Global Law Experts Logo
prepare dora ict outsourcing review romania

How to Prepare for DORA and ICT Outsourcing Review in Romania

By Razvan Alexandru Olaru
– posted 8 minutes ago

If you need to prepare for a DORA ICT outsourcing review in Romania, three questions should drive every decision you make today: Is each of your ICT vendors classified correctly, and could any qualify as a critical third-party provider (CTPP)? Do your existing contracts contain the audit rights, exit clauses, and incident-reporting obligations that Regulation (EU) 2022/2554 demands? And can you produce, within hours of a supervisory request, the documented evidence that proves all of the above? At Olawru, we advise Romanian financial entities and their technology partners on precisely these operational resilience challenges, and the pattern I see repeatedly is that organisations underestimate the depth of contract-level and governance-level work DORA requires.

This guide walks you through every step of a practical DORA ICT outsourcing review, from building your register of information and scoring vendor criticality, through to drafting exit plans and assembling the evidence package a Romanian regulator will expect on inspection. I have structured it as a phased playbook you can hand directly to your compliance, legal, and procurement teams.

  • Within 30 days: Complete a full contracts inventory, tag high-risk vendors, and run first-pass criticality scoring.
  • Within 90 days: Finalise your register of information, negotiate priority contract amendments, and document your incident-reporting workflows.
  • Within 180 days: Test exit and contingency plans, run a tabletop exercise, and assemble your complete audit-ready evidence file.

What DORA Requires and the Enforcement Timeline

The Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied across the EU since 17 January 2025. It imposes uniform requirements on financial entities in four interconnected pillars: ICT risk management, ICT-related incident reporting, digital operational resilience testing, and the management of ICT third-party risk (which is where outsourcing review sits). The regulation is complemented by delegated acts and regulatory technical standards (RTS) developed jointly by the European Supervisory Authorities, the EBA, ESMA, and EIOPA.

For Romanian institutions, the enforcement window is not approaching, it is here. National supervisors are now conducting thematic reviews, and the register of information that entities submitted in early 2025 is being used as a baseline for targeted inspections. The ESAs published their first report on major ICT-related incidents in mid-2026, signalling that supervisory scrutiny is intensifying across the Union.

Key DORA Articles for Outsourcing Reviews

  • Articles 1–5: Scope, definitions, and the entities covered, including credit institutions, insurers, investment firms, payment institutions, and crypto-asset service providers.
  • Articles 28–30: General principles on ICT third-party risk, the requirement to maintain a register of information on all ICT contractual arrangements, and the policy framework for outsourcing governance.
  • Articles 31–37: The EU-level oversight framework for critical ICT third-party providers (CTPPs), including designation criteria and supervisory powers.
  • Articles 38–44: Information-sharing, cooperation between supervisors, and transitional provisions.

Scope and Who Is Affected in Romania

DORA applies to virtually every regulated financial entity. In Romania, the relevant national competent authorities that enforce DORA requirements are determined by entity type. Understanding which supervisor oversees your institution is essential, because inspection methodologies, language requirements, and escalation channels differ.

Entity Type Core DORA Obligations (Summary) Romanian Supervisory Note / Practical Implication
Banks (credit institutions) ICT risk management, incident reporting, resilience testing, outsourcing oversight including CTPP oversight. Supervised by Banca Naţională a României (BNR), expect targeted inspections, records in Romanian and English, evidence of business continuity.
Insurance / pensions Same DORA pillars; heightened outsourcing controls for critical services. ASF (Romanian Financial Supervisory Authority) coordinates with EIOPA, require insurer-specific register of information, testing evidence, and governance records.
Investment firms / asset managers DORA requirements on ICT risk and third-party oversight; incident reporting to relevant authority (ESMA for EU-level guidance). Local regulator oversight varies, ensure documentation maps to both DORA and local licensing conditions; prepare cross-jurisdictional incident escalation.

When to Escalate to Your National Supervisor

Romanian entities should establish a clear internal protocol for notifying BNR or ASF. In my experience, regulators expect proactive engagement, not reactive disclosure. If a vendor you classify as critical experiences a material service disruption, or if you identify a significant gap in your ICT risk management framework, the supervisory expectation is that you escalate promptly and with documented analysis, not wait for the next scheduled report.

Contract Mapping and Vendor Inventory: Building the DORA Register of Information

The register of information is the foundation of every DORA ICT outsourcing review. Article 28(3) of the regulation requires financial entities to maintain a complete, up-to-date register of all contractual arrangements with ICT third-party service providers. In practice, this means every outsourcing, cloud, managed-services, and co-location agreement must be captured, classified, and kept current.

To prepare your DORA ICT outsourcing review in Romania effectively, I recommend the following step-by-step approach to contract mapping:

  1. Centralise all ICT-related contracts. Collect master service agreements, work orders, SLAs, data processing addenda, and any side letters. Include arrangements with sub-processors and fourth-party providers where your primary vendor sub-delegates.
  2. Extract key contractual clauses. For each contract, extract and catalogue: audit rights, termination and exit provisions, data return obligations, sub-outsourcing restrictions, incident notification obligations, service-level targets, and governing law.
  3. Map service dependencies. Document which business functions depend on each vendor’s services. Identify single points of failure, concentration risk, and cross-border data flows.
  4. Populate the register of information. Use structured fields aligned to the ESAs’ templates.

The register should include, at minimum, the following data fields:

Field Description Owner (typical)
Vendor name & LEI Legal name and entity identifier Procurement / Legal
Service type Category of ICT service provided (cloud, network, application management, etc.) IT / Architecture
Criticality classification Whether the service supports a critical or important function Risk / Compliance
Sub-processors Names and locations of any sub-outsourcing chain Procurement / Vendor mgmt
Data flows & storage location Where data is processed, stored, and transferred IT Security / DPO
SLA targets & RTO/RPO Service-level commitments, recovery time and recovery point objectives IT Operations
Exit & termination terms Notice periods, data return, transition assistance, escrow Legal
Audit rights Right to audit, frequency, access to subcontractors Internal Audit / Legal
Contract start/end date Effective and expiry dates, renewal mechanism Procurement
Primary contact Operational and escalation contacts at the vendor Vendor Management

How to Prioritise: The Criticality Assessment Matrix

Not every vendor warrants the same level of scrutiny. I advise clients to score each arrangement against four dimensions: impact on business continuity if the service fails, sensitivity of data accessed, degree of substitutability (can you switch vendors within your RTO?), and concentration risk (do multiple business lines depend on the same provider?). Assign each dimension a score from 1 to 5, sum the results, and tier your vendors into critical, important, and standard categories. Critical-tier vendors receive full due diligence and enhanced contractual protections; standard-tier vendors receive baseline monitoring.

Critical Vendor Assessment and CTPP Oversight

DORA establishes the most comprehensive ICT third-party risk management framework in EU financial regulation. Articles 28–44 require financial entities to evaluate whether any of their providers qualify as critical third-party providers (CTPPs), a designation that triggers EU-level oversight by a lead overseer appointed from among the ESAs.

Indicators that a vendor may warrant CTPP treatment include: a significant market share in a particular ICT service category, systemic importance (where multiple financial entities rely on the same provider), the provider’s access to sensitive or personal data at scale, and the difficulty of migrating away from the provider within an acceptable timeframe. In Romania, major cloud infrastructure providers, core banking platform vendors, and telecommunications operators are the most common candidates.

Due Diligence Steps

  • Security posture assessment. Request SOC 2 Type II or ISO 27001 certifications, review penetration testing results, and evaluate the vendor’s vulnerability management cadence.
  • Service architecture review. Map the vendor’s infrastructure dependencies, redundancy mechanisms, and disaster recovery capabilities. Verify that their RTO/RPO commitments align with your own operational requirements.
  • Subcontractor chain analysis. Identify fourth-party dependencies. DORA requires that you understand, and can monitor, the full sub-outsourcing chain.
  • Financial health check. Assess the vendor’s financial stability. A vendor that is a going-concern risk cannot reliably deliver critical ICT services.
  • Contractual gap analysis. Cross-reference each contract against DORA’s minimum requirements for audit rights, exit provisions, incident reporting, and data location restrictions.

