RegTech

DORA ICT Risk Management for Banks 2026: Chapter II Compliance Guide

Gerard Maymó
June 17, 2026
12 min read
RegTech · DORA · ICT Risk Management · Banking

DORA ICT Risk Management for EU Banks in 2025: The Complete Chapter II Compliance Guide

DORA (Regulation EU 2022/2554) entered into force on 17 January 2025. For CROs and IT Risk Managers at EU banks and payment institutions, Chapter II — ICT Risk Management (Articles 5 to 16) — is the heaviest compliance lift: it mandates a board-owned, documented ICT risk framework covering governance, asset identification, protection, detection, response, recovery and independent review. The EBA, ESMA and EIOPA published final RTS on ICT risk management in January 2024. Yet the EBA reported in Q1 2025 that 34% of EU banks had not yet completed their DORA gap assessment. This guide breaks down every obligation in Articles 5-16, the most common gaps, and how to close them before your next supervisory review.

Quick answer — what does DORA Chapter II require for banks? A fully documented ICT risk management framework, approved and actively supervised by the board of directors (not delegable to the CTO or CISO), covering five pillars: (1) governance and strategy (Art. 5-6), (2) ICT asset identification (Art. 8), (3) protection and prevention (Art. 9), (4) detection and response/recovery (Arts. 10-13), and (5) independent annual review (Art. 15). All credit institutions are in scope — no size threshold. Simplified rules apply only to microenterprises under Art. 16.

What Changed: ICT Risk Rules Before and After DORA

Before DORA, EU banks were subject to a fragmented patchwork: EBA Guidelines on ICT and Security Risk Management (EBA/GL/2019/04), NIS Directive obligations for operators of essential services, and national supervisory expectations that varied significantly between the ECB Single Supervisory Mechanism, the Banco de Espana (BdE) for Spanish entities, and other national competent authorities. DORA replaces and supersedes all of these with a single, directly applicable EU regulation — binding without transposition — and raises the bar considerably.

Dimension Pre-DORA (EBA GL 2019/04) Post-DORA (from Jan 2025)
Legal instrument EBA Guidelines (comply-or-explain) EU Regulation — directly applicable, no national discretion
Board accountability Recommended, delegable in practice Mandatory, non-delegable (Art. 5)
ICT asset inventory Good practice, no mandatory fields Mandatory minimum fields per RTS 2024/1774 (Art. 8)
Third-party ICT risk EBA Outsourcing Guidelines Chapter V DORA + TLPT oversight for critical providers
Incident reporting NIS Directive + PSD2 for payment incidents Harmonised DORA taxonomy + tiered deadlines (Arts. 17-23)
Resilience testing Recommended pen-testing, no harmonised standard TLPT (Threat-Led Penetration Testing) mandatory for significant entities (Art. 26)
Maximum sanction Varied by member state Up to €10M or 2% of global turnover (Art. 50)

Who Is Affected by DORA ICT Risk Requirements?

DORA applies to 21 categories of financial entities. For ICT risk purposes (Chapter II), all credit institutions are in full scope regardless of size. Payment institutions, e-money institutions, investment firms, asset managers, insurance undertakings, crypto-asset service providers, and central counterparties are also covered. Microenterprises (fewer than 10 employees and annual turnover below €2M) may apply the simplified ICT risk management framework under Art. 16 and Delegated Regulation 2024/1773. The BdE issued its own supervisory communication in 2024 clarifying expectations for Spanish entities under ECB supervision and for less significant institutions (LSIs) under national oversight. Entities in Spain must align their DORA implementation with BdE's existing Resolution on ICT governance (Circular 2/2016) to the extent it has not been superseded.

DORA Chapter II: The 5 Pillars of ICT Risk Management (Articles 5-16)

DORA Article Pillar Core obligation Most common gap
Arts. 5-7 Governance & Strategy Management body defines, approves and actively supervises ICT risk strategy. Responsible for ICT budget allocation and CISO-level reporting. Board approval is formal only; no substantive board debate evidenced in minutes.
Art. 8 Identification Maintain a complete, classified ICT asset register (hardware, software, data, third-party dependencies) with mandatory fields per RTS 2024/1774. Annual review minimum. Business-unit SaaS and shadow IT not included in central IT inventory.
Art. 9 Protection & Prevention MFA for critical systems, encryption in transit and at rest, patch management with criticality SLAs, board-approved cryptography policy, access privilege reviews. Cryptography policy exists but has never been formally approved by the management body.
Arts. 10-13 Detection, Response & Recovery SIEM with defined alerting thresholds and escalation paths (Art. 10). BCP/DRP with tested RTO/RPO (Art. 11). Daily backups with offline copies and annual restoration tests (Art. 12). Post-incident reviews integrated into continuous improvement (Art. 13). BCP/DRP targets documented but live testing never conducted with recorded evidence.
Arts. 14-15 Communication & Review Crisis communication plan for ICT-related incidents (Art. 14). Independent annual review of the entire ICT risk management framework (Art. 15). Internal audit review does not meet independence requirements; no external review commissioned.
Art. 16 Simplified Framework Microenterprises and small non-complex entities may apply a proportionate framework per Delegated Regulation 2024/1773. Incident reporting and third-party rules still apply in full. Entities mistakenly apply simplified regime without meeting the qualifying criteria.

