DORA-Art34-P1

Article
34 (1)
Pillar
Third-Party ICT Risk Management
Regulation Ref
Regulation (EU) 2022/2554, Article 34(1)
Last Reviewed
2026-01-15

The Lead Overseer shall, on the basis of the assessment referred to in Article 33, adopt a clear, detailed and reasoned individual oversight plan describing the annual oversight objectives and the main oversight actions planned for each critical ICT third-party service provider.

Evidence Profiles

Critical Provider Oversight Compliance Report RARE

Report documenting the oversight assessment of critical ICT third-party service providers, including their ICT risk management arrangements, security posture, and compliance with oversight requirements as required by DORA Articles 33-44.

Formats
PDF
Evidence Class
oversight-compliance-report
Availability
RARE
Update Frequency
annual
Typical Author
Lead Overseer / Internal Audit
Approval Chain
Head of Internal Audit → CRO

Content Sections

Expected Fields

Common Quality Issues

View Example

Generated example artifact using the default institution profile (COMMON availability, synthetic data only).

PLAIN_TEXT — Inline Preview
CRITICAL PROVIDER OVERSIGHT COMPLIANCE REPORT
Nordvik Bank AG — Assessment of Meridian Cloud Services GmbH
Report Reference: OCR-2025-PRV001
Assessment Date: 10 February 2025
Prepared by: Internal Audit — ICT Risk Assurance Team
Report Status: Final
Classification: Confidential

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

EXECUTIVE SUMMARY

This report presents the findings of Nordvik Bank AG's annual oversight assessment
of Meridian Cloud Services GmbH ("Meridian"), a critical ICT third-party service
provider designated under the Bank's DORA Article 31 criticality framework.
Meridian provides core banking infrastructure hosting services supporting the
Bank's Temenos T24 core banking system, Oracle Database environments, and
associated compute, storage, and network services.

The assessment was conducted in accordance with DORA Articles 33-44 and the Bank's
Third-Party ICT Risk Management Policy (POL-TPR-2025-001). The assessment
methodology included: (a) review of Meridian's ICT risk management documentation;
(b) analysis of Meridian's security certifications and independent audit reports;
(c) on-site inspection of the Frankfurt data centre; and (d) interviews with
Meridian's CISO, Head of Operations, and Service Delivery Manager.

Overall Compliance Rating: PARTIALLY COMPLIANT

  Assessment Area                    Rating
  ─────────────────────────────────────────────────────────────────────────────
  ICT Risk Management Framework      Compliant
  Security Controls                  Compliant
  Incident Management                Partially Compliant
  Business Continuity                Partially Compliant
  Change Management                  Compliant
  Access Management                  Compliant
  Subcontractor Management           Partially Compliant

Total Findings: 7
Critical Findings: 1
High Findings: 2
Medium Findings: 3
Low Findings: 1

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

PROVIDER ICT RISK MANAGEMENT ASSESSMENT

Meridian maintains a documented ICT risk management framework aligned with ISO
27001:2022 and certified by TÜV Rheinland (certificate valid until September
2026). The framework covers risk identification, assessment, treatment, and
monitoring across all service delivery environments.

Key observations:
  — Risk register maintained and reviewed quarterly by Meridian's Risk Committee
  — Risk appetite defined and approved by Meridian's Board of Directors
  — Three Lines of Defence model implemented
  — Annual risk assessment conducted in Q4 2024, covering all customer environments

Finding: No findings. ICT risk management framework is comprehensive and current.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

SECURITY POSTURE REVIEW

Meridian holds the following security certifications:
  — ISO 27001:2022 (TÜV Rheinland, valid until September 2026)
  — SOC 2 Type II (Deloitte, report dated November 2024)
  — C5:2020 (BSI Cloud Computing Compliance Criteria Catalogue)
  — PCI-DSS v4.0 Level 1 (for payment-related hosting environments)

Security controls assessed:
  — Network segmentation: Customer environments isolated using dedicated VLANs
    and firewall rules. Verified during on-site inspection.
  — Encryption: AES-256 at rest, TLS 1.3 in transit. Key management via
    dedicated HSM (Thales Luna).
  — Access management: Privileged access managed via CyberArk PAM with MFA.
    Quarterly access reviews conducted.
  — Vulnerability management: Weekly automated scanning (Qualys). Critical
    patches applied within 72 hours. Verified via patch compliance report.
  — Penetration testing: Annual external penetration test (NCC Group, December
    2024). No critical findings. Two medium findings remediated.

Finding: No findings. Security posture is strong and well-documented.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

INCIDENT MANAGEMENT CAPABILITIES

Meridian operates a 24/7 Network Operations Centre (NOC) with defined incident
management procedures. Incident classification follows a P1-P4 priority scheme
aligned with the SLA.

Key observations:
  — Incident management process documented and aligned with ITIL v4
  — 24/7 NOC staffed with minimum 3 engineers per shift
  — Incident communication to customers via automated alerting platform
  — Post-incident reviews conducted for all P1 and P2 incidents

Findings:

  FINDING OCR-F01 (CRITICAL): Incident notification to the Bank for P1 incidents
  was delayed beyond the 15-minute SLA target in 2 of 5 P1 incidents in 2024.
  Root cause: manual notification process — NOC engineer must manually trigger
  customer notification after initial triage. Automated notification not yet
  implemented for all incident types.

  Recommendation: Implement automated customer notification triggered by P1
  incident declaration, with manual override capability. Target: Q2 2025.

  FINDING OCR-F02 (HIGH): Post-incident review reports for 3 of 8 P2 incidents
  in 2024 were delivered more than 10 business days after incident resolution,
  exceeding the 5-business-day target in the SLA.

  Recommendation: Implement post-incident review tracking with automated
  escalation when delivery deadline approaches. Target: Q1 2025.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

BUSINESS CONTINUITY ARRANGEMENTS

Meridian maintains business continuity and disaster recovery plans for all
customer environments. The Bank's environment is replicated to the Dublin DR
site with a target RPO of 1 hour and RTO of 4 hours.

Key observations:
  — BCP documented and reviewed annually (last review: November 2024)
  — DR failover tested semi-annually
  — Last successful DR test: October 2024 (RTO achieved: 3 hours 22 minutes)

Findings:

  FINDING OCR-F03 (HIGH): The DR failover test in October 2024 did not include
  the Oracle Database managed service component. Meridian confirmed that database
  DR failover has not been tested end-to-end since April 2024, when a test
  failure occurred due to replication lag. The replication issue was resolved in
  June 2024 but the retest has not been scheduled.

  Recommendation: Conduct end-to-end DR failover test including Oracle Database
  within 60 days. Establish quarterly DR test schedule for database services.
  Target: April 2025.

  FINDING OCR-F04 (MEDIUM): BCP does not address the scenario of simultaneous
  loss of both Frankfurt and Dublin sites (e.g., coordinated cyber attack or
  shared infrastructure failure at Equinix).

  Recommendation: Develop third-site recovery strategy or document risk
  acceptance for dual-site loss scenario. Target: Q3 2025.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

COMPLIANCE FINDINGS

  Finding ID   Severity   Area                    Description
  ─────────────────────────────────────────────────────────────────────────────
  OCR-F01      Critical   Incident Management     P1 notification delays
  OCR-F02      High       Incident Management     Late post-incident reviews
  OCR-F03      High       Business Continuity     Database DR test overdue
  OCR-F04      Medium     Business Continuity     No third-site recovery plan
  OCR-F05      Medium     Subcontractor Mgmt      Equinix SLA not reviewed
                                                   since 2023
  OCR-F06      Medium     Subcontractor Mgmt      Cloudflare incident
                                                   notification chain not
                                                   tested
  OCR-F07      Low        Documentation           Service catalogue not
                                                   updated for Kubernetes
                                                   services added in Sep 2024

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

RECOMMENDATIONS

  #   Finding    Recommendation                              Target    Owner
  ─────────────────────────────────────────────────────────────────────────────
  1   OCR-F01    Implement automated P1 notification         Q2 2025   Meridian NOC
  2   OCR-F02    Implement PIR tracking with escalation      Q1 2025   Meridian SM
  3   OCR-F03    Conduct database DR failover test           Apr 2025  Meridian Ops
  4   OCR-F04    Develop third-site recovery strategy        Q3 2025   Meridian BCP
  5   OCR-F05    Review and update Equinix SLA               Q1 2025   Meridian VM
  6   OCR-F06    Test Cloudflare incident notification       Q1 2025   Meridian NOC
  7   OCR-F07    Update service catalogue                    Q1 2025   Meridian SM

Next assessment: February 2026

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

Prepared by: Head of Internal Audit — ICT Risk Assurance
Reviewed by: CRO
Date: 10 February 2025

Expected Structured Facts

Example structured facts that Detrixa would extract from this evidence (synthetic data, deterministic seed).

oversight_compliance_status — fs-oversight-compliance-status
{
  "factId": "c8d9e0f1-a2b3-4567-cdef-789012345678",
  "evidenceId": "b7c8d9e0-f1a2-3456-7890-123456abcdef",
  "evidenceClassId": "oversight-compliance-report",
  "factType": "oversight_compliance_status",
  "data": {
    "provider_id": "PRV-001",
    "assessment_date": "2025-02-10",
    "overall_compliance_rating": "partially_compliant",
    "has_risk_framework": true,
    "has_security_controls": true,
    "has_incident_management": true,
    "has_business_continuity": true,
    "findings_count": 7,
    "critical_findings": 1
  },
  "provenance": "deterministic",
  "extractorVersion": "dora-test-generator/0.1.0",
  "extractedAt": "2025-02-11T15:00:00Z",
  "supersededBy": null
}

Fact Schemas

oversight_compliance_status

Schema ID
fs-oversight-compliance-status
Control
DORA-Art33-P1

Valid Ranges

assessment_date
within last 12 months
overall_compliance_rating
compliant for continued service provision

Related Schemas

JSON Schema

{
  "properties": {
    "assessment_date": {
      "format": "date",
      "type": "string"
    },
    "critical_findings": {
      "minimum": 0,
      "type": "integer"
    },
    "findings_count": {
      "minimum": 0,
      "type": "integer"
    },
    "has_business_continuity": {
      "type": "boolean"
    },
    "has_incident_management": {
      "type": "boolean"
    },
    "has_risk_framework": {
      "type": "boolean"
    },
    "has_security_controls": {
      "type": "boolean"
    },
    "overall_compliance_rating": {
      "enum": [
        "compliant",
        "partially_compliant",
        "non_compliant"
      ],
      "type": "string"
    },
    "provider_id": {
      "minLength": 1,
      "type": "string"
    }
  },
  "required": [
    "provider_id",
    "assessment_date",
    "overall_compliance_rating",
    "has_risk_framework",
    "has_security_controls"
  ],
  "type": "object"
}