[{"data":1,"prerenderedAt":10},["ShallowReactive",2],{"article:en:dora-vendor-due-diligence-rts-2024-1773-the-six-questions-the-five-sources-of-assurance-the-eight-conditions-for-relying-on-your-certificate-and-the-five-reports":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"body":9},"en","dora-vendor-due-diligence-rts-2024-1773-the-six-questions-the-five-sources-of-assurance-the-eight-conditions-for-relying-on-your-certificate-and-the-five-reports","Your bank's DORA vendor policy, RTS 2024\u002F1773: the six due-diligence questions, the five sources of assurance, the eight conditions for accepting your ISO 27001 certificate in place of an audit, and the five reports you will owe","Every financial entity in the Union has a written policy on its contracts for ICT services supporting critical or important functions, and Delegated Regulation (EU) 2024\u002F1773 says what that policy must contain, in force since 15 July 2024. Read from the vendor's side: the six things the customer assesses about you before signing (Article 6), the five sources of assurance it may use and the eight conditions under which it may rely on your certifications or audit reports rather than auditing you itself (Article 8), the key indicators, penalties and five kinds of report the contract will demand (Article 9), and the exit plan it must test (Article 10). With what an ISO 27001 certificate answers, and what it does not.","2026-09-12","\nThe questionnaire a bank sends its software vendors is not the bank's invention. Since 15 July 2024 every financial entity under Regulation (EU) 2022\u002F2554, DORA, has had to keep a written policy on its contracts for ICT services supporting critical or important functions, and Commission Delegated Regulation (EU) 2024\u002F1773 of 13 March 2024, published on 25 June 2024, specifies the detailed content of that policy in eleven articles. Article 28(2) of DORA requires the policy; the Delegated Regulation says what the policy must make the bank ask, check, contract for and monitor. Read from the vendor's side it is the outline of every due-diligence questionnaire, every audit clause and every quarterly report request you will receive from a financial customer. This article reads it from the Official Journal on CELLAR on 12 September 2026. It is not legal advice.\n\n## The six things the customer assesses before signing, Article 6(1)\n\nArticle 6(1) requires the policy to set out a proportionate process for selecting and assessing prospective providers, and to require an assessment, before the contract is entered into, of whether the provider: (a) has the business reputation, sufficient abilities, expertise and adequate financial, human and technical resources, information security standards, an appropriate organisational structure, risk management and internal controls and, if applicable, the required authorisations or registrations to provide the service reliably and professionally; (b) has the ability to monitor relevant technological developments and identify ICT security leading practices and implement them where appropriate; (c) uses or intends to use subcontractors for the service or material parts of it; (d) is located, or processes or stores data, in a third country and, if so, whether that affects operational or reputational risk or the risk of being affected by restrictive measures, embargoes and sanctions included; (e) consents to contractual arrangements that make audits at the provider effectively possible, on site included, by the customer, appointed third parties and competent authorities; (f) acts in an ethical and socially responsible manner, respects human rights and children's rights, including the prohibition of child labour, respects applicable principles of environmental protection, and ensures appropriate working conditions.\n\nPoint (a) is the question your ISO 27001 certificate is usually produced for; point (c) is where the subcontracting Delegated Regulation takes over; point (d) is why the register of information asks for the countries of storage and processing; point (e) is the audit clause, and a vendor that refuses on-site audits fails the assessment before the contract exists. Point (f) is the one most vendor questionnaires now carry and most vendors are surprised by: a supplier code of conduct answer, sourced from this paragraph. Article 6(2) adds that the policy specifies the level of assurance the customer needs on the effectiveness of your risk management framework and requires the due diligence to assess the existence of your risk mitigation and business continuity measures and how their functioning is ensured. Article 5 requires an ex-ante risk assessment on the customer's side covering operational, legal, ICT, reputational, data protection, data availability, data location, provider location and concentration risks, and Article 7 asks the customer to identify and manage conflicts of interest, intra-group pricing included.\n\n## The five sources of assurance, Article 6(3) and (4)\n\nArticle 6(3) requires the policy to say which of the following elements are used for the required level of assurance on the provider's performance: (a) audits or independent assessments performed by the customer or on its behalf; (b) independent audit reports made on request by the provider; (c) audit reports made by the provider's internal audit function; (d) appropriate third-party certifications; (e) other relevant information available to the customer or provided by the provider. Article 6(4) requires an appropriate level of assurance taking those elements into account, and, where appropriate, more than one of them. A vendor's task is to make (b), (c) and (d) available before the customer has to fall back on (a): the certificate, the last surveillance audit report, the internal audit programme and its reports.\n\n## The eight conditions for relying on your certificate or audit report, Article 8\n\nArticle 8(1) requires the contract to be in writing and to include all the elements of Article 30(2) and (3) of DORA, the clauses the [clause checklist](\u002Fdora\u002Fcontract-clauses) lists. Article 8(2) requires the contract to include the customer's right to access information, carry out inspections and audits, and perform tests on ICT, using: (a) its own internal audit or an appointed third party; (b) where appropriate, pooled audits and pooled ICT testing, threat-led penetration testing included, organised jointly with other customers of the same provider; (c) where appropriate, third-party certifications; (d) where appropriate, internal or third-party audit reports made available by the provider.