Skip to main content
DORA Auditor

Simplified ICT Risk Management Framework

Last updated: 1 authoritative sourceDORA Auditor Editorial Team

The simplified ICT risk management framework is the lighter-touch regime DORA Article 16 provides for a named list of smaller or less interconnected financial entities, replacing the full Article 5-15 framework with a streamlined but still documented set of core obligations.

Detailed explanation

Article 16 is not a general small-business carve-out: it applies only to the entities it names, small and non-interconnected investment firms, payment institutions and electronic-money institutions exempted under their respective directives, certain institutions exempted under Directive 2013/36/EU, and small institutions for occupational retirement provision. Entities outside that list, including most banks, insurers, and payment institutions, remain subject to the full ICT risk-management framework regardless of size. Where it applies, the simplified framework still requires a documented ICT risk management approach: continuous monitoring of ICT systems, business-continuity and disaster-recovery arrangements, identification of dependencies on ICT third-party providers, and a mechanism for incorporating lessons from incidents and tests. The framework must be reviewed periodically and after major ICT-related incidents, in line with supervisory instructions, and a report on that review must be submitted to the competent authority on request. In practice this means eligible entities can scope a proportionate compliance programme rather than replicating the full governance structure required of larger institutions, without being exempt from ICT risk management altogether.

In context

This term relates to the ICT Risk Management pillar and is grounded in DORA Article 16.

Related terms

Sources

  1. DORA Article 16, EUR-Lex