Kostenloses Tool

DORA-Article-30-Tool für Klausel-Lücken

Prüfen Sie jeden ICT-Drittparteienvertrag anhand von DORA Article 30 – die verpflichtenden Basisbestimmungen aus 30(2) und die erweiterten Klauseln aus 30(3) für kritische oder wichtige Funktionen – und exportieren Sie einen bewerteten Abdeckungsbericht mit den zu behebenden Lücken.

Steuern Sie KI-Anbieter unter DORA? Lesen Sie Steuerung von AML- und Zahlungsverkehrs-Agenten.

Clause coverage: 0%

Assessed 0/18 · 0 gaps

Baseline provisions: every ICT third-party contract (Article 30(2))

These clauses are mandatory in all ICT third-party arrangements, regardless of criticality.

Clear, complete description of all functions and ICT services, including subcontracting conditions

Clear, complete description of all functions and ICT services, including subcontracting conditions

DORA Art 30(2)(a)

Locations (regions/countries) where services are provided and data is processed, with change notification

Locations (regions/countries) where services are provided and data is processed, with change notification

DORA Art 30(2)(b)

Provisions on availability, authenticity, integrity and confidentiality of data

Provisions on availability, authenticity, integrity and confidentiality of data

DORA Art 30(2)(c)

Access, recovery and return of data on insolvency, resolution or termination

Access, recovery and return of data on insolvency, resolution or termination

DORA Art 30(2)(d)

Service level descriptions, including updates and revisions

Service level descriptions, including updates and revisions

DORA Art 30(2)(e)

Provider assistance on ICT incidents at no additional or agreed cost

Provider assistance on ICT incidents at no additional or agreed cost

DORA Art 30(2)(f)

Obligation to fully cooperate with competent and resolution authorities

Obligation to fully cooperate with competent and resolution authorities

DORA Art 30(2)(g)

Termination rights and minimum notice periods

Termination rights and minimum notice periods

DORA Art 30(2)(h)

Conditions for participation in ICT security awareness programmes and training

Conditions for participation in ICT security awareness programmes and training

DORA Art 30(2)(i)

Augmented provisions: critical or important functions (Article 30(3))

Where the arrangement supports a critical or important function, the contract must additionally contain these.

Full service level descriptions with precise quantitative and qualitative performance targets

Full service level descriptions with precise quantitative and qualitative performance targets

DORA Art 30(3)(a)

Notice periods and provider reporting obligations, including developments that materially impact

Notice periods and provider reporting obligations, including developments that materially impact

DORA Art 30(3)(b)

Requirement to implement and test business contingency plans and ICT security measures

Requirement to implement and test business contingency plans and ICT security measures

DORA Art 30(3)(c)

Participation and full cooperation in the financial entity’s threat-led penetration testing (TLPT)

Participation and full cooperation in the financial entity’s threat-led penetration testing (TLPT)

DORA Art 30(3)(d)

Unrestricted rights of access, inspection and audit (entity, appointee, competent authority)

Unrestricted rights of access, inspection and audit (entity, appointee, competent authority)

DORA Art 30(3)(e)

Exit strategies with mandatory adequate transition periods

Exit strategies with mandatory adequate transition periods

DORA Art 30(3)(f)

Register and AI-vendor linkage

Arrangement recorded in the Register of Information

Arrangement recorded in the Register of Information

DORA Art 28(3)

Critical-or-important determination documented per ICT service

Critical-or-important determination documented per ICT service

DORA Art 28

GenAI / LLM providers assessed and contracted as ICT third parties

GenAI / LLM providers assessed and contracted as ICT third parties

Cloud-hosted model providers (e.g. OpenAI, Anthropic, Azure OpenAI) are ICT third parties; AML, fraud and chatbot use cases can be critical or important functions.

DORA Art 3(19)-(22)

Prioritised gaps
18 item(s) to address
  • Clear, complete description of all functions and ICT services, including subcontracting conditions , Not assessed
  • Locations (regions/countries) where services are provided and data is processed, with change notification , Not assessed
  • Provisions on availability, authenticity, integrity and confidentiality of data , Not assessed
  • Access, recovery and return of data on insolvency, resolution or termination , Not assessed
  • Service level descriptions, including updates and revisions , Not assessed
  • Provider assistance on ICT incidents at no additional or agreed cost , Not assessed
  • Obligation to fully cooperate with competent and resolution authorities , Not assessed
  • Termination rights and minimum notice periods , Not assessed
  • Conditions for participation in ICT security awareness programmes and training , Not assessed
  • Full service level descriptions with precise quantitative and qualitative performance targets , Not assessed
  • Notice periods and provider reporting obligations, including developments that materially impact , Not assessed
  • Requirement to implement and test business contingency plans and ICT security measures , Not assessed
  • + 6 more in the export.

Export your scored assessment and prioritised gap list. Everything stays in your browser : nothing is uploaded.

Keine Übergangsfrist

DORA gilt seit dem 17. Januar 2025 ohne Übergangsfrist für Article 30 – ICT-Verträge von vor 2025, denen diese Klauseln fehlen, sind heute nicht konform.

Basis und erweitert

Trennt die Klauseln aus 30(2), die jeder Vertrag benötigt, von den Klauseln aus 30(3), die erforderlich sind, wenn die Vereinbarung eine kritische oder wichtige Funktion unterstützt.

Ihr KI-Anbieter ist ein ICT-Drittparteienanbieter

Cloud-gehostete Modellanbieter sind ICT-Drittparteien unter DORA; Anwendungsfälle wie AML, Betrugserkennung und Chatbots können kritische oder wichtige Funktionen sein, die die erweiterten Klauseln auslösen.

Haftungsausschluss: Dieses Tool hilft Ihnen, ICT-Drittparteienverträge anhand von DORA Article 30 zu prüfen. Es stellt keine Rechtsberatung dar. Bestätigen Sie Ihre vertraglichen Pflichten mit qualifizierten Rechtsberatern, die mit Ihren Vereinbarungen vertraut sind.

DORA-Article-30-Checkliste für Vertragsklauseln: Kostenloses Lücken-Tool | KLA