Customer · Insurance

TU Europa: ICT vendor risk under DORA with Vendor Assistant

TU Europa — one of Poland's leading insurers — uses Audomate's Vendor Assistant in production to manage ICT vendor risk under DORA: structured questionnaires per vendor, AI review of answers and evidence with citations, verification of vendor contracts against Art. 30, and maintenance of the register of information for reporting to the supervisor.

01

Who

TU Europa, a Polish insurance group supervised by the KNF, a financial entity under Art. 2(1)(n) DORA.

02

What

The Vendor Assistant module: vendor onboarding, questionnaires, evidence review, contract verification, register maintenance.

03

Why

Articles 28–30 DORA make the insurer accountable for every ICT vendor; the number of vendors and documents turned the manual process into a bottleneck.

04

Status

In production. A commercial roll-out of the same engine for vendors and SMEs is under way.

The problem

An insurer depends on dozens of ICT vendors — the core system, the claims platform, cloud, communications, identity, analytics. DORA requires every one of them to be listed in the register of information (Art. 28(3)), assessed before the contract is signed (Art. 28(4)), bound by the clauses in Art. 30 and monitored on an ongoing basis. Done by hand, that is hundreds of pages of questionnaires and contract reviews in every cycle — and the supervisor can ask for the register at any moment.

What runs

  • Vendor profiles and criticality. Every ICT vendor is classified by the function it supports, which decides whether Art. 30(2) applies or the full set in Art. 30(3).
  • Questionnaires per profile. Vendors get a checklist matched to the type of service and its criticality, and upload their evidence.
  • AI review of the answers. Every answer is marked as supported, unsupported or contradicted by the evidence supplied, with page references for the reviewer.
  • Contract verification. Vendor contracts are checked for the mandatory clauses; missing ones are listed with the wording to request.
  • Register of information. Vendor, service, function, criticality, subcontractors and locations are collected once and exported in the structure of Implementing Regulation (EU) 2024/2956.

What changed

The vendor management team reviews findings instead of reading submissions. Questionnaire rounds are shorter because the vendor sees the gaps before sending, and the register is a by-product of the assessment rather than a separate spreadsheet. Audomate runs in production at TU Europa, automating third-party and ICT vendor compliance; a commercial roll-out of the same engine for vendors and SMEs is under way.

Let's talk about vendor assessment

Questions we get most often

Yes. Audomate runs on infrastructure in the EU and offers on-premise deployment to financial entities that require it. No data is transferred outside the EU.
Yes. The DORA vendor obligations are the same for every financial entity under Art. 2(1); vendor profiles and questionnaires are configured to the entity's own outsourcing policy.

Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.

Run vendor assessment the way TU Europa does

The same engine works for a bank with 200 vendors and for a software house answering its first questionnaire. Let's talk about which side you are on.