Contractual arrangements on the use of ICT services shall include at least the following elements: a clear and complete description of all functions and ICT services to be provided, the locations where such functions are provided and where data is to be processed, provisions on availability, authenticity, integrity and confidentiality of data, provisions on ensuring access, recovery and return of data, service level descriptions, assistance obligations, termination rights and related transition periods.
Document reviewing ICT third-party contracts against DORA Article 30 requirements, including assessment of required contractual clauses, SLA provisions, audit rights, and exit strategy provisions.
ict-contract-reviewGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
ICT CONTRACT COMPLIANCE REVIEW
DORA Article 30 Assessment
Nordvik Bank AG
Review Reference: CCR-2025-001
Review Date: 22 January 2025
Prepared by: Dr. Markus Brenner, Legal Counsel — ICT Contracts
Classification: Confidential
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
CONTRACT OVERVIEW
This review assesses the contractual arrangements between Nordvik Bank AG ("the
Bank") and Meridian Cloud Services GmbH ("the Provider") against the requirements
of DORA Article 30, which mandates specific contractual elements for ICT service
arrangements with third-party providers.
Contract ID: CTR-PRV001-2021-003
Provider: Meridian Cloud Services GmbH
Service: Core banking infrastructure hosting (IaaS)
Contract Start: 1 March 2021
Contract End: 28 February 2026
Annual Value: EUR 2,450,000
Criticality: Critical
Previous Review: 15 January 2024 (CCR-2024-001)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SERVICE DESCRIPTION ASSESSMENT
DORA Article 30(2)(a) requires a clear and complete description of all functions
and ICT services to be provided by the third-party service provider.
Assessment:
The contract includes a detailed Service Schedule (Annex A) describing the IaaS
services provided, including compute instances, storage volumes, network
connectivity, and managed database services. The schedule specifies the technical
environment (VMware-based virtualisation on dedicated hardware), the supported
operating systems, and the management interfaces available to the Bank.
The Service Schedule was updated in Amendment 3 (effective September 2024) to
include container orchestration services (Kubernetes) added to support the Bank's
digital banking platform migration.
Finding: COMPLIANT — Service description is clear, complete, and current.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
DATA LOCATION PROVISIONS
DORA Article 30(2)(b) requires provisions on the locations where the contracted
or subcontracted functions are to be provided and where data is to be processed,
including the storage location.
Assessment:
The contract specifies primary data processing in Frankfurt, Germany (Equinix
FR5 data centre) with disaster recovery in Dublin, Ireland (Equinix DB3). Clause
7.3 requires the Provider to obtain prior written consent before any change to
data processing locations. Clause 7.4 prohibits data processing outside the
European Economic Area without explicit Board-level approval.
The subcontractor register (Annex D) identifies Equinix as the colocation
provider and Cloudflare as the CDN provider. Data processing locations for
subcontractors are documented.
Finding: COMPLIANT — Data locations clearly specified with change control
provisions.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
AVAILABILITY AND INTEGRITY CLAUSES
DORA Article 30(2)(c) requires provisions on availability, authenticity, integrity
and confidentiality in relation to the protection of data, including personal data.
Assessment:
Clause 8.1 establishes availability commitments (99.95% monthly uptime for
production environments). Clause 8.2 addresses data integrity through checksummed
storage and replication verification. Clause 8.3 mandates AES-256 encryption at
rest and TLS 1.3 in transit. Clause 8.4 addresses data authenticity through
mutual TLS authentication for all API communications.
However, the contract does not explicitly address data authenticity verification
for backup restoration — the Bank cannot independently verify that restored data
has not been tampered with during the backup lifecycle.
Finding: PARTIALLY COMPLIANT — Core provisions present but backup authenticity
verification gap identified.
Gap: No contractual requirement for cryptographic verification of backup
integrity upon restoration.
Recommendation: Amend Clause 8.2 to require Provider to implement and
demonstrate backup integrity verification using cryptographic checksums.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SLA ASSESSMENT
DORA Article 30(3) requires that contractual arrangements on the use of ICT
services supporting critical or important functions shall include quantitative
and qualitative performance targets.
Assessment:
The SLA Schedule (Annex B) defines:
— Availability: 99.95% monthly uptime (production), 99.9% (non-production)
— Incident Response: P1 — 15 minutes acknowledgement, 1 hour resolution target
P2 — 30 minutes acknowledgement, 4 hours resolution target
P3 — 2 hours acknowledgement, 1 business day resolution
— Change Management: Standard changes — 5 business days; Emergency — 4 hours
— Reporting: Monthly service report within 10 business days of month end
Service credits are defined for SLA breaches: 5% of monthly fee per 0.01%
availability shortfall, capped at 30% of monthly fee.
Finding: COMPLIANT — Quantitative and qualitative targets clearly defined with
penalty provisions.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
AUDIT RIGHTS
DORA Article 30(3)(e) requires that contractual arrangements include the right
of the financial entity to monitor on an ongoing basis the ICT third-party
service provider's performance, including the right of unrestricted access,
inspection and audit.
Assessment:
Clause 12.1 grants the Bank the right to conduct audits of the Provider's
operations, systems, and controls relevant to the contracted services, with
30 days' prior written notice. Clause 12.2 permits the Bank to appoint an
independent third-party auditor. Clause 12.3 requires the Provider to cooperate
fully with audits conducted by the Bank's supervisory authorities (FINMA, ECB).
The Bank exercised its audit rights in Q3 2024, conducting an on-site assessment
of the Provider's Frankfurt data centre. No material findings were identified.
Finding: COMPLIANT — Comprehensive audit rights including supervisory authority
access.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
TERMINATION AND EXIT PROVISIONS
DORA Article 30(3)(f) requires exit strategies and provisions ensuring that
termination does not cause undue disruption to the financial entity's business
activities.
Assessment:
Clause 15.1 provides for termination with 12 months' written notice. Clause 15.2
provides for immediate termination in the event of material breach, insolvency,
or regulatory direction. Clause 15.3 establishes a transition assistance period
of up to 12 months following termination notice, during which the Provider must
continue services at the contracted rate and cooperate with migration activities.
Clause 15.4 requires the Provider to return all Bank data in a standard,
machine-readable format within 30 days of the transition period end. Clause 15.5
requires the Provider to certify destruction of all Bank data within 60 days of
data return.
However, the contract does not specify a detailed transition plan template or
require the Provider to participate in transition planning exercises.
Finding: PARTIALLY COMPLIANT — Core termination and exit provisions present but
transition planning provisions could be strengthened.
Gap: No requirement for periodic transition plan testing or Provider
participation in exit planning exercises.
Recommendation: Add clause requiring annual exit plan review and tabletop
exercise with Provider participation.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
COMPLIANCE GAP SUMMARY
Clause Area Status Gaps
─────────────────────────────────────────────────────────────────────────────
Service Description Compliant 0
Data Location Compliant 0
Availability & Integrity Partially Compliant 1 (backup authenticity)
SLA Provisions Compliant 0
Audit Rights Compliant 0
Termination & Exit Partially Compliant 1 (transition planning)
─────────────────────────────────────────────────────────────────────────────
Total Compliance Gaps: 2
Recommended Actions:
1. Negotiate Amendment 4 to address backup integrity verification (target: Q2 2025)
2. Negotiate addition of annual exit plan review clause (target: Q2 2025)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Reviewed by: Dr. Markus Brenner, Legal Counsel
Approved by: Vendor Management Officer, CRO
Date: 22 January 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
contract_compliance_status — fs-contract-compliance-status
{
"factId": "d3e4f5a6-b7c8-9012-defa-234567890123",
"evidenceId": "c2d3e4f5-a6b7-8901-2345-678901abcdef",
"evidenceClassId": "ict-contract-review",
"factType": "contract_compliance_status",
"data": {
"contract_id": "CTR-PRV001-2021-003",
"review_date": "2025-01-22",
"has_service_description": true,
"has_data_location": true,
"has_availability_provisions": true,
"has_integrity_provisions": true,
"has_audit_rights": true,
"has_exit_strategy": true,
"has_termination_rights": true,
"compliance_gaps_count": 2,
"contract_expiry_date": "2026-02-28"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-01-23T11:00:00Z",
"supersededBy": null
}
sla_monitoring_status — fs-sla-monitoring-status
{
"factId": "e4f5a6b7-c8d9-0123-efab-345678901234",
"evidenceId": "d3e4f5a6-b7c8-9012-3456-789012abcdef",
"evidenceClassId": "sla-documentation",
"factType": "sla_monitoring_status",
"data": {
"sla_id": "SLA-PRV001-2024-002",
"monitoring_date": "2025-01-31",
"availability_target_percent": 99.95,
"availability_achieved_percent": 99.991,
"sla_breaches_count": 2,
"incident_response_sla_met": false,
"reporting_sla_met": true,
"sla_expired": false,
"penalties_applied": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-02-01T08:00:00Z",
"supersededBy": null
}
SLA documentation for ICT third-party services including performance metrics, availability targets, incident response times, and penalty provisions.
sla-documentationGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
SERVICE LEVEL AGREEMENT
Between Nordvik Bank AG and Meridian Cloud Services GmbH
SLA Reference: SLA-PRV001-2024-002
Effective Date: 1 March 2024 | Expiry Date: 28 February 2026
Version 2.1 | Last Amended: 15 September 2024
Classification: Confidential
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
1. SERVICE SCOPE
This Service Level Agreement ("SLA") defines the performance commitments,
measurement methodology, and remedies applicable to the Infrastructure-as-a-Service
("IaaS") platform provided by Meridian Cloud Services GmbH ("Provider") to Nordvik
Bank AG ("Customer") under Master Service Agreement CTR-PRV001-2021-003.
Services covered by this SLA:
— Compute services: VMware-based virtual machines and Kubernetes clusters
— Storage services: Block storage, object storage, and file storage
— Network services: Virtual networking, load balancing, and firewall management
— Managed database services: Oracle Database and PostgreSQL
— Backup and replication services: Daily incremental, weekly full, cross-site
Environments covered:
— Production (Frankfurt DC): Subject to Tier 1 SLA targets
— Disaster Recovery (Dublin DC): Subject to Tier 1 SLA targets
— Pre-Production / UAT: Subject to Tier 2 SLA targets
— Development: Subject to Tier 3 SLA targets (best effort)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
2. PERFORMANCE METRICS
2.1 Availability Targets
Environment Monthly Target Measurement Window Max Downtime/Month
─────────────────────────────────────────────────────────────────────────────
Production 99.95% 24/7/365 21.9 minutes
Disaster Recovery 99.95% 24/7/365 21.9 minutes
Pre-Production 99.9% Business hours 43.8 minutes
Development 99.0% Business hours 7.3 hours
Availability is calculated as:
Availability % = ((Total Minutes − Unplanned Downtime Minutes) / Total Minutes) × 100
Planned maintenance windows (Sundays 02:00–06:00 CET) are excluded from
availability calculations, provided 5 business days' advance notice is given.
2.2 Performance Targets
Metric Target Measurement
─────────────────────────────────────────────────────────────────────────────
Compute latency (API response) < 5ms p99 Continuous monitoring
Storage IOPS (block) > 10,000 IOPS Hourly sampling
Storage throughput > 500 MB/s Hourly sampling
Network latency (intra-DC) < 1ms p99 Continuous monitoring
Network throughput > 10 Gbps Hourly sampling
Database query response < 10ms p95 Continuous monitoring
Backup completion Within 4-hour window Daily verification
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
3. INCIDENT RESPONSE SLAs
Priority Description Acknowledge Target Resolution
─────────────────────────────────────────────────────────────────────────────
P1 Production service outage 15 minutes 1 hour
affecting critical functions
P2 Degraded production service 30 minutes 4 hours
or DR failover impaired
P3 Non-critical service issue 2 hours 1 business day
or pre-production outage
P4 Minor issue, cosmetic defect, 4 hours 5 business days
or information request
Escalation path:
P1: Immediate escalation to Provider Service Director and Customer CIO
P2: Escalation to Provider Account Manager after 2 hours without resolution
P3: Escalation to Provider Account Manager after 1 business day
P4: Standard ticket management
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
4. REPORTING REQUIREMENTS
The Provider shall deliver the following reports to the Customer:
Report Frequency Delivery Deadline
─────────────────────────────────────────────────────────────────────────────
Monthly Service Report Monthly 10th business day of following month
Incident Summary Report Monthly Included in Monthly Service Report
Capacity Planning Report Quarterly 15th business day of following quarter
Security Posture Report Quarterly 15th business day of following quarter
Annual Service Review Annual Within 30 days of anniversary
The Monthly Service Report shall include:
— Availability metrics per environment with trend analysis
— Performance metrics against targets
— Incident summary with root cause analysis for P1/P2 incidents
— Change management summary
— Capacity utilisation and forecasting
— SLA compliance status and any service credit calculations
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
5. PENALTY PROVISIONS
5.1 Service Credits
Availability Achieved Service Credit (% of Monthly Fee)
─────────────────────────────────────────────────────────────────────────────
99.95% – 99.90% 5%
99.90% – 99.50% 10%
99.50% – 99.00% 20%
Below 99.00% 30% (maximum credit)
Service credits are applied automatically to the next monthly invoice. The
Customer is not required to request service credits — the Provider shall
calculate and apply them based on monitoring data.
