DORA Compliance Checklist for UK Financial Services: What Boards Must Own in 2026
DORA Compliance Checklist for UK Financial Services: What Boards Must Own in 2026
The EU Digital Operational Resilience Act (DORA) became fully applicable on 17 January 2025. UK firms that assumed DORA was a continental matter are facing supervisory pressure. If your firm operates in the EU, has an EU-authorised subsidiary, or provides services to EU-regulated financial entities, DORA applies to those activities. Here is what boards must understand and what they must own.
Does DORA apply to your UK firm?
DORA applies to financial entities operating within the EU. The following UK firm profiles are in scope:
- UK bank or insurer with an EU branch or subsidiary. The EU entity is directly in scope. The UK parent board bears responsibility for group-level ICT risk management that affects the EU entity.
- UK firm authorised in an EU member state (e.g., under MiFID II passport equivalent arrangements). The authorised entity is directly subject to DORA and the local competent authority.
- UK firm that is a critical ICT third-party provider (CTPP) to EU financial entities. DORA’s third-party risk provisions pull UK technology vendors, cloud providers, and data service firms into scope if their EU-based financial services clients designate them as critical.
- UK firm exploring EU re-entry post-Brexit. Any re-authorisation strategy must be DORA-compliant from day one.
The five DORA pillars — and what boards must ask
DORA is structured around five pillars. Each has board-level accountability implications.
1. ICT Risk Management
Boards must approve the ICT risk management framework and ensure it is reviewed at least annually. This is not a CIO/CISO responsibility alone — the board must formally adopt and periodically review the framework.
2. ICT Incident Reporting
Material ICT incidents must be reported to regulators within defined timeframes (initial notification within 4 hours of classification; intermediate report within 72 hours; final report within one month). Boards must ensure the incident classification and escalation process is tested and documented.
3. Digital Operational Resilience Testing
DORA requires Threat-Led Penetration Testing (TLPT) for significant financial entities. The board must approve the testing programme and be briefed on findings. This is not delegable to the CIO — regulators expect board-level ownership of the outcomes.
4. ICT Third-Party Risk Management
Financial entities must maintain a register of all ICT third-party providers and conduct due diligence proportionate to the criticality of each provider. The register must be reportable to the competent authority on request. Boards should ask whether the third-party risk register is complete, current, and owned at the right level.
5. Information and Intelligence Sharing
DORA encourages (and in some cases requires) participation in cyber threat intelligence sharing arrangements. While this is not the highest-risk pillar for boards, firms should have a position on whether they participate in the appropriate industry sharing communities.
- Has the board formally adopted and signed off the ICT risk management framework?
- Has the board reviewed the ICT third-party provider register? Is it complete?
- Is the major incident response and notification process documented and tested?
- Has the firm completed a DORA gap assessment against all five pillars?
- Is there a TLPT programme in place for significant entities?
- Has legal counsel reviewed ICT third-party contracts for DORA compliance clauses?
- Is there a board-level owner (typically CRO or CISO) accountable for DORA compliance?
The third-party risk obligation: what it means in practice
DORA’s third-party risk requirements are the most operationally complex pillar. Financial entities must:
- Maintain a register of all ICT third-party service providers (not just “critical” ones)
- Conduct risk assessments proportionate to the criticality and concentration risk of each provider
- Include specific contractual provisions in ICT third-party agreements — covering audit rights, service level standards, incident notification, and termination rights
- Monitor concentration risk — the degree to which the firm depends on a single provider or a small number of providers for critical functions
For many UK firms, the most immediate challenge is the contractual compliance requirement. Legacy contracts with major cloud providers and fintech infrastructure vendors will not contain the required DORA provisions. Firms with EU entities must negotiate contract amendments — a process that can take six to twelve months with large providers.
- Complete the ICT third-party provider register — every provider, not just tier-one
- Classify providers by criticality (critical / important / standard)
- Review contracts for critical and important providers against DORA’s minimum contractual requirements
- Prioritise renegotiation of legacy contracts with the highest-criticality providers
- Assess concentration risk — flag any function dependent on a single third party
What the PRA and FCA expect from UK boards with EU exposure
The PRA and FCA have not directly adopted DORA into UK law. However, both regulators have incorporated DORA-aligned expectations into their operational resilience frameworks. The PRA’s supervisory statement SS1/21 and the FCA’s operational resilience rules already require financial entities to identify important business services and set impact tolerances — concepts that closely mirror DORA’s requirements.
For UK boards with EU subsidiaries, PRA/FCA supervisors are increasingly asking: “How do you assure the board that your EU entity’s DORA compliance is adequate?” Boards that cannot answer this with specifics — not just assurances from management — face heightened supervisory risk.
Enforcement: what the consequences look like
National Competent Authorities (NCAs) — such as BaFin, AMF, and the ECB — are the primary enforcement bodies for DORA, with direct power to penalise financial entities. The European Supervisory Authorities (ESAs — EBA, ESMA, and EIOPA) act as coordinators and standards-setters, and have direct oversight power only over Critical ICT Third-Party Providers (CTPPs).
For financial entities, administrative fines are set by member states and can reach up to 2% of total annual worldwide turnover. The 1% of average daily global turnover periodic penalty applies specifically to Critical ICT Third-Party Providers (CTPPs) to compel compliance with oversight requests — not to financial entities directly. For systemic institutions, the supervisory consequences go beyond financial penalties — DORA non-compliance can trigger operational restrictions or impact authorisation status.
DORA, the UK Cyber Resilience Bill, PRA/FCA operational resilience updates — all covered in Informd’s executive briefing library.
