All insights EU compliance · ICT supply

DORA: What the Bank’s Addendum Can Actually Demand

When a bank hands its ICT supplier a “DORA addendum”, most of it is negotiable. DORA fixes a floor of contractual terms — a lot of what arrives sits well above it.

Răzvan Alexandru Olaru14 June 20266 min read

A bank hands its IT supplier a “DORA addendum” and treats it as boilerplate. Most of it is not. DORA fixes a floor of contractual terms; a great deal of what actually arrives sits well above that floor — and a supplier who signs as-is takes on duties the Regulation never imposed.

Facing this on a live addendum?

This is the analysis behind our fixed-fee service. If a bank, insurer or fund has already sent you a DORA addendum, we sort every clause into required / over-reach / abusive and hand you a signed position to negotiate from — DORA Supplier Defence.

DORA — Regulation (EU) 2022/2554 — lists the contractual terms a financial entity must put in place with its ICT third-party providers (art. 30(2): a clear service description, locations and data-processing sites, access and audit rights, assistance on ICT incidents, subcontracting conditions, and exit). It sets termination grounds (art. 28(7)) and a duty to cooperate on security awareness (art. 13(6)). The crucial word is minimum: these are defined, and they are governed by proportionality and necessity. Beyond them, the supplier is negotiating from a strong position, not a weak one.

Sort every clause into three buckets

The fastest way through a bank’s draft is to triage it: each ask is either required by DORA, an over-reach to be trimmed to the minimum, or simply abusive and to be resisted.

REQUIRED — keep, minimal• Service description & locations• Access / audit (proportionate)• Incident assistance• Exit supportart. 30(2), 28(7), 13(6)OVER-REACH — trim• Unconditional audit• Subcontracting veto• “Comply with all of DORA”• Extensive reportingcut back to the minimumABUSIVE — resist• Subjective instant termination• Perpetual free data duty• Bank-resolution powers• Critical-provider dutiesno DORA basis
Triage the bank's draft: keep the floor, trim the excess, resist the abusive.

Where the drafts overreach

Audit. DORA gives the bank and the authorities access and audit rights (art. 30) — not an unconditional run of the supplier’s systems. Tie audits to the contracted services, with reasonable notice, and carve out the supplier’s IP and other clients’ data.

Subcontracting. Art. 30(2) requires prior information and clear conditions, with notice of material change — it does not, as a rule, hand the bank a consent or veto, still less a right to rewrite the supplier’s contracts with its own subcontractors.

Termination. Art. 28(7) ties termination to objective grounds. A right to terminate immediately on subjective criteria (“deemed capable of affecting…”) is an imbalance to resist; unfounded termination should sound in damages for the supplier.

Two over-reaches that recur. Obligations DORA reserves for critical ICT providers (art. 31) do not bind a supplier that has not been designated — you are presumed non-critical. And bank recovery-and-resolution provisions belong in financial contracts; an ordinary ICT services contract is not one, and those powers should not be imported into it.

The move

Don’t sign the addendum as boilerplate. Sort every clause into required / over-reach / abusive, hold the bank to the DORA minimum drafted proportionately, and keep one fact in front of you throughout: unless you are formally designated a critical provider, you are not a regulated entity — and you should not contract as if you were.

General information on DORA (Regulation (EU) 2022/2554) from the ICT supplier’s perspective, not legal advice, and no lawyer–client relationship is created. DORA and its regulatory technical standards carry detailed conditions; any specific addendum needs advice on its own facts.

Handed a bank’s DORA addendum? Trim it to the DORA minimum before you sign.

Free brochure

The DORA addendum negotiation checklist

A one-page brief on this topic, sent straight to your inbox.

Facing this on a live document?

Book a 30-minute clinic

A quick read on your exact seam — by a lawyer qualified on both sides of it. No charge for the first look.

Your details go to Răzvan Alexandru Olaru (raz@olawru.com) and are held under a lawyer’s professional secrecy (Legea nr. 51/1995 & the Statutul profesiei de avocat) and the corresponding SRA confidentiality rules, processed in line with the GDPR. See our Privacy Policy and GDPR Statement.