Want to learn how to optimize your processes?
Discover our solutions for companies in finance and banking

In short: Under the EU's Digital Operational Resilience Act (DORA), bank board members and senior executives now bear direct personal responsibility for third-party and supplier failures — a vendor outage or breach is treated as an institutional failure, not someone else's problem. Yet most banks depend on thousands of suppliers with little central visibility, leaving procurement as a major blind spot for compliance, cybersecurity, and cost control. This article explains why supplier contracts are now compliance evidence, how fragmented procurement drains value and creates risk, and how a unified, intelligent procurement approach turns that liability into a measurable advantage.
Record quarterly profits can sit alongside a question no board wants to hear unanswered: if your primary cloud provider failed tomorrow, what would your regulatory exposure and recovery timeline be? For many banks, the honest answer is not immediate — and that gap is the point.
Current profitability can mask systemic vulnerabilities. For banking leaders, some of the most serious threats today don't come from traditional competitors; they emerge from fragmented procurement processes that few executives at C-suite level actively monitor.
The Digital Operational Resilience Act fundamentally changed the rules for financial institutions. Under DORA, board members and senior executives can face direct personal liability for third-party failures. When a core system suffers a cybersecurity breach or a payment processor goes down, regulators don't treat it as a "vendor problem" — they treat it as an institutional failure, with leadership accountable for fines that can reach into the millions of euros.
That exposure compounds once you consider that a modern bank may depend on thousands of vendors across its operations, often without a consolidated view of the risk this creates. This largely invisible ecosystem opens the door to service disruptions, data breaches, and regulatory violations originating well beyond direct oversight.
A concrete example: in 2025, First Fed Bank CEO Matthew Deines resigned following a lawsuit involving a fraudulent scheme tied to a third-party vendor, in which the bank reported losses exceeding $100 million and set aside several million in legal reserves. It's a reminder that procurement blind spots don't only create operational risk — they can end careers.
Every supplier contract has shifted from a purely commercial agreement to potential evidence of DORA compliance — or non-compliance. Contracts that lack the audit-rights and resilience-testing clauses DORA expects aren't just weak negotiation; they can constitute regulatory gaps in their own right.
When regulators examine an institution under DORA, they aren't only reviewing risk policies or capital ratios. They look at whether procurement processes demonstrate active control over the operational resilience of the supply chain. Without systematic vendor management, an institution can be carrying large numbers of individual compliance gaps disguised as ordinary commercial relationships.
Much of the recent record profit across European banking stems from high interest rates rather than operational excellence. This can create a misleading picture: institutions may look efficient when they are in fact losing value through uncontrolled third-party risk.
As rates normalize and margins compress, procurement inefficiencies currently hidden by favorable conditions tend to become far more visible — to shareholders, regulators, and boards alike.
Industry research suggests that a significant share of organizational spending — commonly cited in the range of 20-40% — occurs outside approved contracts, with poorly controlled institutions reaching considerably higher. Each off-contract transaction can mean several things at once: bypassed negotiated pricing, skipped compliance checks, and unvetted supply chain risk entering the organization.
The compounding effect is what makes this costly: missed volume discounts, unclaimed rebates, and the automatic renewal of unfavorable terms create a continuous drain that is hard to see, measure, or control.
Critical supplier information often sits across disconnected ERPs, departmental spreadsheets, and legacy systems. When board members ask for basic procurement intelligence — total supplier spend, third-party risk exposure, contract obligations — teams often have to launch company-wide data hunts instead of giving an immediate answer.
That isn't only inefficiency; it's a constraint on strategic decision-making. Sound choices about partnerships, risk mitigation, and competitive positioning depend on reliable supplier intelligence. When you can't quickly assess your supplier relationships, you can't make well-informed strategic decisions.
Manual vendor verification struggles against AI-driven fraud techniques aimed at the supply chain. Wire-transfer fraud — frequently identified as a leading financial crime affecting institutions — exploits weak supplier onboarding and payment-validation controls.
