The Gap AI Automation Who we work with Approach Fintech Garden Blog Start a conversation

DORA Article 28: Building Your Third-Party Vendor Register

2026-09-05 By Dumitru Condrea | Ex-Solarisbank Executive, Regulatory Architect Compliance & Operations

Getting regulatory approval is a snapshot. Running daily operations is a film. With the Digital Operational Resilience Act (DORA) active across the EU, European supervisory authorities (EBA, ESMA, EIOPA) expect payment institutions and EMIs to maintain a live, automated Information Register of all ICT third-party provider arrangements under Article 28.

The Manual Spreadsheet Trap

Most fintech compliance teams start by maintaining vendor registers in static Excel sheets. A typical payment processor relies on 15 to 30 ICT vendors: core ledgers, KYC/KYB screening providers, cloud hosts, acquiring gateways, and device fingerprinting APIs.

When an auditor or central bank inspector asks for your subprocessor concentration map, pulling static files creates three operational risks:

  1. Stale Subprocessor Chains: Third-party APIs update their infrastructure providers without notifying your compliance officer, breaking your Article 28 subprocessor disclosure obligations.
  2. Contractual Gap Exposure: Missing explicit data deletion, incident notification, or audit cooperation clauses required under DORA Article 28(2).
  3. Audit Evidence Delays: Gathering evidence across 20 vendor contracts during an information request takes days of executive time instead of minutes.

The Automated Control Environment

Rather than treating the vendor register as an annual compliance chore, leading payment operators implement continuous ICT risk monitoring:

Human Decides, AI Prepares

Automating DORA vendor registers does not mean replacing human judgment. Your Chief Risk Officer or compliance lead approves every regulatory submission. What automation eliminates is the manual document hunting, CSV formatting, and version mismatch stress before supervisory deadlines.

If you are setting up your DORA control environment or third-party vendor registers, our team at Novafin builds turnkey operational resilience architectures for licensed payment institutions.