Back to Publications
Regulatory Brief · DORA

DORA Chapter V vs OCC Heightened Standards: transatlantic third-party convergence

24 May 2026By NexCyber Editorial DORA

In the complex landscape of financial regulation, global banks face the challenge of aligning compliance efforts across multiple jurisdictions. For those operating under both the EU's Digital Operational Resilience Act (DORA) and the US Office of the Comptroller of the Currency (OCC) Heightened Standards, there is potential to consolidate up to 70% of compliance evidence. This convergence is particularly evident in third-party risk management, where both regulatory frameworks share foundational

In the complex landscape of financial regulation, global banks face the challenge of aligning compliance efforts across multiple jurisdictions. For those operating under both the EU's Digital Operational Resilience Act (DORA) and the US Office of the Comptroller of the Currency (OCC) Heightened Standards, there is potential to consolidate up to 70% of compliance evidence. This convergence is particularly evident in third-party risk management, where both regulatory frameworks share foundational principles but diverge in specific requirements and thresholds.

DORA Chapter V: Registers, Contracts, and Sub-Outsourcing

DORA Chapter V, encompassing Articles 28 to 44, is a cornerstone for managing third-party risk in the EU financial sector. It mandates comprehensive governance over ICT third-party service providers, focusing on several key areas:

Registers

Under DORA, financial entities must maintain a detailed register of all ICT third-party service providers. This register is not merely a list but a structured repository that captures the nature of services, risk assessments, and any incidents or disruptions experienced. The aim is to ensure transparency and facilitate oversight by both the entity and regulatory authorities.

Contracts

DORA emphasizes the importance of robust contractual arrangements with third-party providers. These contracts must include specific clauses on data security, audit rights, and termination conditions. The regulation requires that contracts are not only legally sound but also operationally effective, ensuring that the financial entity retains control over its operational resilience.

Sub-Outsourcing

A critical aspect of DORA's third-party management is the scrutiny of sub-outsourcing arrangements. Financial entities must ensure that their primary contractors impose equivalent standards on any sub-contractors. This chain of accountability is designed to prevent dilution of risk controls and ensure that operational resilience is maintained throughout the supply chain.

OCC Heightened Standards: Third-Party Risk Principles

The OCC's Heightened Standards, applicable to large banks in the United States, provide a framework for managing third-party risks with a focus on governance and risk management practices. These standards are designed to enhance the safety and soundness of financial institutions by ensuring robust oversight of third-party relationships.

Governance and Risk Management

At the heart of the OCC's approach is the requirement for strong governance structures that integrate third-party risk management into the overall risk management framework of the bank. This includes board-level oversight and the establishment of clear accountability for managing third-party risks.

Due Diligence and Monitoring

The OCC mandates comprehensive due diligence processes before entering into third-party relationships. This involves assessing the provider's financial condition, operational capabilities, and compliance with applicable laws and regulations. Continuous monitoring of third-party performance and risk exposure is also required to ensure ongoing compliance and risk mitigation.

Risk Assessment and Mitigation

Banks must conduct thorough risk assessments of their third-party relationships, identifying potential risks and implementing appropriate mitigation strategies. This includes evaluating the impact of third-party failures on the bank's operations and financial condition, and ensuring that contingency plans are in place.

Mapping Table: Overlaps and Divergences

To effectively manage compliance across both DORA and OCC frameworks, global banks need to understand where these regulations overlap and where they diverge. Here are five key dimensions to consider:

  1. 1Register Format - Overlap: Both DORA and OCC require detailed registers of third-party relationships. - Divergence: DORA specifies a more structured format, while OCC allows for flexibility in documentation.
  1. 1Audit Rights - Overlap: Both frameworks emphasize the need for audit rights in contracts. - Divergence: DORA mandates specific contractual clauses, whereas OCC focuses on the outcome of audit processes.
  1. 1Concentration Risk - Overlap: Both recognize the importance of managing concentration risk. - Divergence: DORA sets more explicit thresholds for concentration risk, while OCC provides broader guidance.
  1. 1Sub-Outsourcing - Overlap: Both require oversight of sub-outsourcing arrangements. - Divergence: DORA imposes stricter controls on sub-outsourcing, requiring equivalent standards across the supply chain.
  1. 1Incident Reporting - Overlap: Both require reporting of significant incidents involving third parties. - Divergence: DORA has more prescriptive timelines and reporting formats compared to the OCC's more principle-based approach.

Next Step with NexCyber

For global banks navigating the complexities of DORA and OCC compliance, leveraging technology can streamline the process. NexCyber offers a DORA register template generator, designed to help financial institutions efficiently manage and document their third-party relationships in line with regulatory requirements. Visit [NexCyber's platform](https://www.nexcyber.eu/assess?utm_source=editorial&utm_campaign=dora-chapter-v-vs-occ-heightened-standards) to explore how our tools can support your compliance journey.