Ariadnah
Platform
DORA Understand the responsibilities, common operating gaps, and the path from shared knowledge to evidence. AML & KYC Customer due diligence with the ownership look-through resolved as data. Risk & Control One control catalogue, read through every framework it answers to. Governance & Policies Policies drafted, mapped to requirements clause by clause, and approved in the platform.

Platform

  • Platform overview
  • AI assistant
  • Security & trust
  • Impact & access

Domains and services

  • Register of Information
  • Suppliers & Contracts
  • Asset Management
  • Risk & Control
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • Governance & Policies
  • Incident Management
  • All solutions →

By sector

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services
  • All sectors →
About Pricing Insights Resources Contact
Book a Discovery Call
Home About Platform Solutions Sectors Pricing Insights Resources DORA Guide NIS2 Guide Contact
Book a Discovery Call
Insights

How to classify contracts under DORA: standalone, overarching, or associated?

Ariadnah Solutions DORA 23 Jul 2025 2 min read

01

The challenge

When completing the Digital Operational Resilience Act (DORA) information register, you must specify the type of each contractual arrangement: standalone, overarching, or subsequent/associated. This classification must be recorded in template RT.02.01, column RT.02.01.0020 'Type of contractual arrangement'.

But how should you handle this for a typical ICT service where agreements are spread across multiple documents like terms & conditions (T&Cs), terms of service (ToS), and a data processing agreement (DPA)?

02

What is a contractual arrangement according to DORA?

The DORA regulation and Implementing Technical Standards (ITS) don’t provide a strict definition of a contractual arrangement. However, Article 28(3) makes it clear that it refers to “contractual arrangements on the use of ICT services provided by ICT third-party service providers.” In other words, it includes any agreements governing your use of ICT services.

03

Three types of contractual arrangements under DORA

For column RT.02.01.0020, the ITS specifies the following options:

  • Standalone arrangement – A self-contained agreement.
  • Overarching arrangement – A master or framework agreement.
  • Subsequent/associated arrangement – Linked agreements like implementation contracts, subservice agreements, amendments, or order forms.

04

Classification of contractual arrangements in practice

In many cases, ICT service agreements are documented in several files such as T&Cs, ToS, and a DPA. So how should these be classified?

These documents usually:

  • Relate to the same ICT service
  • Together define the conditions for using that service
  • Must be read together as a complete package

In practice, this means they can be viewed as one contractual arrangement. Alternatively, you could treat them as multiple arrangements (e.g., T&Cs as overarching, ToS and DPA as associated), but this adds unnecessary complexity.

05

Best practice: classify as a standalone arrangement

For RT.02.01.0020, choosing "1. Standalone arrangement" is the most logical option in most cases. Here’s why:

  • The documents form a single package for the same service.
  • It avoids duplicating entries and reduces clutter in your register.
  • It aligns with the register’s goal: understanding risk at the service level, not the individual document level.

06

Conclusion and practical tip

Whenever possible, classify a service and its related documents (T&Cs, ToS, DPA) as one standalone arrangement in RT.02.01, column RT.02.01.0020. This simplifies register maintenance and supports a clearer understanding of ICT risks.

The prebuilt DORA register from DORA-Solutions allows you to store all documents under one ICT service and classify them easily as a single arrangement.

Reach out for a demo of our prebuilt DORA register

Originally published on DORA Solutions Insights.

Continue with DORA

Put this question in context.

The DORA guide connects this issue to governance, ICT risk, incidents, resilience testing, third-party risk and the Register of Information.

Recommended next Read the DORA compliance guide →
Explore the operating approach See the supplier and contract approach Related analysis The Risk You Didn’t Sign Related analysis DORA Supply-Chain Reporting: When Granularity Creates Noise
Manage Consent
We use cookies to keep this site reliable and to understand how it is used. You can accept, deny, or adjust your preferences at any time.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ariadnah

Compliance advisory & technology

Regulatory specialists and technology that help organisations simplify compliance, strengthen operational resilience, and build lasting trust.

ISO/IEC 27001 certified (DNV)

Platform

  • Platform Overview
  • DORA Guide
  • NIS2 Guide
  • Regulatory Library
  • Register of Information
  • Risk & Control
  • Governance & Policies
  • Incident Management
  • Asset Management
  • Suppliers & Contracts
  • AML & KYC
  • AIFMD Reporting
  • Fund Administration
  • Trust & Investor Portal
  • AI
  • Security

Sectors

  • Banking
  • (Re)Insurance
  • Investment Firms
  • Investment Management
  • Payment Institutions
  • Pension Funds
  • Crypto Services

Company

  • About Ariadnah
  • Pricing
  • Our Experts
  • Impact
  • FAQ
  • Insights
  • Contact

Legal

  • General Terms
  • Data & Privacy
  • Cookie Policy
  • Accessibility

© 2026 Ariadnah Solutions B.V.