What does the DORA regulation require for an LLM application, and what will an EU bank ask its suppliers?
The DORA regulation applies to EU financial entities and to ICT third-party service providers. Its register of information covers all contracts for ICT services, which it defines broadly; whether an outside LLM service is one is for the bank’s counsel. If it is, the bank must record the arrangement and its contract must carry the regulation’s terms.
David McMillan, Governed AI Deployment. Checked against the sources on .
§01DORA Art. 2
Who it applies to
DORA Art. 2 lists the financial entities it applies to, from credit institutions and investment firms to insurers and crowdfunding service providers, and it lists ICT third-party service providers too. A supplier that is not a financial entity is reached through the contract the bank must sign (DORA Art. 30).
§02DORA Art. 3
Is an LLM service an ICT service?
The definitions decide it. In the regulation’s words:
‘ICT services’ means digital and data services provided through ICT systems to one or more internal or external users on an ongoing basis, including hardware as a service and hardware services which includes the provision of technical support via software or firmware updates by the hardware provider, excluding traditional analogue telephone services;
‘ICT third-party service provider’ means an undertaking providing ICT services;
DORA Art. 3
Whether a given LLM service meets that definition is for the bank’s counsel to decide.
§03DORA Art. 28
The register of information
In the regulation’s words:
As part of their ICT risk management framework, financial entities shall maintain and update at entity level, and at sub-consolidated and consolidated levels, a register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers.
DORA Art. 28
The bank documents each arrangement, marks whether it supports a critical or important function, reports on its new arrangements at least yearly, and shows the register to its regulator on request.
§04DORA Art. 30
What the contract must say
Every contract must state the regions or countries where the service runs and data is processed, and oblige the supplier to give notice before changing them. For a critical or important function it must also cover service levels, notice and reporting, tested contingency plans and security measures, taking part in threat-led penetration testing, rights of access, inspection and audit, and an exit strategy. The controls matrix lists the records a supplier can produce for each.
§05
Sources
- Regulation (EU) 2022/2554, the DORA regulation, on EUR-Lex
https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng
§06
Book a scoping call
Thirty minutes on one system: what it does, who is asking about it, and which engagement fits. Nothing to prepare. For firms in the UK and Europe.