Operationalresilienceandthird-partydependency

For financial entities, an AI platform is an ICT third-party dependency. The questions are about concentration, substitutability, testing and exit.

ControlsrelevanttotheareasDORAaddresses

  • ICT risk management

    Risk classification per workflow, enforced policy and measured evaluation as inputs to your framework.

  • Third-party dependency

    Documented data flows, subprocessor transparency and contractual control rights.

  • Concentration risk

    Model independence and standard Kubernetes as substitutability controls rather than commercial talking points.

  • Resilience testing

    Support for scenario and recovery testing, including exercising the exit path.

  • Incident reporting

    Detection, classification and evidence available without reconstruction; notification terms contractual.

  • Continuity

    Defined degradation per workload class and tested recovery objectives agreed per deployment.

  • Exit strategy

    Documented export formats, transition window and operational transfer documentation.

  • Audit rights

    Support for your and your supervisor's audit and inspection needs, agreed contractually.

NeuroCluster supports controls relevant to this framework. Whether a particular deployment meets a particular obligation depends on how it is configured, operated and documented, so a deployment-specific assessment remains required. Nothing on this page is legal advice.

Questions

Would you be a critical ICT third-party provider?
That designation is made by supervisors against defined criteria, not self-assigned. What we can do is support the register-of-information and dependency-assessment work your framework requires.
How do we test the exit path?
By exercising it: export the ontology, policies and evidence, stand the platform up in an alternative posture, and verify the workloads run. We would rather that be tested during the relationship than discovered at the end of one.
How is concentration risk on models addressed?
By policy-driven routing with permitted fallbacks, so no single provider is structurally required. That is a resilience control as much as a commercial one.

Bring us one operational problem.

You do not need a finished brief. Bring the problem — we will work out the next step together.

Or book a call with the team