DORA, explained.
The EU's Digital Operational Resilience Act — Regulation (EU) 2022/2554 — brings ICT risk, incident reporting, resilience testing and third-party risk under one supervisory regime. AI systems are ICT assets, so they sit inside it.
What DORA is
DORA — the Digital Operational Resilience Act, Regulation (EU) 2022/2554 — is the EU's single, directly applicable framework for the digital operational resilience of the financial sector. Where operational-resilience expectations were previously scattered across guidelines and national rules, DORA consolidates them into one regulation that applies from 17 January 2025. As an EU regulation it binds financial entities directly, rather than requiring transposition into national law.
What it covers
DORA organises its requirements around four areas:
- ICT risk management — a governance and control framework for identifying, protecting against and recovering from ICT risk.
- ICT-related incident reporting — classifying and reporting major ICT-related incidents to supervisors on defined timelines.
- Digital operational resilience testing — regular testing of ICT systems, up to advanced threat-led testing for the entities that warrant it.
- ICT third-party risk — managing the risk from ICT service providers, including an oversight regime for those designated as critical third parties.
Why it reaches AI
DORA does not name AI, and it does not need to. An AI system is an ICT asset; where it is procured, hosted or served by a vendor, it is an ICT third-party service. That places AI inside the firm's resilience obligations by default — it must be captured in the ICT risk-management framework, considered in incident classification and resilience testing, and assessed as part of third-party risk. Treating an AI model as somehow outside operational-resilience duties is exactly the gap a supervisor will probe.
How AIssure maps to it
AIssure places your AI systems where DORA already expects to find them: inside the firm's ICT risk-management and ICT third-party-risk obligations. The assessment tests whether each AI use-case is captured in the resilience framework — governed, testable, and traceable to the provider behind it — and where it is not, it names the gap. Every finding is cited to the regulatory text, on a regulatory knowledge graph, so a resilience finding reads as evidence rather than assertion.
This is a point-in-time, independent opinion. AIssure attests to how AI sits against your DORA duties; it does not operate, host or monitor the systems it assesses — the separation is what keeps the assessment defensible.
Independence, deliberately
AIssure is an external assessment, not runtime tooling. It tells you where your AI systems stand against DORA's ICT and third-party obligations and what to remediate — it does not become part of the resilience stack it is judging. A control the firm runs cannot be objectively attested by the firm that runs it.
The primary source
The authoritative text is on EUR-Lex. Read it at Regulation (EU) 2022/2554, and see how DORA sits alongside the other regimes in AIssure's regulatory coverage.
Related
Regulations & standards
The eight jurisdictions and the instruments within them.
→ By roleFor the CISO
AI as an ICT asset under operational-resilience duties.
→ The moatThe regulatory knowledge graph
How the citation trail is built, versioned and verified.
→ The frameworksThe assessment frameworks
The two ways in — maturity baseline or ISO deep dive.
→DORA — the questions we get.
What CISOs, resilience teams and AI assistants ask about the Digital Operational Resilience Act and where AI fits inside it.
What is DORA?
DORA is the Digital Operational Resilience Act — Regulation (EU) 2022/2554. It is an EU regulation that sets uniform requirements for the digital operational resilience of financial entities, covering ICT risk management, ICT-related incident reporting, digital operational resilience testing, and the management of ICT third-party risk. It applies from 17 January 2025.
Who does DORA apply to?
A broad range of EU financial entities — banks, investment firms, insurers, payment and e-money institutions, crypto-asset service providers, and more — together with the ICT third-party providers that serve them, including those designated as critical third parties. If your firm is supervised in the EU and depends on ICT, DORA is in scope.
Why does DORA matter for AI systems?
Because an AI system is an ICT asset — and, where it is bought or hosted, an ICT third-party service. That places AI squarely inside a firm's DORA obligations: it has to be captured in ICT risk management, its failure modes considered in resilience testing, and its provider assessed under third-party risk. AI is not exempt from operational-resilience duties because it is 'AI'.
How does AIssure help with DORA?
AIssure maps your AI systems into the firm's ICT risk-management and ICT third-party-risk obligations under DORA, with each finding cited to the regulatory text. It is a point-in-time, independent assessment — it tells you where AI sits against your resilience duties and what to remediate; it does not operate or monitor the systems it assesses.
Start with a thirty-minute read on your readiness.
A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.