Auditability, Monitoring, Logging, and Incident Reporting

When regulators, whether BNR, ASF, or an ESA lead overseer, conduct an inspection, they will ask for evidence that your monitoring and logging arrangements are operational, not merely documented. DORA requires financial entities to implement mechanisms to promptly detect anomalous activities, including ICT-related incidents and significant cyber threats.

From a practical standpoint, this means your outsourcing contracts must include obligations for the vendor to maintain comprehensive logs, grant you (or your auditors) access to those logs, and cooperate during incident investigations. I recommend requiring vendors to retain logs for a minimum period aligned with your supervisory expectations, in practice, at least 12 months for operational logs and longer for security event logs.

ICT Incident Reporting: Flows, Timelines, and Content

Under DORA, an ICT-related incident is defined as a single event or a series of linked events, unplanned by the financial entity, that compromises the security of network and information systems and has an adverse impact on the availability, authenticity, integrity, or confidentiality of data or services. Major incidents must be reported to the relevant national competent authority within prescribed timelines, using the templates developed by the ESAs.

A regulator-ready incident report should include:

  • Incident summary. What happened, when it was detected, and which services were affected.
  • Impact metrics. Number of clients affected, duration of service degradation, financial impact estimate, and data integrity assessment.
  • Timeline. Detection, escalation, containment, and resolution timestamps.
  • Root cause analysis. Preliminary and final root cause, including whether a third-party provider was involved.
  • Remediation steps. Immediate actions taken and longer-term corrective measures.
  • Communications log. Internal and external communications, including notifications to supervisors and affected clients.
  • Lessons learned. What the entity will change in its processes, contracts, or architecture to prevent recurrence.

Exit Plans, Termination, Continuity, and Data Portability

In my view, exit planning is the most commonly under-developed area in DORA outsourcing reviews across Romania. Many contracts I review contain a vague commitment to “assist with transition” but lack enforceable specifics: defined data formats, migration runbooks, transition-period service levels, or escrow arrangements. DORA demands substantially more.

A compliant exit plan must address: the format and mechanism for data extraction (including cryptographic keys and configuration files), a tested runbook for migrating to an alternative provider or bringing the service in-house, service transfer testing conducted at least annually, escrow arrangements where the vendor holds proprietary code or configurations critical to the entity’s operations, and clear SLA commitments during the transition period.

Sample Contract Clauses

Below are three clause templates I regularly use when drafting or amending ICT outsourcing agreements to meet DORA standards:

  • Exit assistance clause. “Upon termination or expiry of this Agreement for any reason, Provider shall deliver transition assistance services for a minimum period of [12] months at the then-current service levels and pricing, including full cooperation with any successor provider designated by Client.”
  • Data return clause. “Within [30] calendar days of the effective termination date, Provider shall return to Client all Client Data in [specified machine-readable format], together with all encryption keys, configuration files, and documentation necessary for Client to operate independently of Provider. Provider shall certify destruction of all copies within [60] days thereafter.”
  • Audit rights clause. “Client and its designated auditors, including any competent supervisory authority, shall have the right to conduct on-site and remote audits of Provider’s facilities, systems, and records relevant to the services, upon [15] business days’ prior written notice, with no limitation on frequency where required by applicable law or regulatory instruction.”

For each critical vendor, maintain documented evidence that exit plans have been reviewed by the board, tested against realistic scenarios, and updated following any material change to the outsourcing arrangement.

Governance, Policy, Roles, and Evidence Collection

DORA places explicit responsibility on the management body, the board of directors or equivalent, for setting, approving, overseeing, and being accountable for the implementation of the ICT risk management framework. In Romania, this translates into a requirement for board-level awareness, documented risk appetite statements, and a governance structure that assigns clear ownership over ICT third-party risk.

I advise clients to establish a dedicated third-party governance committee (or sub-committee of the risk committee) with a mandate that covers vendor onboarding approvals, ongoing monitoring, escalation procedures, and periodic reporting to the board. The committee should meet at least quarterly and maintain formal minutes.

What Evidence to Maintain: The Auditor Checklist

When a BNR or ASF inspection team arrives, they will request specific documentation. Based on the engagements I have conducted at Olawru, the following evidence package represents the minimum expectation:

  • ICT risk management framework. Board-approved policy document, updated at least annually.
  • Register of information. Complete, current, and exportable on demand.
  • Criticality assessments. Documented scoring for each vendor, with rationale.
  • Contract amendment tracker. Evidence of DORA gap analysis and clause remediation for each material contract.
  • Incident reports. All ICT-related incident reports filed, including internal escalation records.
  • Resilience test results. Penetration testing, threat-led penetration testing (TLPT) where applicable, and business continuity test outcomes.
  • Exit plan documentation. Tested exit plans for each critical vendor, with board sign-off.
  • Board and committee minutes. Evidence of governance oversight, risk discussions, and decision-making.
  • Vendor audit reports. SOC reports, ISO certifications, and any on-site audit findings from the past 24 months.
  • Training records. Evidence that staff involved in ICT risk management have received appropriate training.

Practical Checklist to Prepare for a DORA ICT Outsourcing Review in Romania

Below is a consolidated, phased checklist that compliance teams can use as an operational playbook. I have structured it around realistic milestones, with clear ownership assignments.

Phase 1: Days 1–30 (Discovery and Triage)

  • Complete a full inventory of all ICT contracts and vendor relationships. Owner: Procurement + Legal.
  • Tag each vendor with a preliminary criticality score. Owner: Risk / Compliance.
  • Identify contracts missing key DORA clauses (audit, exit, incident notification). Owner: Legal.
  • Confirm which Romanian supervisor applies to your entity. Owner: Compliance.

Phase 2: Days 31–90 (Remediation and Documentation)

  • Populate and validate the register of information against ESAs templates. Owner: IT + Compliance.
  • Negotiate and execute contract amendments for critical-tier vendors. Owner: Legal + Procurement.
  • Document incident-reporting workflows and test with a tabletop scenario. Owner: IT Security + Compliance.
  • Present initial DORA compliance status to the board. Owner: CISO / CRO.

Phase 3: Days 91–180 (Testing and Assurance)

  • Conduct exit-plan testing for all critical vendors. Owner: IT Operations + Legal.
  • Execute digital operational resilience tests (penetration testing, scenario-based exercises). Owner: IT Security.
  • Assemble the complete auditor-ready evidence file. Owner: Compliance.
  • Schedule a governance committee review and obtain board sign-off on the final DORA readiness report. Owner: Board Secretary / CRO.

Red flags requiring immediate escalation: discovery of an undisclosed sub-outsourcing arrangement, a critical vendor’s refusal to grant audit rights, evidence that a vendor’s data-processing location has changed without notification, or identification of a vendor with no viable exit path within your RTO requirements.

Conclusion and Next Steps

The institutions that will navigate DORA inspections successfully are those that treat this regulation not as a one-time compliance exercise but as an ongoing operational discipline. If you are looking to prepare for a DORA ICT outsourcing review in Romania, my advice is to start with two immediate actions: map your critical vendors using a documented scoring methodology, and run a contract gap analysis against DORA’s minimum requirements. Everything else, governance structures, incident workflows, exit plans, and evidence files, builds from that foundation. For Romanian entities navigating these requirements, the Technology practice area and our directory of Romania, Technology lawyers are valuable starting points for specialist guidance.

Need Legal Advice?

For specialist advice on this topic, contact Razvan Alexandru Olaru at Olawru.

Sources

  1. EUR‑Lex, Regulation (EU) 2022/2554 (DORA)
  2. EIOPA, Digital Operational Resilience Act (DORA)
  3. ESMA, European Securities and Markets Authority
  4. European Banking Authority (EBA)
  5. Banca Naţională a României (BNR)
  6. Autoritatea de Supraveghere Financiară (ASF)

saas customer refusing pay after platform
By Razvan Alexandru Olaru

posted 24 minutes ago

By Awatif Al Khouri

posted 2 hours ago

company formation oman
By Jonathon Richards

posted 2 hours ago

company formation qatar
By Jonathon Richards

posted 6 hours ago

Find the right Advisory Expert for your business

The premier guide to leading advisory professionals throughout the world

Specialism
Country
Practice Area
ADVISORS RECOGNIZED
0
EVALUATIONS OF ADVISORS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Prepare for DORA and ICT Outsourcing Review in Romania

Send welcome message

Custom Message