Skip to main content
DORA Auditor

ICT Risk Management under DORA

Last updated: 1 authoritative sourceDORA Auditor Editorial Team

DORA's ICT risk-management pillar (Article 6) requires every financial entity to maintain a sound, comprehensive, and well-documented framework to identify, protect against, detect, respond to, and recover from ICT-related risk, under the accountability of the management body.

What the framework must cover

  • Strategies, policies, procedures, and tools to protect information and ICT assets.
  • Identification and classification of ICT-supported business functions and assets.
  • Continuous monitoring and detection of anomalous activity.
  • ICT business-continuity and disaster-recovery plans, tested regularly.
  • Mechanisms to learn from incidents and evolve the framework.

Governance and accountability

The management body bears ultimate responsibility. It must approve the framework, allocate budget, and maintain sufficient ICT knowledge: resilience is a board-level obligation, not solely an IT function.

A fast-moving risk: AI-driven cyber threats

The framework is not a one-time build. In July 2026 the European Systemic Risk Board warned that frontier AI models are materially raising systemic cyber risk, and the ECB followed with a letter requiring significant institutions to have an AI-cyber action plan by 31 October 2026, both feed directly into the Article 6 obligation to keep the framework current against emerging threats. See our coverage of the warning and the ECB deadline for what it means in practice.

Proportionality: a simplified framework for smaller entities

Not every in-scope entity has to build the full Article 5-15 regime from scratch. Article 16 carves out a simplified ICT risk management frameworkfor small and non-interconnected investment firms, payment institutions exempted under Directive (EU) 2015/2366 (PSD2), electronic money institutions exempted under Directive 2009/110/EC, institutions covered by the Article 2(4) waiver under Directive 2013/36/EU, and small institutions for occupational retirement provision. These entities still need a documented ICT risk approach, monitoring of their systems, a business-continuity plan, and a record of third-party dependencies, but the depth of testing and the frequency of review scale down with the entity's size and interconnectedness. Proportionality reduces the compliance burden; it does not remove the underlying obligation to manage ICT risk (see our explainer on the management body's specific duties for how the same proportionality principle applies to board-level oversight).

Frequently asked questions

Which DORA article covers ICT risk management?
Does the full framework apply to every financial entity, regardless of size?

Sources

  1. Regulation (EU) 2022/2554 (DORA), EUR-Lex