GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

DORA ICT Provider (EU)

stable dora-ict-provider-eu · v1.1

A SaaS AI provider selling to EU financial entities: banks, insurers, investment firms, payment institutions, crypto-asset service providers and the rest of the Art. 2 list. DORA binds the customer, not the vendor, reaching the vendor through the Art. 30 contract every such customer must now sign. On top of the provider baseline this overlay carries the vendor side of Chapter V, Section I: the register data the customer collects, the pre-contractual diligence it runs, the contractual provisions of Art. 30(2) and (3), the audit and inspection rights it must be granted, the subcontracting conditions of the RTS on subcontracting and the transition period it exits through. It changes no control's applicability, because DORA adds nothing a provider can decline. What it changes is depth: nineteen controls acquire a contractual counterparty and an outside auditor. Four duties the library does not yet state are proposed in docs/s7-dora-proposals.md. The oversight framework that applies once the ESAs designate a provider critical is out of scope and tracked as a watch. One limit is recorded rather than closed: RTS 2024/1773 Art. 9(1) asks the customer to monitor confidentiality, integrity and authenticity indicators on an ongoing basis, and a multi-tenant provider cannot expose a per-customer confidentiality or authenticity indicator; see the MON-010 row.

Roles
Provider
Deployment models
Cloud, multi-tenant SaaSCloud, single tenant
Risk classes
noneminimaltransparencyhigh-risk-annex-iiigpai
Jurisdictions
EU
Frameworks
SOC2ISO-27001NIST-800-53CSA-CCMCSA-AICMISO-42001NIST-AI-RMFNIST-AI-600-1OWASP-LLMOWASP-AGENTICEU-AI-ActGDPRDORA

Applicability statement

201 controls Download CSV
required 186 controls In scope for this profile. The control has to be in place and evidenced.

GOV · Governance & Risk

Art. 28(5) lets a financial entity contract only with providers that comply with appropriate information security standards. For services supporting a critical or important function it weighs the use of the most up-to-date and highest quality ones. The programme has to be measurable against a named external standard, not only documented. Art. 30(3)(c) adds that the security level is appropriate in line with the customer's regulatory framework, which puts the customer's supervisor in the judgement.

EX-99 written in S8 wave B (migration 057). GOV-010 now records an obligation that reaches the organisation through a customer contract rather than through an instrument binding it directly, naming the contract that transmits it, the instrument behind it and the authority supervising that customer, so an Art. 30 duty living in a signed schedule is visible to the compliance programme. The inventory is also what a provider answers from when a customer reports the arrangement to its own supervisor under Art. 28(3).

RTS 2024/1773 Art. 6(3), point (c), makes the provider's internal audit report one of the five assurance elements a financial entity may rely on. Art. 8(3), point (f), requires any report relied on to test the operational effectiveness of key controls rather than their design.

The independent assessment is what a financial entity reads under Art. 28(4), point (d) and RTS 2024/1773 Art. 6(3). Art. 8(3) then bars it from relying on that report alone over time, so the report is the entry ticket rather than the whole answer.

This is the control the instrument creates. Art. 30(2)(g) puts full cooperation with the customer's competent authorities and resolution authorities, including persons they appoint, into every contractual arrangement rather than only those covering critical or important functions, so it reaches the whole EU financial customer base. RTS 2024/1773 Art. 3(8) adds the statements the arrangement carries: it neither prevents effective supervision nor contravenes a supervisory restriction, it requires cooperation with the competent authorities, and it gives the financial entity, its auditors and the competent authorities effective access to data and to premises. Premises, not systems, which makes it a facilities commitment as much as a compliance one. Arts. 31 to 44 remain excluded to a designated provider under the condition already recorded against this profile.

DAT · Data Protection

Customer-held keys are a commitment of a hosted service.

EX-94 written in S8 wave B (migration 057). The location record now carries, per service, the countries the service is operated, supported and engineered from and the country of each sub-processor's parent undertaking, with a change notified on the terms a data location change is notified on, so Art. 30(2)(b) holds full. Support, operations or engineering access from an unaccepted country is a change of location under the control as well as under the article, even when no data moves.

EX-90 written in S8 wave B (migration 057). The export register now names the arrangement through which the documented retrieval scope stays reachable where the organisation is insolvent, in resolution or has discontinued the service, with the date that arrangement was last verified, and the scope covers personal and non-personal data alike, so Art. 30(2)(d) holds full. DAT-026 exercises the transition itself and VND-013 carries the same commitment where the customer contract has to hold it as a term.

Art. 30(3)(f) makes the transition period mandatory, so the provider cannot decline it even where it terminated for the customer's breach, and sizes it on the complexity of the service rather than on the notice it would otherwise offer. RTS 2024/1773 Art. 10 builds the customer's exit plan on three scenarios, one of them the provider's own failure, which is the scenario the runbook exercise has to cover. Art. 28(8) is the customer's duty this control serves.

Retrieval interfaces and the information needed to stand the service up elsewhere are commitments of a hosted service to its tenants, on the same footing as the export capability in DAT-023.

