Board resource

DORA compliance checklist for boards and executives.

A practical starting point to test whether your organisation's DORA programme is genuinely resilient — not just documented. Use it to structure board conversations and challenge management assertions.

1. Governance & board accountability

DORA places direct responsibility on the management body. The board must own the ICT risk framework, not delegate it away.

  • Board has formally approved the ICT risk management framework and reviews it at least annually.
  • Roles and responsibilities for ICT risk, resilience and third-party oversight are documented and assigned.
  • Board members have sufficient knowledge to challenge ICT and cyber risk reporting — evidenced through training records.
  • ICT risk appetite is defined, quantified where possible, and cascaded into operational limits.

2. ICT risk management framework

The framework must identify, protect, detect, respond to and recover from ICT risks across all critical functions.

  • Inventory of ICT assets and their mapping to critical or important business functions is complete and current.
  • Information security policies cover access control, cryptography, change management and secure development.
  • Business impact analyses define recovery time and recovery point objectives per critical function.
  • Continuous monitoring and detection capabilities are in place for anomalous activity and cyber threats.

3. Incident management & reporting

Major ICT-related incidents must be classified, escalated and reported to regulators within DORA's timelines.

  • Incident classification criteria (clients affected, data losses, duration, geographical spread, reputational impact) are defined.
  • Playbooks exist for initial (within 4 hours of classification), intermediate and final regulatory notifications.
  • Root-cause analysis and lessons-learned feed back into the risk framework and board reporting.
  • Significant cyber threats can be voluntarily reported where they materially affect financial stability.

4. Digital operational resilience testing

Testing must be risk-based, independent and — for significant firms — include threat-led penetration testing every three years.

  • Annual programme of vulnerability assessments, scenario-based tests and penetration testing on critical systems.
  • Threat-Led Penetration Testing (TLPT) programme aligned to TIBER-EU / CBEST for firms in scope.
  • Testing findings are tracked to remediation with board visibility on residual risk.
  • Independent testers meet DORA's competence and independence criteria.

5. Third-party ICT risk

Firms remain accountable for ICT services they outsource. Concentration and substitutability risks must be actively managed.

  • Register of all ICT third-party contracts is maintained and shared with the regulator on request.
  • Contracts with critical providers meet DORA's minimum contractual requirements (audit rights, exit strategies, sub-outsourcing).
  • Pre-contract due diligence assesses concentration risk and substitutability.
  • Exit and continuity plans are tested for each provider supporting a critical or important function.

6. Information sharing & culture

DORA encourages sharing of cyber threat information within trusted communities under agreed terms.

  • Firm participates in relevant threat intelligence sharing arrangements.
  • Cyber culture and awareness programmes reach the board, executives and wider workforce.
  • Whistleblowing and challenge channels exist for ICT and resilience concerns.

Want an independent view on your DORA readiness?

Arrange a meeting