
Case Study · Financial services / Banking
DORA readiness for a mid-sized financial institution
- 5 monthsprogramme duration
- 38gaps closed of those identified
- 12critical ICT providers mapped
The challenge
A mid-sized financial institution needed to align with the Digital Operational Resilience Act (DORA) ahead of the regulatory deadlines. The IT function was operationally solid, but the DORA scope required a level of formalisation and documentary evidence that was not yet structured.
The most critical points were ICT risk governance, an incident classification and reporting process consistent with regulatory thresholds, and above all third-party ICT provider management, with a register of agreements and a critical-provider assessment to build almost from scratch.
All of this without overloading a team already busy with day-to-day operations, and while avoiding a purely formal approach disconnected from operational reality.
My approach
I opened the programme with a gap analysis against DORA’s five pillars, producing a clear view of what was already in place, what needed formalising, and what genuinely had to be built. The aim was to avoid duplicating existing controls.
On ICT risk I helped operationalise a governance framework with roles, responsibilities, and periodic reporting to the management body. On incident reporting I defined classification criteria, thresholds, and flows consistent with the obligations, integrating them into the incident management processes already in use.
For ICT providers I built the register of contractual arrangements and a methodology to identify critical providers, with a review of key contract clauses and exit strategies. I then set up an operational resilience testing cycle proportionate to the institution’s profile.
Readiness was delivered as a programme transferable to the internal team, not as a one-off exercise: documentation, registers, and processes designed to be sustained over time.
Related
You might also like
DORADORA for the financial sector: digital operational resilience
Regulation (EU) 2022/2554 harmonises ICT risk management, incident reporting, resilience testing and oversight of critical providers.21 Nov 2025 · 4 min read
ComplianceProportionate compliance: why ticking boxes does not protect you
Formal compliance and real risk are not the same thing. Evidence and measured exposure are where looking secure and being secure diverge.17 Jan 2026 · 4 min read