APP · Application Security

EX-93 written in S8 wave B (migration 057). Published terms now state the conditions on which the organisation takes part in a penetration test a customer commissions against its own production environment, the notice required, the testing window, the systems a customer's testers may reach, the threat intelligence supplied and the route by which several customers of one service commission a single test between them, with the findings handled as the organisation's own. Art. 30(3)(d) holds full. RTS 2024/1773 Art. 8(2) stays partial here: its access, inspection, audit, certification and audit-report methods sit on VND-014.

MON · Monitoring & Logging

EX-92 written in S8 wave B (migration 057) for three of its four clauses: at least one qualitative target per service alongside the availability and latency objectives, a recorded corrective action inside the period the service level states when a target is missed, notice to the customers a published service level binds before a revision takes effect, and notice of a development that puts a committed service level at risk through a named channel that is not the status page. Art. 30(2)(e), Art. 30(3)(a) and Art. 30(3)(b) hold full. Recorded limit (product owner, 2026-09-14): a multi-tenant provider exposes availability and integrity signals through its status channel, which EX-92 widens, and does not expose a per-customer confidentiality or authenticity indicator. The customer's ongoing monitoring of those two properties under RTS 2024/1773 Art. 9(1) is met by the provider's assurance evidence, the VND-011 shared responsibility matrix and the APP-015 audit reports, rather than by a live indicator. No MON control is authored for it and the Art. 9(1) mapping stays partial, with the measures that apply when a service level is missed now stated.

VND · Vendor & Third-Party Risk

RTS 2024/1773 Art. 6(1) is the diligence a financial entity runs on the provider. Two of its criteria have no counterpart in the library: exposure to restrictive measures including embargos and sanctions under point (d) and ethical conduct, human rights, the prohibition of child labour, environmental protection and working conditions under point (f).

This row keeps only the GDPR Art. 28 register of personal-data sub-processors. Since S8 wave B the chain DORA actually reaches, every subcontractor underpinning a critical or important function, the RTS 2025/532 Art. 5 hold on a change until the customer approves or the notice period lapses and the ITS 2024/2956 Art. 3(6) legal entity identifier per subcontractor, are VND-015.

VND-006 stays the review of the suppliers the organisation itself buys from. The inversion RTS 2024/1773 Art. 9(2), point (a) asks for, the provider producing periodic, incident, service delivery, ICT security and business continuity testing reports for the customer, is VND-014 since S8 wave B (EX-97 folded there).

EX-103 and the Art. 30(2)(c) authenticity clause written in S8 wave B (migration 057), on the product owner's decision of 2026-09-14. The commitments now state what is undertaken for the availability, the integrity, the confidentiality and the authenticity of customer data, authenticity being the attributability of data, instructions and messages to the party they claim to come from, so Art. 30(2)(c) holds full. Art. 30(1) still asks for one written contract including the service level agreements, which rules out a boundary published only as a matrix the provider can revise unilaterally; VND-013 carries the contractual form.

Requests for customer data reach the provider because it hosts the tenant's data.

The contract terms run both ways under DORA. Art. 28(7) names four circumstances in which a financial customer must be able to terminate, including where its supervisor can no longer effectively supervise it because of the arrangement, and Art. 30(2)(h) requires termination rights and minimum notice periods set against the expectations of competent and resolution authorities. RTS 2025/532 Art. 6 adds three grounds turning on an unapproved subcontracting change, which the control states in full. VND-002 keeps the buying seat.

Art. 30(3)(e) makes the access right unrestricted and makes any other contract or implementation policy that impedes it a breach in its own right. RTS 2024/1773 Art. 8(3) allows an attestation in place of an audit only where the customer keeps a contractual right to widen its scope and to audit at its discretion anyway, and Art. 3(8)(d) extends the access to premises. Art. 9(2)(a) adds the five standing reports, among them the continuity testing report, which means handing a customer the results of the exercises BCM-006 runs. Pooled threat-led penetration testing sits on APP-005.

RTS 2025/532 turns subcontracting from a disclosure into a permission: Art. 5 holds the change until the customer approves or the notice period lapses, Art. 4(1) pushes the customer's monitoring, reporting, security and audit access terms into the subcontract and Art. 3(1)(b) to (d) makes the provider evidence that it can identify every subcontractor of a critical or important service and grant the same access rights through the chain. ITS 2024/2956 Art. 3(6) is where the legal entity identifier per party comes from. VND-003's note shrinks to the personal data arm.

INC · Incident Response

The financial entity has its own Art. 19 major-incident reporting clock, which starts from facts only the provider holds. The statutory reporting register now written into this control is where that dependency becomes visible: an obligation whose trigger is a customer's clock is an entry with its own recipient, timing and content, alongside the GDPR and NIS2 entries. The assistance that serves the customer's clock is INC-006.

Art. 30(2)(f) is now stated. The incident communication process names the assistance available to a customer during that customer's own response, the point of contact for it and the basis on which it is charged, with the basis fixed before an incident rather than quoted during one. The duty binds every contract, not only those covering critical or important functions.

