Skip to main content

      The Digital Operational Resilience Act (DORA) has firmly established the concept of digital resilience in the day-to-day operations of many financial institutions, ensuring that it is no longer viewed as an isolated IT issue but as an integral part of operational management. Financial institutions must integrate risk management, incident response processes, testing and third-party management into a consistent framework – and, above all, demonstrate this in their day-to-day operations. 

      Our benchmark overview shows that the fundamental governance structures are in place in most organisations. The key challenge now lies in operational implementation. Many financial institutions have roles, policies and documented processes in place – but far fewer have evidence that these work under real-world conditions. Our publication shows where the industry actually stands – and where there is still room for improvement.

      Where are the biggest gaps in practical implementation?

      The levels of maturity vary considerably depending on the subject area. Whilst governance models are largely established, there is often a lack of consistent operational implementation and robust evidence.

      This is particularly evident in four areas:

      • ICT Risk Management

        It is structurally well-developed, but the quality of key performance indicators, methodology and reporting varies considerably.

      • Incident Management

        It has a solid technical foundation, but has weaknesses in classification, escalation and impact assessment.

      • Third Party Risk Management

        It is under considerable pressure to adapt – particularly in terms of contracts, governance and exit strategies.

      • Testing & Audit

        It has been formalised, but falls short of the requirements in terms of intensity and frequency. 

      Download the study now (in German only)

      picture_as_pdf

      Whitepaper

      DORA Implementation Survey - 2026 Benchmarking Exercise

      Please complete the form below to receive the KPMG publication:

       


       

      How do financial institutions prioritise the implementation of DORA?

      Hardly any institution implements DORA in a completely uniform manner. Instead, a risk-based approach predominates. Critical functions and dependent service providers are prioritised, whilst less critical areas are deliberately developed at a slower pace. 

      This results in a two-tiered picture:

      • Progress is visible where regulatory pressure and risk relevance are high (e.g. critical service providers).
      • At the same time, differences in maturity levels are deliberately accepted within the organisation.

      Furthermore, it is not the level of investment that determines progress, but the methods chosen. Different approaches to classification, asset allocation or metrics lead to significantly differing results – even with comparable structures. Our paper thus provides an important perspective: progress is not purely a budgetary issue, but a question of implementation methodology.

      What does this mean in practical terms for your organisation?

      For decision-makers below the most senior management level, this publication offers three key benefits in particular:

      • Assessing the current situation realistically

        You can see whether your organisation is actually operating on an equal footing with the market – or whether any supposed progress is merely structural.

      • Setting the right focus

        The greatest potential for improvement currently lies not in new governance models, but in:

        • operational accountability
        • consistent methodology
        • robust KPIs and tests
      • Refining priorities

        Our analysis highlights where other financial institutions are deliberately setting priorities – and where risks arise due to a slow response (particularly in relation to third parties and testing). This overview will help you transform your DORA implementation from a concept into a robust, audit-proof practice.

      Your contacts