DORA ICT third-party risk platform

Take control of DORA third-party risk.

Manage ICT providers, automate vendor assessments, review contracts, collect evidence and maintain your DORA Register of Information from one platform.

Built for European financial organizations.

app.northstar-dora.eu/dashboard

DORA Third-Party Risk Overview

Northstar Financial Europe · updated 9 August 2026

DORA Readiness

84%

ICT Providers

142

Critical Providers

18

High Risks

7

Missing Evidence

23

Register Complete

91%

DORA Readiness

  • ICT Provider Inventory96%
  • Assessments82%
  • Contract Coverage74%
  • Evidence88%
  • Register of Information91%

Attention Required

View all
  • AWS assessment expires soon

    Annual ICT Risk Assessment 2026 · due 18 Aug

  • Microsoft contract needs review

    Exit strategy clause not documented

  • Stripe evidence expires next month

    SOC 2 Type II report valid until 14 Sep

The problem

DORA third-party risk is still managed with spreadsheets, emails and fragmented tools.

Vendor information scattered across teams

Procurement, security and compliance each keep their own list of ICT providers and services.

Assessments managed manually

Questionnaires travel by email and spreadsheet, and progress is impossible to track.

Contracts difficult to review consistently

Article 30 requirements are checked differently by each reviewer, with no shared record.

DORA Register difficult to maintain

The Register is rebuilt from scratch each reporting cycle and drifts from operational reality.

The problem is not collecting more documents. It is keeping providers, services, evidence, contracts and risks continuously connected and up to date.

Platform

One system for the entire ICT third-party risk lifecycle.

Every object is connected, so a change in one place updates the record everywhere it matters.

Step 1

ICT Provider

Step 2

Criticality

Step 3

Assessment

Step 4

Evidence

Step 5

Contract Review

Step 6

Risk

Step 7

Remediation

Step 8

DORA Register

Provider → service → assessment → evidence → contract clause → risk → remediation → Register field. Each link is preserved as an auditable record.

ICT Providers

Know every ICT provider and what they support.

  • Centralize ICT providers in one inventory
  • Map ICT services to each provider
  • Identify critical and important providers
  • Track countries and data locations
  • Link providers to critical or important functions
  • Assign internal owners
Explore ICT Provider Management
app.northstar-dora.eu/providers

ICT Providers

142 providers · 18 critical

Add ICT Provider
AllCriticalHigh RiskAssessment OverdueMissing Evidence
ProviderICT ServiceCriticalityCountryRisk
Amazon Web ServicesCloud InfrastructureCriticalIrelandHigh
Microsoft IrelandCloud & ProductivityCriticalIrelandMedium
Stripe Payments EuropePayment ProcessingCriticalIrelandHigh
Snowflake NetherlandsData PlatformImportantNetherlandsMedium
Cloudflare GermanyNetwork & SecurityImportantGermanyLow
TemenosCore BankingCriticalSwitzerlandMedium

Vendor Assessments

Run vendor assessments without chasing spreadsheets.

  • Send structured DORA questionnaires
  • Give vendors a self-service portal
  • Track progress section by section
  • Request evidence inside the questionnaire
  • Review responses in a single workspace
  • Identify potential gaps before sign-off
Explore Vendor Assessments
app.northstar-dora.eu/assessments/ASM-2041

ASM-2041 · AWS Annual ICT Assessment

Under Review

117 questions · 12 sections · vendor submitted 4 August 2026

Section progress

  • Governance & Oversight100%
  • Information Security92%
  • Business Continuity64%
  • Incident Management88%
  • Subcontracting45%

Q 4.3 · Business Continuity

Describe the frequency and scope of your disaster recovery testing.

“DR testing is performed periodically across production regions.”

AI Finding

Confidence 94%

Disaster recovery testing evidence is missing.

The response describes testing but no test report was attached for the current period. Requires human review before any compliance decision.

Accept FindingDismissRequest ClarificationCreate Risk

Reviewed by Sarah Martin · AI suggestions never change compliance status automatically.

AI Review

Let AI do the first review. Keep humans in control.