5.2 Incident Response Credits
SLA Breach Credit
─────────────────────────────────────────────────────────────────────────────
P1 acknowledgement > 15 minutes EUR 5,000 per incident
P1 resolution > 1 hour EUR 10,000 per hour over target
P2 acknowledgement > 30 minutes EUR 2,000 per incident
P2 resolution > 4 hours EUR 5,000 per hour over target
5.3 Chronic Underperformance
If availability falls below 99.9% for three consecutive months, the Customer
may invoke the Chronic Underperformance clause (MSA Clause 14.7), which triggers:
— Mandatory service improvement plan within 10 business days
— Weekly progress reviews until targets are met for two consecutive months
— Right to terminate without penalty if targets not met within 90 days
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
6. REVIEW AND ESCALATION
This SLA is reviewed annually as part of the Annual Service Review. Either party
may request an interim review following a material change in service scope,
regulatory requirements, or business needs.
Dispute resolution follows the escalation path defined in MSA Clause 16:
Level 1: Account Manager ↔ Vendor Management Officer (5 business days)
Level 2: Service Director ↔ CIO (10 business days)
Level 3: CEO ↔ CEO (20 business days)
Level 4: Mediation / Arbitration per MSA Clause 17
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Signed:
For Nordvik Bank AG:
Name: [Vendor Management Officer]
Title: Head of Vendor Management
Date: 1 March 2024
For Meridian Cloud Services GmbH:
Name: [Provider Account Director]
Title: Account Director — Financial Services
Date: 1 March 2024
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
contract_compliance_status — fs-contract-compliance-status
{
"factId": "d3e4f5a6-b7c8-9012-defa-234567890123",
"evidenceId": "c2d3e4f5-a6b7-8901-2345-678901abcdef",
"evidenceClassId": "ict-contract-review",
"factType": "contract_compliance_status",
"data": {
"contract_id": "CTR-PRV001-2021-003",
"review_date": "2025-01-22",
"has_service_description": true,
"has_data_location": true,
"has_availability_provisions": true,
"has_integrity_provisions": true,
"has_audit_rights": true,
"has_exit_strategy": true,
"has_termination_rights": true,
"compliance_gaps_count": 2,
"contract_expiry_date": "2026-02-28"
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-01-23T11:00:00Z",
"supersededBy": null
}
sla_monitoring_status — fs-sla-monitoring-status
{
"factId": "e4f5a6b7-c8d9-0123-efab-345678901234",
"evidenceId": "d3e4f5a6-b7c8-9012-3456-789012abcdef",
"evidenceClassId": "sla-documentation",
"factType": "sla_monitoring_status",
"data": {
"sla_id": "SLA-PRV001-2024-002",
"monitoring_date": "2025-01-31",
"availability_target_percent": 99.95,
"availability_achieved_percent": 99.991,
"sla_breaches_count": 2,
"incident_response_sla_met": false,
"reporting_sla_met": true,
"sla_expired": false,
"penalties_applied": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-02-01T08:00:00Z",
"supersededBy": null
}
fs-contract-compliance-statusDORA-Art30-P1review_datecompliance_gaps_countcontract_expiry_date{
"properties": {
"compliance_gaps_count": {
"minimum": 0,
"type": "integer"
},
"contract_expiry_date": {
"format": "date",
"type": "string"
},
"contract_id": {
"minLength": 1,
"type": "string"
},
"has_audit_rights": {
"type": "boolean"
},
"has_availability_provisions": {
"type": "boolean"
},
"has_data_location": {
"type": "boolean"
},
"has_exit_strategy": {
"type": "boolean"
},
"has_integrity_provisions": {
"type": "boolean"
},
"has_service_description": {
"type": "boolean"
},
"has_termination_rights": {
"type": "boolean"
},
"review_date": {
"format": "date",
"type": "string"
}
},
"required": [
"contract_id",
"review_date",
"has_service_description",
"has_data_location",
"has_availability_provisions",
"has_audit_rights",
"has_exit_strategy"
],
"type": "object"
}
fs-sla-monitoring-statusDORA-Art30-P1monitoring_dateavailability_achieved_percent{
"properties": {
"availability_achieved_percent": {
"maximum": 100,
"minimum": 0,
"type": "number"
},
"availability_target_percent": {
"maximum": 100,
"minimum": 0,
"type": "number"
},
"incident_response_sla_met": {
"type": "boolean"
},
"monitoring_date": {
"format": "date",
"type": "string"
},
"penalties_applied": {
"type": "boolean"
},
"reporting_sla_met": {
"type": "boolean"
},
"sla_breaches_count": {
"minimum": 0,
"type": "integer"
},
"sla_expired": {
"type": "boolean"
},
"sla_id": {
"minLength": 1,
"type": "string"
}
},
"required": [
"sla_id",
"monitoring_date",
"availability_target_percent",
"availability_achieved_percent",
"sla_breaches_count"
],
"type": "object"
}