Lesson13 min

Basel, London, Brussels

Three texts, three angles

BCBS 516PRA SS1/21 & FCADORA
NaturePrinciplesBinding rulesDirectly applicable regulation
Unit of analysisCritical operationImportant business serviceCritical or important function
ToleranceRecommendedMandatory, quantified, board-approvedImplicit, via ICT risk tolerance
MappingPrinciple 4Mandatory, down to third partiesArticle 8, down to assets
IncidentsNot covered in detailNot covered in detailChapter III, quantified deadlines
Third partiesPrinciple 5CoveredChapter V, mandatory register
TestingPrinciple 6Severe scenarios mandatoryChapter IV, including TLPT

What each contributes

Basel supplies the grammar. The seven principles define the logic — critical operations, mapping, tolerance, testing — without imposing a format. It is the text to read to understand the reasoning.

The UK regime is the most developed on method. It mandates a precise deliverable, the board-approved annual self-assessment, which forces the organisation to document its vulnerabilities rather than display its compliance.

DORA is the most demanding on two points the others barely address: incident management, with quantified notification deadlines, and ICT third-party risk, with a register of information of unmatched granularity.

The practical intersection

An EU entity subject to DORA with a UK subsidiary must satisfy both regimes. The good news: the end-to-end mapping serves both, and it is the costliest deliverable.

The bad news: the units of analysis do not coincide exactly. A UK "important business service" is framed client-side; a DORA "critical or important function" is defined by its effect on the entity's soundness and its authorisation. The overlap is wide but not total.

And outside financial services

Entities under NIS 2 or the CER Directive are not subject to these texts, but the logic transposes without effort: identify essential services, set an intolerability threshold, map, test. The vocabulary differs, the method is identical.

Key takeaways

  • The UK regime is the most prescriptive on tolerances
  • DORA is the most prescriptive on third-party risk and incidents
  • Basel supplies the shared conceptual frame