Article 28: General principles
DORA Art. 28, Chapter V
1. Financial entities shall manage ICT third-party risk as an integral component of ICT risk within their ICT risk management framework as referred to in Article 6(1), and in accordance with the following principles: (a) financial entities that have in place contractual arrangements for the use of ICT services to run their business operations shall, at all times, remain fully responsible for compl
1404 words in the official text.
Sits inside (1)
Cited by (3)
Recitals matched by wording (9)
These recitals name no article. The dataset matched them to this one by text similarity, and they are marked so nobody reads a match as a citation.
Source texts: the Official Journal, through the Publications Office. Dataset built 2026-07-29. Study aid, not legal advice.
Every connection on this page is drawn from the official text of Regulation (EU) 2022/2554. Study aid, not legal advice.
See how DORA sits beside the other three acts on the crossover map, or find what your role must do in the obligations checklist.