DORA-Art30-P1

Article
30 (1)
Pillar
Third-Party ICT Risk Management
Regulation Ref
Regulation (EU) 2022/2554, Article 30(1)
Last Reviewed
2026-01-15

Contractual arrangements on the use of ICT services shall include at least the following elements: a clear and complete description of all functions and ICT services to be provided, the locations where such functions are provided and where data is to be processed, provisions on availability, authenticity, integrity and confidentiality of data, provisions on ensuring access, recovery and return of data, service level descriptions, assistance obligations, termination rights and related transition periods.

Evidence Profiles

ICT Contract Compliance Review PARTIAL

Document reviewing ICT third-party contracts against DORA Article 30 requirements, including assessment of required contractual clauses, SLA provisions, audit rights, and exit strategy provisions.

Formats
DOCX PDF
Evidence Class
ict-contract-review
Availability
PARTIAL
Update Frequency
annual
Typical Author
Legal Counsel
Approval Chain
Legal Counsel → Vendor Management Officer → CRO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
ICT CONTRACT COMPLIANCE REVIEW
DORA Article 30 Assessment
Nordvik Bank AG
Review Reference: CCR-2025-001
Review Date: 22 January 2025
Prepared by: Dr. Markus Brenner, Legal Counsel — ICT Contracts
Classification: Confidential

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

CONTRACT OVERVIEW

This review assesses the contractual arrangements between Nordvik Bank AG ("the
Bank") and Meridian Cloud Services GmbH ("the Provider") against the requirements
of DORA Article 30, which mandates specific contractual elements for ICT service
arrangements with third-party providers.

  Contract ID:          CTR-PRV001-2021-003
  Provider:             Meridian Cloud Services GmbH
  Service:              Core banking infrastructure hosting (IaaS)
  Contract Start:       1 March 2021
  Contract End:         28 February 2026
  Annual Value:         EUR 2,450,000
  Criticality:          Critical
  Previous Review:      15 January 2024 (CCR-2024-001)

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

SERVICE DESCRIPTION ASSESSMENT

DORA Article 30(2)(a) requires a clear and complete description of all functions
and ICT services to be provided by the third-party service provider.

Assessment:

The contract includes a detailed Service Schedule (Annex A) describing the IaaS
services provided, including compute instances, storage volumes, network
connectivity, and managed database services. The schedule specifies the technical
environment (VMware-based virtualisation on dedicated hardware), the supported
operating systems, and the management interfaces available to the Bank.

The Service Schedule was updated in Amendment 3 (effective September 2024) to
include container orchestration services (Kubernetes) added to support the Bank's
digital banking platform migration.

Finding: COMPLIANT — Service description is clear, complete, and current.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

DATA LOCATION PROVISIONS

DORA Article 30(2)(b) requires provisions on the locations where the contracted
or subcontracted functions are to be provided and where data is to be processed,
including the storage location.

Assessment:

The contract specifies primary data processing in Frankfurt, Germany (Equinix
FR5 data centre) with disaster recovery in Dublin, Ireland (Equinix DB3). Clause
7.3 requires the Provider to obtain prior written consent before any change to
data processing locations. Clause 7.4 prohibits data processing outside the
European Economic Area without explicit Board-level approval.

The subcontractor register (Annex D) identifies Equinix as the colocation
provider and Cloudflare as the CDN provider. Data processing locations for
subcontractors are documented.

Finding: COMPLIANT — Data locations clearly specified with change control
provisions.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

AVAILABILITY AND INTEGRITY CLAUSES

DORA Article 30(2)(c) requires provisions on availability, authenticity, integrity
and confidentiality in relation to the protection of data, including personal data.

Assessment:

Clause 8.1 establishes availability commitments (99.95% monthly uptime for
production environments). Clause 8.2 addresses data integrity through checksummed
storage and replication verification. Clause 8.3 mandates AES-256 encryption at
rest and TLS 1.3 in transit. Clause 8.4 addresses data authenticity through
mutual TLS authentication for all API communications.

However, the contract does not explicitly address data authenticity verification
for backup restoration — the Bank cannot independently verify that restored data
has not been tampered with during the backup lifecycle.

Finding: PARTIALLY COMPLIANT — Core provisions present but backup authenticity
verification gap identified.

  Gap: No contractual requirement for cryptographic verification of backup
  integrity upon restoration.
  Recommendation: Amend Clause 8.2 to require Provider to implement and
  demonstrate backup integrity verification using cryptographic checksums.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

SLA ASSESSMENT

DORA Article 30(3) requires that contractual arrangements on the use of ICT
services supporting critical or important functions shall include quantitative
and qualitative performance targets.

Assessment:

The SLA Schedule (Annex B) defines:
  — Availability: 99.95% monthly uptime (production), 99.9% (non-production)
  — Incident Response: P1 — 15 minutes acknowledgement, 1 hour resolution target
                       P2 — 30 minutes acknowledgement, 4 hours resolution target
                       P3 — 2 hours acknowledgement, 1 business day resolution
  — Change Management: Standard changes — 5 business days; Emergency — 4 hours
  — Reporting: Monthly service report within 10 business days of month end

Service credits are defined for SLA breaches: 5% of monthly fee per 0.01%
availability shortfall, capped at 30% of monthly fee.

Finding: COMPLIANT — Quantitative and qualitative targets clearly defined with
penalty provisions.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

AUDIT RIGHTS

DORA Article 30(3)(e) requires that contractual arrangements include the right
of the financial entity to monitor on an ongoing basis the ICT third-party
service provider's performance, including the right of unrestricted access,
inspection and audit.

Assessment:

Clause 12.1 grants the Bank the right to conduct audits of the Provider's
operations, systems, and controls relevant to the contracted services, with
30 days' prior written notice. Clause 12.2 permits the Bank to appoint an
independent third-party auditor. Clause 12.3 requires the Provider to cooperate
fully with audits conducted by the Bank's supervisory authorities (FINMA, ECB).

The Bank exercised its audit rights in Q3 2024, conducting an on-site assessment
of the Provider's Frankfurt data centre. No material findings were identified.

Finding: COMPLIANT — Comprehensive audit rights including supervisory authority
access.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

TERMINATION AND EXIT PROVISIONS

DORA Article 30(3)(f) requires exit strategies and provisions ensuring that
termination does not cause undue disruption to the financial entity's business
activities.

Assessment:

Clause 15.1 provides for termination with 12 months' written notice. Clause 15.2
provides for immediate termination in the event of material breach, insolvency,
or regulatory direction. Clause 15.3 establishes a transition assistance period
of up to 12 months following termination notice, during which the Provider must
continue services at the contracted rate and cooperate with migration activities.

Clause 15.4 requires the Provider to return all Bank data in a standard,
machine-readable format within 30 days of the transition period end. Clause 15.5
requires the Provider to certify destruction of all Bank data within 60 days of
data return.

However, the contract does not specify a detailed transition plan template or
require the Provider to participate in transition planning exercises.

Finding: PARTIALLY COMPLIANT — Core termination and exit provisions present but
transition planning provisions could be strengthened.

  Gap: No requirement for periodic transition plan testing or Provider
  participation in exit planning exercises.
  Recommendation: Add clause requiring annual exit plan review and tabletop
  exercise with Provider participation.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

COMPLIANCE GAP SUMMARY

  Clause Area                    Status               Gaps
  ─────────────────────────────────────────────────────────────────────────────
  Service Description            Compliant            0
  Data Location                  Compliant            0
  Availability & Integrity       Partially Compliant  1 (backup authenticity)
  SLA Provisions                 Compliant            0
  Audit Rights                   Compliant            0
  Termination & Exit             Partially Compliant  1 (transition planning)
  ─────────────────────────────────────────────────────────────────────────────
  Total Compliance Gaps:         2

Recommended Actions:
  1. Negotiate Amendment 4 to address backup integrity verification (target: Q2 2025)
  2. Negotiate addition of annual exit plan review clause (target: Q2 2025)

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Reviewed by: Dr. Markus Brenner, Legal Counsel
Approved by: Vendor Management Officer, CRO
Date: 22 January 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

contract_compliance_status — fs-contract-compliance-status
{
  "factId": "d3e4f5a6-b7c8-9012-defa-234567890123",
  "evidenceId": "c2d3e4f5-a6b7-8901-2345-678901abcdef",
  "evidenceClassId": "ict-contract-review",
  "factType": "contract_compliance_status",
  "data": {
    "contract_id": "CTR-PRV001-2021-003",
    "review_date": "2025-01-22",
    "has_service_description": true,
    "has_data_location": true,
    "has_availability_provisions": true,
    "has_integrity_provisions": true,
    "has_audit_rights": true,
    "has_exit_strategy": true,
    "has_termination_rights": true,
    "compliance_gaps_count": 2,
    "contract_expiry_date": "2026-02-28"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-01-23T11:00:00Z",
  "supersededBy": null
}
sla_monitoring_status — fs-sla-monitoring-status
{
  "factId": "e4f5a6b7-c8d9-0123-efab-345678901234",
  "evidenceId": "d3e4f5a6-b7c8-9012-3456-789012abcdef",
  "evidenceClassId": "sla-documentation",
  "factType": "sla_monitoring_status",
  "data": {
    "sla_id": "SLA-PRV001-2024-002",
    "monitoring_date": "2025-01-31",
    "availability_target_percent": 99.95,
    "availability_achieved_percent": 99.991,
    "sla_breaches_count": 2,
    "incident_response_sla_met": false,
    "reporting_sla_met": true,
    "sla_expired": false,
    "penalties_applied": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-02-01T08:00:00Z",
  "supersededBy": null
}

ICT Service Level Agreement Documentation COMMON

SLA documentation for ICT third-party services including performance metrics, availability targets, incident response times, and penalty provisions.

Formats
PDF
Evidence Class
sla-documentation
Availability
COMMON
Update Frequency
annual
Typical Author
Vendor Management Officer
Approval Chain
Vendor Management Officer → CIO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
SERVICE LEVEL AGREEMENT
Between Nordvik Bank AG and Meridian Cloud Services GmbH
SLA Reference: SLA-PRV001-2024-002
Effective Date: 1 March 2024 | Expiry Date: 28 February 2026
Version 2.1 | Last Amended: 15 September 2024
Classification: Confidential

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

1. SERVICE SCOPE

This Service Level Agreement ("SLA") defines the performance commitments,
measurement methodology, and remedies applicable to the Infrastructure-as-a-Service
("IaaS") platform provided by Meridian Cloud Services GmbH ("Provider") to Nordvik
Bank AG ("Customer") under Master Service Agreement CTR-PRV001-2021-003.

Services covered by this SLA:
  — Compute services: VMware-based virtual machines and Kubernetes clusters
  — Storage services: Block storage, object storage, and file storage
  — Network services: Virtual networking, load balancing, and firewall management
  — Managed database services: Oracle Database and PostgreSQL
  — Backup and replication services: Daily incremental, weekly full, cross-site

Environments covered:
  — Production (Frankfurt DC): Subject to Tier 1 SLA targets
  — Disaster Recovery (Dublin DC): Subject to Tier 1 SLA targets
  — Pre-Production / UAT: Subject to Tier 2 SLA targets
  — Development: Subject to Tier 3 SLA targets (best effort)

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

2. PERFORMANCE METRICS

2.1 Availability Targets

  Environment       Monthly Target    Measurement Window    Max Downtime/Month
  ─────────────────────────────────────────────────────────────────────────────
  Production        99.95%            24/7/365              21.9 minutes
  Disaster Recovery 99.95%            24/7/365              21.9 minutes
  Pre-Production    99.9%             Business hours        43.8 minutes
  Development       99.0%             Business hours        7.3 hours

Availability is calculated as:
  Availability % = ((Total Minutes − Unplanned Downtime Minutes) / Total Minutes) × 100

Planned maintenance windows (Sundays 02:00–06:00 CET) are excluded from
availability calculations, provided 5 business days' advance notice is given.

