DORA

DORA

DORA is an EU law that requires banks, insurers, and other financial companies to secure their IT against outages and attacks. It has been in effect since January 2025 and explicitly includes external service providers such as cloud and AI vendors.

DORA is a European Union law for the financial sector. The abbreviation stands for Digital Operational Resilience Act. It refers to a company’s ability to maintain its operations even when technology fails or comes under attack. Around 22,000 companies in Europe are affected: banks, insurers, payment service providers, exchanges, and crypto providers. They must demonstrate that their computer systems can withstand disruptions and that they have a plan for emergencies. The rules have applied directly in all EU countries since January 17, 2025.

Why Europe is dictating IT rules to banks

A bank today is essentially an IT company. If its data centers go down, transfers, card payments, and ATMs all stop working. In the past, regulators mainly prescribed how much capital a bank had to hold in reserve. But capital does little to help against a system outage. DORA closes this gap and treats technology failures as an independent risk to financial stability.

Adding to this is a concentration that makes regulators nervous. A great many financial companies rely on the same few cloud providers, above all Amazon, Microsoft, and Google. If one of them suffers a prolonged outage, it doesn’t affect just one bank but hundreds at once. It is precisely such chain reactions that DORA aims to prevent.

Those who ignore the requirements risk severe penalties. National supervisory authorities such as BaFin in Germany can impose fines and, in extreme cases, prohibit business activities. For particularly important technology service providers, the regulation provides for periodic penalty payments of up to one percent of global daily turnover, for each day the violation continues.

The five obligations of the regulation

DORA rests on five pillars. First, every company must systematically identify and manage its technology risks, with senior management personally accountable for this. Second, serious incidents must be reported: an initial report within four hours of classification, an interim report within 72 hours, and a final report within one month. Third, defenses must be tested regularly, and at large institutions this includes simulated attacks carried out by real security firms.

The fourth pillar concerns external service providers. Companies must maintain a register of all providers that operate their technology, and the contracts must include certain rights: access for auditors, termination options, and clear exit rules. The fifth pillar requires companies to share information about new threats with one another.

What is new is that the EU directly supervises particularly critical service providers. If a cloud provider is classified as critical, European supervisory authorities examine it themselves, even though it is not a bank at all. Previously, oversight always rested solely with the financial company that purchased the service.

DORA and the use of AI in the financial sector

DORA is relevant to AI because banks are increasingly integrating third-party models. A chatbot in online banking or a fraud-detection program often runs on an external provider’s servers. This makes that provider a technology service provider within the meaning of the regulation. It must be entered in the register, its contract must contain the required clauses, and the bank must be able to explain what happens if the service fails.

DORA should not be confused with the AI Act, the EU’s law on artificial intelligence. The AI Act asks whether an AI system makes decisions fairly and safely. DORA only asks whether the underlying technology runs reliably. A company may be required to comply with both frameworks at the same time. Adding to the confusion is a name clash: in software development, DORA Metrics refer to something entirely different, namely key figures measuring the speed of development teams.

In business news, DORA mainly comes up in two contexts. First, in reports about costs: banks have in some cases invested millions in new reporting processes and contract reviews. Second, whenever a major IT outage at a payment service provider becomes public, since 2025 this has regularly been followed by the question of whether the reporting deadlines were met.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.