Digital Operational Resilience Act, Regulation (EU) 2022/2554
The one-paragraph answer
DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554), is the EU’s ICT resilience law for financial services. It has applied since 17 January 2025, and 2026 is its first genuine supervisory enforcement cycle. Five pillars: ICT risk management, incident reporting, resilience testing, ICT third-party risk, and information sharing. It reaches banks, insurers, investment firms, payment institutions, crypto-asset service providers, and, critically, the ICT third-party providers who serve them, which is how it reaches AI vendors. Under Article 5, the management body bears ultimate responsibility for ICT risk, and the duty is non-delegable.
It is a regulation, not a directive. No national transposition, no local variation, no grace period bought by a slow Member State. It became applicable on 17 January 2025 across the whole EU on the same day.
And the readiness gap is not small. Industry surveys through 2025 suggested only about half of in-scope financial institutions expected to reach full compliance on time, with a substantial share pushing into 2026. That is a large population now operating under binding obligations they have not finished implementing, in front of supervisors who have finished being patient. The Register of Information, the mandatory inventory of every ICT third-party arrangement, has been a particular problem: incomplete, inconsistent, and now a named supervisory focus.
The AI-specific pain is sharper still. Under DORA, an AI vendor with access to a financial entity’s systems or data is an ICT third-party service provider. Full stop. The contractual requirements, the register entry, the exit strategy, the concentration-risk analysis, and, where the function is critical or important, the audit rights all apply. Most AI procurement was not done to that standard.
A documented framework covering identification, protection, detection, response and recovery, and learning. Delegated Regulation (EU) 2024/1774 sets the technical standards, including a policy on encryption and cryptographic controls that must address advances in cryptanalysis.
Classify incidents, report major ones to the competent authority on a defined timetable, and track root causes. Reporting failures are an explicit early enforcement priority.
A regular testing programme, and for significant entities, threat-led penetration testing (TLPT) on a three-year cycle.
The pillar that reaches AI. A Register of Information covering every contractual arrangement with an ICT third-party provider. Mandatory contract terms. Exit strategies. Concentration risk assessment. And an EU-level oversight regime for critical ICT third-party providers, which is how the major cloud and AI platforms are drawn directly into financial supervision.
Voluntary arrangements for exchanging cyber threat intelligence between financial entities.
The management body bears ultimate responsibility for managing ICT risk. It must define, approve, and oversee the ICT risk-management framework. It must set clear roles for all ICT functions. It must approve and review the digital operational resilience strategy and the policy on ICT third-party providers. And it must maintain sufficient knowledge and skills, through regular, dedicated training, to understand and assess ICT risk.
A board may rely on a CISO or a CRO to execute. It cannot outsource the duty to understand and direct. This mirrors NIS2 Article 20 almost exactly, and it points at the same target: the board that receives an annual slide and signs off.
Two routes. If you have an EU financial entity, it applies directly. And if you are a technology or AI vendor serving EU financial entities, your customers are contractually obliged to impose DORA’s terms on you: the register entry, the audit and access rights, the incident notification duties, the exit and subcontracting provisions. If you are designated a critical ICT third-party provider, you fall under direct EU oversight.
AI vendors selling into European banking and insurance are already receiving these clauses. The ones who can answer them are winning the deals.
DORA is lex specialis over NIS2 for financial entities: where it applies, it displaces the corresponding NIS2 obligations rather than adding to them. It sits alongside the US banking model risk framework for institutions operating on both sides of the Atlantic, and alongside the EU AI Act where the AI in question makes credit or insurance decisions. An institution using AI for credit scoring in the EU is squarely inside all three.
“99% of vulnerabilities in client programs are caused by their dependencies”
Which is the entire argument for the Register of Information. If the exposure arrives through the dependency, then the inventory of dependencies is not administrative overhead. It is the control.
“Effective data governance is important for minimizing data breach activity and mitigating bias”
Through your customers, immediately and unavoidably. They are obliged to impose DORA’s contractual terms on you and to register you. If you are designated a critical ICT third-party provider, EU supervisors reach you directly.
DORA. It is lex specialis under NIS2 Article 4 and displaces the corresponding NIS2 ICT obligations for financial entities rather than stacking with them.
No. It is a directly applicable regulation and has been in force since 17 January 2025. 2026 is the first real enforcement cycle, not an extension.
The AI Vendor Tier Map and the AI Vendor Security Review from Volume V produce exactly what the Register of Information and the third-party pillar require. The Four-Page Board Pack produces the Article 5 management-body record.
The AI Business Enablement Audit™ measures your organization against every framework in this library, including DORA, and delivers a defensible governance dossier. Start or finish your audit below.
Start or finish your AI Audit →