• Current students
      • Student centre
        Enrol on a course/exam
        My enrolments
        Exam results
        Mock exams
      • Course information
        Students FAQs
        Student induction
        Course enrolment information
        F2f student events
        Key dates
        Book distribution
        Timetables
        FAE elective information
        CPA Ireland student
      • Exams
        CAP1 exam
        CAP2 exam
        FAE exam
        Access support/reasonable accommodation
        E-Assessment information
        Exam and appeals regulations/exam rules
        Timetables for exams & interim assessments
        Sample papers
        Practice papers
        Extenuating circumstances
        PEC/FAEC reports
        Information and appeals scheme
        Certified statements of results
        JIEB: NI Insolvency Qualification
      • CA Diary resources
        Mentors: Getting started on the CA Diary
        CA Diary for Flexible Route FAQs
      • Admission to membership
        Joining as a reciprocal member
        Admission to Membership Ceremonies
        Admissions FAQs
      • Support & services
        Recruitment to and transferring of training contracts
        CASSI
        Student supports and wellbeing
        Audit qualification
        Diversity and Inclusion Committee
    • Students

      View all the services available for students of the Institute

      Read More
  • Becoming a student
      • About Chartered Accountancy
        The Chartered difference
        Student benefits
        Study in Northern Ireland
        Events
        Hear from past students
        Become a Chartered Accountant podcast series
      • Entry routes
        College
        Working
        Accounting Technicians
        School leavers
        Member of another body
        CPA student
        International student
        Flexible Route
        Training Contract
      • Course description
        CAP1
        CAP2
        FAE
        Our education offering
      • Apply
        How to apply
        Exemptions guide
        Fees & payment options
        External students
      • Training vacancies
        Training vacancies search
        Training firms list
        Large training firms
        Milkround
        Recruitment to and transferring of training contract
      • Support & services
        Becoming a student FAQs
        School Bootcamp
        Register for a school visit
        Third Level Hub
        Who to contact for employers
    • Becoming a
      student

      Study with us

      Read More
  • Members
      • Members Hub
        My account
        Member subscriptions
        Newly admitted members
        Annual returns
        Application forms
        CPD/events
        Member services A-Z
        District societies
        Professional Standards
        ACA Professionals
        Careers development
        Recruitment service
        Diversity and Inclusion Committee
      • Members in practice
        Going into practice
        Managing your practice FAQs
        Practice compliance FAQs
        Toolkits and resources
        Audit FAQs
        Practice Consulting services
        Practice News/Practice Matters
        Practice Link
      • In business
        Networking and special interest groups
        Articles
      • Overseas members
        Home
        Key supports
        Tax for returning Irish members
        Networks and people
      • Public sector
        Public sector presentations
      • Member benefits
        Member benefits
      • Support & services
        Letters of good standing form
        Member FAQs
        AML confidential disclosure form
        Institute Technical content
        TaxSource Total
        The Educational Requirements for the Audit Qualification
        Pocket diaries
        Thrive Hub
    • Members

      View member services

      Read More
  • Employers
      • Training organisations
        Authorise to train
        Training in business
        Manage my students
        Incentive Scheme
        Recruitment to and transferring of training contracts
        Securing and retaining the best talent
        Tips on writing a job specification
      • Training
        In-house training
        Training tickets
      • Recruitment services
        Hire a qualified Chartered Accountant
        Hire a trainee student
      • Non executive directors recruitment service
      • Support & services
        Hire members: log a job vacancy
        Firm/employers FAQs
        Training ticket FAQs
        Authorisations
        Hire a room
        Who to contact for employers
    • Employers

      Services to support your business

      Read More
☰
  • Find a firm
  • Jobs
  • Login
☰
  • Home
  • Knowledge centre
  • Professional development
  • About us
  • Shop
  • News
Search
View Cart 0 Item

Knowledge Centre

☰
  • Home/
  • News/
  • Knowledge centre news item
☰
  • News
  • News archive
    • 2024
    • 2023
  • Press releases
    • 2025
    • 2024
    • 2023
  • Newsletters
  • Press contacts
  • Media downloads

Five practical steps for becoming DORA-ready

Aug 23, 2024

In 2025, DORA will impose rigorous risk management standards on EU financial entities. Shane O’Neill offers five practical steps for compliance readiness

From 17 January 2025, the Digital Operational Resilience Act (DORA) applies to all financial entities operating within the European Union. This wide-reaching legislation aims to strengthen the digital operational resilience of the financial services sector.

Built upon five pillars, it contains rigorous requirements for information and communication technology (ICT) risk management, incident reporting, testing, third-party risk management and information sharing.

Implementing DORA’s requirements can be overwhelming, and knowing where to begin can be difficult. Below are five practical steps that firms can take to become DORA-ready.

Understand the principle of proportionality

Because of the diverse nature of the financial services sector, DORA employs the principle of proportionality. This challenging but critical aspect of compliance means that entities’ regulatory requirements will differ depending on their size and risk profile and the scale, nature and complexity of their business.

For example, large institutions providing multiple services, such as Ireland’s three-pillar banks, must establish a fully-fledged ICT risk management framework that addresses all appropriate areas from DORA’s Level 1 and Level 2 texts. However, smaller entities, such as boutique trading firms, can avail of a simplified ICT risk management framework covering only the areas relevant to their function, services and industry.

Testing requirements also differ depending on proportionality. All entities must set up a general testing programme and comply with digital testing requirements, but through industry engagement with the Central Bank of Ireland (CBI) in recent months, the indication is that only about 10–15 institutions in Ireland will initially fall within scope of the advanced threat-led penetration testing requirements laid out in Articles 26 and 27.

The application of proportionality seeks to create a high standard for the sector as a whole while protecting smaller organisations from unnecessary regulatory encumbrances.

Since DORA does not take a one-size-fits-all approach to compliance, institutions should begin their compliance journey with a scoping exercise to confirm the right-sized approach to meet the requirements without taking on needless regulatory burdens.

Perform a holistic gap assessment

DORA’s five pillars touch many components of business operations, so organisations should analyse their entire operating model to determine which groups and business functions the legislation affects.

They should bring together the stakeholders from each affected area to ensure that everyone understands their role in the compliance journey.

Business as usual will continue throughout the implementation timeline, and having a collaborative approach to the planning stage helps stakeholders align on DORA-related priorities and responsibilities from the get-go.

When conducting the business-wide gap assessment, entities should also inspect existing processes to determine if they can be used for DORA compliance. All firms practise digital operational resilience to some extent, and with a comprehensive review, in many instances, they’ll discover that they can enhance some of their existing procedures to satisfy DORA requirements.

Leveraging and improving existing procedures saves time and allows entities to focus their effort and resourcing on the areas where they’ll need to start from scratch to build practices that achieve compliance.

Be strategic about remediation activities

When building a remediation roadmap, entities should address the compliance areas that need the most work first.

Drafting new frameworks, evaluating them against the legislation and scrutinising their effectiveness will take time. Areas with significant compliance gaps must be addressed thoroughly, and an imminent implementation deadline can create unnecessary pressure on employees.

Whenever possible, businesses should align their remediation plans with existing transformation roadmaps.

To remain competitive, many organisations are already executing transformation roadmaps –digital, operational, environmental, etc. These businesses should ground DORA changes within their existing plans.

For instance, if a current transformation roadmap has a timeframe for updating contracts with third-party suppliers, the business should incorporate the additional contractual changes required by DORA as part of that review cycle.

Document decision-making

While the CBI expects firms to be as compliant as possible by 17 January 2025, it has also recognised that “the regulation of digital operational resilience is not a once-and-done exercise and that is optimal to adopt a multi-year, multifaceted perspective”.

When implementing large-scale change programmes, certain business realities, such as the lengthy process for updating third-party contracts, may prevent organisations from implementing all required changes within the timeframe in place.

The CBI will take such issues into account when evaluating compliance, but it has firm expectations that all entities will have established and begun work on an agreed implementation roadmap by the January deadline.

Firms should, therefore, be prepared to give an account of their DORA decision-making process.

Ensuring oversight and alignment through risk and compliance functions and objective review and challenge from internal audit will show the application of a holistic delivery model to meet DORA requirements.

Plan to test digital operational resilience regularly

DORA requires that firms test digital operational resilience regularly (with the principle of proportionality determining the frequency of the review cycle), so DORA frameworks need to stay top of mind within organisations even after implementation projects stand down next year.

By increasing entity-wide awareness about maintaining digital operational resilience, businesses can help all employees understand that DORA frameworks shouldn’t exist in silos; they need to evolve alongside business practices.

Any large-scale change – restructuring, operational changes, systems updates, etc. – should prompt an evaluation of the existing framework.

For instance, if a firm decides to overhaul its technology systems in 2026, then the DORA framework – despite only being a year old – may need updating to ensure continued compliance and meet the evolving business model of today.

Shane O'Neill is Partner in Consulting at Grant Thornton

The latest news to your inbox

Please enter a valid email address You have entered an invalid email address.

Useful links

  • Current students
  • Becoming a student
  • Knowledge centre
  • Shop
  • District societies

Get in touch

Dublin HQ

Chartered Accountants
House, 47-49 Pearse St,
Dublin 2, D02 YN40, Ireland

TEL: +353 1 637 7200
Belfast HQ

The Linenhall
32-38 Linenhall Street, Belfast,
Antrim, BT2 8BG, United Kingdom

TEL: +44 28 9043 5840

Connect with us

Something wrong?

Is the website not looking right/working right for you?
Browser support
CAW Footer Logo-min
GAA Footer Logo-min
CCAB-I Footer Logo-min
ABN_Logo-min

© Copyright Chartered Accountants Ireland 2020. All Rights Reserved.

☰
  • Terms & conditions
  • Privacy statement
  • Event privacy notice
  • Sitemap
LOADING...

Please wait while the page loads.