The Digital Operational Resilience Act (DORA) establishes comprehensive information and communication technology (ICT) risk management requirements for EU financial entities, applying from 17th January, 2025. It mandates new frameworks for operational resilience testing, third party risk management and incident reporting, while requiring extensive provisions to be embedded in contractual arrangements with ICT third party service providers. Implementation challenges include regulatory delays, complex register of information requirements and difficult contract negotiations. To navigate DORA’s complexities, financial entities should establish cross-functional governance, prioritise contract remediation by criticality and implement proportionate compliance approaches tailored to their specific risk profiles and operational circumstances. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
Lalone et al. (2026) studied this question.