2.2 Performance Targets

  Metric                          Target              Measurement
  ─────────────────────────────────────────────────────────────────────────────
  Compute latency (API response)  < 5ms p99           Continuous monitoring
  Storage IOPS (block)            > 10,000 IOPS       Hourly sampling
  Storage throughput              > 500 MB/s           Hourly sampling
  Network latency (intra-DC)      < 1ms p99           Continuous monitoring
  Network throughput              > 10 Gbps            Hourly sampling
  Database query response         < 10ms p95           Continuous monitoring
  Backup completion               Within 4-hour window Daily verification

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

3. INCIDENT RESPONSE SLAs

  Priority   Description                    Acknowledge    Target Resolution
  ─────────────────────────────────────────────────────────────────────────────
  P1         Production service outage       15 minutes     1 hour
             affecting critical functions
  P2         Degraded production service     30 minutes     4 hours
             or DR failover impaired
  P3         Non-critical service issue      2 hours        1 business day
             or pre-production outage
  P4         Minor issue, cosmetic defect,   4 hours        5 business days
             or information request

Escalation path:
  P1: Immediate escalation to Provider Service Director and Customer CIO
  P2: Escalation to Provider Account Manager after 2 hours without resolution
  P3: Escalation to Provider Account Manager after 1 business day
  P4: Standard ticket management

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

4. REPORTING REQUIREMENTS

The Provider shall deliver the following reports to the Customer:

  Report                          Frequency    Delivery Deadline
  ─────────────────────────────────────────────────────────────────────────────
  Monthly Service Report          Monthly      10th business day of following month
  Incident Summary Report         Monthly      Included in Monthly Service Report
  Capacity Planning Report        Quarterly    15th business day of following quarter
  Security Posture Report         Quarterly    15th business day of following quarter
  Annual Service Review           Annual       Within 30 days of anniversary

The Monthly Service Report shall include:
  — Availability metrics per environment with trend analysis
  — Performance metrics against targets
  — Incident summary with root cause analysis for P1/P2 incidents
  — Change management summary
  — Capacity utilisation and forecasting
  — SLA compliance status and any service credit calculations

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

5. PENALTY PROVISIONS

5.1 Service Credits

  Availability Achieved    Service Credit (% of Monthly Fee)
  ─────────────────────────────────────────────────────────────────────────────
  99.95% – 99.90%          5%
  99.90% – 99.50%          10%
  99.50% – 99.00%          20%
  Below 99.00%             30% (maximum credit)

Service credits are applied automatically to the next monthly invoice. The
Customer is not required to request service credits — the Provider shall
calculate and apply them based on monitoring data.

5.2 Incident Response Credits

  SLA Breach                                    Credit
  ─────────────────────────────────────────────────────────────────────────────
  P1 acknowledgement > 15 minutes               EUR 5,000 per incident
  P1 resolution > 1 hour                        EUR 10,000 per hour over target
  P2 acknowledgement > 30 minutes               EUR 2,000 per incident
  P2 resolution > 4 hours                       EUR 5,000 per hour over target

5.3 Chronic Underperformance

If availability falls below 99.9% for three consecutive months, the Customer
may invoke the Chronic Underperformance clause (MSA Clause 14.7), which triggers:
  — Mandatory service improvement plan within 10 business days
  — Weekly progress reviews until targets are met for two consecutive months
  — Right to terminate without penalty if targets not met within 90 days

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

6. REVIEW AND ESCALATION

This SLA is reviewed annually as part of the Annual Service Review. Either party
may request an interim review following a material change in service scope,
regulatory requirements, or business needs.

Dispute resolution follows the escalation path defined in MSA Clause 16:
  Level 1: Account Manager ↔ Vendor Management Officer (5 business days)
  Level 2: Service Director ↔ CIO (10 business days)
  Level 3: CEO ↔ CEO (20 business days)
  Level 4: Mediation / Arbitration per MSA Clause 17

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Signed:

For Nordvik Bank AG:
Name:  [Vendor Management Officer]
Title: Head of Vendor Management
Date:  1 March 2024

For Meridian Cloud Services GmbH:
Name:  [Provider Account Director]
Title: Account Director — Financial Services
Date:  1 March 2024

