The Lead Overseer shall assess whether each critical ICT third-party service provider has in place comprehensive, sound and effective rules, procedures, mechanisms and arrangements to manage the ICT risk that it may pose to financial entities.
Report documenting the oversight assessment of critical ICT third-party service providers, including their ICT risk management arrangements, security posture, and compliance with oversight requirements as required by DORA Articles 33-44.
oversight-compliance-reportGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
CRITICAL PROVIDER OVERSIGHT COMPLIANCE REPORT
Nordvik Bank AG — Assessment of Meridian Cloud Services GmbH
Report Reference: OCR-2025-PRV001
Assessment Date: 10 February 2025
Prepared by: Internal Audit — ICT Risk Assurance Team
Report Status: Final
Classification: Confidential
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
EXECUTIVE SUMMARY
This report presents the findings of Nordvik Bank AG's annual oversight assessment
of Meridian Cloud Services GmbH ("Meridian"), a critical ICT third-party service
provider designated under the Bank's DORA Article 31 criticality framework.
Meridian provides core banking infrastructure hosting services supporting the
Bank's Temenos T24 core banking system, Oracle Database environments, and
associated compute, storage, and network services.
The assessment was conducted in accordance with DORA Articles 33-44 and the Bank's
Third-Party ICT Risk Management Policy (POL-TPR-2025-001). The assessment
methodology included: (a) review of Meridian's ICT risk management documentation;
(b) analysis of Meridian's security certifications and independent audit reports;
(c) on-site inspection of the Frankfurt data centre; and (d) interviews with
Meridian's CISO, Head of Operations, and Service Delivery Manager.
Overall Compliance Rating: PARTIALLY COMPLIANT
Assessment Area Rating
─────────────────────────────────────────────────────────────────────────────
ICT Risk Management Framework Compliant
Security Controls Compliant
Incident Management Partially Compliant
Business Continuity Partially Compliant
Change Management Compliant
Access Management Compliant
Subcontractor Management Partially Compliant
Total Findings: 7
Critical Findings: 1
High Findings: 2
Medium Findings: 3
Low Findings: 1
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
PROVIDER ICT RISK MANAGEMENT ASSESSMENT
Meridian maintains a documented ICT risk management framework aligned with ISO
27001:2022 and certified by TÜV Rheinland (certificate valid until September
2026). The framework covers risk identification, assessment, treatment, and
monitoring across all service delivery environments.
Key observations:
— Risk register maintained and reviewed quarterly by Meridian's Risk Committee
— Risk appetite defined and approved by Meridian's Board of Directors
— Three Lines of Defence model implemented
— Annual risk assessment conducted in Q4 2024, covering all customer environments
Finding: No findings. ICT risk management framework is comprehensive and current.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SECURITY POSTURE REVIEW
Meridian holds the following security certifications:
— ISO 27001:2022 (TÜV Rheinland, valid until September 2026)
— SOC 2 Type II (Deloitte, report dated November 2024)
— C5:2020 (BSI Cloud Computing Compliance Criteria Catalogue)
— PCI-DSS v4.0 Level 1 (for payment-related hosting environments)
Security controls assessed:
— Network segmentation: Customer environments isolated using dedicated VLANs
and firewall rules. Verified during on-site inspection.
— Encryption: AES-256 at rest, TLS 1.3 in transit. Key management via
dedicated HSM (Thales Luna).
— Access management: Privileged access managed via CyberArk PAM with MFA.
Quarterly access reviews conducted.
— Vulnerability management: Weekly automated scanning (Qualys). Critical
patches applied within 72 hours. Verified via patch compliance report.
— Penetration testing: Annual external penetration test (NCC Group, December
2024). No critical findings. Two medium findings remediated.
Finding: No findings. Security posture is strong and well-documented.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
INCIDENT MANAGEMENT CAPABILITIES
Meridian operates a 24/7 Network Operations Centre (NOC) with defined incident
management procedures. Incident classification follows a P1-P4 priority scheme
aligned with the SLA.
Key observations:
— Incident management process documented and aligned with ITIL v4
— 24/7 NOC staffed with minimum 3 engineers per shift
— Incident communication to customers via automated alerting platform
— Post-incident reviews conducted for all P1 and P2 incidents
Findings:
FINDING OCR-F01 (CRITICAL): Incident notification to the Bank for P1 incidents
was delayed beyond the 15-minute SLA target in 2 of 5 P1 incidents in 2024.
Root cause: manual notification process — NOC engineer must manually trigger
customer notification after initial triage. Automated notification not yet
implemented for all incident types.
Recommendation: Implement automated customer notification triggered by P1
incident declaration, with manual override capability. Target: Q2 2025.
