Is Your Audit Committee Ready for DORA Oversight in 2026? | INFORMD Executive Briefing

Is Your Audit Committee Ready for DORA Oversight in 2026?

How should UK audit committees oversee DORA compliance in 2026? By demanding independent assurance over ICT risk registers, third-party concentration and resilience testing results — not delegating the mandate to the CISO’s slide deck.

The Digital Operational Resilience Act (Regulation (EU) 2022/2554), which entered into application on 17 January 2025, sets binding requirements for ICT risk management, incident reporting, resilience testing and third-party oversight across EU-regulated financial entities. Most UK groups feel its reach directly, through EU subsidiaries, EU clients or EU-facing ICT contracts, and increasingly use it as the reference standard against which the FCA and PRA’s own operational resilience regime is benchmarked. For audit committees, that makes DORA a governance question, not a technology one.

What Does DORA Actually Require of UK Financial Groups?

DORA rests on five pillars: ICT risk management frameworks approved at management-body level; incident classification and reporting to regulators; digital operational resilience testing, including advanced threat-led penetration testing (TLPT) for significant entities; third-party risk management, anchored by a detailed Register of Information (RoI) covering every ICT contract; and structured information-sharing on cyber threats. According to the European Supervisory Authorities, in-scope entities must run basic resilience testing annually and TLPT at least once every three years — a cadence the audit committee should track, not merely note in a compliance update.

For groups without direct EU authorisation, exposure typically arrives through EU-domiciled subsidiaries, branches, or ICT providers who themselves must comply and pass obligations down the supply chain. Audit committees should establish, in writing, exactly where their group sits in that chain before assuming DORA is someone else’s problem.

Executive Action:

  • Ask management to map every legal entity and ICT contract against DORA’s scope criteria, not just the group’s EU-regulated subsidiaries
  • Request the current Register of Information and confirm who owns its accuracy
  • Set a standing agenda item for TLPT and resilience-testing results, not just incident summaries

What Should the Audit Committee Demand From Management on ICT Risk?

The CISO owns implementation; the audit committee owns assurance. That distinction matters because ICT risk management under DORA sits alongside financial and internal-controls reporting as a matter for which the committee is accountable to the main board. In practice, that means the committee should see independently validated evidence — internal audit findings, external assurance reports, or regulator correspondence — rather than management’s self-assessment alone.

Three items deserve standing scrutiny: the accuracy and completeness of the Register of Information, since supervisors have flagged RoI submissions as a common source of early enforcement friction; the outcome and remediation timeline for resilience testing; and whether incident escalation thresholds are calibrated to the board’s actual risk appetite rather than a generic regulatory minimum. A committee that only asks “are we compliant” is asking the wrong question; the right one is “what evidence proves it, and who verified that evidence independently.”

Executive Action:

  • Require internal audit to give an independent opinion on DORA readiness at least annually, separate from IT’s self-assessment
  • Set incident escalation and reporting thresholds explicitly, tied to board-approved risk appetite
  • Document RoI ownership and sign-off in committee minutes, not just IT governance papers

How Does DORA Oversight Differ From the UK’s Own Operational Resilience Regime?

UK firms already operate under a domestic regime. According to the Bank of England, FCA and PRA’s joint operational resilience policy (PS21/3), firms were required to identify important business services and set impact tolerances by March 2022, with full ability to remain within those tolerances during severe disruption mandated by March 2025. That regime is principles-based and outcomes-focused; DORA is prescriptive, with detailed regulatory technical standards governing testing frequency, incident classification and contractual terms with ICT providers.

The practical governance risk is treating the two as duplicates and running a single, lighter-touch process for both. They are not the same test. A firm can meet UK impact-tolerance requirements while still lacking a DORA-compliant Register of Information, or vice versa. The Bank of England is also developing a separate critical third-party regime for systemically important ICT providers under the Financial Services and Markets Act 2023 — a third framework audit committees will need to track as it matures, alongside the wider UK Cyber Security and Resilience Bill working through Parliament.

Executive Action:

  • Map DORA, UK operational resilience (PS21/3) and the emerging critical third-party regime as three distinct compliance tracks, not one
  • Ask which framework is the binding constraint for each ICT service, and confirm it in writing
  • Review the group’s DORA compliance checklist and prior DORA enforcement briefing to close gaps between the CISO’s operational build and the committee’s assurance evidence

What Questions Should NEDs Ask About Third-Party and Concentration Risk?

DORA’s third-party provisions exist because financial services now depend heavily on a small number of cloud and infrastructure providers, a concentration the Bank of England has repeatedly flagged as a systemic vulnerability in its Financial Stability Reports. Audit committees should ask management to name the group’s critical ICT providers explicitly, test contractual exit and step-in rights, and confirm that concentration risk is assessed at group level rather than contract-by-contract, where the aggregate exposure is easy to miss. Benchmark the exercise against INFORMD’s technology strategy review template or run the group through our AI governance and risk assessment tools to pressure-test existing oversight.

Executive Action:

  • Request a named list of critical ICT third parties and their concentration risk rating
  • Confirm exit strategies and substitutability have been tested, not just documented
  • Ask whether any single provider failure could breach impact tolerances across multiple business services simultaneously

INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).

Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk. Questions for our editorial team? Get in touch.

Does DORA apply to UK-only financial firms with no EU presence?

Not directly. DORA binds EU-authorised financial entities and their ICT providers. UK-only firms are typically drawn in indirectly, through EU subsidiaries, EU clients, or shared ICT contracts with EU-regulated group entities.

Who owns DORA oversight — the CISO or the audit committee?

The CISO owns implementation and evidence-gathering. The audit committee owns independent assurance that the evidence is accurate and complete, reporting into the main board alongside financial and internal-controls oversight.

How is DORA different from the FCA and PRA’s operational resilience rules?

PS21/3 is principles-based, focused on impact tolerances for important business services. DORA is prescriptive, with binding technical standards on testing frequency, incident classification and ICT contract terms. Firms must treat them as separate tracks.

What is the Register of Information under DORA?

A structured inventory of every ICT contract an in-scope entity holds, covering criticality, providers and sub-outsourcing chains. Supervisors have identified RoI inaccuracy as a common early source of enforcement attention.

Similar Posts