The Lead Overseer shall, on the basis of the assessment referred to in Article 33, adopt a clear, detailed and reasoned individual oversight plan describing the annual oversight objectives and the main oversight actions planned for each critical ICT third-party service provider.
Report documenting the oversight assessment of critical ICT third-party service providers, including their ICT risk management arrangements, security posture, and compliance with oversight requirements as required by DORA Articles 33-44.
oversight-compliance-reportGenerated example artifact using the default institution profile (COMMON availability, synthetic data only).
CRITICAL PROVIDER OVERSIGHT COMPLIANCE REPORT
Nordvik Bank AG — Assessment of Meridian Cloud Services GmbH
Report Reference: OCR-2025-PRV001
Assessment Date: 10 February 2025
Prepared by: Internal Audit — ICT Risk Assurance Team
Report Status: Final
Classification: Confidential
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
EXECUTIVE SUMMARY
This report presents the findings of Nordvik Bank AG's annual oversight assessment
of Meridian Cloud Services GmbH ("Meridian"), a critical ICT third-party service
provider designated under the Bank's DORA Article 31 criticality framework.
Meridian provides core banking infrastructure hosting services supporting the
Bank's Temenos T24 core banking system, Oracle Database environments, and
associated compute, storage, and network services.
The assessment was conducted in accordance with DORA Articles 33-44 and the Bank's
Third-Party ICT Risk Management Policy (POL-TPR-2025-001). The assessment
methodology included: (a) review of Meridian's ICT risk management documentation;
(b) analysis of Meridian's security certifications and independent audit reports;
(c) on-site inspection of the Frankfurt data centre; and (d) interviews with
Meridian's CISO, Head of Operations, and Service Delivery Manager.
Overall Compliance Rating: PARTIALLY COMPLIANT
Assessment Area Rating
─────────────────────────────────────────────────────────────────────────────
ICT Risk Management Framework Compliant
Security Controls Compliant
Incident Management Partially Compliant
Business Continuity Partially Compliant
Change Management Compliant
Access Management Compliant
Subcontractor Management Partially Compliant
Total Findings: 7
Critical Findings: 1
High Findings: 2
Medium Findings: 3
Low Findings: 1
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
PROVIDER ICT RISK MANAGEMENT ASSESSMENT
Meridian maintains a documented ICT risk management framework aligned with ISO
27001:2022 and certified by TÜV Rheinland (certificate valid until September
2026). The framework covers risk identification, assessment, treatment, and
monitoring across all service delivery environments.
Key observations:
— Risk register maintained and reviewed quarterly by Meridian's Risk Committee
— Risk appetite defined and approved by Meridian's Board of Directors
— Three Lines of Defence model implemented
— Annual risk assessment conducted in Q4 2024, covering all customer environments
Finding: No findings. ICT risk management framework is comprehensive and current.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
SECURITY POSTURE REVIEW
Meridian holds the following security certifications:
— ISO 27001:2022 (TÜV Rheinland, valid until September 2026)
— SOC 2 Type II (Deloitte, report dated November 2024)
— C5:2020 (BSI Cloud Computing Compliance Criteria Catalogue)
— PCI-DSS v4.0 Level 1 (for payment-related hosting environments)
Security controls assessed:
— Network segmentation: Customer environments isolated using dedicated VLANs
and firewall rules. Verified during on-site inspection.
— Encryption: AES-256 at rest, TLS 1.3 in transit. Key management via
dedicated HSM (Thales Luna).
— Access management: Privileged access managed via CyberArk PAM with MFA.
Quarterly access reviews conducted.
— Vulnerability management: Weekly automated scanning (Qualys). Critical
patches applied within 72 hours. Verified via patch compliance report.
— Penetration testing: Annual external penetration test (NCC Group, December
2024). No critical findings. Two medium findings remediated.
Finding: No findings. Security posture is strong and well-documented.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
INCIDENT MANAGEMENT CAPABILITIES
Meridian operates a 24/7 Network Operations Centre (NOC) with defined incident
management procedures. Incident classification follows a P1-P4 priority scheme
aligned with the SLA.
Key observations:
— Incident management process documented and aligned with ITIL v4
— 24/7 NOC staffed with minimum 3 engineers per shift
— Incident communication to customers via automated alerting platform
— Post-incident reviews conducted for all P1 and P2 incidents
Findings:
FINDING OCR-F01 (CRITICAL): Incident notification to the Bank for P1 incidents
was delayed beyond the 15-minute SLA target in 2 of 5 P1 incidents in 2024.
Root cause: manual notification process — NOC engineer must manually trigger
customer notification after initial triage. Automated notification not yet
implemented for all incident types.
Recommendation: Implement automated customer notification triggered by P1
incident declaration, with manual override capability. Target: Q2 2025.
FINDING OCR-F02 (HIGH): Post-incident review reports for 3 of 8 P2 incidents
in 2024 were delivered more than 10 business days after incident resolution,
exceeding the 5-business-day target in the SLA.
Recommendation: Implement post-incident review tracking with automated
escalation when delivery deadline approaches. Target: Q1 2025.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
BUSINESS CONTINUITY ARRANGEMENTS
Meridian maintains business continuity and disaster recovery plans for all
customer environments. The Bank's environment is replicated to the Dublin DR
site with a target RPO of 1 hour and RTO of 4 hours.
Key observations:
— BCP documented and reviewed annually (last review: November 2024)
— DR failover tested semi-annually
— Last successful DR test: October 2024 (RTO achieved: 3 hours 22 minutes)
Findings:
FINDING OCR-F03 (HIGH): The DR failover test in October 2024 did not include
the Oracle Database managed service component. Meridian confirmed that database
DR failover has not been tested end-to-end since April 2024, when a test
failure occurred due to replication lag. The replication issue was resolved in
June 2024 but the retest has not been scheduled.
Recommendation: Conduct end-to-end DR failover test including Oracle Database
within 60 days. Establish quarterly DR test schedule for database services.
Target: April 2025.
FINDING OCR-F04 (MEDIUM): BCP does not address the scenario of simultaneous
loss of both Frankfurt and Dublin sites (e.g., coordinated cyber attack or
shared infrastructure failure at Equinix).
Recommendation: Develop third-site recovery strategy or document risk
acceptance for dual-site loss scenario. Target: Q3 2025.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
COMPLIANCE FINDINGS
Finding ID Severity Area Description
─────────────────────────────────────────────────────────────────────────────
OCR-F01 Critical Incident Management P1 notification delays
OCR-F02 High Incident Management Late post-incident reviews
OCR-F03 High Business Continuity Database DR test overdue
OCR-F04 Medium Business Continuity No third-site recovery plan
OCR-F05 Medium Subcontractor Mgmt Equinix SLA not reviewed
since 2023
OCR-F06 Medium Subcontractor Mgmt Cloudflare incident
notification chain not
tested
OCR-F07 Low Documentation Service catalogue not
updated for Kubernetes
services added in Sep 2024
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
RECOMMENDATIONS
# Finding Recommendation Target Owner
─────────────────────────────────────────────────────────────────────────────
1 OCR-F01 Implement automated P1 notification Q2 2025 Meridian NOC
2 OCR-F02 Implement PIR tracking with escalation Q1 2025 Meridian SM
3 OCR-F03 Conduct database DR failover test Apr 2025 Meridian Ops
4 OCR-F04 Develop third-site recovery strategy Q3 2025 Meridian BCP
5 OCR-F05 Review and update Equinix SLA Q1 2025 Meridian VM
6 OCR-F06 Test Cloudflare incident notification Q1 2025 Meridian NOC
7 OCR-F07 Update service catalogue Q1 2025 Meridian SM
Next assessment: February 2026
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Prepared by: Head of Internal Audit — ICT Risk Assurance
Reviewed by: CRO
Date: 10 February 2025
Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).
oversight_compliance_status — fs-oversight-compliance-status
{
"factId": "c8d9e0f1-a2b3-4567-cdef-789012345678",
"evidenceId": "b7c8d9e0-f1a2-3456-7890-123456abcdef",
"evidenceClassId": "oversight-compliance-report",
"factType": "oversight_compliance_status",
"data": {
"provider_id": "PRV-001",
"assessment_date": "2025-02-10",
"overall_compliance_rating": "partially_compliant",
"has_risk_framework": true,
"has_security_controls": true,
"has_incident_management": true,
"has_business_continuity": true,
"findings_count": 7,
"critical_findings": 1
},
"provenance": "deterministic",
"extractorVersion": "dora-test-generator/0.1.0",
"extractedAt": "2025-02-11T15:00:00Z",
"supersededBy": null
}
fs-oversight-compliance-statusDORA-Art33-P1assessment_dateoverall_compliance_rating{
"properties": {
"assessment_date": {
"format": "date",
"type": "string"
},
"critical_findings": {
"minimum": 0,
"type": "integer"
},
"findings_count": {
"minimum": 0,
"type": "integer"
},
"has_business_continuity": {
"type": "boolean"
},
"has_incident_management": {
"type": "boolean"
},
"has_risk_framework": {
"type": "boolean"
},
"has_security_controls": {
"type": "boolean"
},
"overall_compliance_rating": {
"enum": [
"compliant",
"partially_compliant",
"non_compliant"
],
"type": "string"
},
"provider_id": {
"minLength": 1,
"type": "string"
}
},
"required": [
"provider_id",
"assessment_date",
"overall_compliance_rating",
"has_risk_framework",
"has_security_controls"
],
"type": "object"
}