\n\nThen Article 8(3), the paragraph that decides how far an ISO 27001 certificate carries you. The customer may not over time rely solely on certifications or audit reports, and the policy may permit their use only where the customer: (a) is satisfied with your audit plan for the relevant contract; (b) ensures that the scope of the certification or report covers the systems and key controls it has identified and ensures compliance with the relevant regulatory requirements; (c) thoroughly assesses the content on an ongoing basis and verifies that the report or certification is not obsolete; (d) ensures that key systems and controls are covered in future versions; (e) is satisfied with the aptitude of the certifying or auditing party; (f) is satisfied that the certification is issued, and the audit performed, against widely recognised relevant professional standards and includes a test of the operational effectiveness of the key controls in place; (g) has the contractual right to request, with a reasonable frequency, modifications of the scope of the certification or report to other relevant systems and controls; (h) has the contractual right to perform individual and pooled audits at its discretion and to execute those rights at the agreed frequency. Article 8(4) adds that material changes to the contract are formalised in a dated, signed document, and that the policy specifies the renewal process.\n\nRead as a vendor, (b) means the certificate's scope statement has to name the product and the systems that run it, not the head office; (c) and (d) mean the certificate is only as good as the last surveillance audit and the next one; (e) means an accredited certification body, and the [accreditation registers](\u002Farticles\u002Fhow-to-check-an-iso-9001-certificate-is-real-what-a-certificate-must-show-three-checks-that-take-ten-minutes-and-the-27-accreditation-registers) a customer will check are the same for ISO 27001 as for ISO 9001; (f) means an audit that tested whether the controls work, which a certification audit does and a self-assessment does not; and (g) and (h) mean the certificate never replaces the audit clause, it only reduces how often it is used.\n\n## The key indicators and the five reports, Article 9\n\nArticle 9(1) requires the contract to specify the measures and key indicators for monitoring the provider's performance on an ongoing basis, including measures to monitor compliance with requirements on the confidentiality, availability, integrity and authenticity of data and with the customer's relevant policies, and the measures that apply when service levels are not met, contractual penalties where appropriate. Article 9(2) requires the policy to ensure, in particular, (a) that the provider gives the customer appropriate reports on its activities and services, including periodic reports, incident reports, service delivery reports, reports on ICT security and reports on business continuity measures and testing; (b) that performance is assessed with key performance indicators, key control indicators, audits, self-certifications and independent reviews; (c) that the customer receives other relevant information; (d) that the customer is notified, where appropriate, of ICT-related incidents and operational or security payment-related incidents; (e) that an independent review and audits verifying compliance with legal and regulatory requirements and policies are performed. Article 9(3) makes the assessment documented and fed back into the customer's risk assessment, and Article 9(4) requires measures against shortcomings, with a defined timeframe and monitoring of their implementation.\n\nThe five reports of point (a) are the operational cost of a financial customer, and a vendor with a management system produces four of them as a by-product: the periodic report from the availability and monitoring record, the incident report from the incident process, the ICT security report from the internal audit and management review, and the continuity report from the plan and its test results. The service delivery report is the one the contract's service levels define.\n\n## The exit plan, Article 10\n\nArticle 10 requires the policy to contain a documented exit plan for each contract, periodically reviewed and tested, taking into account unforeseen and persistent service interruptions, inappropriate or failed service delivery, and the unexpected termination of the contract; the plan must be realistic, feasible, based on plausible scenarios and reasonable assumptions, and have an implementation schedule compatible with the exit and termination terms of the contract. Article 30(3)(f) of DORA puts the transition period and your obligation to keep providing the service during it into the contract; Article 10 is why the customer will ask you to rehearse it.\n\n## What an ISO 27001 certificate answers, and what it does not\n\nThe Delegated Regulation names no standard. What follows is StandardOS's reading of where an ISO\u002FIEC 27001:2022 management system answers the questions, with no presumption of conformity. Article 6(1)(a) is the whole system: the certificate, the Statement of Applicability (clause 6.1.3), the internal audit programme (clause 9.2) and the management review (clause 9.3). Article 6(1)(b) is the threat-intelligence and change controls (A.5.7, A.8.32). Article 6(1)(c) is the supplier register (A.5.19 to A.5.21). Article 6(2) is the continuity plan and its tests (A.5.29, A.5.30). Article 6(3)(b) to (d) are the certificate itself, the surveillance audit reports and the internal audit reports. Article 8(3)(f) is met by a certification audit, which tests operational effectiveness, and not by a self-assessment questionnaire. Article 9(2)(a) is the monitoring record (A.8.16), the incident process (A.5.24 to A.5.27) and the continuity tests. What the certificate does not answer: Article 6(1)(d), which is a fact about your locations; Article 6(1)(e) and Article 8(3)(g) and (h), which are contract terms you have to grant; Article 6(1)(f), which no information security standard covers; and Article 8(3)(b), which depends on whether your certificate's scope names the systems the customer relies on.\n\n## What to do before the questionnaire arrives\n\nWrite the certificate scope so that it names the product and its systems. Keep the last surveillance audit report and the internal audit programme ready to share under a non-disclosure agreement, because Article 6(3)(b) and (c) are the cheapest assurance for both sides. Decide the audit frequency and the pooled-audit terms you can grant under Article 8(3)(h), and price on-site audits in the contract. Define the five reports of Article 9(2)(a) once, with their cadence, and produce them from the system rather than by hand. Write the supplier code of conduct answer to Article 6(1)(f). And put the locations, the subcontractors and the notice periods into the [register data sheet](\u002Fdora\u002Fregister-of-information), because the same policy, at Article 4(e), makes the customer keep the register you appear in. The [DORA hub](\u002Fdora) holds the dates of the Regulation and of this act.\n",1789383984232]