Skip to main content
← All posts·
AI Governance

The AI Governance SPOC: Single Point of Contact for DORA, NIS2, and AI Act Regulatory Coordination

DORA, NIS2, and the AI Act all require designated governance contacts. Here's how to structure an AI Governance SPOC that satisfies multiple regulatory frameworks with a single organizational model.

Luca Berton11 min read

Regulated enterprises in the EU face an unprecedented convergence of regulatory requirements for AI and digital operations. DORA demands ICT risk management with clear governance. NIS2 requires incident reporting and supervisory cooperation. The AI Act mandates human oversight and conformity assessment for high-risk AI. Each regulation expects a designated point of accountability — and the worst possible response is creating three separate, disconnected governance functions.

The solution is a unified AI Governance Single Point of Contact (SPOC) that coordinates across all three frameworks while maintaining the domain-specific expertise each requires.

Why a Unified SPOC?

The case for consolidation is compelling:

  • Overlapping requirements: 60-70% of DORA, NIS2, and AI Act requirements overlap in areas like risk assessment, incident reporting, documentation, and third-party management
  • Single view of risk: An AI system failure is simultaneously an ICT risk event (DORA), a potential cybersecurity incident (NIS2), and a high-risk AI compliance issue (AI Act). Separate teams see fragments; a SPOC sees the full picture
  • Regulatory efficiency: When a regulator asks about your AI governance, one team provides a coherent answer. Three teams provide three potentially inconsistent answers
  • Resource optimization: Instead of duplicating governance capabilities across three teams, share infrastructure, tooling, and expertise

The Regulatory Requirements

DORA (Digital Operational Resilience Act)

DORA requires financial entities to:

  • Establish an ICT risk management framework with clear governance structure
  • Designate management body members responsible for ICT risk
  • Report major ICT incidents to competent authorities within defined timelines
  • Manage third-party ICT service provider risk (including AI/ML service providers)
  • Conduct digital operational resilience testing

NIS2 (Network and Information Security Directive)

NIS2 requires essential and important entities to:

  • Implement cybersecurity risk management measures approved by management bodies
  • Notify the national CSIRT of significant incidents within 24 hours (early warning) and 72 hours (full notification)
  • Ensure supply chain security for critical ICT products and services
  • Designate a point of contact for cross-border supervisory cooperation

EU AI Act

The AI Act requires deployers and providers of high-risk AI to:

  • Implement a quality management system covering AI development, deployment, and monitoring
  • Maintain technical documentation and conformity assessments
  • Ensure human oversight of AI system operations
  • Report serious incidents to market surveillance authorities
  • Register high-risk AI systems in the EU database
📘 Book

Kubernetes Recipes

A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).

Watch on Skillshare

SPOC Organizational Model

SPOC Structure

  • SPOC Lead (Head of AI Governance) — Senior executive with direct reporting line to the board. Accountable for regulatory coordination across all three frameworks
  • AI Risk Officer — Manages AI-specific risk assessments, model inventory, and conformity assessments (AI Act primary focus)
  • ICT Resilience Officer — Manages operational resilience, incident response, and third-party risk (DORA primary focus)
  • Cybersecurity Liaison — Coordinates with the CISO on NIS2 compliance, incident reporting, and security measures
  • Regulatory Affairs Specialist — Maintains regulatory tracking, manages supervisor relationships, and coordinates reporting across jurisdictions

Key Responsibilities

1. Unified Risk Register

Maintain a single risk register that captures AI risks from all three regulatory perspectives:

  • Each AI system registered with its DORA ICT asset classification, NIS2 criticality assessment, and AI Act risk tier
  • Cross-referenced risk assessments: a vulnerability in an AI system is simultaneously an ICT risk (DORA), a cybersecurity risk (NIS2), and potentially a conformity issue (AI Act)
  • Integrated treatment plans that address all applicable regulatory requirements in a single remediation action

2. Incident Response Coordination

AI incidents trigger reporting obligations under multiple frameworks simultaneously:

  • DORA: Major ICT incident → report to financial supervisor within 4 hours (initial), 72 hours (intermediate), 1 month (final)
  • NIS2: Significant cybersecurity incident → early warning to CSIRT within 24 hours, full notification within 72 hours
  • AI Act: Serious AI incident → report to market surveillance authority "without undue delay"

The SPOC coordinates a single incident response process with parallel reporting streams:

  1. Detection and triage (0-1 hour): Assess incident scope and determine which regulatory reporting obligations are triggered
  2. Early notification (1-4 hours): DORA initial notification to financial supervisor; NIS2 early warning to CSIRT
  3. Full assessment (4-24 hours): Complete impact analysis across all regulatory dimensions
  4. Detailed reporting (24-72 hours): NIS2 full notification; DORA intermediate report; AI Act serious incident report
  5. Follow-up (1 month): DORA final report; lessons learned across all frameworks

