Outcome · Win and keep contracts

Win — and keep — contracts with banks, insurers and fund managers

Since 17 January 2025, a bank, an insurer, a fund manager or a payment institution can only keep an ICT vendor whose contract contains the Art. 30 DORA clauses and whose details are in the register of information filed with the supervisor. A vendor who arrives with cited evidence, ready clauses and a verified mark wins the tender; one who needs four rounds of questionnaires loses it to someone who does not.

01

The bank is not being difficult — the bank is accountable

Art. 28(1) DORA makes the financial entity fully accountable for its ICT vendors. Their vendor manager has to document your compliance or replace you.

02

Evidence beats promises

A tender answer that cites a page of your policy and links a verification page gets accepted; “we take security seriously” does not.

03

Vendors get cut at renewal

Existing contracts had to be brought into line. At renewal, the vendor without an Art. 30 clause set is the easiest one to replace.

04

One evidence pack, every customer

Do the work once in Audomate; answer every bank's questionnaire from the same cited evidence.

What changed for vendors in 2025

DORA (Regulation (EU) 2022/2554) has applied since 17 January 2025. It does not regulate you directly if you are a software house or a SaaS company — it regulates your customer and makes them accountable for you. Specifically: your customer has to keep a register of every ICT service you provide (Art. 28(3)), assess you before signing (Art. 28(4)), put a specific set of clauses in the contract (Art. 30) and be able to terminate it if you do not meet them (Art. 28(7)). Each of those obligations turns into a question aimed at you.

How a tender is actually decided today

What the bank's vendor manager needsVendor AVendor B
Art. 30(2) clause set acceptedAccepted with two comments“Legal will look at it” — 3 weeks
Data locations and sub-processorsA table of countries and providers“In the EU, mostly”
Incident notificationA procedure, a 4 h target, a named contact“We'll let you know”
Exit and transitionA plan with data return format and timelineNone
Evidence of security measuresCited policy pages and a verification reportA slide deck
Rounds needed14

Vendor A is no bigger and no more secure than Vendor B. Vendor A read the rules once and can show it.

What Audomate does here

  • Audits your existing documents against the vendor-side requirements in Art. 28–30 DORA and lists the gaps in the order a bank checks them.
  • Drafts the Art. 30 clauses you can offer up front, so the addendum negotiation starts from your text.
  • Generates the register of information data your customer needs, in the format their tool imports.
  • Answers the questionnaire from cited evidence and gives you a one-page summary for the vendor manager.
  • Produces a verification report you can attach to a tender response (the verified mark is coming soon).

Book a 4-week pilot before your next renewal

Questions we get most often

Yes. DORA grandfathers nothing for ICT contracts. Financial entities were expected to bring existing contracts into line; if yours has not been amended yet, expect an addendum — or use the renewal to offer your own.
Usually yes. Art. 30(2)(a) requires the contract to state whether subcontracting is permitted, and the RTS on subcontracting pushes key conditions down the chain for critical or important functions. Your direct customer will pass the requirements on to you.
No — the mark (in preparation) opens the door; the vendor manager still reads the evidence behind it. But a linked verification page usually turns a 40-question questionnaire into 8 contract-specific questions.

Updated 7 September 2026 · This page explains the rules in plain language and is not legal advice. What applies to you always depends on your own contracts and services.

Reach this outcome in four weeks

One regulation, your real documents, a cited gap list and remediation drafts — plus a verified mark if you pass.