Skip to main content
DORA Auditor

Article 16: Simplified ICT risk management framework

Last updated: 1 authoritative sourceDORA Auditor Editorial Team

Article 16 carves out a lighter-touch ICT risk management regime for a named list of smaller or less interconnected financial entities: small and non-interconnected investment firms, exempted payment and electronic-money institutions, certain institutions exempted under Directive 2013/36/EU, and small institutions for occupational retirement provision. Instead of the full Articles 5-15 framework, these entities maintain a streamlined but still documented framework covering monitoring, business continuity, third-party dependencies, and lessons learned, reviewed periodically and reported to the competent authority on request.

Chapter II, ICT risk management · Pillar: ICT Risk Management

Key points

  • Applies only to entities named in Article 16(1), not a general small-business exemption
  • Replaces Articles 5-15 with a reduced set of core obligations rather than removing them entirely
  • Framework must still be documented, periodically reviewed, and reported to the competent authority on request

How this fits DORA

Article 16 sits within the ICT Risk Management pillar. For the full set of obligations and how they interlock, see the DORA requirements overview.

Read the official text

This is an editorial summary. Read the binding text of Article 16 in the consolidated regulation on EUR-Lex.

Sources

  1. Regulation (EU) 2022/2554 (DORA), EUR-Lex