Skip to main content
← All posts·
Regulatory Compliance

DORA Compliance for Banking: AI Infrastructure Requirements & Implementation Guide

How banks and credit institutions implement DORA-compliant AI infrastructure. Covers ICT risk management, incident reporting, resilience testing, and third-party oversight for banking AI systems. Includes ECB supervisory expectations and implementation timeline.

Luca Berton12 min read

Why Banking AI Infrastructure Needs DORA-Specific Architecture

The Digital Operational Resilience Act (DORA) took effect on 17 January 2025, and banks face the strictest enforcement regime of any regulated sector. For AI systems in banking — from credit scoring models to fraud detection to algorithmic trading — DORA creates specific infrastructure obligations that generic cloud deployments cannot satisfy.

This guide maps DORA's five pillars directly to banking AI infrastructure decisions, with implementation patterns we've seen work across European financial institutions.

DORA's Five Pillars Applied to Banking AI

Pillar 1: ICT Risk Management (Articles 5-16)

Banking AI systems must have documented risk management frameworks covering the entire model lifecycle. This means:

  • Model inventory — Every AI model catalogued with risk classification, data sources, and business criticality
  • Change management — Documented approval workflows for model updates, retraining, and deployment
  • Continuity planning — Recovery time objectives (RTOs) for each AI system, tested quarterly
  • Vulnerability management — Automated scanning of AI infrastructure components, ML libraries, and model serving endpoints

Pillar 2: ICT Incident Management (Articles 17-23)

AI-related incidents in banking require specific reporting:

  • Model drift alerts — When credit scoring models deviate beyond thresholds, this triggers incident classification
  • Data quality incidents — Corrupted training data or feature pipeline failures must be reported if they affect business services
  • 4-hour initial notification for major ICT incidents to national competent authorities
  • Automated incident classification — Infrastructure must auto-classify AI incidents by severity using DORA's criteria

Pillar 3: Digital Operational Resilience Testing (Articles 24-27)

Banks classified as significant institutions must conduct threat-led penetration testing (TLPT) on AI systems:

  • Adversarial ML testing — Model evasion, data poisoning, and prompt injection attacks on production models
  • Infrastructure chaos testing — GPU node failures, model serving endpoint outages, feature store degradation
  • Load testing under stress — AI inference performance during market volatility (100x normal volume)
  • Recovery validation — Automated failover to backup models within documented RTO

Pillar 4: ICT Third-Party Risk (Articles 28-44)

Banking AI infrastructure typically depends on multiple vendors:

  • Cloud providers — AWS, Azure, GCP hosting AI workloads need contractual DORA provisions
  • Model providers — OpenAI, Anthropic, Cohere API dependencies require exit strategies
  • Data vendors — Market data feeds, credit bureaus, alternative data providers
  • Concentration risk — Cannot have critical AI functions dependent on a single third party

Pillar 5: Information Sharing (Article 45)

Banks should participate in threat intelligence sharing for AI-specific risks:

  • Adversarial attack patterns — New model evasion techniques targeting financial AI
  • Supply chain vulnerabilities — Compromised ML libraries or poisoned pre-trained models
  • Sector-specific IOCs — Indicators of compromise specific to financial AI infrastructure

Banking AI Infrastructure Architecture for DORA

Reference Architecture Components

LayerComponentsDORA Requirement
ComputeKubernetes with GPU nodes, multi-AZ deploymentArt. 11 — Business continuity
Model ServingBlue-green deployment, A/B testing, canary rolloutsArt. 9 — Change management
ObservabilityModel performance monitoring, drift detection, audit loggingArt. 13 — Learning and evolving
SecurityNetwork policies, RBAC, encryption at rest and in transitArt. 7 — ICT systems security
GovernanceModel registry, approval workflows, SBOM generationArt. 5 — Governance requirements
📘 Book

Kubernetes Recipes

Practical guide for container orchestration and deployment — hands-on patterns you can use today.

View on Amazon →

Implementation Timeline for Banks

90-Day DORA AI Compliance Roadmap

Days 1-30: Assessment

  • Inventory all AI models with business criticality classification
  • Map third-party AI dependencies and concentration risk
  • Gap analysis against DORA's five pillars

Days 31-60: Architecture

  • Design resilient AI infrastructure with documented RTOs
  • Implement automated incident classification for AI systems
  • Establish model change management workflows

Days 61-90: Implementation

  • Deploy monitoring and alerting for model drift and data quality
  • Run first resilience test on critical AI systems
  • Document everything for supervisory review

Common Mistakes Banks Make with DORA AI Compliance

  1. Treating AI like traditional IT — AI systems have unique failure modes (model drift, data poisoning, hallucination) that standard ICT risk frameworks don't cover
  2. Ignoring model-level resilience — Testing infrastructure failover without testing model fallback strategies
  3. Incomplete third-party mapping — Missing the AI model providers, training data sources, and annotation services in vendor registers
  4. No AI-specific incident classification — Model performance degradation doesn't fit traditional incident severity matrices
  5. Assuming cloud compliance = DORA compliance — Cloud provider certifications don't cover your AI-specific obligations
🎓 Course

IT Automation with Ansible Quickstart

Automate IT tasks, deploy apps, and streamline workflows in 40 minutes.

Start on Skillshare →

ECB Supervisory Expectations for AI

The ECB has been increasingly focused on AI in banking supervision. Key expectations include:

  • Explainability requirements for AI models used in credit decisions
  • Model validation frameworks aligned with ECB guide on internal models
  • Board-level accountability for AI risk management
  • Regular stress testing of AI systems under adverse scenarios

How Open Empower Helps Banks with DORA AI Compliance

We specialise in building DORA-compliant AI infrastructure for European financial institutions. Our approach:

  • Assessment — Map your current AI infrastructure against DORA's five pillars
  • Architecture — Design resilient, auditable AI platforms with built-in compliance
  • Implementation — Deploy and test the infrastructure with your team
  • Advisory — Ongoing support for regulatory changes and supervisory reviews
📋 Free Resource

EU AI Act Compliance Checklist

40-point checklist covering risk classification, data governance, transparency, and human oversight. Based on the official regulation.

Get Free Checklist →
DORA
banking
financial services
AI infrastructure
compliance
ECB
ICT risk management

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

Or see AI readiness assessment scope & pricing

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →