DORA-Art33-P1

Article
33 (1)
Pillar
Third-Party ICT Risk Management
Regulation Ref
Regulation (EU) 2022/2554, Article 33(1)
Last Reviewed
2026-01-15

The Lead Overseer shall assess whether each critical ICT third-party service provider has in place comprehensive, sound and effective rules, procedures, mechanisms and arrangements to manage the ICT risk that it may pose to financial entities.

Evidence Profiles

Critical Provider Oversight Compliance Report RARE

Report documenting the oversight assessment of critical ICT third-party service providers, including their ICT risk management arrangements, security posture, and compliance with oversight requirements as required by DORA Articles 33-44.

Formats
PDF
Evidence Class
oversight-compliance-report
Availability
RARE
Update Frequency
annual
Typical Author
Lead Overseer / Internal Audit
Approval Chain
Head of Internal Audit → CRO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
CRITICAL PROVIDER OVERSIGHT COMPLIANCE REPORT
Nordvik Bank AG — Assessment of Meridian Cloud Services GmbH
Report Reference: OCR-2025-PRV001
Assessment Date: 10 February 2025
Prepared by: Internal Audit — ICT Risk Assurance Team
Report Status: Final
Classification: Confidential

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

EXECUTIVE SUMMARY

This report presents the findings of Nordvik Bank AG's annual oversight assessment
of Meridian Cloud Services GmbH ("Meridian"), a critical ICT third-party service
provider designated under the Bank's DORA Article 31 criticality framework.
Meridian provides core banking infrastructure hosting services supporting the
Bank's Temenos T24 core banking system, Oracle Database environments, and
associated compute, storage, and network services.

The assessment was conducted in accordance with DORA Articles 33-44 and the Bank's
Third-Party ICT Risk Management Policy (POL-TPR-2025-001). The assessment
methodology included: (a) review of Meridian's ICT risk management documentation;
(b) analysis of Meridian's security certifications and independent audit reports;
(c) on-site inspection of the Frankfurt data centre; and (d) interviews with
Meridian's CISO, Head of Operations, and Service Delivery Manager.

Overall Compliance Rating: PARTIALLY COMPLIANT

  Assessment Area                    Rating
  ─────────────────────────────────────────────────────────────────────────────
  ICT Risk Management Framework      Compliant
  Security Controls                  Compliant
  Incident Management                Partially Compliant
  Business Continuity                Partially Compliant
  Change Management                  Compliant
  Access Management                  Compliant
  Subcontractor Management           Partially Compliant

Total Findings: 7
Critical Findings: 1
High Findings: 2
Medium Findings: 3
Low Findings: 1

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

PROVIDER ICT RISK MANAGEMENT ASSESSMENT

Meridian maintains a documented ICT risk management framework aligned with ISO
27001:2022 and certified by TÜV Rheinland (certificate valid until September
2026). The framework covers risk identification, assessment, treatment, and
monitoring across all service delivery environments.

Key observations:
  — Risk register maintained and reviewed quarterly by Meridian's Risk Committee
  — Risk appetite defined and approved by Meridian's Board of Directors
  — Three Lines of Defence model implemented
  — Annual risk assessment conducted in Q4 2024, covering all customer environments

Finding: No findings. ICT risk management framework is comprehensive and current.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

SECURITY POSTURE REVIEW

Meridian holds the following security certifications:
  — ISO 27001:2022 (TÜV Rheinland, valid until September 2026)
  — SOC 2 Type II (Deloitte, report dated November 2024)
  — C5:2020 (BSI Cloud Computing Compliance Criteria Catalogue)
  — PCI-DSS v4.0 Level 1 (for payment-related hosting environments)

Security controls assessed:
  — Network segmentation: Customer environments isolated using dedicated VLANs
    and firewall rules. Verified during on-site inspection.
  — Encryption: AES-256 at rest, TLS 1.3 in transit. Key management via
    dedicated HSM (Thales Luna).
  — Access management: Privileged access managed via CyberArk PAM with MFA.
    Quarterly access reviews conducted.
  — Vulnerability management: Weekly automated scanning (Qualys). Critical
    patches applied within 72 hours. Verified via patch compliance report.
  — Penetration testing: Annual external penetration test (NCC Group, December
    2024). No critical findings. Two medium findings remediated.

Finding: No findings. Security posture is strong and well-documented.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

INCIDENT MANAGEMENT CAPABILITIES

Meridian operates a 24/7 Network Operations Centre (NOC) with defined incident
management procedures. Incident classification follows a P1-P4 priority scheme
aligned with the SLA.

Key observations:
  — Incident management process documented and aligned with ITIL v4
  — 24/7 NOC staffed with minimum 3 engineers per shift
  — Incident communication to customers via automated alerting platform
  — Post-incident reviews conducted for all P1 and P2 incidents

Findings:

  FINDING OCR-F01 (CRITICAL): Incident notification to the Bank for P1 incidents
  was delayed beyond the 15-minute SLA target in 2 of 5 P1 incidents in 2024.
  Root cause: manual notification process — NOC engineer must manually trigger
  customer notification after initial triage. Automated notification not yet
  implemented for all incident types.

  Recommendation: Implement automated customer notification triggered by P1
  incident declaration, with manual override capability. Target: Q2 2025.

  FINDING OCR-F02 (HIGH): Post-incident review reports for 3 of 8 P2 incidents
  in 2024 were delivered more than 10 business days after incident resolution,
  exceeding the 5-business-day target in the SLA.

  Recommendation: Implement post-incident review tracking with automated
  escalation when delivery deadline approaches. Target: Q1 2025.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

BUSINESS CONTINUITY ARRANGEMENTS

Meridian maintains business continuity and disaster recovery plans for all
customer environments. The Bank's environment is replicated to the Dublin DR
site with a target RPO of 1 hour and RTO of 4 hours.

Key observations:
  — BCP documented and reviewed annually (last review: November 2024)
  — DR failover tested semi-annually
  — Last successful DR test: October 2024 (RTO achieved: 3 hours 22 minutes)

Findings:

  FINDING OCR-F03 (HIGH): The DR failover test in October 2024 did not include
  the Oracle Database managed service component. Meridian confirmed that database
  DR failover has not been tested end-to-end since April 2024, when a test
  failure occurred due to replication lag. The replication issue was resolved in
  June 2024 but the retest has not been scheduled.

  Recommendation: Conduct end-to-end DR failover test including Oracle Database
  within 60 days. Establish quarterly DR test schedule for database services.
  Target: April 2025.

  FINDING OCR-F04 (MEDIUM): BCP does not address the scenario of simultaneous
  loss of both Frankfurt and Dublin sites (e.g., coordinated cyber attack or
  shared infrastructure failure at Equinix).

  Recommendation: Develop third-site recovery strategy or document risk
  acceptance for dual-site loss scenario. Target: Q3 2025.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

COMPLIANCE FINDINGS

  Finding ID   Severity   Area                    Description
  ─────────────────────────────────────────────────────────────────────────────
  OCR-F01      Critical   Incident Management     P1 notification delays
  OCR-F02      High       Incident Management     Late post-incident reviews
  OCR-F03      High       Business Continuity     Database DR test overdue
  OCR-F04      Medium     Business Continuity     No third-site recovery plan
  OCR-F05      Medium     Subcontractor Mgmt      Equinix SLA not reviewed
                                                   since 2023
  OCR-F06      Medium     Subcontractor Mgmt      Cloudflare incident
                                                   notification chain not
                                                   tested
  OCR-F07      Low        Documentation           Service catalogue not
                                                   updated for Kubernetes
                                                   services added in Sep 2024

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

RECOMMENDATIONS

  #   Finding    Recommendation                              Target    Owner
  ─────────────────────────────────────────────────────────────────────────────
  1   OCR-F01    Implement automated P1 notification         Q2 2025   Meridian NOC
  2   OCR-F02    Implement PIR tracking with escalation      Q1 2025   Meridian SM
  3   OCR-F03    Conduct database DR failover test           Apr 2025  Meridian Ops
  4   OCR-F04    Develop third-site recovery strategy        Q3 2025   Meridian BCP
  5   OCR-F05    Review and update Equinix SLA               Q1 2025   Meridian VM
  6   OCR-F06    Test Cloudflare incident notification       Q1 2025   Meridian NOC
  7   OCR-F07    Update service catalogue                    Q1 2025   Meridian SM

