Solutions

Effective Third-Party ICT Risk Management

Leno is a DORA-compliant solution for ICT third-party risk management, outsourcing management, and audit-ready IT compliance.

Get a demo

When external ICT becomes business-critical

Cloud providers, software vendors, platforms and IT service providers are deeply embedded in the operations of financial institutions. With this dependency comes a growing exposure to third-party ICT risks that can directly affect availability, security and operational stability.

Lack of a holistic view

  • No central overview of all ICT third parties
  • Dependencies between services, systems and providers are not fully transparent
  • Critical providers are identified too late

Reactive instead of preventive risk management

  • Risks become visible only during audits or incidents
  • Assessments are performed sporadically rather than continuously
  • Risk mitigation measures are not consistently linked to identified risks

High effort during audits and supervisory reviews

  • Information is distributed across multiple systems
  • Evidence must be compiled manually
  • Decisions and risk assessments are difficult to trace retrospectively
Credit card mockups

How Leno is rethinking ICT third-party risks

Leno enables financial institutions to actively manage third-party ICT risks rather than merely documenting them, fully integrated into existing risk, compliance and resilience processes.

Central view of all ICT third parties

  • Uniform identification of all ICT services
  • Clear allocation to processes and systems
  • Systematically determining the criticality of ICT services
  • Reporting to management and supervisory authorities at the push of a button

Structured and comparable risk assessments

  • Consistent assessment of all risks associated with ICT services
  • Evaluations, approvals and measures comprehensible at any time
  • Linking to contracts as proof of adequate management

Continuous monitoring instead of selective checks

  • Regular update of reviews
  • Tracking changes with service providers
  • Clear responsibilities for monitoring and action
  • Supporting ongoing compliance with DORA
Credit card mockups

Why Leno is better suited for managing third-party ICT risks

IKT-Third Party Risk Management mit Leno bedeutet, Risiken nicht nur zu dokumentieren, sondern aktiv zu steuern. Leno verbindet Transparenz über IKT-Drittparteien mit strukturierter Risikobewertung, laufender Überwachung und prüfungssicherer Dokumentation.

Other Tools

Fragmented solutions with limited transparency and high manual effort.
Centralised, DORA-aligned management of third-party ICT risks in a single platform.
Test for free
Risk transparency
Andere
Isolated view of individual service providers and services.
Holistic overview of all ICT dependencies.
Risk management
Andere
Evaluations without a clear logic of action.
Structured management of risks including responsibilities.
Regulatory alignment
Andere
Generic, not ICT-specific
Explicitly focused on DORA, MaRisk, BAIT and EBA guidelines.
Audit readiness
Andere
High manual preparation costs.
Evidence is consistent and retrievable at any time.
Timeliness
Andere
Deadlines for regular updates are often missed.
Continuous monitoring with task and reminder function
Flexibilität
Andere Tools sind statisch oder nur mit Programmierung
Leno ist konfigurierbar ohne Code
Modul-Integration
Andere Tools bilden getrennte Einzellösungen
Leno ist eine All-in-One-Plattform, nahtlos verknüpft
Startgeschwindigkeit
Andere Tools erfodern lange Implementierung
Leno ist sofort einsatzbereit mit Templates
KI-Funktionen
In anderen Tools oft nicht vorhanden
Leno verfügt über integrierte KI für Analyse & Automatisierung

Key questions on third-party ICT risks

What you should know about third-party ICT risk management
What are ICT third-party providers?

ICT third-party providers are external service providers that deliver information and communication technology services for a financial institution.

Which regulatory requirements apply to ICT third-party providers?

Financial institutions must, in particular under DORA (Digital Operational Resilience Act), systematically record, assess, and monitor ICT third-party providers.

Why is the management of ICT third-party providers so important?

ICT third-party providers are often critical to business operations. Disruptions, security incidents, or dependencies can directly impact business continuity, information security, and regulatory compliance.

How can Leno help with the management of ICT third-party providers?

Leno helps financial institutions centrally, structurally, and in a regulatory-compliant manner manage ICT third-party providers. All relevant providers are recorded consistently, risks are assessed comparably, and changes are continuously monitored. Decisions, assessments, and actions are documented in a traceable manner and are always audit-proof.

Which ICT services are considered critical?

ICT services are considered critical if they support critical or important functions. The classification is risk-based and depends on the significance of the supported functions for the institution - not on contract volume or provider size.

This is distinct from whether an ICT provider is classified as a critical third-party by the supervisory authority and subject to corresponding oversight.

Get to know Leno

Book a demo
Book a meeting today to discover Leno.