EU financial-sector framework for ICT risk management, incident reporting, resilience testing and third-party risk.
TL;DR:
- EU financial-sector framework for ICT risk management, incident reporting, resilience testing and third-party risk.
- Maintain ICT governance, incident response, testing, continuity and third-party risk controls.
- Classify and report major ICT incidents and maintain registers of information.
Summary
DORA establishes a common EU framework for the digital operational resilience of covered financial entities. Applicable from 17 January 2025, it connects technology governance, incident management, resilience testing and third-party ICT risk. The objective is the continued provision and recovery of financial services when technology fails or is attacked. Requirements are proportionate to the entity's size, risk and complexity, with specified exclusions and simplified arrangements.
Management remains accountable for the ICT risk-management framework. Entities identify critical functions, information assets and technology dependencies; protect and detect threats; maintain response, recovery and backup arrangements; and learn from incidents. Major ICT-related incidents must be classified and reported through the prescribed process. Testing ranges from regular assessments to more advanced threat-led penetration testing for selected entities.
Outsourcing does not transfer the financial entity's responsibility. ICT contracts, due diligence, registers of information, concentration risk, access and audit rights, subcontracting and exit arrangements form part of third-party risk management. A separate European oversight framework addresses designated critical ICT providers. An institution therefore needs to understand both its direct suppliers and the services whose failure could interrupt an important financial function.
In a payments operation, the practical unit of analysis is an end-to-end service: authentication, processing, communications, settlement support and customer access may depend on different providers. A technically available server is insufficient if the customer-facing service cannot complete its function. DORA brings those dependencies, recovery objectives, incident evidence and management decisions into one resilience framework.
Keywords
- EU Digital Operational Resilience Act
- DORA
- Regulation (EU) 2022/2554
- EU Digital Operational Resilience Act summary
- EU Digital Operational Resilience Act requirements
- EU Digital Operational Resilience Act compliance
- European Union payment regulation
- European Union financial regulation
- European Union regulation
- operational resilience