Next assessment: February 2026

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Prepared by: Head of Internal Audit — ICT Risk Assurance
Reviewed by: CRO
Date: 10 February 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

oversight_compliance_status — fs-oversight-compliance-status
{
  "factId": "c8d9e0f1-a2b3-4567-cdef-789012345678",
  "evidenceId": "b7c8d9e0-f1a2-3456-7890-123456abcdef",
  "evidenceClassId": "oversight-compliance-report",
  "factType": "oversight_compliance_status",
  "data": {
    "provider_id": "PRV-001",
    "assessment_date": "2025-02-10",
    "overall_compliance_rating": "partially_compliant",
    "has_risk_framework": true,
    "has_security_controls": true,
    "has_incident_management": true,
    "has_business_continuity": true,
    "findings_count": 7,
    "critical_findings": 1
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-02-11T15:00:00Z",
  "supersededBy": null
}
provider_ict_risk_management_status — fs-provider-ict-risk-management
{
  "factId": "d9e0f1a2-b3c4-5678-defa-890123456789",
  "evidenceId": "c8d9e0f1-a2b3-4567-8901-234567abcdef",
  "evidenceClassId": "provider-ict-risk-management",
  "factType": "provider_ict_risk_management_status",
  "data": {
    "provider_id": "PRV-001",
    "assessment_date": "2025-01-15",
    "has_risk_framework": true,
    "has_security_certifications": true,
    "certifications_list": [
      "ISO 27001:2022",
      "SOC 2 Type II",
      "C5:2020",
      "PCI-DSS v4.0 Level 1"
    ],
    "last_independent_audit_date": "2024-11-15",
    "audit_findings_resolved": true,
    "subcontractor_risk_managed": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-01-16T11:30:00Z",
  "supersededBy": null
}

Provider ICT Risk Management Summary PARTIAL

Plain text summary of a critical ICT third-party service provider's ICT risk management arrangements, compiled from provider-supplied documentation and audit reports.

Formats
PLAIN_TEXT
Evidence Class
provider-ict-risk-management
Availability
PARTIAL
Update Frequency
annual
Typical Author
Vendor Management Officer
Approval Chain
Vendor Management Officer → CISO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
PROVIDER ICT RISK MANAGEMENT SUMMARY
Meridian Cloud Services GmbH
Compiled by: Nordvik Bank AG — Vendor Management Office
Assessment Date: 15 January 2025
Sources: Provider-supplied documentation, SOC 2 Type II report, ISO 27001 certificate, on-site assessment notes
Classification: Confidential

═══════════════════════════════════════════════════════════════════════════════

PROVIDER OVERVIEW

Provider Name:          Meridian Cloud Services GmbH
Registered Office:      Frankfurt am Main, Germany
Founded:                2012
Employees:              ~420 (as of December 2024)
Revenue (2024):         EUR 68M (estimated, private company)
Primary Services:       Infrastructure-as-a-Service (IaaS) for regulated
                        financial institutions
Data Centre Locations:  Frankfurt (Equinix FR5), Dublin (Equinix DB3),
                        Amsterdam (Equinix AM7)
Financial Entities
  Served:               15 (12 banks, 3 insurance companies)
Jurisdictions:          Germany, Switzerland, Austria, Ireland, Netherlands

Meridian specialises in hosting regulated workloads for mid-market European
financial institutions. The company was founded by former Deutsche Börse
infrastructure engineers and has built its platform specifically for financial-
grade hosting requirements, including dedicated hardware, customer isolation,
and regulatory compliance tooling.

