Asset Management Under DORA
DORA applies to asset managers, UCITS management companies, and AIFMs. While banks have dominated the DORA conversation, asset managers face distinct challenges: portfolio management systems calculating NAV across thousands of positions, dependency on market data providers, and outsourced operations models where the fund administrator, custodian, and transfer agent are all third parties.
Critical Systems for Asset Managers
Portfolio Management & NAV
- Order management systems (OMS): Trade execution, allocation, and compliance checking — downtime means missed market opportunities and regulatory breaches
- NAV calculation: Daily or intraday pricing of fund positions. Incorrect NAV triggers regulatory reporting and investor compensation.
- Risk management systems: Real-time risk monitoring, VaR calculations, stress testing — UCITS requires daily risk limit monitoring
- Market data feeds: Bloomberg, Refinitiv, ICE — single-source dependency for pricing data is a concentration risk under DORA
Third-Party Risk — The Outsourced Model
- Fund administrators: NAV calculation, investor servicing, regulatory reporting — often a single provider for all funds
- Custodians: Asset safekeeping, settlement, corporate actions — systemically important third parties
- Transfer agents: Investor registry, subscription/redemption processing
- Cloud providers: Infrastructure for portfolio analytics, risk engines, and increasingly, AI-driven investment tools
Under DORA Article 28, asset managers must maintain a register of all ICT third-party arrangements, classify them by criticality, and ensure contractual provisions for audit rights, exit strategies, and sub-outsourcing controls.
Resilience Testing
- NAV failover testing: Can you calculate NAV if your primary administrator is unavailable? Do you have a backup pricing source?
- Trade execution failover: If your primary execution venue is down, can you route to alternatives while maintaining best execution obligations?
- Market data switchover: Test switching from Bloomberg to Refinitiv (or vice versa) for pricing data
- Cyber resilience: Ransomware scenario — can you reconstruct portfolio positions from custodian records?
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Implementation Priorities
- Third-party register: Complete inventory of all ICT service providers with criticality assessment
- Contract remediation: Update service agreements with DORA-required clauses (audit rights, exit plans, incident notification)
- NAV continuity plan: Document and test NAV calculation backup procedures
- Incident reporting: Establish 4-hour/24-hour/72-hour reporting chain to NCA
- Board reporting: Regular ICT risk reporting to management body
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton