DORA Board Governance Obligations 2026: What the Management Body Must Actually Do
Under DORA Article 5, the management body of every in-scope financial entity is personally responsible for approving, overseeing, and periodically reviewing the ICT risk management framework — not the CIO, not the IT department. Supervisors across the EU are now checking board minutes, training records, and governance documentation. If your board cannot demonstrate active ownership of ICT risk strategy, you have a material compliance gap.
DORA Art. 5 — Management Body: The governing body of a financial entity that bears ultimate responsibility for defining, approving and overseeing the implementation of all arrangements relating to ICT risk management. The obligation cannot be delegated to a committee or outsourced to a third-party provider.
67%
"67% of management bodies at DORA in-scope entities have not yet updated board-level ICT risk ownership structures to meet Article 5 requirements."
— EBA Supervisory Convergence Report, 2025
What does DORA Article 5 actually require from the board?
Article 5 sets out eight specific obligations for the management body. The key ones regulators are focusing on in 2026 supervisory reviews:
- Approve and periodically review the ICT risk management framework (not just receive a report)
- Define and own the ICT risk appetite — in writing, with quantified thresholds
- Approve the ICT strategy ensuring alignment with the overall business strategy
- Receive regular reporting on ICT incidents, third-party risks, and audit findings
- Ensure adequate resources and training — board members must maintain sufficient ICT risk knowledge
What is the difference between board duties and IT department duties under DORA?
| Obligation | Management Body | IT / CISO |
|---|---|---|
| ICT risk framework approval | Approve & own | Design & implement |
| ICT risk appetite | Define & document | Operationalise |
| Incident reporting to regulator | Accountable | Prepare & submit |
| Third-party ICT risk oversight | Approve policy & review | Due diligence & monitoring |
| DORA training & knowledge | Mandatory for board members | Technical training |
What documentation must the board produce to satisfy supervisors?
Board-approved ICT risk management framework
A standalone document (not embedded in general risk policy) with explicit board signature. Must be reviewed at least annually.
Board minutes evidencing active oversight
Supervisors review minutes for evidence of genuine discussion — not just rubber-stamping IT reports. Record questions asked, decisions made, and follow-up actions.
ICT risk appetite statement
Quantified tolerances for system downtime, data loss, and third-party dependency concentration. Reviewed at least annually and after any major incident.
Board training records
Evidence that board members have completed DORA-specific ICT risk training. Frequency and depth are not prescribed — but supervisors expect at least annual structured sessions.
What are the most common board-level DORA gaps regulators find?
Based on EBA and national competent authority supervisory findings published in 2025, the top five board-level gaps are: (1) ICT risk framework not separately approved by the board — embedded in general risk policy; (2) No quantified risk appetite; (3) Board minutes show no substantive ICT discussion; (4) No board training records for DORA; (5) Third-party ICT risk policy approved at CIO level, not board level.
Is your board's DORA documentation audit-ready?
IgeraLegal generates board-ready DORA governance documentation and answers compliance queries citing the exact regulation article.
Try IgeraLegal free for 14 daysNo credit card · Setup under 24 hours
How IgeraLegal supports DORA board governance
How IgeraLegal answers your team
Board member question:
"Do we need a separate board resolution to approve the ICT risk framework, or is it enough to include it in the annual risk committee report?"
IgeraLegal answers:
"Under DORA Art. 5(2), the management body must 'define, approve, oversee and be responsible for' the ICT risk management framework. The EBA supervisory guidance (JC 2023 86) indicates this requires a standalone board-level approval — not merely endorsement via a committee report. A formal board resolution with documented discussion is expected."
Need to brief your board on DORA obligations before the next supervisory review?
IgeraLegal produces board briefing packs and answers Article 5 queries with exact regulatory citations in seconds.
Book a free IgeraLegal demo →In summary: DORA board governance obligations
- DORA Art. 5 places personal legal responsibility on the management body, not the IT department
- Boards must approve, own and periodically review the ICT risk management framework
- A quantified ICT risk appetite statement is required — not optional
- Board minutes must show substantive ICT risk discussion, not passive approval
- Board members must maintain sufficient ICT risk knowledge — training records are audited
Frequently asked questions: DORA board governance
Can the board delegate DORA Art. 5 responsibilities to a risk committee?
Partial delegation is allowed — the board can task a risk or audit committee with monitoring. However, the management body retains ultimate accountability. Approval of the ICT risk framework and the risk appetite statement must remain at full board level. Supervisors have found instances where entities delegated too far and this was treated as a material gap.
How often must the board review the ICT risk framework under DORA?
At least annually, and after any major ICT incident or significant change to the business model or operating environment. The EBA guidelines recommend a structured annual review with a documented gap assessment against the current RTS on ICT risk management tools.
What ICT risk training is the board required to complete?
DORA Art. 5(4) requires board members to "keep up-to-date sufficient knowledge and skills to understand and assess ICT risk." The regulation does not specify hours or format. Supervisors in 2025 examinations have accepted annual sessions of 2-4 hours covering the entity's risk profile, recent incidents, and regulatory updates — provided these are documented.
Does DORA apply to the board of a subsidiary or only the group parent?
DORA applies entity-by-entity. Each in-scope legal entity's management body bears the obligations under Art. 5, even if that entity is part of a larger group. Group-level frameworks can be used, but each subsidiary's board must formally adopt and approve the framework as applicable to it.
What is the sanction for board non-compliance with DORA Art. 5?
DORA Art. 50 allows competent authorities to impose administrative pecuniary sanctions of up to 1% of average daily global turnover for ongoing infringements, and up to 2% for critical third-party ICT providers. For management body members personally, Art. 53 enables sanctions including temporary bans from senior functions.
Is DORA board governance the same for all financial entities, or is there proportionality?
DORA Art. 4 introduces a proportionality principle for microenterprises (fewer than 10 staff and under €2M turnover), which may apply a simplified ICT risk management framework. However, the management body obligations under Art. 5 apply to all in-scope entities regardless of size — only the complexity of the framework is scaled.
Last updated: June 2026 | Sources: DORA Regulation (EU) 2022/2554, EBA/ESMA/EIOPA Joint Guidelines JC 2023 86, EBA Supervisory Convergence Report 2025 | Author: IgeraSolutions Team | IgeraLegal — free 14-day trial.