═══════════════════════════════════════════════════════════════════════════════

ICT RISK MANAGEMENT FRAMEWORK

Meridian maintains a documented ICT risk management framework that was last
reviewed and updated in October 2024. The framework is structured around the
following components:

  Governance:
    — Board-level Risk Committee meeting quarterly
    — Dedicated CISO reporting directly to the CEO
    — Risk Management function independent of operations
    — Three Lines of Defence model implemented

  Risk Identification:
    — Continuous threat monitoring via internal SOC
    — Quarterly risk assessments covering all service environments
    — Annual comprehensive risk assessment with external input
    — Threat intelligence feeds from FS-ISAC and CERT-EU

  Risk Assessment:
    — Semi-quantitative methodology (5x5 likelihood-impact matrix)
    — Scenario-based assessment for emerging risks
    — Customer-specific risk assessments for critical environments

  Risk Treatment:
    — Risk register maintained in GRC platform (ServiceNow)
    — Treatment plans tracked with defined owners and deadlines
    — Quarterly reporting to Board Risk Committee

  Monitoring:
    — Key Risk Indicators monitored continuously
    — Monthly risk dashboard published to management
    — Quarterly risk report to Board

Assessment: Meridian's ICT risk management framework is comprehensive and
appropriate for a provider of its size and criticality. The framework aligns
with DORA requirements and ISO 27001 standards.

═══════════════════════════════════════════════════════════════════════════════

SECURITY CONTROLS

Meridian implements a layered security control framework. Key controls observed:

  Physical Security:
    — Equinix Tier IV data centres with biometric access control
    — Dedicated cages for financial institution environments
    — 24/7 on-site security personnel
    — CCTV with 90-day retention

  Network Security:
    — Customer environments isolated via dedicated VLANs and firewalls
    — Micro-segmentation within customer environments
    — IDS/IPS at all network boundaries (Palo Alto)
    — DDoS protection (Cloudflare Enterprise)

  Access Management:
    — Privileged access via CyberArk PAM with MFA
    — Just-in-time access provisioning for operational tasks
    — Quarterly access reviews with customer participation
    — All privileged sessions recorded and auditable

  Encryption:
    — AES-256 encryption at rest for all customer data
    — TLS 1.3 for all data in transit
    — Customer-managed encryption keys available (BYOK via Thales Luna HSM)
    — Key rotation enforced annually

  Endpoint Security:
    — CrowdStrike Falcon EDR on all servers and workstations
    — Automated patch management with 72-hour critical patch SLA
    — Application whitelisting on production servers

═══════════════════════════════════════════════════════════════════════════════

INCIDENT MANAGEMENT

Meridian operates a 24/7 Network Operations Centre (NOC) with defined incident
management procedures:

  — Incident classification: P1 (critical) through P4 (minor)
  — P1 response: 15-minute acknowledgement, 1-hour resolution target
  — Customer notification: Manual process (automated notification in development)
  — Post-incident reviews: Required for all P1/P2 incidents within 5 business days
  — Root cause analysis: Formal RCA for all P1 incidents

2024 Incident Summary (Nordvik Bank environment):
  — P1 incidents: 5 (3 resolved within SLA, 2 exceeded notification SLA)
  — P2 incidents: 8 (6 resolved within SLA)
  — Total unplanned downtime: 47 minutes (99.991% availability achieved)

Note: Two P1 notification delays identified — Meridian has committed to
implementing automated notification by Q2 2025.

═══════════════════════════════════════════════════════════════════════════════

BUSINESS CONTINUITY

Meridian maintains business continuity and disaster recovery capabilities:

  — BCP reviewed annually (last review: November 2024)
  — DR site: Dublin (Equinix DB3) with synchronous replication for critical data
  — DR failover tested semi-annually
  — Last successful test: October 2024 (RTO achieved: 3h 22m, target: 4h)
  — RPO achieved in testing: 12 minutes (target: 1 hour)

Note: October 2024 DR test did not include Oracle Database managed service
component. Database DR retest pending — see oversight report OCR-2025-PRV001.

═══════════════════════════════════════════════════════════════════════════════

COMPLIANCE CERTIFICATIONS

  Certification              Issuer              Valid Until    Scope
  ─────────────────────────────────────────────────────────────────────────
  ISO 27001:2022             TÜV Rheinland       Sep 2026      All DC operations
  SOC 2 Type II              Deloitte            Nov 2025      IaaS platform
  C5:2020                    BSI                 Jun 2025      Cloud services
  PCI-DSS v4.0 Level 1      Coalfire            Mar 2025      Payment hosting

Last independent audit: SOC 2 Type II audit by Deloitte, completed November 2024.
No qualified opinions. Three advisory observations related to change management
documentation completeness.

