EU data and model residency
The managed service, customer data and the standard language models are hosted and processed within the European Union.
Banks can use offgen as part of a fully DORA-compliant operating model. The review still has to cover the concrete use case, service classification, contract and customer controls. offgen supports that review with EU hosting, documented security controls and native PowerPoint output.
Yes. offgen can be integrated into a fully DORA-compliant setup when the bank classifies the service and supported function, completes its due diligence, records the arrangement, agrees the applicable contractual clauses and operates the required internal controls. offgen provides the technical, organizational and supplier information needed for this assessment. The final decision remains part of the bank’s ICT risk management framework.
BaFin highlights the full service lifecycle: ex-ante risk assessment, due diligence, contractual safeguards, ongoing monitoring, the Register of Information and an exit strategy for services supporting critical or important functions.
| DORA topic | What the bank assesses | What offgen provides |
|---|---|---|
| Classification and due diligence | The bank determines whether offgen is an ICT service and whether it supports a critical or important function. It evaluates security, concentration, location and dependency risks before signing. | Architecture, hosting boundary, processing locations, relevant suppliers, ISO 27001 status and security documentation for the scoped service. |
| Written contract | Article 30 requires a written agreement with clear service descriptions, data locations, security duties, availability, assistance and termination provisions. | Enterprise contracting can document the selected deployment, service boundary, processing locations, support model and the controls that apply to the agreed plan. |
| Register of Information | Article 28 requires financial entities to maintain a register of contractual arrangements for ICT services. | Provider, service, location, deployment and supplier information can be supplied for the bank’s register and procurement record. |
| ICT incidents and continuity | The bank needs notification paths, assistance for service-related incidents and continuity measures proportionate to the supported function. | Operational contacts, incident cooperation, availability and recovery responsibilities are documented for the scoped service. |
| Access, inspection and audit | For services supporting critical or important functions, Article 30 includes access, inspection and audit rights that must not be contractually impeded. | Current control evidence is available through the Trust Center. The appropriate audit and assurance approach is agreed during enterprise review based on scope and criticality. |
| Subcontracting | The bank assesses the ICT supply chain and applicable conditions for subcontracting, including risks to critical or important functions. | The relevant service and model boundaries, processing locations and supplier dependencies are disclosed for the scoped service. |
| Exit and termination | The bank plans how to leave the service without disrupting critical or important functions and defines return, access, migration and deletion requirements. | Generated work remains available as native .pptx files. Export, retention, deletion and transition support are defined for the contract. |
DORA is broader than data residency. These controls reduce the specific operational and information risks created when deal teams, finance teams or committees use AI in PowerPoint workflows.
The managed service, customer data and the standard language models are hosted and processed within the European Union.
Templates, prompts, financial context and generated presentations are not used to train the standard managed models by default.
Enterprise access controls, tenant isolation and audit logging support controlled use across deal teams, functions and legal entities.
Teams can work from approved templates, slide libraries, wording and business context instead of sending presentation work to uncontrolled public tools.
Outputs remain native and editable. Bank employees retain responsibility for figures, disclosures, approvals and the final communication.
Security documentation, the Data Processing Agreement and current assurance material can be reviewed before deployment.
The fastest review starts with the actual presentation workflow, not a generic vendor questionnaire. This keeps the assessment proportionate and makes contractual requirements concrete.
Define users, data categories, affected legal entities and whether the service supports a critical or important function.
Assess the documented EU hosting boundary for the service, customer data and standard language models against the bank’s risk appetite.
Review controls, suppliers, locations, incident duties, assurance rights, subcontracting conditions and register information.
Validate access, logging, approved content, output handling, continuity assumptions and the practical route to export or terminate.
offgen is designed to support the contractual, security, evidence and exit requirements relevant to an ICT third-party review. The bank must still decide how the concrete service is classified, which DORA provisions apply and whether its own configuration, permissions, retention and approval process meet those requirements.
Use the detailed architecture and evidence pages to validate the statements for your planned service scope.
Review ISO 27001, encryption, access controls, isolation and audit logs.
Review the European hosting boundary for the service, customer data and standard language models.
Review jurisdiction, model residency, data control, portability and exit.
Request current security and procurement evidence.
Use our practical guide to review scope, contracts, the Register of Information, incidents, testing and exit planning.
The page reflects the regulation and current supervisory guidance. Legal and compliance teams should assess the latest official texts against the specific deployment and contract.
Bring the intended users, data classes, supported function and hosting preference. We will map the service boundary and the available evidence to your review.
Choose a time and share how your company creates PowerPoint presentations today.
We will map your PowerPoint knowledge base, MCP use cases, governance rules, and first agentic presentation workflow.
In 30 minutes, you will see
How existing masters, templates, slide libraries, and approved content become a Company Brain
How people and AI agents can create native PowerPoint presentations through MCPs
How brand governance, editability, human review, and enterprise security work together