IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

With the Indicium report, you screen ICT service providers and key personnel using the same methodology — documented, with dated sources and final human review.

DORA Requirements for Personnel and ICT Service Providers

What Regulation (EU) 2022/2554 requires for training, due diligence and contracts with third-party ICT providers — an overview.

DORA — Regulation (EU) 2022/2554, applicable since 17 January 2025 — addresses not only systems but explicitly people and service providers as well: financial entities must train their staff and management body in digital resilience (Art. 13(6)) and subject third-party ICT service providers to due diligence before contract signature (Art. 28). Responsibility for outsourced ICT services always remains with the financial entity — it cannot be contracted away.

The Human Factor: Training Obligations Under Art. 13(6)

DORA does not treat digital operational resilience as a purely IT matter. Under Art. 13(6) of the Regulation, financial entities must include ICT security awareness programmes and digital operational resilience training in their staff training schemes — mandatory for all employees and for members of the management body. That is remarkable: the leadership level is not merely a recipient of reports but a training participant itself. The scope and depth of training may be calibrated to the role — anyone responsible for ICT risk or working with critical systems needs more than an annual compliance briefing. Taking resilience seriously therefore means starting with personnel, not just technology — an idea that mirrors the personnel-related safeguards of supervisory law, such as the reliability check under § 6 GwG (the German Anti-Money Laundering Act).

Third-Party Risk: Due Diligence and Register Under Art. 28

The centrepiece of the third-party chapter is Art. 28. Among other things, it requires financial entities to:

  • manage ICT third-party risk as an integral part of ICT risk management — under their own responsibility, even where services are fully outsourced,
  • maintain and keep up to date a register of information on all contractual arrangements with third-party ICT service providers,
  • assess the provider before contract signature: suitability, risks, concentration risks and potential conflicts of interest,
  • contract only with providers that comply with appropriate information security standards.

Pre-contractual due diligence is therefore not a recommendation but an obligation. Anyone conducting it seriously needs the same structured review process as for individuals: registry data, ultimate beneficial owners (UBO), sanctions lists, adverse media — documented and traceable rather than researched informally. Because in an audit or incident, the supervisor will not ask whether the provider seemed reputable, but which facts the financial entity gathered, assessed and documented before contract signature.

Contract Content: What Art. 30 Prescribes

Art. 30 of the Regulation defines minimum content for contracts with third-party ICT service providers — including clear service descriptions, rules on subcontractors, access, inspection and audit rights, and termination rights. In practice, this means the review of a provider does not end with selection but continues through contract drafting and ongoing monitoring. A provider that shows gaps during due diligence is unlikely to fulfil contractual cooperation duties reliably either.

Individuals and Companies: One Review Process, Two Objects

In implementation, it becomes clear that DORA due diligence and personnel screening are methodologically the same task: a risk-based, documented integrity review — applied once to a company, once to a person. Financial entities that already run structured employee screening can extend the same process to service providers and their key personnel; anyone deploying external staff with far-reaching access should also read screening external and interim managers. Indicium covers both review objects in an audit-proof report with dated sources and final human review (Art. 22 GDPR) — from €79 per report, details under pricing.

First gain clarity on your current position: is the register of information under Art. 28 complete and up to date? Does a documented pre-contractual assessment exist for every material ICT service provider — or only a contract folder? Then define a repeatable due diligence standard (review categories, depth, frequency) and apply it to new contracts and existing providers alike. In parallel, reconcile your existing contracts against the minimum content of Art. 30 — in particular audit and termination rights, without which review findings cannot be enforced later. This turns an abstract regulatory obligation into a lived process that withstands supervisory scrutiny. For a starting point on practical implementation, feel free to book a demo.

This article provides general information and does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built — from name to verdict in minutes, not weeks.

Book a demo See a sample report