FINDING OCR-F02 (HIGH): Post-incident review reports for 3 of 8 P2 incidents
in 2024 were delivered more than 10 business days after incident resolution,
exceeding the 5-business-day target in the SLA.
Recommendation: Implement post-incident review tracking with automated
escalation when delivery deadline approaches. Target: Q1 2025.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
BUSINESS CONTINUITY ARRANGEMENTS
Meridian maintains business continuity and disaster recovery plans for all
customer environments. The Bank's environment is replicated to the Dublin DR
site with a target RPO of 1 hour and RTO of 4 hours.
Key observations:
— BCP documented and reviewed annually (last review: November 2024)
— DR failover tested semi-annually
— Last successful DR test: October 2024 (RTO achieved: 3 hours 22 minutes)
Findings:
FINDING OCR-F03 (HIGH): The DR failover test in October 2024 did not include
the Oracle Database managed service component. Meridian confirmed that database
DR failover has not been tested end-to-end since April 2024, when a test
failure occurred due to replication lag. The replication issue was resolved in
June 2024 but the retest has not been scheduled.
Recommendation: Conduct end-to-end DR failover test including Oracle Database
within 60 days. Establish quarterly DR test schedule for database services.
Target: April 2025.
FINDING OCR-F04 (MEDIUM): BCP does not address the scenario of simultaneous
loss of both Frankfurt and Dublin sites (e.g., coordinated cyber attack or
shared infrastructure failure at Equinix).
Recommendation: Develop third-site recovery strategy or document risk
acceptance for dual-site loss scenario. Target: Q3 2025.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
COMPLIANCE FINDINGS
Finding ID Severity Area Description
─────────────────────────────────────────────────────────────────────────────
OCR-F01 Critical Incident Management P1 notification delays
OCR-F02 High Incident Management Late post-incident reviews
OCR-F03 High Business Continuity Database DR test overdue
OCR-F04 Medium Business Continuity No third-site recovery plan
OCR-F05 Medium Subcontractor Mgmt Equinix SLA not reviewed
since 2023
OCR-F06 Medium Subcontractor Mgmt Cloudflare incident
notification chain not
tested
OCR-F07 Low Documentation Service catalogue not
updated for Kubernetes
services added in Sep 2024
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
RECOMMENDATIONS
# Finding Recommendation Target Owner
─────────────────────────────────────────────────────────────────────────────
1 OCR-F01 Implement automated P1 notification Q2 2025 Meridian NOC
2 OCR-F02 Implement PIR tracking with escalation Q1 2025 Meridian SM
3 OCR-F03 Conduct database DR failover test Apr 2025 Meridian Ops
4 OCR-F04 Develop third-site recovery strategy Q3 2025 Meridian BCP
5 OCR-F05 Review and update Equinix SLA Q1 2025 Meridian VM
6 OCR-F06 Test Cloudflare incident notification Q1 2025 Meridian NOC
7 OCR-F07 Update service catalogue Q1 2025 Meridian SM
Next assessment: February 2026
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Prepared by: Head of Internal Audit — ICT Risk Assurance
Reviewed by: CRO
Date: 10 February 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
oversight_compliance_status — fs-oversight-compliance-status
{
"factId": "c8d9e0f1-a2b3-4567-cdef-789012345678",
"evidenceId": "b7c8d9e0-f1a2-3456-7890-123456abcdef",
"evidenceClassId": "oversight-compliance-report",
"factType": "oversight_compliance_status",
"data": {
"provider_id": "PRV-001",
"assessment_date": "2025-02-10",
"overall_compliance_rating": "partially_compliant",
"has_risk_framework": true,
"has_security_controls": true,
"has_incident_management": true,
"has_business_continuity": true,
"findings_count": 7,
"critical_findings": 1
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-02-11T15:00:00Z",
"supersededBy": null
}
provider_ict_risk_management_status — fs-provider-ict-risk-management
{
"factId": "d9e0f1a2-b3c4-5678-defa-890123456789",
"evidenceId": "c8d9e0f1-a2b3-4567-8901-234567abcdef",
"evidenceClassId": "provider-ict-risk-management",
"factType": "provider_ict_risk_management_status",
"data": {
"provider_id": "PRV-001",
"assessment_date": "2025-01-15",
"has_risk_framework": true,
"has_security_certifications": true,
"certifications_list": [
"ISO 27001:2022",
"SOC 2 Type II",
"C5:2020",
"PCI-DSS v4.0 Level 1"
],
"last_independent_audit_date": "2024-11-15",
"audit_findings_resolved": true,
"subcontractor_risk_managed": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-01-16T11:30:00Z",
"supersededBy": null
}
Plain text summary of a critical ICT third-party service provider's ICT risk management arrangements, compiled from provider-supplied documentation and audit reports.
provider-ict-risk-managementGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
PROVIDER ICT RISK MANAGEMENT SUMMARY
Meridian Cloud Services GmbH
Compiled by: Nordvik Bank AG — Vendor Management Office
Assessment Date: 15 January 2025
Sources: Provider-supplied documentation, SOC 2 Type II report, ISO 27001 certificate, on-site assessment notes
Classification: Confidential
═══════════════════════════════════════════════════════════════════════════════
PROVIDER OVERVIEW
Provider Name: Meridian Cloud Services GmbH
Registered Office: Frankfurt am Main, Germany
Founded: 2012
Employees: ~420 (as of December 2024)
Revenue (2024): EUR 68M (estimated, private company)
Primary Services: Infrastructure-as-a-Service (IaaS) for regulated
financial institutions
Data Centre Locations: Frankfurt (Equinix FR5), Dublin (Equinix DB3),
Amsterdam (Equinix AM7)
Financial Entities
Served: 15 (12 banks, 3 insurance companies)
Jurisdictions: Germany, Switzerland, Austria, Ireland, Netherlands
Meridian specialises in hosting regulated workloads for mid-market European
financial institutions. The company was founded by former Deutsche Börse
infrastructure engineers and has built its platform specifically for financial-
grade hosting requirements, including dedicated hardware, customer isolation,
and regulatory compliance tooling.
═══════════════════════════════════════════════════════════════════════════════
ICT RISK MANAGEMENT FRAMEWORK
Meridian maintains a documented ICT risk management framework that was last
reviewed and updated in October 2024. The framework is structured around the
following components:
Governance:
— Board-level Risk Committee meeting quarterly
— Dedicated CISO reporting directly to the CEO
— Risk Management function independent of operations
— Three Lines of Defence model implemented
Risk Identification:
— Continuous threat monitoring via internal SOC
— Quarterly risk assessments covering all service environments
— Annual comprehensive risk assessment with external input
— Threat intelligence feeds from FS-ISAC and CERT-EU
Risk Assessment:
— Semi-quantitative methodology (5x5 likelihood-impact matrix)
— Scenario-based assessment for emerging risks
— Customer-specific risk assessments for critical environments
Risk Treatment:
— Risk register maintained in GRC platform (ServiceNow)
— Treatment plans tracked with defined owners and deadlines
— Quarterly reporting to Board Risk Committee
Monitoring:
— Key Risk Indicators monitored continuously
— Monthly risk dashboard published to management
— Quarterly risk report to Board
Assessment: Meridian's ICT risk management framework is comprehensive and
appropriate for a provider of its size and criticality. The framework aligns
with DORA requirements and ISO 27001 standards.
═══════════════════════════════════════════════════════════════════════════════
SECURITY CONTROLS
Meridian implements a layered security control framework. Key controls observed:
Physical Security:
— Equinix Tier IV data centres with biometric access control
— Dedicated cages for financial institution environments
— 24/7 on-site security personnel
— CCTV with 90-day retention
Network Security:
— Customer environments isolated via dedicated VLANs and firewalls
— Micro-segmentation within customer environments
— IDS/IPS at all network boundaries (Palo Alto)
— DDoS protection (Cloudflare Enterprise)
Access Management:
— Privileged access via CyberArk PAM with MFA
— Just-in-time access provisioning for operational tasks
— Quarterly access reviews with customer participation
— All privileged sessions recorded and auditable
Encryption:
— AES-256 encryption at rest for all customer data
— TLS 1.3 for all data in transit
— Customer-managed encryption keys available (BYOK via Thales Luna HSM)
— Key rotation enforced annually
Endpoint Security:
— CrowdStrike Falcon EDR on all servers and workstations
— Automated patch management with 72-hour critical patch SLA
— Application whitelisting on production servers
═══════════════════════════════════════════════════════════════════════════════
INCIDENT MANAGEMENT
Meridian operates a 24/7 Network Operations Centre (NOC) with defined incident
management procedures:
— Incident classification: P1 (critical) through P4 (minor)
— P1 response: 15-minute acknowledgement, 1-hour resolution target
— Customer notification: Manual process (automated notification in development)
— Post-incident reviews: Required for all P1/P2 incidents within 5 business days
— Root cause analysis: Formal RCA for all P1 incidents
2024 Incident Summary (Nordvik Bank environment):
— P1 incidents: 5 (3 resolved within SLA, 2 exceeded notification SLA)
— P2 incidents: 8 (6 resolved within SLA)
— Total unplanned downtime: 47 minutes (99.991% availability achieved)
Note: Two P1 notification delays identified — Meridian has committed to
implementing automated notification by Q2 2025.