Article 5: ICT Governance — What Supervisors Are Actually Checking

Article 5 is the most scrutinised provision in supervisory assessments. It requires the management body — not the IT department — to define, approve, and actively oversee the digital operational resilience strategy. This means board minutes must show substantive discussion of ICT risk, not just routine sign-offs. Supervisors from the ECB Single Supervisory Mechanism, CNMV, and BdE are requesting: (a) evidence of annual board approval of the ICT risk policy; (b) records of board-level training in cybersecurity and ICT risk; (c) documentation that the ICT budget allocation was reviewed and approved with reference to the institution's risk profile; and (d) at minimum one annual written report from the CISO (or equivalent function) received by the management body. In Spain, the BdE has additionally flagged that the management body's responsibility cannot be satisfied merely by establishing a Risk Committee — the full board or equivalent collegial body must retain direct accountability.

Article 8: ICT Asset Identification — The Minimum Required Register Fields

Article 8 requires institutions to maintain and regularly update a complete register of all ICT assets — hardware, software, data repositories, and dependencies on ICT third-party service providers — classified by criticality. Delegated Regulation 2024/1774 (RTS on ICT risk management tools) specifies the minimum mandatory fields for each registered asset: unique asset identifier, asset type, supported business function, criticality classification (critical / important / standard), accountable owner, physical or logical location, supporting contract reference, and end-of-support date. The register must be reviewed at least annually and following any significant infrastructure change. The most widespread compliance gap: cloud SaaS subscriptions procured directly by business units (HR, marketing, finance) that are not captured in the central IT asset management system. Art. 8(1) is explicit — all ICT assets supporting business functions must be mapped, irrespective of whether the vendor is classified as a critical ICT third-party provider under Chapter V.

Articles 9-13: Protection, Detection and Recovery in Practice

Art. 9 mandates that for systems classified as critical, multi-factor authentication (MFA) is mandatory with no exceptions. Other required controls include: network segmentation to isolate critical systems, encryption of data in transit and at rest equivalent to AES-256 or stronger, patch management with defined SLAs tied to CVSSv3 severity scores (critical patches at CVSSv3 9.0 or above must be applied within 24-72 hours), quarterly access privilege reviews, and a formally board-approved cryptography and key management policy.

Art. 10 requires near-real-time anomaly detection across all critical ICT infrastructure, including monitoring of third-party access points. In practice this means a SIEM (Security Information and Event Management) system with documented baseline behaviour for critical systems, automated alerting for deviations, correlation of security events across the estate, and a formally documented escalation path with defined response times. Institutions relying on cloud infrastructure must extend monitoring to provider-side logs.

Art. 11 requires Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP) with defined and tested Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for every critical system. Plans must be tested at least annually — or following a major incident or significant infrastructure change — and test results, including deficiencies found and corrective actions taken, must be formally documented and reported to the management body. Art. 12 requires daily backups as a minimum, with offline copies for critical systems and annual full restoration tests. Art. 13 mandates post-incident reviews for all major incidents and integration of threat intelligence into the continuous improvement cycle of the framework.

DORA ICT Risk Compliance Checklist for Banks (2025)

