1. Gap Analysis Process
Many Irish financial entities have completed their gap assessment and have refined this into their implementation plans. However, there are still firms who have not yet commenced, approved or concluded this gap analysis. Considering the Level 1 text is set in stone, in-scope entities should conclude their L1 gap analysis as soon as possible. With the deadline fast approaching, this may leave minimal time available for sufficient remediation to be undertaken.
The technical standards (RTS and ITS) are still a major topic of discussion. Although we have seen drafts of both the first and second batch of technical standards, neither are fully official.? With the European elections imminent, it is expected that the Level 2 standards will not be fully finalised until September 2024 at the earliest. This leaves financial entities in a precarious position, particularly if they have not commenced a Level 2 gap analysis of the latest draft standards. Since all DORA Level 1 and Level 2 requirements are mandatory, and Level 1 is further supplemented by more detailed Level 2 standards, firms should perform a comprehensive gap analysis of both levels to identify any gaps early on in the process.

David Spollen
2. Adequate Resourcing
Another area of difficulty relates to resources, including people, processes, and technology. Regarding people, we continue to see competing priorities within firms, impacting the same key Senior Management Roles (SMRs) such as IT Risk Managers, IT Disaster Recovery Analysts, and Cyber Analysts. Concerning processes, firms are struggling to allocate the necessary time, effort, and resources to update their end-to-end IT and IS processes promptly. On the technology front, achieving DORA compliance requires a focus on minimum mandatory standards. However, less mature firms face challenges due to the assumed level of tooling needed, such as ICT Risk Management, ICT Third Party Risk Management, Vulnerability Scanning, and IT Service Management. Additionally, some of DORA’s more technical requirements, like network segmentation, are proving difficult to interpret and implement.
3. What does ‘DORA ready’ actually mean?
Understanding what it means to be “DORA ready” is a significant challenge. How robust and well-documented should processes and controls be? What level of evidence is needed to demonstrate DORA compliance? To what extent should there be an independent review, such as via the second or third line of defence, on DORA compliance efforts?
Many firms are testing the effectiveness of their updated controls where possible, while less advanced firms focus on “test of design” before the January deadline, as “test of effectiveness” is harder to complete within short timelines. More mature firms have an embedded process aligned with DORA’s requirement for a “three lines of defence” approach, ensuring second-line oversight and third-line assurance. However, many firms lack the time or resources to reach this level of maturity before the deadline, though it remains an ideal goal.
What are the some of the major lessons learned to date and what can firms do to address these before January 2025?
1. Critical or Important Functions (CIFs), the Register of Information (RoI) and ICT third party contracts remain the top challenge. Firms are still struggling to identify their CIFs, have not given sufficient time to the RoI and are grappling with their approach to contract remediation. As these are cornerstone aspects of DORA compliance, they require early and robust completion.
2. Another major lesson learned relates to the build-out of a comprehensive ICT Risk Management Framework (ICTRMF), as required by DORA. Several firms have not realised or accepted the need to define a robust ICTRMF. However, the ICTRMF as part of best practice should also align to other core frameworks (e.g. Operational Risk Management, Individual Accountability Framework, Operational Resilience and Third-Party Risk Management).
3. With respect to the timing and effectiveness of DORA programme itself, we have seen some entities not focussed enough on minimum mandatory compliance, which can lead to a misalignment with their overarching Digital Operational Resilience Strategy (a specific requirement in its own right under DORA).
What can firms expect in the coming months?
There are further regulatory developments to come. The technical standards will finalise in September 2024 necessitating a final assessment of these by firms (or a “top-up” assessment in the case of others). The European Supervisory Authorities’ (ESA) dry run on the Register of Information will help participants to identify their ICT services, contracts and CIFs. The ESAs will conduct further data benchmarking over financial entities (akin to the ICT third party contractual exercise previously conducted via national competent authorities) and the “Oversight Framework” of critical ICT third parties (CTPPs) will become clarified with the eventual list of CTPPs becoming publicised.
Some firms are already starting to talk about potential non-compliance (or partial compliance) given the scale of work to be done and their expectation that this may not completed ahead of the January deadline. Although non-compliance may well be a reality for some entities, the consequences are potentially severe and best avoided. Entities found to be in violation of DORA’s requirements may face fines of up to 2% of their total annual worldwide turnover or, in the case of an individual, a maximum fine of EUR 1,000,000. The amount of the fine will depend on the severity of the violation and the financial entity’s cooperation with authorities.
For those in a healthier position, we will no doubt see more independent DORA programme reviews commissioned. Coupled with this, the Central Bank of Ireland (CBI) continues to strengthen its own capabilities and is planning its local supervision, which we expect to hear more about across the second half of 2024. In addition, the ESAs have recently launched public recruitment campaigns for a number of select roles which they’re looking to fill as part of the to-be “Oversight Framework” which will oversee DORA from the perspective of the eventual list of ICT critical third party providers.