AI özellikli, ESG-integrated ve global olarak bağlantılı muhasebeciler ve danışmanlar. Denetim, vergi, danışmanlık, şirket finansmanı ve 16 uzman hizmet sütunları.AI özellikli, ESG-integrated ve global olarak bağlantılı muhasebeciler ve danışmanlar. Denetim, vergi, danışmanlık, şirket finansmanı ve 16 uzman hizmet sütunları.AI özellikli, ESG-integrated ve global olarak bağlantılı muhasebeciler ve danışmanlar. Denetim, vergi, danışmanlık, şirket finansmanı ve 16 uzman hizmet sütunları.AI özellikli, ESG-integrated ve global olarak bağlantılı muhasebeciler ve danışmanlar. Denetim, vergi, danışmanlık, şirket finansmanı ve 16 uzman hizmet sütunları.
All insights

DORA Compliance UK: A Financial Services Guide

DORA compliance for UK financial services firms: scope, ICT risk, incident reporting, testing, third-party oversight and practical readiness steps.

12 September 2026

DORA compliance for UK financial services firms requires more than a technology checklist. It requires leaders to determine whether the Digital Operational Resilience Act applies to their EU-regulated activities, understand the evidence expected under the regime, and align ICT risk management with the firm's wider operational resilience framework. This guide sets out the practical issues UK boards, CFOs, risk leaders and compliance teams should address now. For broader context, see Aureliant Global's regulatory compliance advisory guide for UK financial services.

Discuss your DORA readiness with Aureliant Global

What is DORA and which UK firms does it affect?

DORA is Regulation (EU) 2022/2554, the European Union's framework for digital operational resilience in the financial sector. It applies from 17 January 2025 and establishes requirements covering ICT risk management, ICT incident reporting, resilience testing, ICT third-party risk, and oversight of critical ICT providers.

For a UK-headquartered group, the first question is not simply whether the parent company is based in the UK. The practical question is whether the group, its subsidiaries, branches, or regulated activities fall within the scope of an EU financial regulator. DORA can therefore remain relevant to a UK group with an EU entity, EU branch, cross-border regulated activity, or ICT service relationship that is captured by the regulation.

  • Credit institutions, payment institutions and electronic money institutions
  • Investment firms, management companies and alternative investment funds
  • Insurance and reinsurance undertakings and relevant intermediaries
  • Trading venues, central counterparties and other financial-market infrastructures
  • Crypto-asset, crowdfunding, data-reporting and other in-scope financial entities
  • ICT third-party providers supporting regulated financial entities

Scope analysis should also consider the relationship between the UK firm and its EU operations. A parent may provide group technology, security, procurement or recovery services without being the regulated entity that carries the primary obligation. The group should document which entity owns each control, which entity receives regulatory communications, and how evidence is shared across borders. This avoids a common weakness in multi-jurisdiction programmes: a control exists somewhere in the group, but no one can show that it is available to the entity or service that needs it.

Management should also record the basis for any scope conclusion. That record can include the entity's permissions, services, jurisdictions, material ICT dependencies and advice received. It should be reviewed when the group launches a product, changes a supplier, acquires a business or changes its operating model. A static scope memo is unlikely to remain reliable as the business evolves.

How should UK firms approach DORA compliance?

A sound DORA compliance programme turns regulatory requirements into accountable operating practices. The management body needs visibility of ICT risk, important dependencies, incident response, resilience testing and remediation. The programme should also connect with the firm's FCA operational resilience work rather than creating a parallel set of controls with no common evidence base.

DORA area

Practical management question

Evidence to maintain

ICT risk management

Can the firm identify, assess and treat technology risk across services and dependencies?

Risk framework, inventories, assessments, controls and board reporting

Incident management

Can the firm classify and report a material ICT-related incident within the required process?

Incident taxonomy, playbooks, records, escalation and reporting evidence

Resilience testing

Does testing demonstrate that critical services can withstand disruption?

Test plans, results, findings, remediation and retest records

ICT third-party risk

Can the firm govern outsourced ICT services and concentration risk?

Supplier inventory, due diligence, contracts, exit plans and oversight

What are the key ICT risk management and incident reporting requirements?

DORA expects an ICT risk management framework that is documented, proportionate and connected to governance. It should address the lifecycle of ICT risk, including identification, protection, detection, response, recovery and learning. The management body remains accountable for oversight, even where specialist work is delegated to a technology, security or external advisory team.

In practice, UK firms should establish a controlled view of their ICT assets, information systems, critical services, dependencies and vulnerabilities. They should define ownership for risk decisions, control exceptions and remediation. Policies should be supported by operating evidence, not treated as the end product.

Incident readiness is equally important. The organisation needs a consistent method for detecting, classifying, escalating and recording ICT-related incidents. It should know who decides whether a threshold for reporting has been met, what information must be assembled, and how regulatory communications are coordinated with customer, board and third-party communications.

Incident classification should be tested against realistic ambiguity. A disruption may begin as a service alert, involve a supplier, affect several legal entities and become reportable only as the extent of impact becomes clear. Teams should therefore test how they update an initial assessment, preserve a decision trail and coordinate information across risk, technology, compliance, legal and communications functions. This is more useful than relying on a playbook that has never been exercised.

Useful preparation steps include:

  1. Map ICT services to important business and financial services.
  2. Agree incident severity criteria and accountable decision-makers.
  3. Test escalation and reporting playbooks using realistic scenarios.
  4. Capture decisions, timestamps, dependencies and lessons learned.
  5. Reconcile incident records with risk registers and remediation plans.

How does digital operational resilience testing work under DORA?

Digital operational resilience testing is designed to show whether technology-supported services can withstand, respond to and recover from disruption. The right testing programme is risk-based. It should cover ordinary control assurance as well as more demanding scenarios that challenge the firm's assumptions about people, processes, systems and suppliers.

Testing may include vulnerability assessments, scenario-based exercises, recovery tests, end-to-end service tests and, for firms within the relevant requirements, advanced testing such as threat-led penetration testing. The important output is not a polished exercise report. It is a defensible record of what was tested, what failed, who accepted the risk, and whether remediation was completed and retested.

UK firms should align DORA testing with the FCA's operational resilience expectations where the same services, tolerances and dependencies are involved. The regimes are not identical, but duplicated mapping and testing can create unnecessary complexity and inconsistent evidence.

What does DORA require for third-party ICT providers?

Third-party ICT risk is a central DORA concern because a regulated firm's resilience can be limited by the providers on which it depends. A DORA programme should identify material ICT services, understand substitutability and concentration risk, and assess whether contractual arrangements support oversight, access, incident cooperation, continuity and exit.

Supplier due diligence should be proportionate to the service and its impact. Firms should be able to explain which providers support important functions, what happens if a provider fails, and whether the firm can maintain control over data, access, recovery and regulatory evidence. Contracts should be reviewed against the firm's actual operational requirements rather than accepted as a one-time procurement exercise.

The review should distinguish a provider that is important from one that is merely convenient. Consider the service's substitutability, recovery assumptions, data portability, geographic dependencies, subcontracting model and access to assurance information. Where concentration risk is material, management should be able to explain the mitigation, the trigger for escalation and the practical feasibility of an exit or alternative arrangement.

For UK groups, this review should connect EU DORA obligations with UK operational resilience, outsourcing and third-party risk work. A single supplier inventory and evidence model can reduce duplication while preserving the distinct regulatory requirements that apply to each entity.

Read Aureliant Global's regulatory compliance advisory guide for UK financial services

What is the DORA implementation timeline and what should the FCA-regulated firm do now?

DORA has applied since 17 January 2025, so the relevant question in 2026 is not whether a firm should start planning. It is whether the firm can demonstrate a functioning, governed and tested approach. The FCA's own operational resilience transition period ended on 31 March 2025 for firms in scope of its rules, but the FCA continues to expect ongoing mapping, testing, learning and investment.

A practical readiness sequence is:

  1. Confirm scope: identify EU-regulated entities, activities, branches, services and relevant ICT providers.
  2. Establish governance: assign accountable owners and give the management body a clear view of material ICT risk.
  3. Map services and dependencies: connect ICT assets, suppliers and processes to important business services.
  4. Assess gaps: compare current policies, controls, contracts, incident processes and tests against the applicable requirements.
  5. Prioritise remediation: address weaknesses that could cause intolerable customer, market or regulatory harm first.
  6. Test and evidence: run scenarios, record outcomes, close findings and retain a defensible audit trail.
  7. Refresh continuously: update the framework after incidents, material changes, supplier events and regulatory developments.

Boards and senior management should receive decision-useful reporting, not only compliance completion percentages. Reporting should show material exposures, overdue remediation, service impact, supplier concentration, test results and accepted risks.

Reporting should make the decision required from management explicit. For example, a board pack may need approval for a remediation investment, acceptance of a time-bound risk, escalation of a supplier concentration issue or confirmation that a test finding has been closed. Clear decisions and accountable owners make the DORA programme easier to govern and provide stronger evidence of oversight.

What should a DORA readiness assessment test?

A useful DORA readiness assessment should test both design and operation. A policy can appear complete while the firm still lacks a current dependency map, a clear escalation route or evidence that a supplier recovery arrangement works in practice. The assessment should therefore sample decisions and records across the full service lifecycle.

Assessment lens

Questions for management

Governance

Are responsibilities, risk acceptance and reporting routes clear at management-body level?

Service mapping

Can the firm trace an important service through applications, data, people, facilities and ICT providers?

Incident response

Can the firm detect, classify, escalate and report an ICT incident using an agreed process?

Testing and recovery

Do scenarios challenge realistic failure modes, and are findings closed and retested?

Third-party oversight

Are material providers, concentration risks, contract protections and exit options understood?

Evidence quality

Can an independent reviewer connect controls and test results to accountable decisions?

This approach also helps senior leaders distinguish a control gap from a documentation gap. Both matter, but they require different responses. A missing control may require investment or a change in operating design. Weak documentation may require clearer ownership, disciplined record keeping and a reporting process that reaches the right decision-makers.

Assessment findings should be ranked by service impact, regulatory exposure, customer harm, dependency concentration and time to remediate. This gives the board a practical basis for approving investment and tracking progress. It also prevents teams from treating every open action as equally urgent.

How can an operational resilience adviser help achieve DORA readiness?

An operational resilience adviser can help a firm translate DORA into a proportionate programme of governance, controls, testing and evidence. The value is greatest where a firm has multiple jurisdictions, complex outsourcing, fast-changing technology, or uncertainty about how EU and UK requirements should work together.

Support may include scope assessment, ICT risk framework review, important-service mapping, incident readiness, supplier and contract assessment, testing design, board reporting, remediation tracking and independent challenge. The engagement should be tailored to the firm's regulated activities and risk profile. External support complements management accountability; it does not transfer the firm's regulatory responsibility.

For Aureliant Global, this work sits within a broader regulatory compliance and financial services advisory proposition. Its partner-led model is designed to keep senior expertise involved through the engagement, with practical recommendations that connect governance, operational resilience, technology risk and evidence.

Request a consultation on DORA and operational resilience readiness

Frequently asked questions about DORA compliance in the UK

Does DORA apply to UK financial services firms?

DORA can apply to UK-headquartered groups where an EU-regulated entity, branch, activity or in-scope ICT relationship is involved. UK headquarters alone does not determine scope. Each group entity and regulated activity should be assessed against the regulation and the relevant EU supervisory expectations.

What are the five main areas of DORA?

The five main areas are ICT risk management, ICT-related incident management and reporting, digital operational resilience testing, ICT third-party risk management, and oversight of critical ICT third-party providers. Information sharing is also supported within the framework.

How is DORA different from FCA operational resilience?

DORA is an EU regulation focused on digital operational resilience and ICT risk across in-scope financial entities. FCA operational resilience rules focus on important business services, impact tolerances, mapping, testing and the prevention of intolerable harm in the UK regulatory context. A UK group may need to meet both regimes.

What evidence should a firm retain for DORA compliance?

Evidence should include scope analysis, governance records, ICT risk assessments, inventories, incident classifications and reports, resilience test plans and results, supplier due diligence and contracts, remediation records, board reporting and lessons learned. The evidence should be current, attributable and connected to decisions.

When should a DORA readiness review begin?

A readiness review should begin as soon as a firm identifies a possible EU DORA perimeter or a material gap in its ICT resilience framework. Since DORA has applied since January 2025, firms should focus on closing evidence and control gaps rather than treating readiness as a future project.

Sources and further reading