Chapter II readiness checklist — use before any supervisory visit

  • Board minutes show substantive ICT risk discussion and formal approval of ICT risk policy (Art. 5)
  • Board training records on cybersecurity and digital resilience exist and are dated within 12 months (Art. 5)
  • ICT risk management framework document approved at board level, with version control and annual review evidence (Art. 6)
  • ICT asset register contains all mandatory RTS 2024/1774 fields for every asset, including business-unit SaaS (Art. 8)
  • Criticality classification applied to all registered assets; critical systems clearly identified (Art. 8)
  • MFA enforced on all systems classified as critical; evidence of enforcement in access logs (Art. 9)
  • Patch management SLA documented by CVSSv3 severity tier; patch compliance reports available (Art. 9)
  • Cryptography and key management policy formally approved by management body (Art. 9)
  • SIEM in place with documented alert thresholds, baseline behaviour definition, and escalation path (Art. 10)
  • BCP and DRP exist with defined RTO/RPO per critical system (Art. 11)
  • Annual BCP/DRP test conducted with documented results, deficiencies, and corrective actions (Art. 11)
  • Daily backups confirmed; offline copies for critical systems; annual restoration test completed (Art. 12)
  • Post-incident review process documented; threat intelligence feed integrated into framework updates (Art. 13)
  • Crisis communication plan for ICT incidents covering staff, clients, and competent authorities (Art. 14)
  • Independent annual review of ICT risk management framework commissioned and completed (Art. 15)
  • If applying simplified regime: confirm entity meets Art. 16 qualifying criteria per Delegated Reg. 2024/1773

How IgeraRegTech Closes the Gap: Article-Level Answers in Under 3 Seconds

The EBA finding that 34% of EU banks had not completed their DORA gap assessment by Q1 2025 reflects a real operational bottleneck: compliance teams are overwhelmed by the volume and specificity of Article-level queries, and legal counsel costs are substantial. IgeraRegTech clients in banking have seen the RAG bot answer DORA Article-level queries in under 3 seconds with exact regulatory citations, reducing compliance team queries by 58% in the first month of deployment.

IgeraRegTech — live DORA Article 5 query

IT Risk Manager asks:

"Can our Risk Committee satisfy the DORA Art. 5 management body accountability requirement, or does it need to go to the full board?"

IgeraRegTech answers:

"Under Art. 5(2) DORA, the \"management body\" is defined by reference to Art. 4(1)(36) CRD IV — it means the full board of directors (or equivalent collegial body) in its supervisory function. A Risk Committee may perform preparatory work and day-to-day oversight, but the obligation to define and formally approve the ICT risk strategy, approve the ICT budget, and receive the CISO annual report sits with the full management body and cannot be delegated. Evidence: DORA Art. 5(2); Recital 45; EBA Final Report on DORA RTS January 2024, paragraph 23."

Response time: 2.4 seconds Sources cited: DORA Art. 5(2), CRD IV Art. 4(1)(36), EBA RTS Jan 2024

Is your DORA ICT risk framework inspection-ready?

IgeraRegTech answers Article-level DORA queries in under 3 seconds, citing the exact provision — Chapter II, RTS 2024/1774, or EBA Guidelines. Banking compliance teams using IgeraRegTech reduced inbound regulatory queries by 58% in month one.

Explore IgeraRegTech for DORA compliance

For a deeper look at how DORA regulates your ICT third-party providers and what contract clauses are now mandatory, see our companion guide: DORA and ICT Third-Party Risk: The Complete Guide for EU Banks and Asset Managers. For the full DORA product overview and how IgeraRegTech maps to all five DORA chapters, visit the IgeraRegTech DORA hub page.

Frequently Asked Questions: DORA ICT Risk Management for Banks

Can the board delegate its DORA Article 5 ICT governance responsibilities to the CTO or CISO?

No. Art. 5 DORA is explicit: the management body is directly responsible for defining, approving, and actively overseeing the ICT risk strategy. Operational management and day-to-day execution can be delegated, but strategic approval of the ICT risk policy, budget allocation, and receipt of the annual CISO report are non-delegable. ECB supervisors and national competent authorities including the BdE are now examining board minutes and training records as evidence of substantive engagement, not just formal sign-off.

What are the mandatory fields in a DORA-compliant ICT asset register under Article 8?

Delegated Regulation 2024/1774 (RTS on ICT risk management tools) sets the minimum fields: unique asset identifier, asset type (hardware / software / data / ICT service), supported business function, criticality classification (critical / important / standard), accountable owner, physical or logical location, contractual support reference, and end-of-support or end-of-life date. All ICT assets supporting any business function must be included — not only those linked to critical or important functions. Business-unit SaaS tools, HR platforms, marketing automation software, and cloud storage services are all in scope if they process business data.

What RTO and RPO targets are acceptable under DORA Article 11?

DORA does not prescribe specific numeric RTO/RPO values. The regulation requires that RTO and RPO be defined in proportion to the criticality and the potential business impact of each system's disruption, and — critically — that they be demonstrated as achievable through actual tests. The EBA has indicated in its supervisory priorities that for payment systems and essential services, supervisors will expect RTOs measured in hours rather than days. Objectives that have never been tested are non-compliant regardless of the documented values.

