Create an assessment and enhance digital resilience data
Create an assessment of the Information and Communication Technology (ICT) service in Digital resilience third-party registers using Third-party Risk Management. Add details such as the contractual arrangement reference number, identification code, and type of code for the ICT third-party service provider. You can then enhance its digital resilience information for compliance with DORA regulation.
Before you begin
Role required: sn_vdr_risk_asmt.vendor_assessor
About this task
It's required that you review your contracts and third parties annually. You can provide the following assessment details on the assessment form:
- Contractual reference number, which helps identify the following details:
- Users of the contract
- Providers of the contract
- Other relevant details that are automatically pulled in
- Audit information:
- Has the third-party provider been audited?
- When was the audit last conducted?
- Exit strategy details:
- Existence of an exit plan
- Possibility of integrating with the ICT service provider if terminated
- Impact assessment of discontinuing the ICT service
- Identification of any alternatives
Procedure
What to do next
Once all details are captured, you can perform the following tasks:
- Download the information using the Microsoft Excel download feature. For more information, see Create a Microsoft Excel download request.
- Upload updated records as needed. For more information, see Update existing records in bulk.