Operationalize DORA third-party risk management.
DORA turns ICT third-party oversight into a continuous operational process. Northstar gives European financial organizations the system to run it: providers, assessments, contracts, evidence, risks and the Register of Information in one connected platform.
DORA Third-Party Risk Overview
Northstar Financial Europe · updated 9 August 2026
DORA Readiness
84%
ICT Providers
142
Critical Providers
18
High Risks
7
Missing Evidence
23
Register Complete
91%
DORA Readiness
- ICT Provider Inventory96%
- Assessments82%
- Contract Coverage74%
- Evidence88%
- Register of Information91%
Attention Required
View allAWS assessment expires soon
Annual ICT Risk Assessment 2026 · due 18 Aug
Microsoft contract needs review
Exit strategy clause not documented
Stripe evidence expires next month
SOC 2 Type II report valid until 14 Sep
Coverage
From inventory to reporting.
Each area maps to the operational work behind DORA ICT third-party risk requirements. Whether a specific obligation applies to your entity depends on your own regulatory analysis.
ICT provider inventory
One register of providers and the ICT services they deliver.
Criticality classification
Structured scoring to identify critical or important functions supported.
Vendor assessments
DORA-focused questionnaires with a vendor self-service portal.
Contract requirements
Clause-by-clause coverage analysis against Article 30 topics.
Subcontractor visibility
Capture dependencies, countries and data locations.
Risk management
Findings become tracked risks with owners and remediation.
Register of Information
Maintained continuously from your operational records.
Reporting
Board packs, audit packs and readiness reporting.
Inventory
Start from a provider inventory you trust.
Everything downstream — assessments, contracts, evidence and the Register — depends on knowing which providers support which functions.
- Import existing provider lists
- Map ICT services and data processed
- Classify criticality with a documented method
- Assign internal owners for accountability
ICT Providers
142 providers · 18 critical
| Provider | ICT Service | Criticality | Country | Risk |
|---|---|---|---|---|
| Amazon Web Services | Cloud Infrastructure | Critical | Ireland | High |
| Microsoft Ireland | Cloud & Productivity | Critical | Ireland | Medium |
| Stripe Payments Europe | Payment Processing | Critical | Ireland | High |
| Snowflake Netherlands | Data Platform | Important | Netherlands | Medium |
| Cloudflare Germany | Network & Security | Important | Germany | Low |
| Temenos | Core Banking | Critical | Switzerland | Medium |
Register of Information
Reporting output, generated from live data.
Validation highlights errors and warnings before submission, so the Register reflects the same records your teams work in daily.
- Register completeness tracked continuously
- Errors and warnings surfaced per provider
- Field-level lineage to source and evidence
- Structured export when reporting is required
Register of Information
Reporting entity: Northstar Financial Europe · LEI 549300XKZ9Q2P1F4T083
Register Completeness
91%
Errors
3
Warnings
9
Validation issues
- AWSMissing contractual arrangement reference.Error
- StripeSubcontractor country incomplete.Error
- MicrosoftExit strategy not documented.Error
- SnowflakeData location not confirmed by evidence.Warning
- TemenosFunction criticality pending sign-off.Warning
Workflow
A repeatable DORA operating rhythm.
Make DORA third-party risk operational.
See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.