Not long ago I was consulting a group of high level bank employees in the EU. In the beginning of the meeting the head of the bank’s Legal department asked me “Who is DORA for?”. He did not seek an answer such as “financial sector entities”, which he already knew. He wanted to clarify who among themselves is the most accountable when dealing with DORA requirements and compliance.
With us in the room were also the head of IT department, the Chief Risk Manager, head of HR and the head of PR. It was evident they were caught up in this discussion for some time and were seeking an opinion from outside their echo-chamber.
My short answer was “DORA is for everyone in your bank and even beyond- to the third party service providers. Because some of the employees must be at least aware about DORA. Some of them have daily operational tasks related to DORA and some carry the ultimate legal responsibility for compliance and third party risk management. So everyone in a different way.” The attendance was extensive, but that did not represent the top management body, which is responsible for DORA compliance under article 5.
They all had a role in the bank’s functioning under DORA- the legal department must follow the regulation and advise as well as prepare legal contracts with third party service providers. The IT department performs the technical aspect of mitigating risks from cyberspace, the risk management must constantly assess and manage the risks from third party service providers, the HR ensures the staff has the required level of awareness and competences, and the PR department must communicate with regulators and interested parties.
These are just a small number of aspects to consider about this deceptively simple question regarding DORA. Above all, the top governing body carries the ultimate, non-delegable responsibility for aligning the financial institution in scope of DORA in compliance with the regulation.