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

contract_compliance_status — fs-contract-compliance-status
{
  "factId": "d3e4f5a6-b7c8-9012-defa-234567890123",
  "evidenceId": "c2d3e4f5-a6b7-8901-2345-678901abcdef",
  "evidenceClassId": "ict-contract-review",
  "factType": "contract_compliance_status",
  "data": {
    "contract_id": "CTR-PRV001-2021-003",
    "review_date": "2025-01-22",
    "has_service_description": true,
    "has_data_location": true,
    "has_availability_provisions": true,
    "has_integrity_provisions": true,
    "has_audit_rights": true,
    "has_exit_strategy": true,
    "has_termination_rights": true,
    "compliance_gaps_count": 2,
    "contract_expiry_date": "2026-02-28"
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-01-23T11:00:00Z",
  "supersededBy": null
}
sla_monitoring_status — fs-sla-monitoring-status
{
  "factId": "e4f5a6b7-c8d9-0123-efab-345678901234",
  "evidenceId": "d3e4f5a6-b7c8-9012-3456-789012abcdef",
  "evidenceClassId": "sla-documentation",
  "factType": "sla_monitoring_status",
  "data": {
    "sla_id": "SLA-PRV001-2024-002",
    "monitoring_date": "2025-01-31",
    "availability_target_percent": 99.95,
    "availability_achieved_percent": 99.991,
    "sla_breaches_count": 2,
    "incident_response_sla_met": false,
    "reporting_sla_met": true,
    "sla_expired": false,
    "penalties_applied": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-02-01T08:00:00Z",
  "supersededBy": null
}

Fact Schemas

contract_compliance_status

Schema ID
fs-contract-compliance-status
Control
DORA-Art30-P1

Valid Ranges

review_date
within last 12 months
compliance_gaps_count
should be 0 for full DORA compliance
contract_expiry_date
future date for active contracts

Related Schemas

JSON Schema

{
  "properties": {
    "compliance_gaps_count": {
      "minimum": 0,
      "type": "integer"
    },
    "contract_expiry_date": {
      "format": "date",
      "type": "string"
    },
    "contract_id": {
      "minLength": 1,
      "type": "string"
    },
    "has_audit_rights": {
      "type": "boolean"
    },
    "has_availability_provisions": {
      "type": "boolean"
    },
    "has_data_location": {
      "type": "boolean"
    },
    "has_exit_strategy": {
      "type": "boolean"
    },
    "has_integrity_provisions": {
      "type": "boolean"
    },
    "has_service_description": {
      "type": "boolean"
    },
    "has_termination_rights": {
      "type": "boolean"
    },
    "review_date": {
      "format": "date",
      "type": "string"
    }
  },
  "required": [
    "contract_id",
    "review_date",
    "has_service_description",
    "has_data_location",
    "has_availability_provisions",
    "has_audit_rights",
    "has_exit_strategy"
  ],
  "type": "object"
}

sla_monitoring_status

Schema ID
fs-sla-monitoring-status
Control
DORA-Art30-P1

Valid Ranges

monitoring_date
within last 3 months
availability_achieved_percent
should meet or exceed availability_target_percent

Related Schemas

JSON Schema

{
  "properties": {
    "availability_achieved_percent": {
      "maximum": 100,
      "minimum": 0,
      "type": "number"
    },
    "availability_target_percent": {
      "maximum": 100,
      "minimum": 0,
      "type": "number"
    },
    "incident_response_sla_met": {
      "type": "boolean"
    },
    "monitoring_date": {
      "format": "date",
      "type": "string"
    },
    "penalties_applied": {
      "type": "boolean"
    },
    "reporting_sla_met": {
      "type": "boolean"
    },
    "sla_breaches_count": {
      "minimum": 0,
      "type": "integer"
    },
    "sla_expired": {
      "type": "boolean"
    },
    "sla_id": {
      "minLength": 1,
      "type": "string"
    }
  },
  "required": [
    "sla_id",
    "monitoring_date",
    "availability_target_percent",
    "availability_achieved_percent",
    "sla_breaches_count"
  ],
  "type": "object"
}