Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

What DORA Article 29 requires when assessing ICT concentration risk

ICT Concentration Risk: 6 Essential Checks Before You Sign

ICT concentration risk under DORA is not the annual portfolio report most firms think it is. Article 29 calls it a preliminary assessment, and preliminary means before you sign.

That single word moves the obligation out of risk reporting and into procurement, where almost nobody has put it.

When the assessment has to happen

What DORA Article 29 requires when assessing ICT concentration risk

Article 29 is titled Preliminary assessment of ICT concentration risk at entity level, and it attaches to the risk identification financial entities already perform under Article 28(4), point (c) — the work done before entering a contractual arrangement.

So the ICT concentration risk question is not “how concentrated is our estate?” It is “what would this particular contract do to our concentration?” Asked at the point the answer can still change the outcome.

An entity that reviews ICT concentration risk once a year, after the contracts are signed, is doing something useful but is not doing Article 29.

The two ICT concentration risk triggers

Article 29(1) asks whether the envisaged arrangement, for ICT services supporting critical or important functions, would lead to either of:

  • (a) contracting an ICT third-party service provider that is not easily substitutable; or
  • (b) having in place multiple contractual arrangements for ICT services supporting critical or important functions with the same provider, or with closely connected providers.

Limb (b) is the ICT concentration risk trigger that catches people. “Closely connected” reaches beyond the legal entity you are contracting with, so three arrangements with three subsidiaries of one group is a single concentration, not three independent ones. Any assessment built from a supplier list keyed on contracting entity will miss it.

Limb (a) is a judgement you have to be able to defend. Substitutability is not a property of the vendor; it is a property of your dependency on them — the data formats, the integrations, the skills, and the time an alternative would take to stand up. It is the same analysis as a DORA exit strategy, which is why the two should be produced together rather than by different teams a year apart.

ICT concentration risk means showing the alternative you rejected

This is the requirement with teeth. Financial entities shall weigh the benefits and costs of alternative solutions, such as the use of different ICT third-party service providers — taking into account if and how the envisaged solutions match the business needs and objectives set out in their digital resilience strategy.

Three things follow.

An alternative must actually have been considered. Not “no realistic alternative exists”, but a named option with its benefits and costs weighed.

The comparison is against the digital resilience strategy, not against price. If your strategy does not set out business needs and objectives in terms a procurement decision can be tested against, this limb cannot be satisfied — which makes the strategy document load-bearing rather than decorative.

It is contemporaneous. Reconstructing the reasoning after the fact is exactly what “preliminary” rules out.

ICT concentration risk follows the subcontracting chain

Article 29(2) extends the assessment past your counterparty. Where the contract permits the provider to further subcontract ICT services supporting a critical or important function, you must weigh the benefits and risks — in particular where the subcontractor is established in a third country.

Then two obligations that are rarely in anyone’s due diligence pack:

  • Insolvency. Duly consider the insolvency law provisions that would apply in the event of the provider’s bankruptcy, and any constraint on the urgent recovery of your data. That is a legal opinion about a jurisdiction, not a questionnaire answer — and it is the question that decides whether your exit plan works on the worst day.
  • Enforceability. For third-country providers, also consider compliance with Union data protection rules and the effective enforcement of the law in that third country. A contract term is only worth what a court there will do with it.

Chain length is its own ICT concentration risk

The last limb is easy to skim and hard to satisfy. Where subcontracting is provided for, entities must assess whether and how potentially long or complex chains of subcontracting may impact their ability to fully monitor the contracted functions, and the ability of the competent authority to effectively supervise the financial entity in that respect.

Note the second half. The test is not only whether you can see down the chain — it is whether your supervisor can still supervise you through it. A chain that defeats supervision is a problem even where you are personally comfortable with the risk, and it connects directly to the Article 28(7) termination right that bites where a competent authority can no longer effectively supervise you because of an arrangement.

Entity-level ICT concentration risk is not the whole picture

Article 29 is expressly at entity level. The systemic layer sits elsewhere: the European Supervisory Authorities designate critical ICT third-party service providers and place them under a Union oversight framework with a Lead Overseer.

The practical reading for a single firm is that you get no comfort from that. Your provider being overseen at Union level does not reduce your own concentration, and does not discharge the Article 29 assessment.

How ICT concentration risk connects

Area Connection
Register of information Where the arrangements, providers and their relationships are recorded — the data the assessment reads
DORA exit strategy Substitutability under 29(1)(a) and exit planning under 28(8) are the same analysis
Third-party risk management The pre-contract due diligence this obligation lives inside
DORA requirements Where Articles 28 to 30 sit in the third-party chapter

Where to start

  1. Move the ICT concentration risk assessment into procurement, before signature, since “preliminary” is the operative word.
  2. Group providers by ownership, so “closely connected” is visible rather than hidden across three contracts.
  3. Record a named alternative with its benefits and costs, not a statement that none existed.
  4. Make the digital resilience strategy testable, because the comparison is measured against it.
  5. Get an insolvency and enforceability view for third-country providers and subcontractors.
  6. Map the subcontracting chain and ask whether your supervisor could follow it.

This guide reflects Regulation (EU) 2022/2554 as published on EUR-Lex, read at 16 August 2026. Regulatory technical standards on subcontracting add detail — confirm the current position with your competent authority.

The DORA Toolkit provides 100+ editable templates covering the pre-contractual assessments, the register of information, the exit strategies and the ICT third-party contractual requirements Articles 28 to 30 depend on.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.