Lesson15 min

Scope, proportionality, accountability

Who is in scope

DORA applies to some twenty categories of financial entities: credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, central securities depositories, central counterparties, trading venues, trade repositories, fund managers, insurance and reinsurance undertakings, insurance intermediaries, institutions for occupational retirement provision, credit rating agencies, benchmark administrators, crowdfunding service providers, and securitisation repositories.

Added to these, by designation, are critical ICT third-party service providers, subject to a direct European oversight framework.

A few entities benefit from a simplified framework under Article 16 — notably small investment firms and certain pension institutions. Simplified does not mean exempt: the fundamental requirements remain.

Proportionality

Article 4 allows requirements to be applied taking account of size, risk profile and the nature of activities. It modulates effort, it does not grant a dispensation.

The practical rule: any decision to simplify must be written, reasoned and approved. A three-page proportionality note, approved by the management body, explaining article by article what is simplified and why, is worth infinitely more than a general assertion in a meeting.

Article 5, the first one examined

DORA innovates by making the management body personally accountable for the ICT risk management framework. It must:

  • define, approve and oversee its implementation;
  • allocate an identified budget to it;
  • keep its own knowledge current through regular training;
  • receive periodic reporting on ICT risk.

The director-training obligation is new and often overlooked. It is demonstrated by dated records, not by a mention in the minutes.

The five pillars and their deliverables

PillarArticlesPrincipal deliverable
ICT risk management5–16Documented framework + digital resilience strategy
Incidents17–23Classification and reporting procedure
Testing24–27Multi-year testing programme, TLPT if designated
ICT third-party risk28–44Register of information + compliant contracts
Information sharing45Optional

The pillar-4 register of information is by far the costliest deliverable to produce and the most underestimated at the outset.

The regulatory architecture

DORA is completed by regulatory technical standards and implementing technical standards developed by the European Supervisory Authorities. They specify the content of the risk framework, incident classification criteria, the register-of-information template, and the oversight arrangements for critical providers.

Practical consequence: reading the regulation is not enough. The operational templates and thresholds sit in the technical standards, and they determine the exact format of the expected deliverables.

Key takeaways

  • Some twenty entity categories, plus designated critical ICT providers
  • Proportionality is documented, not merely invoked
  • The management body is personally accountable and must be trained