AI can review assessment responses, detect missing evidence, extract information from documents, analyze contracts and suggest potential risks. Every compliance decision stays with your team.

  • Suggestions are always labelled and reviewable
  • Findings carry a confidence score and a source reference
  • Nothing changes compliance status without human approval
  • AI features can be disabled per workspace
Explore AI Review

AI Finding

Confidence 94%

Disaster recovery testing evidence is missing.

The response describes testing but no test report was attached for the current period. Requires human review before any compliance decision.

Accept FindingDismissRequest ClarificationCreate Risk

Reviewed by Sarah Martin · AI suggestions never change compliance status automatically.

Contract Review

Find DORA contract gaps faster.

Contract Coverage: 78% · 3 clauses need review.

  • Audit rights
  • Incident notification
  • Regulatory access
  • Subcontracting
  • Business continuity
  • Data location
  • Termination
  • Exit strategy
Explore Contract Review
app.northstar-dora.eu/contracts/CTR-1002

CTR-1002 · Microsoft Ireland Operations Ltd

3 clauses need review

DORA Article 30 clause coverage · analysed 7 August 2026

Contract Coverage

78%

  • Audit rightsCovered
  • Incident notificationCovered
  • Regulatory accessCovered
  • SubcontractingNeeds Review
  • Business continuityCovered
  • Data locationNeeds Review
  • TerminationCovered
  • Exit strategyMissing

DORA Register of Information

Build and maintain your DORA Register continuously.

Connect providers, ICT services, contracts, critical functions and subcontractors so the Register stays aligned with your operational data.

app.northstar-dora.eu/dora-register

Register of Information

Reporting entity: Northstar Financial Europe · LEI 549300XKZ9Q2P1F4T083

Export

Register Completeness

91%

Errors

3

Warnings

9

Validation issues

  • AWSMissing contractual arrangement reference.Error
  • StripeSubcontractor country incomplete.Error
  • MicrosoftExit strategy not documented.Error
  • SnowflakeData location not confirmed by evidence.Warning
  • TemenosFunction criticality pending sign-off.Warning
91%Register completeness
3 Errors9 Warnings
  • AWS

    Missing contractual arrangement reference.

  • Stripe

    Subcontractor country incomplete.

  • Microsoft

    Exit strategy not documented.

Explore DORA Register

Data lineage

Every regulatory field has a source.

Compliance teams can trace each regulatory value back to the operational record and the evidence it came from, with the person and date behind the last change.

  • Trace Register fields to providers, services and contracts
  • See which evidence document supports a value
  • Know who changed a field and when
  • Answer regulator questions without rebuilding the trail

Register field · lineage

Traceable
Field
Data Location
Value
Germany
Source
Microsoft Azure Production Service
Evidence
Microsoft DPA
Last Updated
12 July 2026
Updated By
Sarah Martin

Risk management

Turn findings into action.

  • Create a risk directly from an assessment, evidence or contract finding
  • Assign an owner and set severity
  • Add a mitigation plan and due date
  • Accept a risk with documented rationale
  • Resolve risks and keep the full history
Explore Risk Management
app.northstar-dora.eu/risks

Risk Register

7 high risks · 18 open · linked to assessments, evidence and contracts

IDRiskProviderSeverityStatusOwner
RSK-311DR testing evidence not providedAWSHighMitigation PlannedS. Martin
RSK-318Exit strategy absent from contractMicrosoftHighOpenT. Weber
RSK-324Subcontractor countries incompleteStripeMediumIn ReviewL. Dubois
RSK-327Pen test older than 12 monthsSnowflakeMediumOpenS. Martin
RSK-330No documented incident SLATemenosLowAcceptedM. Rossi

Evidence

Stop chasing expired compliance documents.

SOC 2, ISO 27001, penetration tests, business continuity plans and disaster recovery tests tracked as Valid, Expiring, Expired or Missing.

