Article contents
.png&w=3840&q=75)
Struggling with TPRM? Our guide covers GDPR, HIPAA, PCI DSS, and more. Learn robust strategies and advanced solutions. Stay compliant and secure.
What this guide covers
Third-party risk management (TPRM) compliance is no longer optional for European organisations. Regulatory frameworks now impose explicit, audit-enforceable obligations on how you select, assess, monitor, and exit third-party vendors. This guide covers the key regulations — including DORA, NIS2, GDPR, ISO 27001, and others — and what each requires from your TPRM programme.
- European obligations first: DORA Article 28, NIS2 Article 21, and GDPR Article 28 are the primary frameworks for regulated entities in the EU and Switzerland.
- Implement audit-ready TPRM: Regulators expect documented evidence of assessments, not just policies.
- Use purpose-built tooling: Spreadsheet-based TPRM fails DORA and NIS2 audits — automated platforms produce the evidence trail regulators require.
- Cross-functional alignment: Legal, compliance, IT, and procurement must all operate from the same vendor register.
- Resilience is measurable: Proactively managing third-party regulatory compliance reduces audit findings and regulatory enforcement risk.
Introduction
In today's global business environment, companies increasingly rely on third parties — cloud providers, SaaS vendors, outsourced services — to deliver critical operations. This reliance creates regulatory exposure that is growing sharper every year. European regulators have moved from guidance to hard obligations: DORA entered into force in January 2025 with binding ICT third-party risk requirements; NIS2 brought supply chain security obligations to 18 critical sectors; and GDPR Article 28 has always required documented data processor management.
For European regulated entities, TPRM compliance is not a best-practice exercise — it is a legal obligation with enforcement teeth. This guide covers the key regulatory frameworks, what they require from your vendor programme, and how advanced TPRM solutions like Supplier Shield help compliance and risk teams meet these obligations systematically.
European regulatory obligations for third-party risk
DORA — Digital Operational Resilience Act (Article 28)
DORA applies to financial entities in the EU — banks, insurers, asset managers, investment firms, payment institutions, and their ICT third-party service providers. Article 28 sets out specific requirements for ICT third-party risk management:
- Mandatory ICT vendor register: Financial entities must maintain a complete register of all ICT third-party service providers, including contractual arrangements, criticality classification, and concentration risk analysis.
- Pre-contract due diligence: Before signing, entities must assess the vendor's security posture, business continuity capabilities, subcontracting chain, and auditability.
- Contractual minimum requirements: DORA Article 30 specifies mandatory contract clauses — including audit rights, incident notification timelines, and exit provisions.
- Ongoing monitoring: Critical ICT providers must be monitored continuously. Performance metrics, incident reports, and audit results must be retained.
- Concentration risk management: Where multiple entities rely on the same third party, firms must assess systemic risk and maintain viable exit strategies.
DORA enforcement began in January 2025. The European Supervisory Authorities (EBA, EIOPA, ESMA) are actively reviewing ICT vendor registers and contractual compliance. Firms that cannot produce audit-ready evidence of their Article 28 programme face supervisory action.
NIS2 — Network and Information Security Directive (Article 21)
NIS2 covers essential and important entities across 18 sectors including energy, transport, healthcare, financial infrastructure, and digital infrastructure. Article 21(2)(d) requires supply chain security as a mandatory risk management measure:
- Vendor security assessment: Entities must assess the security practices of their suppliers and service providers, including software and hardware vendors.
- Supply chain risk policies: Documented policies for assessing and managing supply chain risk are required — not just a list of vendors.
- Incident notification: Where a supplier incident affects your operations, NIS2 imposes 24-hour early warning and 72-hour notification obligations to national authorities.
- Board accountability: NIS2 Article 20 makes management personally liable for non-compliance. Board members can face temporary bans and personal fines.
NIS2 was transposed into national law across EU member states by October 2024. If your organisation operates critical infrastructure or delivers essential services, NIS2 supply chain obligations apply regardless of company size.
GDPR — Article 28 Data Processor Management
GDPR Article 28 imposes obligations on any organisation that engages third-party processors handling EU personal data:
- Written Data Processing Agreements (DPAs): Every processor relationship requires a documented DPA specifying processing scope, data subject rights obligations, security measures, and sub-processor management.
- Due diligence on processors: Controllers must use processors that provide sufficient guarantees — meaning security assessments are legally required, not optional.
- Sub-processor management: Where processors engage sub-processors, controllers retain liability. Written authorisation and flow-down obligations are required.
- Audit rights: DPAs must grant the controller the right to audit or commission audits of the processor's compliance.
nDSG — Swiss Federal Act on Data Protection
Switzerland's revised Data Protection Act (nDSG), in force since September 2023, closely mirrors GDPR requirements for data processor management. Swiss organisations must maintain documented DPAs with all processors, conduct risk assessments for cross-border data transfers, and maintain records of processing activities. For Swiss-based entities, nDSG and GDPR obligations frequently overlap — particularly where processors handle both Swiss and EU personal data.
