DORA imposes enhanced requirements for the financial sector's digital operational resilience. Companies must be able to prevent, detect and manage ICT-related incidents and recover their operations following such incidents. The requirements cover areas including management responsibility, ICT risk management, incident reporting, digital operational resilience testing and ICT third-party risk management.
RSM helps you understand which requirements apply, identify gaps and translate the regulation into processes and controls that work in practice.
Are you directly in scope, or do you face the requirements through your customers?
DORA applies directly to a broad range of financial entities, including banks, payment institutions, insurance companies, pension funds, investment firms and certain crypto-asset service providers.
ICT service providers may also be affected even if they are not directly in scope. Financial entities must impose specific requirements on their ICT service providers, assess the risks associated with the services and maintain an overview of their contractual ICT arrangements. This may result in new requirements relating to contracts, documentation, incident reporting, audit access, continuity and exit plans.
How we help you
Overview of requirements and responsibilities
We determine how DORA affects your organisation, systems, suppliers and customer agreements.
This typically includes:
- management responsibility and governance
- ICT risk management
- incident management and reporting
- resilience, continuity and recovery
- digital operational resilience testing
- ICT third-party risk management
- contractual requirements and supplier follow-up
- the register of contractual ICT arrangements
DORA places overall responsibility for ICT risk with the management body and requires a documented framework that forms part of the company's overall risk management.
GAP assessment and roadmap
We assess your current framework against the relevant DORA requirements and identify where processes, controls or documentation are missing.
You receive a prioritised roadmap containing:
- identified gaps and risks
- recommended activities
- responsible functions
- priorities and timetable
- necessary documentation requirements
The aim is not merely to prepare new policies, but to create an operational framework that can be used and evidenced in day-to-day operations.
Implementation and follow-up
If required, we help establish or improve the necessary processes and controls.
This may include ICT risk management, incident processes, resilience plans, testing programmes, supplier registers, contractual requirements and management reporting.
Do you need to provide customers with assurance regarding DORA-related controls?
ICT service providers to the financial sector increasingly face requirements to demonstrate how they support their customers' compliance with DORA.
This may result in repeated questionnaires, customer audits and requests for documentation relating to areas including:
- information security and access management
- incident management
- resilience and recovery
- vulnerability and security testing
- subcontractor management
- monitoring and reporting
- contractual DORA obligations
If customers request independent assurance, an ISAE 3000 report on DORA-related controls may be relevant.
An ISAE 3000 report on DORA-related controls can be tailored to the controls supporting the provider's DORA-related obligations and give relevant customers insight into which controls are covered, how they were tested and the results of the testing. The report is not an official DORA certification.
Advisory services and any subsequent assurance engagement are planned in accordance with the applicable auditor independence requirements.
A straightforward and targeted engagement
- Clarification: We determine how DORA affects the company and your services.
- GAP assessment: We identify gaps in processes, controls and documentation.
- Roadmap: You receive a prioritised plan with clear activities and responsibilities.
- Implementation: We help establish the necessary solutions.
- Assurance: Where required by customers, a separate ISAE 3000 report may be the next step.
Find out where you stand
Contact us for an initial discussion about your DORA obligations, most significant gaps and need to provide customers with assurance.