01
The challenge
When completing the Digital Operational Resilience Act (DORA) information register, you must specify the type of each contractual arrangement: standalone, overarching, or subsequent/associated. This classification must be recorded in template RT.02.01, column RT.02.01.0020 'Type of contractual arrangement'.
But how should you handle this for a typical ICT service where agreements are spread across multiple documents like terms & conditions (T&Cs), terms of service (ToS), and a data processing agreement (DPA)?
02
What is a contractual arrangement according to DORA?
The DORA regulation and Implementing Technical Standards (ITS) don’t provide a strict definition of a contractual arrangement. However, Article 28(3) makes it clear that it refers to “contractual arrangements on the use of ICT services provided by ICT third-party service providers.” In other words, it includes any agreements governing your use of ICT services.
03
Three types of contractual arrangements under DORA
For column RT.02.01.0020, the ITS specifies the following options:
- Standalone arrangement – A self-contained agreement.
- Overarching arrangement – A master or framework agreement.
- Subsequent/associated arrangement – Linked agreements like implementation contracts, subservice agreements, amendments, or order forms.
04
Classification of contractual arrangements in practice
In many cases, ICT service agreements are documented in several files such as T&Cs, ToS, and a DPA. So how should these be classified?
These documents usually:
- Relate to the same ICT service
- Together define the conditions for using that service
- Must be read together as a complete package
In practice, this means they can be viewed as one contractual arrangement. Alternatively, you could treat them as multiple arrangements (e.g., T&Cs as overarching, ToS and DPA as associated), but this adds unnecessary complexity.
05
Best practice: classify as a standalone arrangement
For RT.02.01.0020, choosing "1. Standalone arrangement" is the most logical option in most cases. Here’s why:
- The documents form a single package for the same service.
- It avoids duplicating entries and reduces clutter in your register.
- It aligns with the register’s goal: understanding risk at the service level, not the individual document level.
06
Conclusion and practical tip
Whenever possible, classify a service and its related documents (T&Cs, ToS, DPA) as one standalone arrangement in RT.02.01, column RT.02.01.0020. This simplifies register maintenance and supports a clearer understanding of ICT risks.
The prebuilt DORA register from DORA-Solutions allows you to store all documents under one ICT service and classify them easily as a single arrangement.
Reach out for a demo of our prebuilt DORA register
Originally published on DORA Solutions Insights.