Why Banking AI Infrastructure Needs DORA-Specific Architecture
The Digital Operational Resilience Act (DORA) took effect on 17 January 2025, and banks face the strictest enforcement regime of any regulated sector. For AI systems in banking — from credit scoring models to fraud detection to algorithmic trading — DORA creates specific infrastructure obligations that generic cloud deployments cannot satisfy.
This guide maps DORA's five pillars directly to banking AI infrastructure decisions, with implementation patterns we've seen work across European financial institutions.
DORA's Five Pillars Applied to Banking AI
Pillar 1: ICT Risk Management (Articles 5-16)
Banking AI systems must have documented risk management frameworks covering the entire model lifecycle. This means:
- Model inventory — Every AI model catalogued with risk classification, data sources, and business criticality
- Change management — Documented approval workflows for model updates, retraining, and deployment
- Continuity planning — Recovery time objectives (RTOs) for each AI system, tested quarterly
- Vulnerability management — Automated scanning of AI infrastructure components, ML libraries, and model serving endpoints
Pillar 2: ICT Incident Management (Articles 17-23)
AI-related incidents in banking require specific reporting:
- Model drift alerts — When credit scoring models deviate beyond thresholds, this triggers incident classification
- Data quality incidents — Corrupted training data or feature pipeline failures must be reported if they affect business services
- 4-hour initial notification for major ICT incidents to national competent authorities
- Automated incident classification — Infrastructure must auto-classify AI incidents by severity using DORA's criteria
Pillar 3: Digital Operational Resilience Testing (Articles 24-27)
Banks classified as significant institutions must conduct threat-led penetration testing (TLPT) on AI systems:
- Adversarial ML testing — Model evasion, data poisoning, and prompt injection attacks on production models
- Infrastructure chaos testing — GPU node failures, model serving endpoint outages, feature store degradation
- Load testing under stress — AI inference performance during market volatility (100x normal volume)
- Recovery validation — Automated failover to backup models within documented RTO
Pillar 4: ICT Third-Party Risk (Articles 28-44)
Banking AI infrastructure typically depends on multiple vendors:
- Cloud providers — AWS, Azure, GCP hosting AI workloads need contractual DORA provisions
- Model providers — OpenAI, Anthropic, Cohere API dependencies require exit strategies
- Data vendors — Market data feeds, credit bureaus, alternative data providers
- Concentration risk — Cannot have critical AI functions dependent on a single third party
Pillar 5: Information Sharing (Article 45)
Banks should participate in threat intelligence sharing for AI-specific risks:
- Adversarial attack patterns — New model evasion techniques targeting financial AI
- Supply chain vulnerabilities — Compromised ML libraries or poisoned pre-trained models
- Sector-specific IOCs — Indicators of compromise specific to financial AI infrastructure
Banking AI Infrastructure Architecture for DORA
Reference Architecture Components
| Layer | Components | DORA Requirement |
|---|---|---|
| Compute | Kubernetes with GPU nodes, multi-AZ deployment | Art. 11 — Business continuity |
| Model Serving | Blue-green deployment, A/B testing, canary rollouts | Art. 9 — Change management |
| Observability | Model performance monitoring, drift detection, audit logging | Art. 13 — Learning and evolving |
| Security | Network policies, RBAC, encryption at rest and in transit | Art. 7 — ICT systems security |
| Governance | Model registry, approval workflows, SBOM generation | Art. 5 — Governance requirements |
Kubernetes Recipes
Practical guide for container orchestration and deployment — hands-on patterns you can use today.
View on Amazon →Implementation Timeline for Banks
90-Day DORA AI Compliance Roadmap
Days 1-30: Assessment
- Inventory all AI models with business criticality classification
- Map third-party AI dependencies and concentration risk
- Gap analysis against DORA's five pillars
Days 31-60: Architecture
- Design resilient AI infrastructure with documented RTOs
- Implement automated incident classification for AI systems
- Establish model change management workflows
Days 61-90: Implementation
- Deploy monitoring and alerting for model drift and data quality
- Run first resilience test on critical AI systems
- Document everything for supervisory review
Common Mistakes Banks Make with DORA AI Compliance
- Treating AI like traditional IT — AI systems have unique failure modes (model drift, data poisoning, hallucination) that standard ICT risk frameworks don't cover
- Ignoring model-level resilience — Testing infrastructure failover without testing model fallback strategies
- Incomplete third-party mapping — Missing the AI model providers, training data sources, and annotation services in vendor registers
- No AI-specific incident classification — Model performance degradation doesn't fit traditional incident severity matrices
- Assuming cloud compliance = DORA compliance — Cloud provider certifications don't cover your AI-specific obligations
IT Automation with Ansible Quickstart
Automate IT tasks, deploy apps, and streamline workflows in 40 minutes.
Start on Skillshare →ECB Supervisory Expectations for AI
The ECB has been increasingly focused on AI in banking supervision. Key expectations include:
- Explainability requirements for AI models used in credit decisions
- Model validation frameworks aligned with ECB guide on internal models
- Board-level accountability for AI risk management
- Regular stress testing of AI systems under adverse scenarios
How Open Empower Helps Banks with DORA AI Compliance
We specialise in building DORA-compliant AI infrastructure for European financial institutions. Our approach:
- Assessment — Map your current AI infrastructure against DORA's five pillars
- Architecture — Design resilient, auditable AI platforms with built-in compliance
- Implementation — Deploy and test the infrastructure with your team
- Advisory — Ongoing support for regulatory changes and supervisory reviews
EU AI Act Compliance Checklist
40-point checklist covering risk classification, data governance, transparency, and human oversight. Based on the official regulation.
Get Free Checklist →Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton
