EU Financial Regulation

DORA (Digital Operational Resilience Act)

In force since January 2025 for EU financial entities, with strict expectations around Information and Communication Technology (ICT) access control and third-party risk.

What is DORA?

The Digital Operational Resilience Act is an EU regulation requiring financial entities (and increasingly their UK counterparts operating in the EU) to demonstrate robust ICT risk management, including strong controls over access to critical systems.

DORA places particular emphasis on third-party and ICT vendor risk: financial firms must be able to show they govern not just their own staff's access, but every vendor, contractor, and service provider touching critical systems.

DORA's binding Regulatory Technical Standards go further than the headline regulation: they specify role-based access rights reviewed at a defined frequency, strong authentication for privileged and remote access, and logging sufficient to reconstruct who did what. For UK groups with EU subsidiaries, the practical trigger is usually a risk committee asking for consolidated evidence across every entity, not just the EU one, which is where a third-party access register most often turns out to be incomplete.

How IAM Tech helps

Third-party access governance and privileged access management are exactly where DORA's expectations bite hardest, and exactly where we spend most of our time.

  • Third-party and vendor access lifecycle governance
  • Privileged access management for critical system access
  • Access certification evidence mapped to ICT risk requirements
  • Non-human identity governance for service accounts and integrations
See Privileged Access Management (PAM) →

See our full approach to IAM for Financial Services & Banking →

See our full approach to IAM for Insurance →

Common questions

Does DORA apply to UK financial services firms?

Directly, DORA only binds EU financial entities and their EU-established ICT providers. In practice, UK groups with EU subsidiaries, or that provide critical ICT services into the EU, end up governed by it regardless, and UK regulators already expect equivalent third-party and access control discipline under the existing operational resilience regime, so the practical bar converges either way.

What counts as a critical third party under DORA?

DORA leaves the exact designation to a risk-based assessment, but in practice it means any ICT provider whose failure or compromise would disrupt a critical or important function: cloud hosting and core banking platforms are the obvious examples, and increasingly identity and authentication providers themselves fall inside that definition too.

How does DORA differ from GDPR on access control?

GDPR governs access to personal data specifically. DORA governs access to ICT systems supporting critical business functions, whether or not personal data is involved. A firm can be fully compliant on access to customer data under GDPR and still fail a DORA review on privileged access to a trading platform that touches no personal data at all.

Want to know where you stand?

Take the free 2-minute IAM Health Check, or talk to us directly about your DORA requirements.

Talk to us
Talk to us