Harmonised Risk Analysis

Harmonised Risk Analyses

Risk analysis pursuant to DORA, MaRisk, MaGo and the EBA Guidelines on Outsourcing in a single process, implemented as a stringent workflow, enabling efficient monitoring of all third parties.

Risk analysis is an instrument for initial, event-driven, and regular governance of externally sourced services. The obligation to conduct risk analysis for outsourcing arrangements arises from MaRisk, MaGo and the EBA Guidelines on Outsourcing. For ICT services, the obligation originates from the Digital Operational Resilience Act (DORA). Many ICT services under DORA are also subject to the requirements applicable to outsourcing arrangements. The requirements overlap significantly in many areas, but differ in some aspects. Integrating all requirements into a single process significantly increases the effectiveness of risk analysis and greatly reduces the effort required for its execution.

Risk Analyses with IQRisk – Key Benefits

Orange Schutzschild-Symbol, das Sicherheit und Schutz darstellt.
Rotes Schild-Icon mit schwarzem Kreuz, symbolisiert Schutz und Sicherheit.

100% Compliance

Fulfilment of all requirements of DORA, MaRisk (especially AT 9), MaGo (especially Chapter 13) and the EBA Guidelines on Outsourcing.

Symbol für Datenanalyse auf einem orangefarbenen Dokument mit einem Diagramm
Orange Symbol mit Dokument und Aufwärtstrend-Linie.

Stringent Workflow/Intuitive Cockpit

Each risk analysis is executed via a stringent process that is always maintained in a consistent state. An intuitive management cockpit provides full transparency on the status of all risk analyses.

Top-Management Beratung Icon
Top-Management Beratung Icon BG

Automated Reporting to Authority

If an initial outsourcing is intended, there is an obligation to notify the authority. The same applies to changes, such as classifying a function as important or critical.The required notifications are automatically generated upon authorisation and transmitted to the competent authority.

Orange Klemmbrett mit Stift-Symbol auf transparentem Hintergrund.
Orange Klemmbrett-Icon mit Linien und Stift, minimalistisch.

Consistent Documentation

Newly analysed outsourcing arrangements or ICT services are automatically stored in the integrated register of information and outsourcing arrangements. Only information not yet digitised must be recorded manually.

Orange Info-Icon mit Ausrufezeichen in Klammern, auf weißem Hintergrund.
Orange Info-Symbol mit kleinem 'i' auf weißem Hintergrund.

Consideration of Concentration Risks

Existing concentration risks are automatically fed into the risk analysis decision process. The concentration risks existing at the time of each risk analysis are automatically documented.

Audit Icon
Computerbildschirm mit Dokument und Häkchen-Symbol, orangefarbenes Icon.

Transfer to Operational Risk Management

Specific risks can be automatically transferred to operational risk management, including their respective probabilities of occurrence and potential loss severities.

Contact us now

Benefit from harmonised risk analysis. Meet the requirements of DORA and other relevant (national) regulations through a consistent risk management process.

DORA Risikoanalyse [New] – EN
Screen displaying information about Zoom Communications and a chart within a software interface.

Risk Analysis and Process Automation

Regularly conducted risk analyses are automatically performed at the scheduled intervals. The involved parties receive a digital reminder beforehand. If actions are not completed or delayed, a specially configured escalation workflow is triggered.

For stringent third-party governance, complementary actions are necessary. Examples include typically monthly provider meetings or quarterly performance quality assessments. These complementary processes can be instantiated and executed at any time via IQThirdParty’s process engine.

Contact us now

Would you like to learn more about our SaaS solution IQThirdParty or schedule a demo appointment? 

    Contact






    Thank you!

    We have received your request and will get back to you shortly with all the information