Skip to content
DORA

DORA Contract Clauses Banks Expect from Vendors

5 min readUpdated 1 July 2026

DORA Article 30 specifies the minimum contractual provisions that financial entities must include in contracts with ICT third-party service providers. If you sell to banks, payment institutions, or other financial entities, your customers are required to have these provisions in your contract. Companies that are not ready for DORA contract negotiations will face delays, renegotiation demands, and potential lost deals.

This article covers every Article 30 provision and how to handle them.


Why These Clauses Are Now Standard

DORA has been in force since January 2025. Every major bank is auditing their ICT vendor contracts for Article 30 compliance. Contracts that were signed before DORA are being reviewed and renegotiated. New vendor contracts must include these provisions from the outset.

A SaaS vendor that receives a DORA contract addendum from a bank customer and has never seen it before is behind. A vendor with a pre-prepared DORA addendum can turn this from a friction point into a selling point.


The Full Article 30 Checklist

1. Full Description of ICT Services and SLAs

What it requires: A clear, complete description of the services provided, including:

  • Specific services covered by the agreement
  • Service levels — uptime commitments, response times, processing times
  • Update/maintenance windows and advance notice requirements

How to handle it: Your standard order form or service schedule typically covers this. Ensure SLAs are specific and measurable — "best efforts" language will not satisfy DORA requirements.

2. Locations Where ICT Services Are Provided and Data Is Processed

What it requires: The contract must identify:

  • Where data centres are located
  • Where data is stored and processed
  • Any planned changes to data locations (with advance notification obligation)

How to handle it: Add a Data Location Schedule to your standard agreement. Include primary and backup data centre locations, cloud provider regions, and any DR site locations.

3. Full Description of ICT Services Including Sub-Contractors

What it requires: Disclosure of all sub-contractors involved in delivering the service, particularly those that handle the financial entity's data.

How to handle it: Maintain a sub-processor list and make it available to customers. Include an obligation to notify customers before making material changes to sub-contractors.

4. Data Accessibility, Availability, Integrity, and Security

What it requires: Provisions covering:

  • The vendor's data protection standards
  • Encryption and access control requirements
  • Data integrity measures
  • Notification if security standards change

How to handle it: Reference your ISO 27001 certification or SOC 2 Type II report. Include a clause confirming minimum security standards and a process for updating security documentation.

5. Provisions Ensuring Accessibility, Availability, Integrity, Confidentiality, and Safety

What it requires: Performance guarantees linked to the financial entity's own operational resilience requirements.

How to handle it: Include uptime SLAs with service credits. Include provisions on maximum allowable downtime for different service tiers.

6. Rights to Full Access, Inspection, and Audit

What it requires: The financial entity (and their supervisory authority) must have the right to:

  • Audit the vendor's security practices
  • Access security audit reports (SOC 2, ISO 27001, pen test results)
  • Conduct on-site inspections with reasonable notice

How to handle it: Include an audit rights clause. Offer a report exchange (provide your SOC 2/ISO 27001 report as an alternative to on-site audit for standard annual reviews). Reserve on-site audit rights for when reports are insufficient or an incident has occurred.

7. Implementation and Testing of Business Continuity Plans

What it requires: The vendor must implement and periodically test a BCP relevant to the services provided. The financial entity should receive evidence of testing.

How to handle it: Include a provision confirming your BCP covers the services and that test results will be made available on request (or summarised annually).

8. Cooperation with Competent Authorities

What it requires: The vendor must cooperate with the financial entity's supervisory authorities when requested.

How to handle it: Include a clause confirming cooperation with regulatory inquiries — this is standard in financial services contracts.

9. Termination Rights and Minimum Notice Periods

What it requires: The financial entity must have the right to terminate for:

  • Material breach of the contract
  • Major security incident
  • Regulator direction
  • Financial entity's own insolvency/licence revocation

How to handle it: Include termination-for-cause provisions, including security incidents as a termination trigger. Set minimum notice periods for ordinary termination that allow adequate data migration time.

10. Conditions for Sub-Contracting

What it requires: Rules on when and how sub-contractors can be used, with notification rights for the financial entity.

How to handle it: Include a general authorisation for existing sub-contractors with a notification obligation for changes. Match this to your GDPR sub-processor notification approach.


Building a DORA-Ready Contract

The most efficient approach: create a DORA Contract Addendum that can be attached to your standard terms. The addendum:

  • Incorporates all Article 30 provisions
  • References your existing security certifications
  • Includes the data location schedule
  • Covers audit rights and report sharing

Having this ready before customer requests removes friction from enterprise sales cycles.

ComplyOne maps your DORA obligations, tracks your readiness across all five pillars, and maintains your audit evidence.

Run your DORA compliance check →