3. Third-Party AI Risk Management

All three frameworks require third-party risk management, and AI infrastructure typically involves multiple third-party providers:

  • Cloud providers — Hosting AI infrastructure (DORA critical third-party assessment; NIS2 supply chain security)
  • AI model providers — OpenAI, Anthropic, etc. (AI Act provider obligations; DORA ICT third-party risk)
  • Data providers — Training data sources (AI Act data governance; DORA ICT service provider risk)
  • MLOps platforms — SaaS ML platforms (DORA ICT third-party risk; NIS2 supply chain)

The SPOC maintains a unified vendor risk assessment that addresses all three frameworks, avoiding duplicate assessments for the same vendor.

4. Documentation and Audit Readiness

Maintain a single documentation framework that satisfies all three regulations:

  • AI System Documentation: Technical documentation (AI Act Art. 11), ICT system documentation (DORA Art. 9), and security documentation (NIS2 Art. 21) unified into a single document per AI system
  • Governance Policies: One AI governance policy that maps to DORA ICT risk management, NIS2 cybersecurity measures, and AI Act quality management requirements
  • Audit Trail: Single audit logging infrastructure satisfying DORA's audit requirements, NIS2's monitoring requirements, and AI Act's traceability requirements

Infrastructure for the SPOC

Governance Platform

  • GRC tool integration: ServiceNow GRC, Archer, or similar platform configured with all three regulatory frameworks as compliance modules
  • AI model inventory: Automated discovery and registration of AI models with regulatory classification
  • Risk assessment workflows: Templated assessments that cover DORA, NIS2, and AI Act requirements in a single questionnaire
  • Regulatory tracking: Monitoring regulatory updates, enforcement actions, and guidance across all three frameworks

Incident Management

  • Unified incident platform: PagerDuty or Opsgenie with regulatory escalation rules
  • Automated reporting templates: Pre-populated report templates for DORA, NIS2, and AI Act incident notifications
  • Regulatory communication channels: Secure, audited communication channels with each regulatory authority

Monitoring and Detection

  • AI performance monitoring: Drift detection, accuracy degradation, fairness metric monitoring (AI Act continuous compliance)
  • Security monitoring: SIEM integration for AI infrastructure events (NIS2 security measures)
  • Operational resilience monitoring: Availability, latency, and error rate monitoring for AI services (DORA operational resilience)
🎓 Course with Starweaver

Operationalizing ML Models: MLOps for Scalable AI

Turn ML prototypes into robust, scalable systems using real-world tools. In collaboration with Starweaver.

Start on Coursera

SPOC Maturity Levels

  1. Level 1 — Reactive: Separate compliance functions respond to regulatory requirements independently. High duplication, inconsistent responses
  2. Level 2 — Coordinated: SPOC established as coordination function. Shared risk register but separate operational processes
  3. Level 3 — Integrated: Unified processes for risk assessment, incident response, and vendor management. Single documentation framework
  4. Level 4 — Automated: GRC platform automates cross-regulatory compliance checking. Automated incident classification and parallel reporting. Policy-as-code enforcement
  5. Level 5 — Predictive: AI-assisted compliance monitoring that predicts regulatory risks and recommends preventive actions before issues materialize

Implementation Roadmap

  1. Month 1: Establish SPOC team — appoint SPOC Lead, identify team members from existing risk, compliance, and IT functions
  2. Month 2: Regulatory mapping — create unified requirement matrix covering DORA, NIS2, and AI Act obligations
  3. Month 3: Build unified risk register — inventory all AI systems with regulatory classifications from all three frameworks
  4. Month 4: Implement incident response playbook — unified process with parallel regulatory reporting streams
  5. Month 5: Deploy governance platform — GRC tooling configured for cross-regulatory compliance tracking
  6. Month 6: Vendor risk consolidation — unified third-party assessment covering DORA, NIS2, and AI Act requirements
  7. Ongoing: Continuous improvement — regulatory tracking, enforcement trend analysis, and process optimization
📋 Free Resource

AI Readiness Checklist

50-point interactive checklist covering strategy, data, infrastructure, governance, and people. Score your organisation's AI readiness.

Get Free Checklist

Board Reporting

The SPOC must provide the board with a consolidated AI governance report that covers:

  • Compliance posture: Single dashboard showing compliance status across DORA, NIS2, and AI Act
  • Risk exposure: Top AI risks with regulatory impact assessment
  • Incident summary: AI-related incidents with regulatory notifications issued
  • Regulatory horizon: Upcoming regulatory changes and their impact on AI operations
  • Resource requirements: Budget and headcount needs for maintaining compliance as AI adoption scales
spoc
ai governance
dora
nis2
ai act
regulatory compliance
governance framework
single point of contact

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →