RegTech

DORA Board Governance Obligations 2026: What the Management Body Must Actually Do

Gerard Maymó
June 17, 2026
11 min read
Board meeting DORA ICT governance compliance

DORA Board Governance Obligations 2026: What the Management Body Must Actually Do

Under DORA Article 5, the management body of every in-scope financial entity is personally responsible for approving, overseeing, and periodically reviewing the ICT risk management framework — not the CIO, not the IT department. Supervisors across the EU are now checking board minutes, training records, and governance documentation. If your board cannot demonstrate active ownership of ICT risk strategy, you have a material compliance gap.

DORA Art. 5 — Management Body: The governing body of a financial entity that bears ultimate responsibility for defining, approving and overseeing the implementation of all arrangements relating to ICT risk management. The obligation cannot be delegated to a committee or outsourced to a third-party provider.

67%

"67% of management bodies at DORA in-scope entities have not yet updated board-level ICT risk ownership structures to meet Article 5 requirements."

— EBA Supervisory Convergence Report, 2025

What does DORA Article 5 actually require from the board?

Article 5 sets out eight specific obligations for the management body. The key ones regulators are focusing on in 2026 supervisory reviews:

  • Approve and periodically review the ICT risk management framework (not just receive a report)
  • Define and own the ICT risk appetite — in writing, with quantified thresholds
  • Approve the ICT strategy ensuring alignment with the overall business strategy
  • Receive regular reporting on ICT incidents, third-party risks, and audit findings
  • Ensure adequate resources and training — board members must maintain sufficient ICT risk knowledge

What is the difference between board duties and IT department duties under DORA?

Obligation Management Body IT / CISO
ICT risk framework approval Approve & own Design & implement
ICT risk appetite Define & document Operationalise
Incident reporting to regulator Accountable Prepare & submit
Third-party ICT risk oversight Approve policy & review Due diligence & monitoring
DORA training & knowledge Mandatory for board members Technical training

What documentation must the board produce to satisfy supervisors?

1

Board-approved ICT risk management framework

A standalone document (not embedded in general risk policy) with explicit board signature. Must be reviewed at least annually.

2

Board minutes evidencing active oversight

Supervisors review minutes for evidence of genuine discussion — not just rubber-stamping IT reports. Record questions asked, decisions made, and follow-up actions.

3

ICT risk appetite statement

Quantified tolerances for system downtime, data loss, and third-party dependency concentration. Reviewed at least annually and after any major incident.

4

Board training records

Evidence that board members have completed DORA-specific ICT risk training. Frequency and depth are not prescribed — but supervisors expect at least annual structured sessions.

What are the most common board-level DORA gaps regulators find?

Based on EBA and national competent authority supervisory findings published in 2025, the top five board-level gaps are: (1) ICT risk framework not separately approved by the board — embedded in general risk policy; (2) No quantified risk appetite; (3) Board minutes show no substantive ICT discussion; (4) No board training records for DORA; (5) Third-party ICT risk policy approved at CIO level, not board level.

Is your board's DORA documentation audit-ready?

IgeraLegal generates board-ready DORA governance documentation and answers compliance queries citing the exact regulation article.

Try IgeraLegal free for 14 days

No credit card · Setup under 24 hours

How IgeraLegal supports DORA board governance

How IgeraLegal answers your team

Board member question:

"Do we need a separate board resolution to approve the ICT risk framework, or is it enough to include it in the annual risk committee report?"

IgeraLegal answers:

"Under DORA Art. 5(2), the management body must 'define, approve, oversee and be responsible for' the ICT risk management framework. The EBA supervisory guidance (JC 2023 86) indicates this requires a standalone board-level approval — not merely endorsement via a committee report. A formal board resolution with documented discussion is expected."

⏱ 3 seconds 🕐 24/7 📄 DORA Art. 5 cited 🚫 0 hallucinations

Need to brief your board on DORA obligations before the next supervisory review?

IgeraLegal produces board briefing packs and answers Article 5 queries with exact regulatory citations in seconds.

Book a free IgeraLegal demo →

In summary: DORA board governance obligations

  • DORA Art. 5 places personal legal responsibility on the management body, not the IT department
  • Boards must approve, own and periodically review the ICT risk management framework
  • A quantified ICT risk appetite statement is required — not optional
  • Board minutes must show substantive ICT risk discussion, not passive approval
  • Board members must maintain sufficient ICT risk knowledge — training records are audited

Frequently asked questions: DORA board governance

Can the board delegate DORA Art. 5 responsibilities to a risk committee?

Partial delegation is allowed — the board can task a risk or audit committee with monitoring. However, the management body retains ultimate accountability. Approval of the ICT risk framework and the risk appetite statement must remain at full board level. Supervisors have found instances where entities delegated too far and this was treated as a material gap.

How often must the board review the ICT risk framework under DORA?

At least annually, and after any major ICT incident or significant change to the business model or operating environment. The EBA guidelines recommend a structured annual review with a documented gap assessment against the current RTS on ICT risk management tools.

What ICT risk training is the board required to complete?

DORA Art. 5(4) requires board members to "keep up-to-date sufficient knowledge and skills to understand and assess ICT risk." The regulation does not specify hours or format. Supervisors in 2025 examinations have accepted annual sessions of 2-4 hours covering the entity's risk profile, recent incidents, and regulatory updates — provided these are documented.

Does DORA apply to the board of a subsidiary or only the group parent?

DORA applies entity-by-entity. Each in-scope legal entity's management body bears the obligations under Art. 5, even if that entity is part of a larger group. Group-level frameworks can be used, but each subsidiary's board must formally adopt and approve the framework as applicable to it.

What is the sanction for board non-compliance with DORA Art. 5?

DORA Art. 50 allows competent authorities to impose administrative pecuniary sanctions of up to 1% of average daily global turnover for ongoing infringements, and up to 2% for critical third-party ICT providers. For management body members personally, Art. 53 enables sanctions including temporary bans from senior functions.

Is DORA board governance the same for all financial entities, or is there proportionality?

DORA Art. 4 introduces a proportionality principle for microenterprises (fewer than 10 staff and under €2M turnover), which may apply a simplified ICT risk management framework. However, the management body obligations under Art. 5 apply to all in-scope entities regardless of size — only the complexity of the framework is scaled.

Last updated: June 2026 | Sources: DORA Regulation (EU) 2022/2554, EBA/ESMA/EIOPA Joint Guidelines JC 2023 86, EBA Supervisory Convergence Report 2025 | Author: IgeraSolutions Team | IgeraLegal — free 14-day trial.

#DORA board governance#DORA Art 5 management body#DORA board responsibilities#ICT risk governance board#DORA compliance 2026#DORA supervisory review#financial entity board DORA#DORA management body obligations

COMPARTIR

Comparte el conocimiento con tu red