Win — and keep — contracts with banks, insurers and fund managers
Since 17 January 2025, a bank, an insurer, a fund manager or a payment institution can only keep an ICT vendor whose contract contains the Art. 30 DORA clauses and whose details are in the register of information filed with the supervisor. A vendor who arrives with cited evidence, ready clauses and a verified mark wins the tender; one who needs four rounds of questionnaires loses it to someone who does not.
The bank is not being difficult — the bank is accountable
Art. 28(1) DORA makes the financial entity fully accountable for its ICT vendors. Their vendor manager has to document your compliance or replace you.
Evidence beats promises
A tender answer that cites a page of your policy and links a verification page gets accepted; “we take security seriously” does not.
Vendors get cut at renewal
Existing contracts had to be brought into line. At renewal, the vendor without an Art. 30 clause set is the easiest one to replace.
One evidence pack, every customer
Do the work once in Audomate; answer every bank's questionnaire from the same cited evidence.
What changed for vendors in 2025
DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025. It does not regulate you directly if you are a software house or a SaaS company — it regulates your customer and makes them accountable for you. Specifically: your customer has to keep a register of every ICT service you provide (Art. 28(3)), assess you before signing (Art. 28(4)), put a specific set of clauses in the contract (Art. 30) and be able to terminate it if you do not meet them (Art. 28(7)). Each of those obligations turns into a question aimed at you.
How a tender is actually decided today
| What the bank's vendor manager needs | Vendor A | Vendor B |
|---|---|---|
| Art. 30(2) clause set accepted | Accepted with two comments | “Legal will look at it” — 3 weeks |
| Data locations and sub-processors | A table of countries and providers | “In the EU, mostly” |
| Incident notification | A procedure, a 4 h target, a named contact | “We'll let you know” |
| Exit and transition | A plan with data return format and timeline | None |
| Evidence of security measures | Cited policy pages and a verification report | A slide deck |
| Rounds needed | 1 | 4 |
Vendor A is no bigger and no more secure than Vendor B. Vendor A read the rules once and can show it.
What Audomate does here
- Audits your existing documents against the vendor-side requirements in Art. 28–30 DORA and lists the gaps in the order a bank checks them.
- Drafts the Art. 30 clauses you can offer up front, so the addendum negotiation starts from your text.
- Generates the register of information data your customer needs, in the format their tool imports.
- Answers the questionnaire from cited evidence and gives you a one-page summary for the vendor manager.
- Produces a verification report you can attach to a tender response (the verified mark is coming soon).
Questions we get most often
Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.
Reach this outcome in four weeks
One regulation, your real documents, a cited gap list and remediation drafts — plus a verified mark if you pass.