The essentials
DORA connects governance, operations, cyber, continuity and suppliers around the financial functions. The subject boils down neither to a contract register nor to an annual technical test.
1. Confirm the entity and the functions in scope
The regulatory category, the group, the critical or important functions and the ICT dependencies must be qualified before calibrating the requirements and proportionality.
2. Make the risk framework usable by leadership
The mapping must connect functions, assets, data, scenarios, tolerances, decisions and residual risks. It must be able to explain why a measure is funded, deferred or compensated.
3. Unify incident, crisis and notification
Technical detection, regulatory qualification, business impact and communication must share a chronology and criteria. An exercise must test the interfaces, not just the written plan.
4. Treat the third-party register as a steering tool
The register of contractual arrangements becomes useful when it makes it possible to identify concentration, subcontracting, shared dependencies, audit rights, service levels and exit capability.
5. Organise a risk-based testing programme
Scenarios, scopes, evidence, remediation and retesting must follow the criticality of the functions. Documentary compliance is no substitute for demonstrating that the organisation can maintain or recover the service.