Start with the function, not the vendor. DORA defines a critical or important function by the impact its disruption, defective performance, or failure would have on financial performance, service continuity, authorisation conditions, or other financial-services obligations. If an ICT service supports that function, subcontracting of the service or a material part of it needs explicit treatment.
The chain review should cover direct ICT third-party providers and the subcontractors that effectively underpin ICT services supporting critical or important functions or material parts of them. Intra-group ICT subcontractors are not automatically outside the review: Delegated Regulation 2025/532 treats ICT intra-group subcontractors providing those services as ICT subcontractors.
DORA, Implementing Regulation 2024/2956, and Delegated Regulation 2025/532 are binding EU rules. The chain map, approval log, and suggested evidence file below are practical ways to prove the required assessment and control; the regulations do not prescribe a particular diagram or internal workflow.