← All frameworks
Cyber
DORA (Digital Operational Resilience Act)
EU / ESAs · Brussels, EU · effective 17 Jan 2025
Binding ICT & operational-resilience regime for EU financial entities — including AI models used in finance. ICT risk management, incident reporting, resilience testing and third-party (cloud/AI) oversight.
Your Council assistant — do it all here
You are interacting with an AI system.
Who must comply
- ▸Banks, insurers, investment firms, crypto-asset providers
- ▸Their critical ICT/AI third parties
Penalties
Regulator-set; critical third parties face fines up to 1% of daily worldwide turnover per day.
Key obligations
ICT risk framework
Board-owned ICT risk management across the lifecycle.
Resilience testing
Regular testing incl. threat-led penetration testing.
Incident reporting
Classify and report major ICT-related incidents.
Third-party oversight
Register of, and controls over, critical ICT/AI providers.
Sectors in scope
BankingInsuranceInvestmentCrypto / digital assetsPayments
Threats & cybersecurity it addresses
Financial-system outageModel-driven trading failureCloud concentration riskICT third-party compromise
Crosswalks — comply once, cover many
CSOAI Layer 0 mapping
Charter Art. 21, 39
Governed MCP tools — open source, pip/npx install