DORA in 60 Seconds
The Digital Operational Resilience Act (DORA) is an EU regulation that requires financial entities to manage their ICT (Information and Communication Technology) risks systematically. It entered into force on 16 January 2023 and applies from 17 January 2025.
In simple terms: DORA makes financial institutions responsible for the resilience of their digital systems — not just their own, but also those of their critical third-party providers.
Who Does DORA Apply To?
21 Types of Financial Entities
- Banks and credit institutions
- Investment firms
- Insurance and reinsurance undertakings
- Payment institutions and e-money institutions
- Crypto-asset service providers
- Central securities depositories
- Trading venues
- Fund managers (UCITS and AIFMs)
- Credit rating agencies
- Crowdfunding service providers
- Pension funds
- And their critical ICT third-party service providers (cloud, SaaS, managed services)
Proportionality principle: Requirements scale with entity size and complexity. Microenterprises have simplified obligations.
The 5 Pillars of DORA
- ICT Risk Management (Articles 5-16): Establish and maintain a comprehensive ICT risk management framework with identification, protection, detection, response, and recovery capabilities.
- ICT Incident Management (Articles 17-23): Classify, report, and learn from ICT-related incidents. Major incidents must be reported to supervisory authorities within strict timelines.
- Digital Operational Resilience Testing (Articles 24-27): Regular testing including vulnerability assessments, network security testing, and advanced threat-led penetration testing (TLPT) for significant entities.
- ICT Third-Party Risk Management (Articles 28-44): Due diligence, contractual requirements, and ongoing monitoring of ICT service providers. Critical providers subject to EU-level oversight.
- Information Sharing (Article 45): Voluntary sharing of cyber threat intelligence between financial entities.
Kubernetes Recipes
Practical guide for container orchestration and deployment — hands-on patterns you can use today.
View on Amazon →DORA and AI Systems
DORA doesn't mention "AI" explicitly, but AI systems are ICT systems. If your financial institution uses AI for credit scoring, fraud detection, algorithmic trading, or customer service, those AI systems fall under DORA's ICT risk management requirements:
- AI model risk → ICT risk management framework (Pillar 1)
- AI system failures → Incident classification and reporting (Pillar 2)
- AI resilience → Operational resilience testing (Pillar 3)
- AI cloud providers → Third-party risk management (Pillar 4)
Key Deadlines
- 17 January 2025: DORA applies — all requirements are enforceable
- 2025-2026: Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) being finalised by ESAs
- Ongoing: Critical ICT third-party provider oversight framework being established
Back-End Infrastructure: Servers, Secure APIs and Data
Build secure back-end infrastructure from the ground up. In collaboration with Starweaver.
Start on Coursera →Penalties
DORA penalties are determined by national competent authorities (NCAs) in each EU member state. Penalties can include:
- Administrative fines
- Periodic penalty payments (up to 1% of average daily worldwide turnover per day for up to 6 months)
- Public statements identifying the entity and the violation
- Orders to cease conduct
- Temporary bans on management body members
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton
