ICT Risk Management under DORA
DORA's ICT risk-management pillar (Article 6) requires every financial entity to maintain a sound, comprehensive, and well-documented framework to identify, protect against, detect, respond to, and recover from ICT-related risk, under the accountability of the management body.
What the framework must cover
- Strategies, policies, procedures, and tools to protect information and ICT assets.
- Identification and classification of ICT-supported business functions and assets.
- Continuous monitoring and detection of anomalous activity.
- ICT business-continuity and disaster-recovery plans, tested regularly.
- Mechanisms to learn from incidents and evolve the framework.
Governance and accountability
The management body bears ultimate responsibility. It must approve the framework, allocate budget, and maintain sufficient ICT knowledge: resilience is a board-level obligation, not solely an IT function.
A fast-moving risk: AI-driven cyber threats
The framework is not a one-time build. In July 2026 the European Systemic Risk Board warned that frontier AI models are materially raising systemic cyber risk, and the ECB followed with a letter requiring significant institutions to have an AI-cyber action plan by 31 October 2026, both feed directly into the Article 6 obligation to keep the framework current against emerging threats. See our coverage of the warning and the ECB deadline for what it means in practice.
Proportionality: a simplified framework for smaller entities
Not every in-scope entity has to build the full Article 5-15 regime from scratch. Article 16 carves out a simplified ICT risk management frameworkfor small and non-interconnected investment firms, payment institutions exempted under Directive (EU) 2015/2366 (PSD2), electronic money institutions exempted under Directive 2009/110/EC, institutions covered by the Article 2(4) waiver under Directive 2013/36/EU, and small institutions for occupational retirement provision. These entities still need a documented ICT risk approach, monitoring of their systems, a business-continuity plan, and a record of third-party dependencies, but the depth of testing and the frequency of review scale down with the entity's size and interconnectedness. Proportionality reduces the compliance burden; it does not remove the underlying obligation to manage ICT risk (see our explainer on the management body's specific duties for how the same proportionality principle applies to board-level oversight).
Frequently asked questions
Which DORA article covers ICT risk management?
Article 6, supported by Articles 5–16 of Chapter II.
Does the full framework apply to every financial entity, regardless of size?
No. Article 16 gives small and non-interconnected investment firms, certain exempted payment and e-money institutions, and a handful of other narrowly defined entities a simplified version of the framework, still substantive, but scaled to their size and risk profile.