VVendorDORA

Answer library · sample

Eight DORA answers, written the way a bank expects to read them

These are model answers from the VendorDORA library: the question as it arrives, the answer you send, and the evidence that closes it. Square brackets are the fields you fill once and reuse with every customer.

✓ 8 of 120 answers shown✓ Mapped to Art. 28-30 + RTS✓ No legal advice, just the work
01Register of information

What the bank asks

List the services you provide to us, the contractual entity, the delivery model and the functions supported.

Model answer

VendorDORA provides [PRODUCT] to [ENTITY] under contract [REF], delivered as a single-tenant SaaS from [REGION]. The service supports the [FUNCTION] function. The contracting entity is [LEGAL ENTITY], and no other group entity consumes the service. The corresponding row in your register of information should reference our VAT ID [VAT], our LEI if applicable, and the start date [DATE].

Evidence to attach

  • Signed contract cover page showing both legal entities
  • One-page service description with delivery model and region

Why this version works

Banks fail this field most often because the legal entity that signs is not the entity that operates the service. Naming both up front removes the follow-up question.

02Subcontractors (Art. 28(6))

What the bank asks

Do you use subcontractors for the delivery of this service? List them, the function they perform and their location.

Model answer

Yes. We use [N] subcontractors for this service: [PROVIDER A] for hosting in [REGION], [PROVIDER B] for transactional email, and [PROVIDER C] for monitoring. None of them is used for the storage of customer production data. Our full list, with location and the function performed, is in the table attached. We notify you of any addition or replacement of a subcontractor before it goes live, and our agreements impose the same operational-resilience obligations on them.

Evidence to attach

  • Subcontractor table: name, function, region, tier (critical / non-critical)
  • Clause extract showing the flow-down obligation in our supplier agreements

Why this version works

The answer is only credible if the list is a table with locations and a criticality flag, not a paragraph.

03Access control

What the bank asks

Describe how access to production systems and customer data is granted, reviewed and revoked.

Model answer

Production access is granted through [SSO PROVIDER] with mandatory hardware-key or app-based MFA, using just-in-time elevation: engineers have no standing production access and request a time-boxed role, approved by a second person. Every session is logged and recorded. Access review runs quarterly, and revocation is automatic on offboarding: the identity provider is the source of truth, so a departed employee loses every grant the same day.

Evidence to attach

  • Screenshot of the access-review record for the current quarter
  • Offboarding runbook showing the automatic revocation path

Why this version works

Reviewers look for two words: just-in-time and automatic. Standing admin access is the finding that most often blocks a supplier.

04Incident reporting (Art. 17-19)

What the bank asks

What is your incident notification process and how fast will we hear from you?

Model answer

We classify an event against the RTS criteria (number of affected entities, criticality of the function, duration, data involved) within one hour of detection. A major incident is reported to your contact by phone and email within 4 hours of confirmation, with a written update every 2 hours and a preliminary report within 24 hours. We also support your own reporting obligation by providing the facts your regulator needs: root cause, affected services, remediation status.

Evidence to attach

  • Incident notification template with the fields a bank needs
  • Contact matrix with escalation hours and out-of-hours path

Why this version works

Every bank has its own deadline. Stating a shorter one than they require, and a written cadence, is what turns this from a risk into a strength.

05Business continuity & testing

What the bank asks

What are your recovery objectives and when did you last test them?

Model answer

Our recovery time objective for the core service is [RTO] and our recovery point objective is [RPO], backed by continuous replication across availability zones and point-in-time backups retained [N] days. We ran a full failover test on [DATE], restoring the service in a secondary region in [ACTUAL TIME]; the report and the two follow-up actions are attached. Backup restoration is verified monthly, not only on paper.

Evidence to attach

  • Failover test report with the measured recovery time
  • Latest backup restore verification log

Why this version works

A tested number beats a designed number. Banks routinely reject RPO/RTO claims with no date attached.

06Exit strategy (Art. 28(13))

What the bank asks

If we terminate, how do we get our data out and how long does the transition take?

Model answer

Your data is exportable at any time through the product's export API and a full structured dump (schema plus data) in [FORMAT]. Termination assistance covers [N] days of continued access at the contracted rate, after which data is deleted within [N] days and a deletion certificate is issued. A documented exit runbook exists for this service and was exercised on [DATE].

Evidence to attach

  • Exit runbook section covering export, transition and deletion
  • Sample deletion certificate

Why this version works

This is the section most small vendors leave empty. A written exit path is also the fastest way to unblock procurement.

07Data location & access

What the bank asks

Where is our data stored and processed, and who can access it?

Model answer

Customer data is stored at rest in [REGION] and never replicated outside it. Processing happens in [REGION]; support staff with data access are limited to [N] people, all contracted in [COUNTRIES], and all access is logged. No data is used for model training, product analytics or any purpose outside service delivery.

Evidence to attach

  • Hosting region configuration extract
  • Support-access policy listing the roles allowed to read customer data

Why this version works

The answer needs to cover storage, processing and human access separately. Saying only 'EU region' invites three follow-up questions.

08Audit rights

What the bank asks

Do you accept our right to audit, and how do you handle audit requests in practice?

Model answer

We accept your right to audit and to have audits performed on your behalf, at your cost, with 30 days' notice and no more than once a year unless an incident occurred. In practice we satisfy most requests with a shared assurance pack: current penetration-test summary, ISO/SOC-style control matrix, subprocessor list and this answer library. Where a control cannot be shared, we offer a working session instead of a site visit.

Evidence to attach

  • Audit clause extract from your standard terms
  • Assurance pack index showing what is available on request

Why this version works

You want to keep the contractual right broad and the operational answer narrow: a packaged evidence set is cheaper for both sides than an on-site visit.

The full library

Get the remaining answers before anyone else

The toolkit carries the full library, the register template and the evidence checklist. Founding members lock the price below and get a setup call to adapt the answers to their stack.

No spam. One launch email, plus early-bird pricing. Unsubscribe anytime.