Programmers Working On Software In Office. Team Of People Coding New App. High Resolution

Ready for the next DORA audit?


Learn about the latest DORA regulatory developments, early findings and practical remedies.


In brief

  • DORA supervision is shifting toward testing operational resilience in practice, not just reviewing policies.
  • Early audits reveal significant gaps and misalignment across all four DORA pillars.
  • Scalable operating models, automation and structured evidence are becoming essential.

A year after it became fully applicable in January 2025, the Digital Operational Resilience Act (DORA) has entered its supervisory phase. Recent regulatory developments and the first published observations from European supervisors, including the Bundesanstalt für Finanzdienstleistungsaufsicht (BaFin) in Germany and the Autorité de Contrôle Prudentiel et de Résolution (ACPR) in France, provide insight into the current state of financial institutions’ digital operational resilience, highlighting both areas of progress and the pain points identified.

Meanwhile, the focus of supervision is moving beyond framework design toward demonstrable resilience in practice. Authorities are no longer just checking whether policies exist, but rather whether critical services continue to operate during disruption and whether institutions can prove this with structured evidence.

From implementation to enforcement

Since mid-2025, several regulatory developments have clarified how DORA will be supervised in practice and what financial institutions should expect in upcoming audits.

upcoming audits

Taken together, these developments signal a clear shift. While 2025 was largely an “accompaniment year” focused on gauging the maturity of the implementation processes and design effectiveness tests in place, 2026 marks the beginning of deeper supervisory enforcement and higher expectations relating to actual operational effectiveness. For financial institutions, this means DORA compliance will increasingly be assessed through operational evidence rather than implementation roadmaps and policy work.

Implications for Swiss-based groups

Although DORA directly applies to EU-regulated entities, supervision effectively follows services.

In practice, Swiss headquarters or other Swiss legal entities providing ICT services to EU entities are indirectly drawn into DORA supervision.

What the first regulatory DORA audits reveal

Initial DORA reviews across Europe show a differentiated and increasingly granular supervisory model. Whereas the Swiss Financial Market Supervisory Authority (FINMA) publishes concrete audit programs for specific operational resilience topics that apply to all banks, subject only to limited size-based exemptions, there is no one-size-fits-all DORA audit program across the EU.

Supervisory approaches vary by jurisdiction and institution. In Poland, France and Luxembourg, regulators conduct direct audits. In Germany and Liechtenstein, DORA audits are performed by external auditors. Italy follows a differentiated approach, combining self-assessments for banks, European Central Bank (ECB) onsite inspections for significant banks and Istituto per la Vigilanza sulle Assicurazioni (IVASS) inspections in the insurance sector.

Individual audit programs are tailored to each institution’s size, business model and risk profile. At the same time, the scope of audits has broadened significantly. DORA audits combine governance, ICT risk management, detection and response capabilities, business continuity, testing and third-party risk management into integrated supervisory fields.

Supervisors report that while all inspected institutions have initiated DORA programs, operationalization frequently lags behind policy updates. In several cases, documentation was adjusted shortly before inspections, yet lacked sufficient depth, coherence or institution-specific tailoring.

The four pillars under supervisory scrutiny

The first DORA audits confirm that supervisory focus aligns closely with the four DORA pillars. However, the emphasis is shifting from framework validation to checking the practical implementation of operational resilience concepts in the next audit cycle.

Addressing regulatory findings – what institutions need to change now

The first supervisory findings point to a clear conclusion: DORA compliance is evolving from a framework exercise into an operating model challenge. As regulatory expectations for complete, consistent and scalable third-party oversight increase, leading financial institutions are shifting toward centralized, industrialized TPRM models enabled by automation, data-driven controls, assurance mechanisms for group environments and specialized services.

To effectively ensure the operational resilience of their digital operations against ICT risk, financial institutions need to work on the pain points identified. Key points commonly relate to ICT inventories and interdependencies, including external relationships. These need to be identified and defined as the foundation for effective risk management. Building on that, institutions must close the gaps and put comprehensive business continuity and recovery policies and plans in place, along with testing and incident detection mechanisms, to strengthen their defense capabilities. Once the groundwork has been done, attention can turn to demonstrating resilience and related documentation and reporting requirements. In short, there are three imperatives: Improve underlying processes, improve operations and improve assurance.

Improve processes – increase automation and obtain data-driven control

Many of the weaknesses flagged by supervisors – incomplete inventories, fragmented monitoring and inconsistent evidence – are closely linked to manual processes and fragmented tooling. To address these challenges, institutions are increasingly investing in automation and data-driven control environments.

Leading organizations are adopting workflow tools, AI-driven due diligence questionnaire (DDQ) reviews and automated evidence validation. Organizations are investing in unified, structured data models and underlying data quality to enable better vendor visibility, concentration-risk insights and readiness for automation and AI.

Leveraging appropriate tooling and AI not only helps organizations achieve DORA compliance across all four pillars, but also enhances their operational efficiency, reduces manual effort, team workload and cost as well as fosters a culture of continuous improvement in operational resilience.

Institutions increasingly require:

  • Automated asset discovery and dependency mapping, with particular attention placed on critical services, to support completeness, consistency and documentation in relation to ICT risk management (Pillar 1), as well as automated vulnerability and patch management tracking
  • Workflow-driven incident classification and reporting, with centralized monitoring dashboards and integrated systems automating escalation processes (Pillar 2)
  • Integrated tools for frequent, documented resilience testing (Pillar 3)
  • Structured and integrated third-party registers to demonstrate third-party risk management (Pillar 4)

AI- and machine learning-based solutions are likewise beginning to support several of these areas, particularly in analyzing incident patterns, identifying anomalies and automating parts of third-party due diligence or control validation.

