Panorays
Guide to DORA Compliance and Third-Party Risk Management
Pages
9
Time to read
11 mins
Publication
Language
English
Pages
9
Time to read
11 mins
Publication
Language
English
This guide focuses on DORA, the Digital Operational Resilience Act, which is a regulation established by the European Union aimed at enhancing operational resilience within the financial sector. The document outlines the main areas of focus regarding DORA compliance, including ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, and information sharing. It explains that organizations must prepare for compliance by conducting risk assessments, implementing necessary security controls, and managing relationships with third-party ICT providers. This guide emphasizes the urgency of compliance as the enforcement date is set for January 17, 2025, and highlights the need for organizations to review their existing processes and address potential gaps. The guide also details the expectations for incident reporting and the monitoring of third, fourth, and fifth parties involved in ICT services, stressing the importance of a robust framework to mitigate risks associated with third-party dependencies.