Previous audit findings: All findings from the 2023 SOC 2 audit have been
remediated and verified by Deloitte in the 2024 audit cycle.

═══════════════════════════════════════════════════════════════════════════════

Compiled by: Vendor Management Office
Reviewed by: CISO
Date: 15 January 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

oversight_compliance_status — fs-oversight-compliance-status
{
  "factId": "c8d9e0f1-a2b3-4567-cdef-789012345678",
  "evidenceId": "b7c8d9e0-f1a2-3456-7890-123456abcdef",
  "evidenceClassId": "oversight-compliance-report",
  "factType": "oversight_compliance_status",
  "data": {
    "provider_id": "PRV-001",
    "assessment_date": "2025-02-10",
    "overall_compliance_rating": "partially_compliant",
    "has_risk_framework": true,
    "has_security_controls": true,
    "has_incident_management": true,
    "has_business_continuity": true,
    "findings_count": 7,
    "critical_findings": 1
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-02-11T15:00:00Z",
  "supersededBy": null
}
provider_ict_risk_management_status — fs-provider-ict-risk-management
{
  "factId": "d9e0f1a2-b3c4-5678-defa-890123456789",
  "evidenceId": "c8d9e0f1-a2b3-4567-8901-234567abcdef",
  "evidenceClassId": "provider-ict-risk-management",
  "factType": "provider_ict_risk_management_status",
  "data": {
    "provider_id": "PRV-001",
    "assessment_date": "2025-01-15",
    "has_risk_framework": true,
    "has_security_certifications": true,
    "certifications_list": [
      "ISO 27001:2022",
      "SOC 2 Type II",
      "C5:2020",
      "PCI-DSS v4.0 Level 1"
    ],
    "last_independent_audit_date": "2024-11-15",
    "audit_findings_resolved": true,
    "subcontractor_risk_managed": true
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-01-16T11:30:00Z",
  "supersededBy": null
}

Fact Schemas

oversight_compliance_status

Schema ID
fs-oversight-compliance-status
Control
DORA-Art33-P1

Valid Ranges

assessment_date
within last 12 months
overall_compliance_rating
compliant for continued service provision

Related Schemas

JSON Schema

{
  "properties": {
    "assessment_date": {
      "format": "date",
      "type": "string"
    },
    "critical_findings": {
      "minimum": 0,
      "type": "integer"
    },
    "findings_count": {
      "minimum": 0,
      "type": "integer"
    },
    "has_business_continuity": {
      "type": "boolean"
    },
    "has_incident_management": {
      "type": "boolean"
    },
    "has_risk_framework": {
      "type": "boolean"
    },
    "has_security_controls": {
      "type": "boolean"
    },
    "overall_compliance_rating": {
      "enum": [
        "compliant",
        "partially_compliant",
        "non_compliant"
      ],
      "type": "string"
    },
    "provider_id": {
      "minLength": 1,
      "type": "string"
    }
  },
  "required": [
    "provider_id",
    "assessment_date",
    "overall_compliance_rating",
    "has_risk_framework",
    "has_security_controls"
  ],
  "type": "object"
}

provider_ict_risk_management_status

Schema ID
fs-provider-ict-risk-management
Control
DORA-Art33-P1

Valid Ranges

assessment_date
within last 12 months
last_independent_audit_date
within last 18 months

Related Schemas

JSON Schema

{
  "properties": {
    "assessment_date": {
      "format": "date",
      "type": "string"
    },
    "audit_findings_resolved": {
      "type": "boolean"
    },
    "certifications_list": {
      "items": {
        "type": "string"
      },
      "type": "array"
    },
    "has_risk_framework": {
      "type": "boolean"
    },
    "has_security_certifications": {
      "type": "boolean"
    },
    "last_independent_audit_date": {
      "format": "date",
      "type": "string"
    },
    "provider_id": {
      "minLength": 1,
      "type": "string"
    },
    "subcontractor_risk_managed": {
      "type": "boolean"
    }
  },
  "required": [
    "provider_id",
    "assessment_date",
    "has_risk_framework",
    "has_security_certifications"
  ],
  "type": "object"
}