DORA: dates, tool and articles
Delegated Regulation (EU) 2024/1773
The DORA vendor questionnaire, written by the Regulation
Delegated Regulation (EU) 2024/1773, in force since 15 July 2024, says what a financial entity's policy on contracts for ICT services supporting critical or important functions must make it ask a vendor: the six assessments before signing, the sources of assurance, the audit methods, the conditions for relying on a certificate, the reports. 21 of its items are the vendor's to answer. Choose what your policy uses; the questionnaire is written below in the Regulation's own words.
The questionnaire
Each item is the Delegated Regulation's text. The evidence lines are StandardOS's reading of where an ISO/IEC 27001 management system produces the answer; the Regulation names no standard.
# DORA due-diligence questionnaire Sent on by the financial entity under Article 28(4) of Regulation (EU) 2022/2554 and Delegated Regulation (EU) 2024/1773, in force since 15 July 2024, as published in the Official Journal and read on 12 September 2026. Each numbered item is the Delegated Regulation's text; the answer and evidence lines are the entity's request. ## Part A. What we assess before contracting (Article 6(1)) Our policy requires us to assess, before entering into the contract, whether you: ### 6(1)(a) has the business reputation, sufficient abilities, expertise and adequate financial, human and technical resources, information security standards, appropriate organisational structure, risk management and internal controls and, if applicable, the required authorisations or registrations to provide the ICT services supporting the critical or important function in a reliable and professional manner; Your answer: [to be completed] Evidence an ISO 27001 system produces (StandardOS's reading): Clause 6.1.3, Clause 9.2, Clause 9.3 ### 6(1)(b) has the ability to monitor relevant technological developments and identify ICT security leading practices and implement them where appropriate to have an effective and sound digital operational resilience framework; Your answer: [to be completed] Evidence an ISO 27001 system produces (StandardOS's reading): A.5.7, A.8.32 ### 6(1)(c) uses or intends to use ICT sub-contractors to perform the ICT services supporting critical or important functions or material parts thereof; Your answer: [to be completed] Evidence an ISO 27001 system produces (StandardOS's reading): A.5.19, A.5.20, A.5.21 ### 6(1)(d) is located, or processes or stores the data in a third country and, if this is the case, whether this practice affects the level of operational or reputational risks or the risk of being affected by restrictive measures, including embargos and sanctions, that may impact the ability of the ICT third-party service provider to provide the ICT services or the financial entity to receive those ICT services; Your answer: [to be completed] Evidence an ISO 27001 system produces (StandardOS's reading): A.5.9 ### 6(1)(e) consents to contractual arrangements that ensure that it is effectively possible to conduct audits at the ICT third-party service provider, including onsite, by the financial entity itself, appointed third parties, and competent authorities; Your answer: [to be completed] Evidence an ISO 27001 system produces (StandardOS's reading): A.5.35 ### 6(1)(f) acts in an ethical and socially responsible manner, respects human rights and children’s rights, including the prohibition of child labour, respects applicable principles on environmental protection, and ensures appropriate working conditions. Your answer: [to be completed] No ISO 27001 record answers this item; a factual answer is required. ## Part B. The assurance we will use (Article 6(3)) No assurance element selected yet; Article 6(4) requires at least one, and more than one where appropriate. ## Part C. Access, inspection, audit and testing (Article 8(2)) No audit or testing method selected yet. ## Part D. Reports and monitoring (Article 9(2)) The periodic report is required at the following cadence: Quarterly. Our policy ensures: ### 9(2)(a) that the ICT third-party service providers provide appropriate reports on their activities and services to the financial entity, including periodic reports, incidents reports, service delivery reports, reports on ICT security and reports on business continuity measures and testing; Please provide: [to be completed] Evidence an ISO 27001 system produces (StandardOS's reading): A.8.16, A.5.24, A.5.29, A.5.30, Clause 9.2, Clause 9.3 ### 9(2)(b) that the performance of ICT third-party service providers is assessed with key performance indicators, key control indicators, audits, self-certifications and independent reviews in line with the financial entity’s ICT risk management framework; Our own assessment; no answer required. ### 9(2)(c) that the financial entity receives other relevant information from the ICT third-party service providers; Please provide: [to be completed] No ISO 27001 record answers this item; a factual answer is required. ### 9(2)(d) that the financial entity is notified, where appropriate, of ICT-related incidents and operational or security payment-related incidents; Please provide: [to be completed] Evidence an ISO 27001 system produces (StandardOS's reading): A.5.24, A.5.26 ### 9(2)(e) that an independent review and audits verifying compliance with legal and regulatory requirements and policies are performed. Our own assessment; no answer required. ## Part E. The register of information and the contract Please complete the register-of-information data sheet (the columns of Implementing Regulation (EU) 2024/2956 that only you can supply: legal identifier, headquarters, ultimate parent, type of ICT service, countries of provision, storage and processing, governing law, notice periods, subcontractors by rank) and return the Article 30 clause checklist with a status per clause. Both are available as free tools on the page this questionnaire was written on. Answers are assessed against Article 6(2): the existence of your risk mitigation and business continuity measures and how their functioning is ensured. The assessment is repeated periodically under Article 9(3). This questionnaire is generated from the Delegated Regulation's text and is not legal advice; the entity's own policy governs.
If the vendor runs StandardOS, the answers come from its records
Every evidence line above names a record an ISO 27001 management system keeps: the Statement of Applicability, the internal audit programme, the supplier register, the incident and continuity records. StandardOS keeps them dated and hash-chained in six languages, so the vendor answers from the system rather than from memory.
The register-of-information data sheetThe Article 30 clause checklistThe vendor's guide to this Delegated Regulation