TU Europa: ICT vendor risk under DORA with Vendor Assistant
TU Europa — one of Poland's leading insurers — uses Audomate's Vendor Assistant in production to manage ICT vendor risk under DORA: structured questionnaires per vendor, AI review of answers and evidence with citations, verification of vendor contracts against Art. 30, and maintenance of the register of information for reporting to the supervisor.
Who
TU Europa, a Polish insurance group supervised by the KNF, a financial entity under Art. 2(1)(n) DORA.
What
The Vendor Assistant module: vendor onboarding, questionnaires, evidence review, contract verification, register maintenance.
Why
Articles 28–30 DORA make the insurer accountable for every ICT vendor; the number of vendors and documents turned the manual process into a bottleneck.
Status
In production. A commercial roll-out of the same engine for vendors and SMEs is under way.
The problem
An insurer depends on dozens of ICT vendors — the core system, the claims platform, cloud, communications, identity, analytics. DORA requires every one of them to be listed in the register of information (Art. 28(3)), assessed before the contract is signed (Art. 28(4)), bound by the clauses in Art. 30 and monitored on an ongoing basis. Done by hand, that is hundreds of pages of questionnaires and contract reviews in every cycle — and the supervisor can ask for the register at any moment.
What runs
- Vendor profiles and criticality. Every ICT vendor is classified by the function it supports, which decides whether Art. 30(2) applies or the full set in Art. 30(3).
- Questionnaires per profile. Vendors get a checklist matched to the type of service and its criticality, and upload their evidence.
- AI review of the answers. Every answer is marked as supported, unsupported or contradicted by the evidence supplied, with page references for the reviewer.
- Contract verification. Vendor contracts are checked for the mandatory clauses; missing ones are listed with the wording to request.
- Register of information. Vendor, service, function, criticality, subcontractors and locations are collected once and exported in the structure of Implementing Regulation (EU) 2024/2956.
What changed
The vendor management team reviews findings instead of reading submissions. Questionnaire rounds are shorter because the vendor sees the gaps before sending, and the register is a by-product of the assessment rather than a separate spreadsheet. Audomate runs in production at TU Europa, automating third-party and ICT vendor compliance; a commercial roll-out of the same engine for vendors and SMEs is under way.
Questions we get most often
Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.
Run vendor assessment the way TU Europa does
The same engine works for a bank with 200 vendors and for a software house answering its first questionnaire. Let's talk about which side you are on.