# DORA

**DORA Statement**

The EU Digital Operational Resilience Act (Regulation (EU) 2022/2554, “DORA”) sets operational-resilience requirements for financial entities and for the ICT providers that serve them. This statement explains how Employee Zero supports financial-entity clients that are in scope of DORA. It applies only to those clients and does not change the terms for clients outside the EU financial sector.

**How we support DORA**

Where we act as an ICT third-party service provider to an in-scope financial entity, we support our client’s DORA obligations, including by agreeing the contractual provisions DORA expects (Article 30), such as:

- clear descriptions of the services and the locations where data is processed
- commitments on accessibility, availability and security
- assistance with ICT-related incidents
- conditions for sub-contracting
- participation in resilience testing
- audit and access rights for the financial entity and the relevant competent authorities
- support on exit and termination

**Register of information and incident reporting**

We support our client’s register of information and provide the information they need for ICT incident reporting.

**Risk management and continuity**

Our ICT risk-management and business-continuity practices are summarised in our Trust Centre.

**Scope**

This statement applies only to EU financial-entity clients in scope of DORA. If you are unsure whether it applies to you, please contact us.
