandru Olaru at Olawru.
posted 24 minutes ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 4 hours ago
posted 5 hours ago
posted 5 hours ago
posted 6 hours ago
posted 6 hours ago
posted 7 hours ago
posted 7 hours ago
posted 7 hours ago
No results available
Find the right Advisory Expert for your business
Send welcome message