By reducing manual effort and improving data quality, automation helps institutions scale resilience processes while simultaneously improving audit readiness and reducing operational costs.

Improve delivery – review operational resilience activities

The growing complexity of ICT environments and supply chains is driving the adoption of more industrialized operating models for key resilience functions. These models combine specialized expertise with standardized processes and technology-enabled workflows. Examples include:

  • Centralized TPRM functions coordinating assessments across the organization
  • Security operations centers (SOCs) providing continuous monitoring and incident detection
  • Automated incident reporting capabilities aligned with regulatory reporting timelines
  • Dedicated resilience testing teams responsible for scenario testing and TLPT
  • Threat Intelligence teams identifying and monitoring threats that are specific to the institution and its third parties

Such approaches allow institutions to combine specialized expertise with standardized processes and tooling.

scalable operating models

In particular, scalable operating models can help address one of the most resource-intensive areas of DORA implementation: third-party risk management. As the number of ICT service providers and subcontractors grows, maintaining comprehensive registers, conducting due diligence and monitoring concentration risks requires significant operational capacity.

To address these challenges, some institutions are exploring more structured delivery models for TPRM activities, including co-sourced or managed services approaches. Governance remains with the regulated entity, but operational execution becomes more scalable, transparent and easier to supervise. When implemented within a clear governance framework, such models can support institutions in:

  • Increasing efficiency and streamlining end-to-end TPRM processes
  • Supporting the business with consistent, high-quality risk assessments, continuous monitoring and real-time threat detection across third parties and subcontractors
  • Improving data quality to enable greater use of automation and AI‑supported analysis
  • Accelerating onboarding and reassessment cycles for ICT providers, improving time to market
  • Reducing reliance on scarce specialist expertise in areas such as cyber risk, vendor risk and resilience testing
  • Creating greater cost predictability while avoiding additional technology investments

By combining standardized processes, specialist expertise and improved data management, such operating models can help institutions scale their resilience capabilities while maintaining strong governance and regulatory accountability.

Improve assurance – implement mechanisms for group environments

Multiple regulated entities, shared service providers and cross-border ICT setups mean that, for corporate groups, DORA implementation challenges are often structural as much as technical. To manage the complexity of third-party risk management in group structures, coordinated assurance approaches can help organizations meet their TPRM requirements under DORA by enhancing transparency and providing scalable evidence across intra-group third parties and outsourced services. Properly scoped assurance mechanisms confirm the operating effectiveness of key controls and reduce duplicated audit effort.

Corporate groups can effectively use properly scoped assurance mechanisms to:

  • Reduce DORA audit effort through scope tailored to DORA requirements and by applying appropriate reporting standards. Issued by qualified auditors, assurance reports confirm the operating effectiveness of key controls.
  • Avoid duplicated audit effort by producing a single audit report on intra-group third parties for distribution to all legal entities using the ICT service instead of having each legal entity perform a separate audit.
  • Define the DORA narrative (i.e., a clear, coherent explanation of how the organization manages digital operational resilience and meets DORA requirements) to provide a standardized, group-wide assessment framework aligned with DORA requirements.
  • Clarify accountability and roles between regulated entities and intra-group ICT providers.
  • Strengthen ICT third-party risk management by obtaining an independent review of completeness of the ICT third-party register, criticality assessments and monitoring processes.
  • Validate operational resilience based on an assessment of the design and execution of controls.
  • Support board accountability and supervisory dialogue by providing structured risk insights.

DORA attestation reports allow organizations to change the audit narrative from reactive responses to proactive demonstration. With a clearly defined framework in place, transparent mapping of controls to requirements and independent third-party validation of effectiveness, organizations can take control of the audit process.

Looking ahead: the next DORA audit cycle

The first DORA inspections confirm a fundamental shift. Across jurisdictions, one common theme is emerging: more deep-dives and operating effectiveness testing are forthcoming.

DORA has shifted from checking policies to testing whether digital operational resilience works in practice.

Supervisors are no longer assessing only whether institutions have implemented policies. They are assessing whether digital operational resilience works in practice – across risk management, detection, continuity and third-party ecosystems. Supervisors now expect full operationalization. In Germany, for instance, findings related to operating effectiveness will be classified as regulatory irregularities starting from 2026.

Rather than establishing a one-time compliance exercise, DORA in effect establishes ongoing supervision of how financial institutions operate their technology services. Institutions that rely on documentation alone will face increasing supervisory pressure. Those that can demonstrate resilience in operation will be better prepared for the next audit cycle.


Summary

Early DORA audits in the EU show that, while many institutions have updated their “DORA-ready” policies, operationalization, data quality and governance remain uneven. Common weaknesses appear across all four DORA pillars. For Swiss organizations, intra-group service arrangements create indirect exposure to DORA. As audits shift toward operationalization and testing in the next cycle, financial institutions need effective, scalable operating models and an efficient way to demonstrate compliance.

Acknowledgement

Many thanks to Yulia Brun, Isabella Scheibler and Marc Schenk for their valuable contribution to this article.


FAQs

Related articles


Explore how EY can help you with Cybersecurity

Secure Creators can innovate and adopt emerging technology without compromising cybersecurity. Explore our service offering.

Programmers Working On Software In Office. Team Of People Coding New App. High Resolution

About this article

Authors

Request for proposal (RFP) - exclusively for Switzerland

|

Submit your request now!