DORA has been in effect since January 17, 2025. For financial institutions, this means that digital resilience is no longer just an issue for the IT department; it has become a matter of corporate governance.
The Digital Operational Resilience Act shifts the focus from isolated IT security to demonstrable resilience in digital operations. It is not just a matter of whether systems are protected. It is about whether an institution understands its risks, detects incidents, has established reporting procedures, can test recovery processes, and can provide robust evidence to management and regulators.
At first glance, that sounds technical. But it’s only half technical. The other half is governance.
Image source: AI-generated | Description: "Icon image for oversight and governance"
For a long time, many companies viewed IT security primarily as a matter of protection: firewalls, access rights, backups, patches. All of these are important. And they’re still all valid.
However, DORA demands more: risks, controls, assets, providers, incidents, and tests must be integrated from a technical perspective—not as a loose collection of individual measures, but as an operational system.
This makes digital resilience a management task. The governing body must be more closely involved in strategy, reviews, and risk appetite. Roles must be more clearly separated: management, the control function, and internal audit must not disappear into a friendly fog of overlapping responsibilities.
In other words: DORA doesn't just ask whether a policy exists. DORA asks whether the policy works in practice.
A key issue is transparency regarding ICT systems, applications, and dependencies. Institutions need to know which systems they use, which business processes depend on them, and which vendors are involved.
Without this perspective, risk management remains incomplete. After all, you can only protect, test, and restore what you know.
This is particularly challenging in the financial and insurance sectors. Many processes rely on internal systems, cloud providers, software service providers, specialized platforms, and other third-party ICT service providers. DORA places greater emphasis on these dependencies within the context of governance and oversight.
Digital resilience isn't something you see in an organizational chart. It becomes apparent when a crisis strikes.
That is why incident management, resilience testing, recovery, and communication play a central role. Institutions must be able to detect, classify, and address incidents, and report them in serious cases. At the same time, backup, restart, and restore processes must be tested regularly.
What matters is not just that tests are conducted. What matters is what comes of them: findings must be documented, prioritized, and translated into concrete improvements.
In this way, the ability to provide evidence itself becomes the focus of control. Policies, exceptions, reviews, findings, decisions, and controls must be verifiable. Not because documentation is particularly appealing, but because without evidence, robust control cannot be achieved.
DORA does not apply only to internal systems. Third-party ICT service providers and critical providers are also coming under greater scrutiny.
Contracts, provider management, exit strategies, and the Register of Information thus become practical building blocks of resilience. Companies must be able to identify which service providers are relevant for which functions and where critical dependencies arise.
This is particularly important because modern financial processes rarely take place entirely in-house. The cloud, platforms, software providers, and specialized service providers have long been part of day-to-day operations. If you don’t manage them properly, you’re failing to manage part of your own risk.
When it comes to implementation, the goal is not to produce as many documents as possible. The key is to establish a viable operating model.
In practical terms, this means:
This isn't purely an IT task. Nor is it purely a legal project. DORA lies exactly where governance must become practical: at the intersection of IT, information security, compliance, risk management, business units, and management.
DORA is more than just IT security. DORA is an operational framework for management, control, and compliance in the financial sector's digital operations.
Those who view DORA merely as an additional regulatory requirement will, above all, generate more documentation. Those who view DORA as a governance task can build digital resilience in a more structured, verifiable, and management-friendly way.
K11 helps companies translate regulatory requirements into robust implementation programs—from embedding governance and conducting gap assessments to documentation, reporting channels, and management reporting.