Global regulatory frameworks relevant to European TPRM
ISO 27001 — Information Security Management
As an international standard for information security management, ISO 27001 provides the most widely recognised framework for assessing third-party security posture. Annex A Control 5.19 ("Information security in supplier relationships") and Control 5.20 ("Addressing information security within supplier agreements") directly address TPRM requirements. Many European organisations require ISO 27001 certification from critical vendors as a baseline due diligence standard.
HIPAA — Healthcare Information
For organisations in healthcare or life sciences with US operations or partnerships, HIPAA requires covered entities and business associates to implement safeguards to secure Protected Health Information (PHI). Business Associate Agreements (BAAs) are required for any third party handling PHI — the functional equivalent of GDPR's DPA requirement.
PCI DSS — Payment Card Industry Data Security Standard
PCI DSS mandates security requirements for organisations handling cardholder data. Third parties involved in payment processing must be assessed against PCI DSS controls, and relevant requirements must be passed down through the supply chain.
SOC 2
SOC 2 assessments evaluate a service organisation's controls for security, availability, processing integrity, confidentiality, and privacy. Reviewing a vendor's SOC 2 Type II report is a common component of TPRM due diligence, particularly for cloud and SaaS providers. Unlike GDPR or DORA, SOC 2 is a voluntary framework — but many regulated entities require it from critical ICT vendors as a proxy for security maturity.
CCPA and US State Privacy Laws
For European organisations with US operations, the California Consumer Privacy Act (CCPA) and its successor CPRA impose data processing obligations similar to GDPR's Article 28. Service provider agreements must include specified contractual terms, and audit rights apply.
Implementing a TPRM programme that satisfies multiple frameworks
1. Build a complete vendor register
Every major regulatory framework — DORA, NIS2, GDPR, ISO 27001 — starts with a complete inventory of your third parties. Your vendor register should capture criticality classification, data processing scope, contractual status, applicable frameworks, and assessment history. Without a maintained register, audit readiness is impossible.
2. Conduct structured due diligence before onboarding
Pre-contract due diligence is an explicit requirement under DORA Article 28 and a legal expectation under GDPR Article 28. Questionnaires should cover: security certifications, data residency and transfer mechanisms, business continuity and disaster recovery, sub-processor and fourth-party relationships, audit rights and cooperation clauses, and incident notification processes.
3. Establish compliant contracts and DPAs
Contracts must contain framework-specific minimum clauses. DORA Article 30 specifies mandatory ICT service provider contract provisions. GDPR Article 28 specifies the minimum DPA content. NIS2 requires security obligations to be reflected in supply chain agreements. Using generic contract templates without these specific clauses creates regulatory exposure.
4. Monitor continuously, not just at onboarding
DORA requires ongoing monitoring of critical ICT providers. NIS2 requires continuous management of supply chain risk. Periodic annual reviews are insufficient — risk profiles change, certifications expire, incidents occur. Automated monitoring tools track certificate expiry, news-based risk signals, and assessment response completion without manual follow-up.
5. Produce audit-ready evidence
Regulators do not accept assurances — they review evidence. Under DORA, supervisors may request the ICT vendor register, contractual documentation, assessment results, and incident logs. Under GDPR, DPA records and due diligence documentation must be available on request. TPRM platforms like Supplier Shield generate exportable audit packages from assessment data automatically.
Enhancing business resilience through regulatory compliance
Protect sensitive data
Ensuring third parties comply with data protection frameworks — GDPR Article 28, nDSG, CCPA — protects your organisation from data breach liability and regulatory enforcement. The average cost of a data breach reached USD 4.88 million in 2024 (IBM Cost of a Data Breach Report). Third-party breaches account for a growing proportion of these incidents.
Avoid regulatory penalties
DORA non-compliance exposes financial entities to supervisory action, public reprimands, and operational restrictions. NIS2 Article 34 allows fines of up to EUR 10 million or 2% of global turnover for essential entities. GDPR enforcement has exceeded EUR 4 billion in total fines since 2018. A documented, auditable TPRM programme is the primary defence.
Maintain operational continuity
Ensuring critical vendors have robust business continuity and exit plans maintains operational continuity during disruptions — a core requirement under DORA's operational resilience framework.
Strengthen board accountability
NIS2 Article 20 places personal liability on management for TPRM programme failures. Documented assessment evidence, board-level reporting, and approved risk tolerance policies protect both the organisation and its directors.
Conclusion
Third-party risk management compliance is no longer a peripheral concern for European regulated entities — it is embedded in primary legislation that carries enforcement consequences. DORA, NIS2, and GDPR have each elevated TPRM from best practice to binding obligation. Organisations that treat vendor risk management as an administrative exercise will face growing audit findings and enforcement risk as regulators intensify scrutiny.
Supplier Shield is purpose-built for European regulated entities — with native support for DORA Article 28, NIS2 supply chain obligations, GDPR Article 28 DPA management, ISO 27001, and 50+ additional frameworks. Assessments, evidence, and audit packages are generated automatically — no spreadsheets, no manual follow-up. Talk to our team about building a programme that satisfies your regulators.
Want this applied to your supplier ecosystem? See the platform in action and map your top vendor risks live in one walkthrough.