BCM · Business Continuity

Art. 30(3)(c) makes the contingency plan a contract term for any service supporting a critical or important function. RTS 2025/532 Art. 4(1), point (h), pushes the same requirement into the provider's contracts with its own subcontractors, with service levels attached.

Art. 30(3)(c) requires the plans to be tested, not only held. RTS 2024/1773 Art. 9(2), point (a), then requires the results to reach the customer as a standing report on business continuity measures and testing.

EX-98 written in S8 wave B (migration 057). An entry for a third party whose loss would breach a recovery objective for a customer-committed service now names the clause of that third party's own contract requiring a contingency plan and its testing, with the service level that plan is held to, which is RTS 2025/532 Art. 4(1), points (g) and (h). Art. 29 still scores the provider on substitutability and on the length of its subcontracting chain before a contract exists, which is a commercial consequence of the register rather than a further control requirement.

AIG · AI Governance

Art.50 disclosure binds every provider of an interacting or generating system, whatever its risk class.

Art.5 binds every provider, whatever the risk class of its other systems.

Instructions for use, the provider identification and the customer agreement are provider duties (Art.13, Art.16.2, ISO 42001 A.8).

The provider is also a user of AI systems, including the models beneath its product. The use register covers both.

The statement on customer data in training and the opt-out are the provider's to give.

Any organisation that trains, fine-tunes or evaluates a production model runs the pipeline this control secures. A provider that only calls a third-party model records that no pipeline exists against the inventory entry.

Required, as the library states every control whose trigger is a feature set rather than a facet (DAT-018, AIG-014, AIG-042, AIG-056): the documented assessment the control opens with is the first artefact. It bites where a system relies on user-supplied or external audio, image or video as evidence of a person's identity, of the provenance of an artefact or of a real-world event, which is a live case for identity verification, onboarding, claims and content-moderation features. An organisation whose assessment finds no such intake point records that finding and the detection limb has nothing to attach to. Restated from recommended on the S13 benchmark (ADR-049 amendment, 2026-09-16).

HRS · Human Resources Security

EX-96 written in S8 wave B (migration 057). The training record now identifies, for each person assigned to a customer's service, the training that customer required and its completion date, and the export can be filtered to that customer, so Art. 30(2)(i) holds full and completion is producible to the customer. HRS-005 holds role-based training content; the record of a customer-required completion sits on HRS-004.

conditional 4 controls In scope when the stated condition holds. Read the condition before deciding.

AIG · AI Governance

Condition: ai_risk_class in high-risk-annex-iii

Art.17 quality management system binds providers of high-risk systems.

Condition: ai_risk_class in high-risk-annex-iii

Conformity assessment, the declaration and the CE marking (Art.43, 47, 48) bind providers of high-risk systems.

Condition: ai_risk_class in high-risk-annex-iii and the organisation is established outside the Union

Art.22 binds providers of high-risk systems established outside the Union. The Art.54 arm for general-purpose model providers belongs to the gpai-model-provider profile.

Condition: ai_risk_class in high-risk-annex-iii

Art.20 and Art.21 bind providers of high-risk systems. The Art.53.5 cooperation duty on general-purpose model providers belongs to the gpai-model-provider profile.

not-applicable 11 controls Out of scope for this profile. It is stated rather than omitted so the exclusion is auditable.

AIG · AI Governance

Worker notification before a system is put into use at a workplace is an employer's duty under Art.26(7). A provider placing the system on the market owes it for its own workforce only where it is also the deployer, which is the enterprise-ai-deployer seat.

Registration by the organisation using the system is a deployer duty under Art.49(3). The provider registration of Art.49(1) and (2) sits on AIG-003 and is required of this profile there.

The fundamental rights impact assessment of Art.27 is owed by the deployer about the use it makes of the system. A provider's duty is to supply the information the assessment draws on, which AIG-034 carries.

Documentation of a general-purpose model as such is the gpai-provider seat (gpai-model-provider, ADR-046). A SaaS provider documents its product under AIG-015 and, where it also trains and offers a general-purpose model, holds the gpai-provider role and that profile alongside this one.

The public training content summary is the gpai-provider seat (ADR-046). A provider that fine-tunes a third-party model for its product records provenance under AIG-013 and is not the models provider.

The copyright policy and crawler conduct of a general-purpose model provider are the gpai-provider seat (ADR-046). A SaaS providers own licensed assets and training data licences are GOV-015 and AIG-013.

Systemic risk at Union level attaches to a designated general-purpose model and its provider (ADR-046). Risk from the systems a SaaS provider builds is AIG-005.

Evaluation under standardised protocols attaches to a designated general-purpose model (ADR-046). A SaaS provider evaluates the systems it operates under AIG-026 and AIG-008.

Protection of a designated models weights to a stated security goal is the gpai-provider seat (ADR-046). A SaaS providers development assets and training pipeline are IAM-014 and AIG-055.

Reporting to the AI Office about a designated model is the gpai-provider seat (ADR-046). A SaaS provider reports a systems serious incident to the competent authority under AIG-021.

The safety and security model report is the gpai-provider seat (ADR-046) and is recommended rather than required even there.

Published 2026-09-14