Article 16: Simplified ICT risk management framework
Article 16 carves out a lighter-touch ICT risk management regime for a named list of smaller or less interconnected financial entities: small and non-interconnected investment firms, exempted payment and electronic-money institutions, certain institutions exempted under Directive 2013/36/EU, and small institutions for occupational retirement provision. Instead of the full Articles 5-15 framework, these entities maintain a streamlined but still documented framework covering monitoring, business continuity, third-party dependencies, and lessons learned, reviewed periodically and reported to the competent authority on request.
Chapter II, ICT risk management · Pillar: ICT Risk Management
Key points
- Applies only to entities named in Article 16(1), not a general small-business exemption
- Replaces Articles 5-15 with a reduced set of core obligations rather than removing them entirely
- Framework must still be documented, periodically reviewed, and reported to the competent authority on request
How this fits DORA
Article 16 sits within the ICT Risk Management pillar. For the full set of obligations and how they interlock, see the DORA requirements overview.
Read the official text
This is an editorial summary. Read the binding text of Article 16 in the consolidated regulation on EUR-Lex.