ILP Abogados
Madrid · Internacional

DORA: key contractual clauses for access, inspection and audit of ICT providers

Last updated: 5 August 2026.

Quick answer. Under the Digital Operational Resilience Act (DORA), contracts for ICT services supporting essential or important functions must include specific provisions guaranteeing the financial entity’s rights of access, inspection and audit over the provider. These rights matter for four reasons: they enable continuous monitoring of the provider’s performance against agreed service levels and security measures, allow early identification of vulnerabilities or contractual breaches, let entities demonstrate compliance with DORA to the competent authorities, and strengthen the contractual relationship by fostering transparency and trust. In scope, they cover access to the provider’s information and systems relevant to the contracted services and the inspection of its facilities, whether carried out by the financial entity or by a third party designated by it.

The Digital Operational Resilience Act (DORA) Regulation establishes a robust regulatory framework to ensure the digital operational resilience of the financial sector. Within this framework, contracts for the provision of ICT services that support essential or important functions become crucially relevant. Beyond the already mentioned contractual clauses, it is essential that these contracts include specific provisions guaranteeing the rights of access, inspection, and audit by the financial entity.

Below we present the collaboration in video format, in case it is of interest to you:

DORA: key contractual clauses for access, inspection and audit of ICT providers?

Why Are These Rights Important?

These rights are important for the following reasons:

1) Monitoring Provider Performance:

The rights of access, inspection, and audit enable financial entities to continuously monitor the performance of third-party ICT service providers, verifying compliance with agreed service levels and the adoption of necessary security measures.

2) Early Risk Identification:

Through inspections and audits, financial entities can promptly identify potential vulnerabilities or contractual breaches that may jeopardize their operations.

3) Regulatory Compliance:

These rights allow financial entities to demonstrate to competent authorities that they are complying with the requirements set forth in the DORA Regulation and other applicable regulations.

4) Strengthening Contractual Relationships:

By clearly establishing the rights of access and audit, the contractual relationship between the financial entity and the third-party ICT service provider is strengthened, fostering transparency and trust.

Scope of Access, Inspection, and Audit Rights

Access, inspection, and audit rights allow:

  1. Access to Information and Systems: Financial entities must have the right to access information and systems of the provider that are relevant to the provision of the contracted services.
  2. Inspection of Facilities: Financial entities or a third party designated by them must have the right to inspect the provider’s facilities where the services are delivered.
  3. Audits: Financial entities must be able to conduct periodic audits of the provider’s systems and processes, including the review of documentation and the performance of tests.
  4. Copy of Information: Financial entities must have the right to make copies of relevant information for the provision of services as part of monitoring and control activities.
  5. Provider Cooperation: The third-party ICT service provider must fully cooperate with the financial entity during inspections and audits, providing all necessary information and access.

Intervention by the Competent Authority:

In addition to the rights of financial entities, the DORA Regulation also provides for the possibility that the competent authority of the financial entity may conduct inspections and audits of the third-party ICT service provider, upon notification. This mechanism allows authorities to oversee compliance with regulations and ensure the protection of consumer interests.

In Conclusion:

The rights of access, inspection, and audit are fundamental tools for financial entities to ensure the digital operational resilience of their services. By including these provisions in contracts with third-party ICT service providers, financial entities can exercise greater control over technology-related risks and comply with the requirements established in the DORA Regulation.

If you enjoyed this article, you might also find the following interesting:

DORA and ICT Incident Notification: A Digital Big Brother for Banking?

Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.

Frequently asked questions

Why does DORA require access, inspection and audit clauses in ICT contracts?

For four reasons: they enable financial entities to continuously monitor the performance of third-party ICT providers, verifying compliance with agreed service levels and security measures; they allow early identification of vulnerabilities or contractual breaches; they help demonstrate regulatory compliance to competent authorities; and they strengthen the contractual relationship by fostering transparency and trust.

Which contracts are affected by these DORA requirements?

Contracts for the provision of ICT services that support essential or important functions of the financial entity. Within the DORA framework, these contracts become crucially relevant and must include, beyond other contractual clauses, specific provisions guaranteeing the rights of access, inspection and audit.

What do the access rights cover under DORA?

Financial entities must have the right to access the information and systems of the ICT provider that are relevant to the provision of the contracted services, so that they can verify performance and security throughout the life of the contract.

Who may inspect the facilities of an ICT provider?

The financial entity itself or a third party designated by it must have the right to inspect the provider’s facilities, as part of the inspection and audit rights that the contract must guarantee.

How do these rights help with regulatory compliance?

Through inspections and audits, financial entities can demonstrate to the competent authorities that they are complying with the requirements set forth in the DORA Regulation and other applicable rules, while also identifying early any risk that may jeopardize their operations.



Contact
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.

Related tool, free to use: the financial regulation tools.

GUÍA GRATUITA

Regulación Financiera España 2026

DORA + MiCA + MiFID II + EMIR en un solo documento

Descargar gratis →

Videos relacionados

Cargando videos…

Discover more from ILP Abogados

Subscribe now to keep reading and get access to the full archive.

Continue reading