DORA
DORA Statement
The EU Digital Operational Resilience Act (Regulation (EU) 2022/2554, “DORA”) sets operational-resilience requirements for financial entities and for the ICT providers that serve them. This statement explains how Employee Zero supports financial-entity clients that are in scope of DORA. It applies only to those clients and does not change the terms for clients outside the EU financial sector.
How we support DORA
Where we act as an ICT third-party service provider to an in-scope financial entity, we support our client’s DORA obligations, including by agreeing the contractual provisions DORA expects (Article 30), such as:
- clear descriptions of the services and the locations where data is processed
- commitments on accessibility, availability and security
- assistance with ICT-related incidents
- conditions for sub-contracting
- participation in resilience testing
- audit and access rights for the financial entity and the relevant competent authorities
- support on exit and termination
Register of information and incident reporting
We support our client’s register of information and provide the information they need for ICT incident reporting.
Risk management and continuity
Our ICT risk-management and business-continuity practices are summarised in our Trust Centre.
Scope
This statement applies only to EU financial-entity clients in scope of DORA. If you are unsure whether it applies to you, please contact us.