Regulations & standards

DORA, explained.

The EU's Digital Operational Resilience Act — Regulation (EU) 2022/2554 — brings ICT risk, incident reporting, resilience testing and third-party risk under one supervisory regime. AI systems are ICT assets, so they sit inside it.

Jurisdiction
EU
Body
European Supervisory Authorities
Applies to
EU financial entities
Status
In force (Jan 2025)

What DORA is

DORA — the Digital Operational Resilience Act, Regulation (EU) 2022/2554 — is the EU's single, directly applicable framework for the digital operational resilience of the financial sector. Where operational-resilience expectations were previously scattered across guidelines and national rules, DORA consolidates them into one regulation that applies from 17 January 2025. As an EU regulation it binds financial entities directly, rather than requiring transposition into national law.

What it covers

DORA organises its requirements around four areas:

  • ICT risk management — a governance and control framework for identifying, protecting against and recovering from ICT risk.
  • ICT-related incident reporting — classifying and reporting major ICT-related incidents to supervisors on defined timelines.
  • Digital operational resilience testing — regular testing of ICT systems, up to advanced threat-led testing for the entities that warrant it.
  • ICT third-party risk — managing the risk from ICT service providers, including an oversight regime for those designated as critical third parties.

Why it reaches AI

DORA does not name AI, and it does not need to. An AI system is an ICT asset; where it is procured, hosted or served by a vendor, it is an ICT third-party service. That places AI inside the firm's resilience obligations by default — it must be captured in the ICT risk-management framework, considered in incident classification and resilience testing, and assessed as part of third-party risk. Treating an AI model as somehow outside operational-resilience duties is exactly the gap a supervisor will probe.

How AIssure maps to it

AIssure places your AI systems where DORA already expects to find them: inside the firm's ICT risk-management and ICT third-party-risk obligations. The assessment tests whether each AI use-case is captured in the resilience framework — governed, testable, and traceable to the provider behind it — and where it is not, it names the gap. Every finding is cited to the regulatory text, on a regulatory knowledge graph, so a resilience finding reads as evidence rather than assertion.

This is a point-in-time, independent opinion. AIssure attests to how AI sits against your DORA duties; it does not operate, host or monitor the systems it assesses — the separation is what keeps the assessment defensible.

Independence, deliberately

AIssure is an external assessment, not runtime tooling. It tells you where your AI systems stand against DORA's ICT and third-party obligations and what to remediate — it does not become part of the resilience stack it is judging. A control the firm runs cannot be objectively attested by the firm that runs it.

The primary source

The authoritative text is on EUR-Lex. Read it at Regulation (EU) 2022/2554, and see how DORA sits alongside the other regimes in AIssure's regulatory coverage.

FAQ

DORA — the questions we get.

What CISOs, resilience teams and AI assistants ask about the Digital Operational Resilience Act and where AI fits inside it.

What is DORA?

DORA is the Digital Operational Resilience Act — Regulation (EU) 2022/2554. It is an EU regulation that sets uniform requirements for the digital operational resilience of financial entities, covering ICT risk management, ICT-related incident reporting, digital operational resilience testing, and the management of ICT third-party risk. It applies from 17 January 2025.

Who does DORA apply to?

A broad range of EU financial entities — banks, investment firms, insurers, payment and e-money institutions, crypto-asset service providers, and more — together with the ICT third-party providers that serve them, including those designated as critical third parties. If your firm is supervised in the EU and depends on ICT, DORA is in scope.

Why does DORA matter for AI systems?

Because an AI system is an ICT asset — and, where it is bought or hosted, an ICT third-party service. That places AI squarely inside a firm's DORA obligations: it has to be captured in ICT risk management, its failure modes considered in resilience testing, and its provider assessed under third-party risk. AI is not exempt from operational-resilience duties because it is 'AI'.

How does AIssure help with DORA?

AIssure maps your AI systems into the firm's ICT risk-management and ICT third-party-risk obligations under DORA, with each finding cited to the regulatory text. It is a point-in-time, independent assessment — it tells you where AI sits against your resilience duties and what to remediate; it does not operate or monitor the systems it assesses.

Next step

Start with a thirty-minute read on your readiness.

A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.