Financial services · ICT third parties & outsourcing
ICT third-party risk and the Register of Information, set up to be audit-ready
Your critical IT services now sit with third parties: cloud, SaaS, hosting, managed services. DORA requires a Register of Information covering all ICT third parties, clear contract clauses and exit strategies for them. FINMA expects comparable diligence for material outsourcing under Circular 2018/03. We build the register, classify critical and important functions and make your third-party risk audit-ready.
DORA Pillar 4 · Register of InformationFINMA Circular 2018/03 outsourcingDE · FR · EN
Outsourced IT remains your responsibility. DORA makes the management of ICT third parties a dedicated pillar, and FINMA expects comparable diligence for material outsourcing. Whether and how DORA applies to your institution directly or indirectly is something we verify case by case.
Most financial institutions now source their most important IT services from third parties. A substantial part of operational risk thereby moves outside, while the regulatory responsibility does not move with it. Supervisors and lawmakers have responded by elevating third-party risk into a duty in its own right.
DORA bundles these requirements into a dedicated pillar for managing ICT third-party risk. At its core is a complete register of all contractual arrangements for ICT services, the Register of Information. Added to this are duties on contract content, on designating critical or important functions, on concentration risk, on subcontracting, and on audit and access rights and exit strategies. For Swiss institutions DORA usually applies indirectly, for instance via EU branches, subsidiaries or contracts with EU-regulated financial entities. Direct versus indirect we verify per institution.
In parallel, FINMA requires comparable diligence under Circular 2018/03 on outsourcing. Material outsourcing must be recognised as such, documented and contractually safeguarded, the institution's responsibility remains, and data protection and auditability must be preserved. The circular is in force. Where the DORA register and the FINMA outsourcing documentation overlap, we bring them together instead of maintaining two separate worlds.
A Register of Information covering all contractual arrangements with ICT third parties, complete and maintained
Designation of which services support a critical or important function, with higher requirements for those
Contractual minimum content: service description, service levels, audit and access rights, subcontracting rules, termination and exit provisions
Management of concentration risk where many critical services sit with few providers
Visibility over the subcontracting chain and the conditions under which a provider may onward-outsource
Documented exit strategies for critical functions so a provider change or withdrawal stays orderly
Recognition and safeguarding of material outsourcing under FINMA Circular 2018/03, with data protection and auditability preserved
How we build your third-party risk management
We start at the register and end with a running process. A list of contracts becomes an audit-ready control that covers concentration risk, subcontractors and exit plans. We maintain the register in the Priverion Platform.
First we capture your ICT third parties completely and build the Register of Information so that it meets the DORA requirements and at the same time carries the FINMA outsourcing documentation. We inventory the contracts, map each service to the business function it supports and classify which ones concern a critical or important function. This classification determines how strict the further requirements are.
Next we check your existing contracts against the required minimum content and draft or upgrade the missing clauses: audit and access rights, subcontracting rules, service levels, security and reporting duties, plus termination and exit provisions. For critical functions we develop documented exit strategies so a provider change or a withdrawal stays orderly and without an operational interruption.
To keep third-party risk controllable over time, we set up the TPRM process: onboarding new providers with a risk assessment, periodic review of existing ones, handling of subcontractors and a view on concentration risk where many critical services sit with few providers. The one-off intake thereby becomes a recurring control.
We keep the Register of Information, the classifications, the contract evidence and the exit plans in the Priverion Platform, the Swiss compliance-management software. If your audit team, internal audit or FINMA asks, the evidence is ready, maintained and exportable. Where operational tests are needed, such as pentests or vulnerability scans at a provider, our in-house technical team covers that.
Why SIDD for your ICT third-party risk
Third-party risk is half contract and half technology. We cover exactly that combination from one partner, legally led and technically backed.
Law and technology from a single team
Contract clauses, exit plans and the FINMA outsourcing logic are led by doctorate-level lawyers, the providers' risk assessment and the technical review by an in-house technical team under an ISO 27001 Lead Auditor. So legal and technical requirements fit together in the register.
One register for DORA and FINMA
Instead of two separate documentations, we run the Register of Information so that it also carries the FINMA outsourcing requirements under Circular 2018/03. You maintain the third parties once and serve both worlds with it.
