DEFINITION
DORA is the EU regulation on digital operational resilience in the financial sector; it harmonises requirements for ICT risk management, incidents, testing, third-party risk management and information sharing. It applies to financial entities and critical ICT third-party service providers.
DeclarationDORA
DORA requires, among other things, an ICT risk management framework, reporting processes for ICT incidents, regular resilience testing, and contractual as well as regulatory management of critical third-party providers. Supervisory authorities can promote information-sharing mechanisms and order interventions.
Practice: Establish an ISMS-compatible ICT risk framework, incident playbooks with reporting lines, testing programmes (e.g. TLPT), and third-party risk management incorporating contractual, exit, and supervisory clauses. Map DORA to existing ISO/IT controls for efficient implementation.
Key Points
– Applies to financial entities and critical ICT third-party service providers.
– Comprehensive requirements for ICT risk management and incident reporting.
– Highly relevant to third-party risk management (TPRM).
Related Terms
On this page
→ Definition
→ Statement
→ Key points
→ Related terms
→ Sources
Relevant Blog Articles
How turnus.ai provides support
turnus.ai automates the answering of compliance questionnaires and customer inquiries with just a single click.



