The Digital Operational Resilience Act (DORA) is an EU regulation that came into force on January 2023. It is part of the EU Commission's digital financial package with the aim of increasing the digital resilience of the European financial market. The aim is to ensure that financial market participants can continue to operate reliably even in the event of incidents concerning ICT (information and communications technology) or key suppliers.
For participants affected by the regulation, there is a transition period until January 2025 for full implementation. During this timeline, we expect further expectations from the European Supervisory Authorities (ESAs) through regulatory technical standards and guidelines.
The new requirements focus on ICT security, operational resilience and reporting obligations in the event of cyber-attacks, for example, and other ICT incidents. These are explained below and illustrated by examples.
Challenges for customers
The introduction of the DORA Regulation may pose several challenges for financial firms, as they may not be adequately prepared to implement the new requirements.
To meet the requirements and continue to conduct business appropriately and successfully, ICT systems must be brought up to date, processes optimised, and employees trained.
Why KPMG?
- KPMG has a comprehensive professional repertoire regarding all relevant disciplines in the area of DORA regulation, including management consulting, ISM (Information Security Management), IRM (Information Risk Management), BCM (Business Continuity Management), outsourcing and cloud solutions. We specialise in advising and supporting our clients in all aspects of these disciplines.
- We have a deep understanding of processes, risks and controls as well as governance structures. Our expertise and know-how enable us to support our clients in implementing effective control mechanisms and risk management strategies.
- Our extensive project experience with companies in the industry has provided us with valuable insights and knowledge that help us better understand our clients' challenges and requirements. With our proven process model, we apply these insights in a targeted manner and develop customised solutions, optimally tailored to the individual needs of our customers.
- We benefit from direct access to global expertise and experience through our corporate network. We work closely with our international teams and can draw on a broad range of experience and expertise specifically tailored to the financial sector.
- In addition to our technical and methodological expertise, we also offer know-how for the implementation of tools. We support our clients in the implementation of market standard GRC tools to efficiently manage and control risks and controls. Furthermore, we offer tools for the effective management of third-party vendors and their contracts in the area of information technology (ICT) .
Get in touch
It is imperative that financial firms prepare for DORA implementation. If you have any concerns or queries about how DORA will apply to your business, please contact our team below. We'd be delighted to hear from you.
Contact our team
Dani Michaux
Partner, EMA Cyber Leader
KPMG in Ireland
Jackie Hennessy
Partner
KPMG in Ireland
Carmen Cronje
Associate Director
KPMG in Ireland
Read more on DORA
4 Results
Nothing found