Concentration risk in view
We make visible where many critical services sit with few providers or in a single cloud region, and propose measures. A silent cluster risk thereby becomes a conscious, documented decision.
Multilingual & independent
We negotiate provider contracts in German, French and English, relevant for institutions in CH and EU and their international providers. Because we do not sell an in-house SOC, our recommendations on providers stay independent.
Audit-ready evidence in tooling
We maintain the Register of Information, the classifications, the contract evidence and the exit plans in the Priverion Platform. If internal audit or FINMA asks, the evidence is ready, maintained and exportable.
Fixed-fee entry
You start with a fixed-fee build of the Register of Information including the TPRM setup and then decide on ongoing operation. The entry stays predictable before you commit to a retainer mandate.
Two routes to controlled third-party risk
Register of Information & TPRM setup
Fixed fee
The one-off build of your third-party risk management, from the complete register to a running process.
Register of Information covering all ICT third parties, DORA-aligned and FINMA-fit, in the Priverion Platform
Classification of critical and important functions per service, with a traceable rationale
Gap analysis of existing contracts against the required minimum content and against FINMA Circular 2018/03
Drafting or upgrading of contract clauses and documented exit strategies for critical functions
A set-up TPRM process with provider onboarding, a concentration-risk view and subcontractor handling
The ongoing operation: someone who maintains the register, assesses new providers and keeps the third-party risk audit-ready.
Ongoing maintenance of the Register of Information and the classifications in the Priverion Platform
Risk assessment of new providers and periodic review of existing ones
Monitoring of concentration risk and subcontracting chains, with proposed measures
Negotiation and updating of provider contracts in DE, FR or EN
Point of contact for internal audit and FINMA questions on third-party risk
LexCMD
Our tool: LexCommand
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your register of information, concretely: LexCommand drafts contract clauses, exit plans and the register of information as traceable templates with sources, and places the duties from the DORA third-party rules and FINMA Circular 2018/03 side by side, so critical outsourcing is demonstrably covered.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions
Does DORA apply to our Swiss institution at all?
DORA applies in the EU since 17 January 2025. For Swiss institutions it usually takes effect indirectly, for instance via EU branches, subsidiaries or via contracts with EU-regulated financial entities that pass their requirements on to you. Whether it reaches you directly or indirectly depends on your structure and your business relationships. We verify this case by case before we size the effort.
What all goes into the Register of Information?
The register captures all contractual arrangements for ICT services, so not only the large cloud but also SaaS, hosting, managed services and comparable engagements. Each entry includes, among other things, the provider, the service obtained, the business function it supports, whether that function is critical or important, and details on the subcontracting chain. We build it so that it stays complete and maintainable.
How does this relate to the FINMA outsourcing duty?
FINMA Circular 2018/03 on outsourcing requires that material outsourcing is recognised, documented and contractually safeguarded, that the institution's responsibility remains, and that data protection and auditability are preserved. The circular is in force. In substance it overlaps strongly with the DORA requirements, which is why we run a single register that serves both duties instead of maintaining two separate ones.
What does a critical or important function mean?
It is about how badly your business suffers if the service fails or is delivered poorly. If an ICT service supports a function whose failure would noticeably impair your business operations, your regulatory duties or financial stability, that function counts as critical or important. Such services carry higher requirements on contract, audit rights and exit. We make the designation in a traceable way and document the rationale.
Do we have to renegotiate all provider contracts?
No, not across the board. We prioritise by criticality. Contracts for critical and important functions we review first against the required minimum content and close the most important gaps in audit rights, subcontracting and exit. Less critical services we work through step by step. This focuses your negotiating power where the risk is.
Do you also carry out technical reviews of our providers?
Yes, within our existing services. Pentests and vulnerability scans are carried out by our in-house technical team, for instance to evidence the security of a critical provider or an interface. We do not run continuous managed 24/7 monitoring or live incident response, we coordinate that with specialised partners when needed so our advice stays independent.
Matching next steps
Your third-party risk ties closely to FINMA and DORA governance and to source-code escrow:
Ready to make your ICT third-party risk audit-ready?
We build your Register of Information, classify critical and important functions, close contract gaps and set up the TPRM process, one register for DORA and FINMA.