In other words, a procurement weakness can become a cybersecurity vulnerability. Every unverified supplier relationship is a potential entry point for attacks designed to exploit operational gaps rather than technical systems.
A growing number of banking leaders treat procurement transformation as a source of competitive differentiation rather than a back-office necessity. The business case is real: research has associated world-class procurement organizations with a meaningful cost advantage over peers and a strong return on investment, though the exact figures vary by study and methodology.
Reported transformations point to measurable impact — for example, improvements in cost-to-income ratio through procurement benchmarking, alongside savings from negotiated contracts, bulk purchasing, and vendor discounts.
A unified, intelligent procurement platform typically provides real-time supply chain intelligence (full visibility across vendor relationships, with automated scoring for operational, compliance, cybersecurity, and ESG risk, so an audit is met with dashboards rather than scattered spreadsheets); predictive contract management (AI-supported tracking of renewals, enforcement of service-level agreements, and DORA clause compliance across large contract volumes); and stronger supply chain security (authentication that helps block social-engineering and deepfake attacks targeting payment processes).
Handled well, procurement transformation lets a leader close one of the institution's least-watched risk areas before competitors act on the same opportunity; build confidence that third-party risk management offers genuine protection against DORA-related failures; and demonstrate profitability that doesn't depend solely on interest-rate cycles. Done poorly — or not at all — it leaves the same risks compounding quietly.
Procurement transformation works best when it's treated as a strategic architectural decision rather than a departmental tweak. Fragmentation, data silos, and uncontrolled supply chain risk are systemic problems, and tactical fixes tend to leave the underlying issue in place.
DORA and ongoing market consolidation have narrowed the room for purely gradual improvement. The institutions that emerge stronger won't simply be those with larger balance sheets — they'll be the ones with the most resilient and intelligent procurement foundations.
A bank's procurement function is either building competitive advantage or quietly accumulating executive liability. DORA, competitive pressure, and operational reality have converged to make this a genuine C-suite priority rather than a back-office concern.
The question for any banking leader is whether to lead this transformation and capture its benefits, or to wait until regulatory requirements force a reactive response when the strategic advantage is no longer available.
Procurement Software Evaluation Checklist - Detailed checklist to evaluate your software opportunities. The checklist includes:
Download the procurement software evaluation checklist here.
1. What is DORA, and why does it matter for procurement?
DORA (the Digital Operational Resilience Act) is an EU regulation governing the digital operational resilience of financial entities. It matters for procurement because it extends accountability for third-party and ICT-provider failures directly to the institution and its leadership — making supplier contracts and vendor oversight a compliance issue, not just a commercial one.
2. Are executives really personally liable for vendor failures?
Under DORA, board members and senior management carry responsibility for the institution's operational resilience, including risks introduced by third parties. A vendor outage or breach can be treated as an institutional failure, which is why leadership-level accountability — and proper contractual safeguards — have become central.
3. Why is fragmented procurement a security and compliance risk, not just a cost issue?
When supplier data is scattered across disconnected systems, no one has a reliable, real-time view of exposure. That makes it hard to demonstrate control during an audit, easy to miss unfavorable contract terms, and easier for fraud to exploit weak onboarding and payment controls. The cost leakage is real, but the compliance and cybersecurity exposure is often the bigger risk.
4. What should a bank prioritize first?
A practical starting point is consolidating supplier and contract data into a single, visible source, then ensuring contracts include the audit-rights and resilience-testing clauses DORA expects. From there, automated risk scoring and contract-renewal tracking address the highest-exposure gaps first.
5. What does a unified procurement platform actually change?
It replaces scattered spreadsheets and siloed systems with a single view of vendor relationships, risk, and obligations — enabling real-time risk scoring, proactive contract management, and stronger payment-fraud defenses. In a DORA context, that means being able to evidence control rather than scrambling to assemble it.