AWS, Azure, and Google Cloud are not financial entities under DORA — they are ICT third-party service providers to financial entities. DORA reaches them through two mechanisms: the contractual obligations that financial entity customers must impose, and the Critical Third-Party Provider (CTPP) oversight framework that gives EU supervisors direct authority over the most systemically important cloud providers.
How DORA Applies to the Major Cloud Providers
As ICT third-party service providers: Every bank, payment institution, and insurer using AWS, Azure, or GCP is required to:
- Include them in their Register of Information
- Assess their criticality
- Include DORA Article 30 provisions in their contracts
- Conduct due diligence on their security practices
The hyperscale cloud providers have all proactively developed DORA-aligned contractual frameworks, compliance documentation, and security certifications to enable their financial services customers to meet these obligations.
As Critical Third-Party Providers: The major hyperscale cloud providers are at the centre of the CTPP designation process. AWS, Azure, and GCP have been engaged in the CTPP assessment process and are expected to be designated. Once designated, they are subject to direct oversight by the EU Joint Oversight Network — receiving annual assessments, information requests, and remediation obligations from EU supervisors.
What the Cloud Providers Have Built for DORA
All three major cloud providers publish DORA-specific compliance documentation:
AWS:
- DORA-aligned shared responsibility model documentation
- AWS Customer Agreement includes EU financial sector addendum with Article 30 provisions
- AWS Artifact provides access to compliance reports relevant to DORA customers
- AWS publishes its sub-processor list and data processing addendum with DORA provisions
Microsoft Azure:
- Azure Financial Services Compliance Program includes DORA documentation
- Microsoft Customer Agreement includes DORA-aligned provisions for financial services customers
- Azure Compliance Manager includes DORA assessment templates
- Microsoft publishes a DORA responsibility matrix
Google Cloud:
- Google Cloud DORA compliance framework documentation
- Google Cloud Data Processing Addendum includes DORA financial sector provisions
- Google Cloud Trust & Security section includes DORA-relevant certifications
- Google publishes its DORA sub-processor information
What Financial Entities Must Configure
Using a DORA-compliant cloud platform does not automatically make the financial entity DORA-compliant. The shared responsibility model means:
Cloud provider responsible for:
- Physical security of data centres
- Underlying infrastructure security
- Availability and resilience of the platform
- Platform-level encryption
- Platform incident notification to customers
- CTPP oversight engagement
Financial entity responsible for:
- Configuring security controls in their cloud tenancy
- Data encryption using customer-managed keys (where required for additional control)
- Identity and access management within their cloud accounts
- Network controls (VPC configuration, security groups, access policies)
- Logging and monitoring configuration
- Backup and recovery configuration within the cloud environment
- Exit strategy planning
The DORA Register of Information entry for the cloud provider must reflect this division clearly — identifying which functions the cloud provider performs and which the financial entity performs.
Multi-Cloud and Concentration Risk
DORA specifically addresses concentration risk — the risk that excessive dependence on a single provider creates systemic vulnerability. Financial entities relying heavily on a single hyperscale cloud provider face:
Concentration assessment requirement: The Register of Information must capture concentration. If 80% of critical functions run on a single cloud provider, this concentration must be documented and the risk assessed.
Exit strategy requirement: Financial entities must maintain documented exit strategies for critical providers. For a deeply cloud-native fintech with all production systems on one cloud, the exit strategy must address how operations would be maintained if that cloud were unavailable.
Regulatory attention: Supervisors are scrutinising single-cloud dependence. There is no explicit requirement to use multiple cloud providers, but firms with extreme concentration must demonstrate credible resilience plans.
Multi-cloud architecture: For significant financial entities, multi-cloud or cloud + private architecture is increasingly expected. The operational and cost complexity of multi-cloud must be weighed against the concentration risk of single-cloud.
Practical Steps for Financial Entities Using Major Cloud Providers
- Review your existing cloud contracts against Article 30 requirements — access the provider's DORA-specific addendum or DPA that includes Article 30 provisions
- Add the cloud provider to your Register of Information in the correct ESA format
- Assess criticality — which functions would fail without the cloud provider?
- Document the shared responsibility model — clearly separate what the provider does from what you do
- Enable required logging and monitoring — configure audit logging, CloudTrail/Azure Monitor/GCP Cloud Audit Logs to support your incident response
- Test recovery within the cloud environment — multi-region failover, backup restoration, documented within your BCP
- Develop exit strategy documentation — even if a full cloud migration is impractical, a credible partial exit or portability plan addresses the DORA requirement