DORA's Article 5 puts ultimate responsibility for ICT risk on the management body, not the IT department. The board or equivalent governing body must approve and oversee the ICT risk-management framework, set the entity's risk appetite, allocate adequate budget, and keep up to date with ICT risk through regular training. In most member states, individual members can be fined personally if they fail to meet these duties.
What Article 5 actually asks of the board
Article 5(2) lists the management body's obligations in specific, checkable terms rather than a general duty of care. It must: define, approve, and oversee the implementation of all arrangements related to the ICT risk-management framework required by Article 6; set clear roles and responsibilities for every ICT-related function; approve, oversee, and periodically review the entity's digital operational resilience strategy, including the ICT risk tolerance level; approve and review the internal audit plan for ICT; and allocate and periodically review the budget needed to satisfy the entity's digital operational resilience needs. None of this can be delegated away in substance. A chief information security officer can run the programme day to day, but Article 5 makes the board the party that owns the outcome.
Setting risk appetite is a board decision, not a technical input
One duty that gets underestimated: the management body must approve the entity's ICT risk tolerance level, the threshold at which residual ICT risk becomes unacceptable and requires a response. This is not a number a security team hands up for rubber-stamping. Article 5 expects the board to actively engage with what that tolerance means in practice, for example, how long a core payments system can be unavailable before the entity considers the impact unacceptable, and to revisit it as the business and threat landscape change. A readiness assessment that surfaces gaps in the underlying ICT risk-management framework is only useful if the board has first defined what "acceptable risk" means for the entity; otherwise there is no baseline to assess gaps against.
"Sufficient knowledge" is a training obligation, not a slogan
Article 5(4) requires members of the management body to "actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk and its impact on the operations of the financial entity," including following training on a regular basis. Supervisors treat this as an enforceable duty, not an aspiration: a board that approves an ICT risk strategy it does not understand is itself a governance failure under Article 5, independent of whether the strategy turns out to be adequate. In practice this means documented, recurring training for non-executive and executive directors alike, calibrated to the entity's complexity, and evidence (agendas, attendance, materials) that a supervisor can review during an inspection. Firms building this out from scratch, rather than folding it into existing compliance training, typically turn to a dedicated DORA training programme for the board specifically, separate from staff-level awareness training.
How Article 5 connects to the rest of the framework
Article 5 does not stand alone; it is the governance layer that makes Article 6's technical framework enforceable. Article 6 requires a documented framework covering identification, protection, detection, response, and recovery; Article 5 is what makes the board accountable for that framework actually existing, being resourced, and being reviewed. The same logic threads through the other pillars: incident classification and reporting decisions, resilience-testing remediation, and third-party risk contract approvals all ultimately roll up to a management body that Article 5 has already made responsible for the outcome. A board that treats Article 5 as boilerplate tends to discover the gap only when one of those downstream obligations is tested by a supervisor or an incident.
Proportionality: smaller entities still can't skip it
DORA applies the principle of proportionality throughout, and Article 4 lets entities scale their ICT risk-management framework to their size, risk profile, and the nature of their services. That proportionality affects how elaborate the framework itself needs to be under Article 6, and certain small and non-interconnected entities can apply a simplified version. It does not, however, remove the management body's Article 5 accountability. A small payment institution can run a lighter framework than a global bank, but its board still has to approve it, understand it, and fund it. Proportionality changes the scale of the obligation, not who is accountable for it.
Personal liability: the exposure varies sharply by member state
DORA's enforcement Article 50 requires member states to give competent authorities the power to apply administrative penalties not just to the financial entity but to individual members of the management body and other natural persons responsible for a breach. DORA itself does not set a single EU-wide cap for these individual fines; it leaves the ceiling to national law, and the gap between jurisdictions is wide. Legal analysis of how member states transposed this provision has found maximum penalties for individuals ranging from roughly EUR 100,000 in Finland to as much as EUR 5 million in Germany, with some regimes also distinguishing intentional from negligent breaches when calculating the fine. Several member states additionally allow criminal penalties to sit alongside, or instead of, the administrative regime. A board member's actual exposure therefore depends heavily on where the entity, or the breach, is deemed to have occurred, which matters particularly for groups operating across several EU jurisdictions. Our broader DORA penalties overview covers the enforcement regime for entities and providers as a whole.
What boards should check now
- Confirm approval, not just awareness, is documented. Minutes should show the management body actually approving the ICT risk-management framework, the resilience strategy, and the risk tolerance level, not merely receiving a briefing on them.
- Check the ICT budget line was reviewed by the board, not set solely by IT or finance and passed through without discussion.
- Verify board-level ICT training is recurring and evidenced, not a one-off session delivered before go-live and never repeated.
- Map personal liability exposure by jurisdiction if the group operates in more than one member state, since Article 50 penalty ceilings for individuals differ significantly across the EU.
- Run a full-framework check, not just a governance one, with the DORA Readiness Score or a gap assessment if any of the above cannot be answered with a document reference.
Frequently asked questions
What does DORA Article 5 require of the management body?
Can board members be personally fined under DORA?
Does DORA require specific ICT training for board members?
What is the difference between DORA Article 5 and Article 6?
Do smaller financial entities get a simplified version of Article 5?
Who counts as the 'management body' under DORA?
Sources
- Regulation (EU) 2022/2554 (DORA), Articles 4, 5, 6, and 50, EUR-Lex.
- European Banking Authority, Digital Operational Resilience Act (DORA).
- DLA Piper, DORA Penalty Regimes: Overview of Divergence Among Member States, October 2025 (comparative penalty-ceiling analysis, cited for the Finland/Germany figures).
Last updated: 10 August 2026.