Data Sovereignty / Source date:

DORA (Digital Operational Resilience Act) Takes Effect: Financial Services Data Sovereignty

DORA's 2023 implementation created new operational resilience requirements for EU financial services — mandating ICT risk frameworks, incident reporting, and third-party oversight.

Illustration of reviewers reconciling ICT provider contracts, locations and exit evidence in an operational register.

The Digital Operational Resilience Act entered into force in January and applies from 17 January 2025. That is eighteen months away, and the reason it belongs on this quarter's agenda rather than next year's is what happened last month: the European supervisory authorities opened consultation on the first batch of technical standards, covering the risk management framework, the criteria for classifying major incidents, the policy on providers supporting critical functions, and the template for the register of information. The rulebook is being drafted in public, right now, and the drafts tell you what the register will ask for. That is more useful than waiting for the final text.

Every previous rule asked whether you managed your providers. This one gives the supervisor a line to the provider

Financial regulators have addressed outsourcing for twenty years, always through the regulated firm. Guidelines told banks to assess providers, obtain audit rights and plan for exit, and the supervisor's remedy when a provider failed was to criticise the bank. DORA breaks that pattern. Providers designated as critical to the European financial sector come under a direct oversight framework, with lead overseers able to request information, conduct inspections and issue recommendations. Where a provider does not cooperate, supervisors can ultimately require financial entities to suspend or terminate the arrangement. That is a structural change, and it explains why the largest cloud and technology providers have been paying close attention to a financial regulation they are not themselves regulated by.

Three things that are genuinely new

Direct oversight of critical providers, as above, with designation to follow application of the regulation. The register of information. Every contractual arrangement for ICT services, recorded in a prescribed template, maintained at entity and group level, and made available to supervisors. This is not a policy document. It is a data set. Mandatory contractual content. Service descriptions and locations, data processing and storage locations, access, audit and inspection rights, subcontracting conditions, service levels, exit strategies and transition assistance, and cooperation with authorities. Contracts lacking these must be amended before application.

The register is the work, and it is larger than it sounds

Every entity in scope. Every ICT contract, including the small ones. Which business functions each supports, and whether those functions are critical or important. The subcontracting chain behind each provider. The locations where data is stored and processed. Contract dates, renewal terms and termination provisions. Almost no financial group currently holds this in one place. Contracts sit with procurement in one country, legal in another, and a line manager's inbox in a third. Building the register is nine to twelve months of collection and reconciliation for a mid-sized group, and it is a prerequisite for almost everything else: concentration analysis, exit planning and criticality mapping all depend on it. The template is in consultation now. Build against the draft, accept that fields will move, and start collecting.

Connect the register to evidenceQualitative article-derived preparation prompts, not the complete statutory register or a legal compliance determination.
Review areaEvidence question
FunctionWhich activity depends on the service?
Provider chainWhich contracting and subcontracting entities support it?
LocationWhere is data processed and accessed?
ExitWho owns the plan, and what has been tested?

Qualitative summary of this article's source text, not a measured outcome or performance estimate.

Contracts: the deadline is your renewal cycle, not January 2025

Any ICT agreement signed today that runs beyond application must contain the required provisions, or be amended before then. Amendment negotiations conducted in late 2024, under deadline, with a provider who knows you are obliged, will go badly. The practical response is a change of default from this quarter. Every new ICT contract and every renewal uses the compliant clause set, whether or not the counterparty is technically in scope, because the marginal cost at signature is nothing and the cost of retrofitting is real. Then work the existing portfolio in order of criticality and expiry date, not alphabetically.

Incident reporting: build the data capture before the thresholds settle

The regulation requires classification of ICT-related incidents against defined criteria and a staged reporting sequence — an initial notification, an intermediate report and a final report — with the detailed thresholds among the items currently in consultation. You cannot know the final numbers yet. You can know the dimensions, because they are visible in the draft: clients and counterparties affected, duration and downtime, geographical spread, data losses, criticality of the services affected, and economic impact. Most incident processes capture none of these reliably today. Instrument for them now, and the classification decision becomes arithmetic rather than a workshop conducted while an outage is ongoing.

Testing, and the bottleneck nobody has priced

Advanced threat-led penetration testing applies to entities identified as significant, on a multi-year cycle, conducted against live production systems and covering critical functions — including, where relevant, those delivered by providers, who are required to participate. The constraint is supply. The number of qualified testing providers is finite, the pool of entities required to test is large, and the first cycle will arrive for everyone at roughly the same time. Scope and book early.

Practical Guidance for DORA Compliance Assessment

  • Confirm which legal entities are in scope, including smaller EU subsidiaries.
  • Start the register now, against the draft template.
  • Map business functions to critical or important before mapping contracts.
  • Switch to the compliant clause set for all new contracts and renewals.
  • Document intra-group ICT services as third-party arrangements.
  • Instrument incident data for the classification dimensions.
  • Write exit plans for the arrangements you could not actually exit.
  • Book resilience testing capacity before the queue forms.

The Regional Angle

Three consequences matter for groups based here, and the first is the one that surprises people. If your group has a European banking, investment, payment or insurance subsidiary, and that subsidiary receives technology services from a shared services function in Dubai, Riyadh or Bahrain, the regulation treats your own group function as an ICT third-party service provider. Intra-group arrangements are explicitly within scope. That means a written contract containing the mandatory provisions, an entry in the register, defined service levels, audit and inspection rights exercisable against your own head office, documented subcontracting, and an exit plan describing how the European entity would obtain those services elsewhere. Most regional groups have no intra-group technology agreement at all, or a one-page recharge memorandum written for transfer pricing purposes. Those documents will not survive a supervisory review, and drafting a proper service agreement between affiliates is slower than it sounds because it forces the group to state what it actually delivers and at what standard — questions nobody has had to answer internally before. The second concerns regional technology firms selling into European financial institutions, and it goes further than the supply chain obligations arriving from other European legislation. The clause set your customers will present includes audit and inspection rights, which in practice means a European bank or its supervisor turning up at your premises in the Gulf, and cooperation obligations with authorities that have no jurisdiction over you. It also includes subcontracting controls that reach your own suppliers. Some of this is negotiable and some is not, and the distinction matters commercially: the access rights are effectively mandatory because your customer cannot sign without them, while scope, notice periods and cost allocation are genuinely open. Decide in advance what you will concede, price the compliance overhead into the contract rather than absorbing it, and be aware that success carries its own consequence — providers that become significant to enough European financial entities may find themselves designated critical and subject to oversight directly. The third is a collision between two residency logics. The regulation requires contracts to specify where data is stored and processed, and requires exit strategies that let a European entity move its data and resume the service elsewhere. Regional rules, meanwhile, push data into specific territories and sometimes onto specific platforms. Groups that have consolidated onto an in-country platform to satisfy local requirements, and then pooled the European subsidiary's data into the same environment, have created something that is difficult to describe in the register and harder to exit. Decide per data set which regime binds it, keep the European entity's data logically separable with its own extract path, and document the arrangement before a supervisor asks. Untangling a shared platform under a supervisory deadline is the worst version of this project.

The objection worth taking seriously

The strongest objection is timing. The regulation applies in January 2025, the technical standards are in consultation and will not be finalised until next year, and an organisation that mobilises now will build against drafts that change. Everyone who lived through the last major financial regulation remembers the rework: control frameworks designed against a consultation paper, then rebuilt when the final text moved a threshold. Waiting for the standards and running a focused twelve-month programme is a defensible plan, and it is cheaper. That is a fair argument about the parts of the work that depend on the final text, and the incident classification thresholds and reporting formats are exactly that. Do not build those yet. It does not apply to the two items that will determine whether you are ready, because neither depends on the drafting. The register is a data collection exercise across entities, contracts and functions, and its duration is fixed by how disorganised your contract estate is rather than by what the template eventually requires. Contract remediation is bounded by renewal cycles, which are calendar events you do not control; every agreement you sign between now and next summer without the required clauses is one you will renegotiate later at a disadvantage. Start those two. Defer the rest until the standards land.

Common Questions

Does this apply to us if our European entity is small?

Probably yes, with proportionality. The scope is broad across financial entity types, and a simplified risk management framework applies to certain smaller entities rather than an exemption from the regime.

Is the register really different from our existing outsourcing records?

Yes. Existing records typically cover material outsourcing only. The register covers ICT service arrangements broadly, with prescribed fields, function mapping and subcontracting detail that outsourcing registers rarely hold.

Can we rely on our provider's certifications?

Not as a substitute. Certifications support your assessment; they do not satisfy the contractual, register or exit requirements, all of which are obligations on you.

What should we expect over the next twelve months?

Expect the first batch of technical standards to be delivered to the Commission around the start of next year, with a second batch following in mid-2024, and expect the incident thresholds to attract the most comment in the meantime. Expect designation of critical providers to begin only after the regulation applies, which means the oversight framework will feel theoretical until 2025 and then move quickly. Expect supervisors to use the registers, once collected, to map sector-wide concentration on a handful of providers, and to ask pointed questions of the firms clustered on them. And expect contract amendment requests from European financial customers to begin arriving in the first half of next year, which is the moment this regulation stops being a European matter and starts being your inbox.


DORA Compliance Assessment — we scope your entities, build the register while the template is still in draft, and paper the intra-group services your European subsidiary depends on before a supervisor asks to see them.

Continue reading

Talk to OPS

Start with the operating problem.