1. Governance & board accountability
DORA places direct responsibility on the management body. The board must own the ICT risk framework, not delegate it away.
- Board has formally approved the ICT risk management framework and reviews it at least annually.
- Roles and responsibilities for ICT risk, resilience and third-party oversight are documented and assigned.
- Board members have sufficient knowledge to challenge ICT and cyber risk reporting — evidenced through training records.
- ICT risk appetite is defined, quantified where possible, and cascaded into operational limits.