  • Automated evidence requests to vendors
  • Expiry tracking with early warnings
  • Documents linked to providers, services and risks
  • Review queue for newly submitted evidence
Explore Evidence Management
app.northstar-dora.eu/evidence

Evidence Library

418 documents · 23 missing · 11 expiring within 60 days

Request Evidence
  • SOC 2 Type II

    Amazon Web Services

    Valid
  • ISO 27001

    Microsoft Ireland

    Valid
  • Penetration Test

    Stripe Payments Europe

    Expiring
  • Business Continuity Plan

    Snowflake Netherlands

    Expired
  • Disaster Recovery Test

    Amazon Web Services

    Missing

Supply chain

See beyond your direct ICT providers.

Capture subcontractors, countries, data locations and dependencies associated with each ICT service.

  • Record subcontractors declared during assessments
  • Track country and data location per dependency
  • Flag incomplete supply-chain records for the Register
  • Understand concentration across shared providers
  • Your Organization

    Northstar Financial Europe · Netherlands

  • AWS

    ICT Provider · Ireland · Critical

  • ICT Service

    Core hosting for payments platform

  • Subcontractor

    Regional CDN partner · Germany

Executive visibility

See what needs attention today.

An operational view of provider risk, assessments, evidence gaps, contract gaps, outstanding risks and Register completeness — not static documentation.

app.northstar-dora.eu/dashboard

DORA Third-Party Risk Overview

Northstar Financial Europe · updated 9 August 2026

DORA Readiness

84%

ICT Providers

142

Critical Providers

18

High Risks

7

Missing Evidence

23

Register Complete

91%

DORA Readiness

  • ICT Provider Inventory96%
  • Assessments82%
  • Contract Coverage74%
  • Evidence88%
  • Register of Information91%

Attention Required

View all
  • AWS assessment expires soon

    Annual ICT Risk Assessment 2026 · due 18 Aug

  • Microsoft contract needs review

    Exit strategy clause not documented

  • Stripe evidence expires next month

    SOC 2 Type II report valid until 14 Sep

How it works

From vendor inventory to DORA-ready reporting.

  1. 1

    Import ICT providers

  2. 2

    Classify critical services

  3. 3

    Launch assessments

  4. 4

    Collect evidence

  5. 5

    Review contracts

  6. 6

    Track risks and remediation

  7. 7

    Maintain the DORA Register

Who it is for

Built for regulated financial organizations.

Typically used by compliance, ICT risk, procurement and operational resilience teams. Whether a specific entity falls within DORA scope depends on its own regulatory analysis.

Banks
Fintechs
Payment Institutions
Insurance Companies
Investment Firms
Asset Managers

Why it is different

DORA workflows, not another generic GRC platform.

Generic GRC
Northstar
Generic vendor records
ICT Provider + Service mapping
Generic questionnaires
DORA-focused vendor assessments
Document repository
Evidence connected to provider risk
Manual contract review
AI-assisted contract analysis
Spreadsheet Register
Connected DORA Register
Periodic review
Continuous readiness view

Security

Built for sensitive compliance data.

We label what is available today and what is planned. We do not claim certifications we do not hold.

Encryption in transit and at rest

Available

Role-based access control

Available

Audit logs

Available

Tenant isolation

Available

EU data hosting

Available

Multi-factor authentication

Available

SSO / SAML

Enterprise

Data retention controls

Planned
View Security

Pricing

Plans that scale with your ICT provider portfolio.

Essential

€299/month

For smaller regulated organizations.

  • Up to 50 ICT providers · 5 users
  • Vendor Qualification Register
  • Assessments, evidence and risk register
  • Basic Article 30 Gap Register
  • DORA Register and Management Body Report
  • Basic resilience testing programme
Contact Sales

Growth

Most Popular

€799/month

For established compliance and ICT risk teams.

  • Up to 250 ICT providers · 25 users
  • Everything in Essential
  • AI assessment, evidence and contract review
  • Advanced Article 30 Gap Register
  • Testing coverage analytics
  • Priority support
Contact Sales

Enterprise

Custom

For groups with multiple legal entities.

  • Custom provider and user limits
  • SSO / SAML sign-in
  • SLA and dedicated support
  • Multi-entity Register, SCIM, API — planned
Contact Sales

Compare all plan details

Get your ICT third-party risk under control.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.

ICT Provider
Criticality
Assessment
Evidence
Contract Review