═══════════════════════════════════════════════════════════════════════════════
BUSINESS CONTINUITY
Meridian maintains business continuity and disaster recovery capabilities:
— BCP reviewed annually (last review: November 2024)
— DR site: Dublin (Equinix DB3) with synchronous replication for critical data
— DR failover tested semi-annually
— Last successful test: October 2024 (RTO achieved: 3h 22m, target: 4h)
— RPO achieved in testing: 12 minutes (target: 1 hour)
Note: October 2024 DR test did not include Oracle Database managed service
component. Database DR retest pending — see oversight report OCR-2025-PRV001.
═══════════════════════════════════════════════════════════════════════════════
COMPLIANCE CERTIFICATIONS
Certification Issuer Valid Until Scope
─────────────────────────────────────────────────────────────────────────
ISO 27001:2022 TÜV Rheinland Sep 2026 All DC operations
SOC 2 Type II Deloitte Nov 2025 IaaS platform
C5:2020 BSI Jun 2025 Cloud services
PCI-DSS v4.0 Level 1 Coalfire Mar 2025 Payment hosting
Last independent audit: SOC 2 Type II audit by Deloitte, completed November 2024.
No qualified opinions. Three advisory observations related to change management
documentation completeness.
Previous audit findings: All findings from the 2023 SOC 2 audit have been
remediated and verified by Deloitte in the 2024 audit cycle.
═══════════════════════════════════════════════════════════════════════════════
Compiled by: Vendor Management Office
Reviewed by: CISO
Date: 15 January 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
oversight_compliance_status — fs-oversight-compliance-status
{
"factId": "c8d9e0f1-a2b3-4567-cdef-789012345678",
"evidenceId": "b7c8d9e0-f1a2-3456-7890-123456abcdef",
"evidenceClassId": "oversight-compliance-report",
"factType": "oversight_compliance_status",
"data": {
"provider_id": "PRV-001",
"assessment_date": "2025-02-10",
"overall_compliance_rating": "partially_compliant",
"has_risk_framework": true,
"has_security_controls": true,
"has_incident_management": true,
"has_business_continuity": true,
"findings_count": 7,
"critical_findings": 1
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-02-11T15:00:00Z",
"supersededBy": null
}
provider_ict_risk_management_status — fs-provider-ict-risk-management
{
"factId": "d9e0f1a2-b3c4-5678-defa-890123456789",
"evidenceId": "c8d9e0f1-a2b3-4567-8901-234567abcdef",
"evidenceClassId": "provider-ict-risk-management",
"factType": "provider_ict_risk_management_status",
"data": {
"provider_id": "PRV-001",
"assessment_date": "2025-01-15",
"has_risk_framework": true,
"has_security_certifications": true,
"certifications_list": [
"ISO 27001:2022",
"SOC 2 Type II",
"C5:2020",
"PCI-DSS v4.0 Level 1"
],
"last_independent_audit_date": "2024-11-15",
"audit_findings_resolved": true,
"subcontractor_risk_managed": true
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-01-16T11:30:00Z",
"supersededBy": null
}
fs-oversight-compliance-statusDORA-Art33-P1assessment_dateoverall_compliance_rating{
"properties": {
"assessment_date": {
"format": "date",
"type": "string"
},
"critical_findings": {
"minimum": 0,
"type": "integer"
},
"findings_count": {
"minimum": 0,
"type": "integer"
},
"has_business_continuity": {
"type": "boolean"
},
"has_incident_management": {
"type": "boolean"
},
"has_risk_framework": {
"type": "boolean"
},
"has_security_controls": {
"type": "boolean"
},
"overall_compliance_rating": {
"enum": [
"compliant",
"partially_compliant",
"non_compliant"
],
"type": "string"
},
"provider_id": {
"minLength": 1,
"type": "string"
}
},
"required": [
"provider_id",
"assessment_date",
"overall_compliance_rating",
"has_risk_framework",
"has_security_controls"
],
"type": "object"
}
fs-provider-ict-risk-managementDORA-Art33-P1assessment_datelast_independent_audit_date{
"properties": {
"assessment_date": {
"format": "date",
"type": "string"
},
"audit_findings_resolved": {
"type": "boolean"
},
"certifications_list": {
"items": {
"type": "string"
},
"type": "array"
},
"has_risk_framework": {
"type": "boolean"
},
"has_security_certifications": {
"type": "boolean"
},
"last_independent_audit_date": {
"format": "date",
"type": "string"
},
"provider_id": {
"minLength": 1,
"type": "string"
},
"subcontractor_risk_managed": {
"type": "boolean"
}
},
"required": [
"provider_id",
"assessment_date",
"has_risk_framework",
"has_security_certifications"
],
"type": "object"
}