Does internal audit satisfy the independent review requirement in DORA Article 15?

Not automatically. Art. 15 requires that the ICT risk management framework be reviewed by parties independent of the function being reviewed, with sufficient technical expertise in cybersecurity. Internal audit can qualify if it has the requisite independence and technical capability. However, many institutions' internal audit functions lack specialist ICT security expertise, and some institutions' internal audit teams directly supported the framework implementation — which compromises independence. External review by a qualified third party is often required to satisfy the Art. 15 standard, and supervisors are beginning to request evidence of reviewer qualifications.

How does DORA Article 9 define the minimum protection requirements for critical ICT systems?

Art. 9 requires, for systems classified as critical: mandatory multi-factor authentication with no exception pathways, network segmentation isolating critical systems from general IT infrastructure, encryption of all data in transit and at rest using algorithms meeting current cryptographic standards (RTS 2024/1774 refers to ENISA recommendations), a formally board-approved cryptography and key management policy, patch management SLAs defined by CVSSv3 severity (critical-rated vulnerabilities within 24-72 hours), and quarterly reviews of access privileges. The information security policy itself — not just the cryptography sub-policy — must be formally approved by the management body and reviewed annually.

Do smaller EU banks and payment institutions have lighter DORA ICT risk obligations?

Yes, but only if they qualify. Art. 16 DORA and Delegated Regulation 2024/1773 establish a simplified ICT risk management framework for microenterprises (fewer than 10 employees, annual turnover below €2M) and entities classified as small and non-complex. Under the simplified regime, certain governance and documentation requirements are proportionate. However, the incident reporting obligations (Arts. 17-23), the third-party ICT risk management requirements (Chapter V), and the digital operational resilience testing obligations (Chapter IV) apply without simplification to all entities. Misidentifying your institution as eligible for the simplified regime is one of the most common compliance errors observed post-January 2025.

What is the EBA's assessment of DORA readiness among EU banks as of Q1 2025?

The EBA reported in Q1 2025 that 34% of EU banks had not yet completed their DORA gap assessment — a significant compliance lag given that the regulation became applicable on 17 January 2025. The most frequently incomplete areas were the Art. 8 ICT asset register (particularly coverage of third-party SaaS dependencies), Art. 11 BCP/DRP testing evidence, and Art. 15 independent review. Supervisory letters were issued to a number of significant institutions by the ECB reminding them of their obligations and requesting remediation timelines by Q3 2025.

Conclusion: DORA ICT Risk Compliance Is Supervisory Priority No. 1 in 2025

DORA Chapter II ICT risk management is no longer a future compliance exercise — supervisory assessments are live across the EU, with the ECB, ESMA, EIOPA and national authorities including the BdE actively reviewing compliance. With 34% of EU banks still completing gap assessments in Q1 2025, the compliance window is narrowing. The five-pillar structure of Arts. 5-16 creates a clear compliance map: governance, identification, protection, detection/response/recovery, and independent review. Institutions that invest in structured compliance tooling — rather than relying on manual legal research for every Article-level question — are closing gaps faster and at lower cost.

Start your DORA Article-level gap analysis today

IgeraRegTech gives your compliance team instant, cited answers to any DORA Article 5-16 question — sourced from the Regulation text, EBA/ESMA/EIOPA RTS, and your institution's own policies. No hallucinations. No delay. Exact article, every time.

Try IgeraRegTech free for 14 days

Editorial note: This article was written by the Equip IgeraSolutions editorial team and reviewed by the IgeraSolutions Regulatory Affairs Team for regulatory accuracy. It is intended for informational purposes only and does not constitute legal or compliance advice. Entities should obtain advice from qualified legal counsel for their specific circumstances.

Updated: July 2026 · Canonical URL: /en/blog/dora-ict-risk-banks/ · hreflang: en-GB (this page), es-ES (/es/blog/dora-ict-risk-banks/), ca-ES (/ca/blog/ca-dora-entitats-financeres/) · Pillar page: IgeraRegTech DORA hub

Sources: Regulation (EU) 2022/2554 (DORA), Arts. 5-16; Delegated Regulation (EU) 2024/1774 (RTS on ICT risk management tools); Delegated Regulation (EU) 2024/1773 (RTS on simplified ICT risk framework); Joint ESA Final Report on DORA RTS, January 2024; EBA Q1 2025 supervisory assessment report on DORA readiness; BdE supervisory communication on DORA implementation for Spanish entities, 2024.

#DORA ICT risk management banks#DORA Chapter II compliance#DORA regulation banks 2026#EU 2022/2554 ICT risk framework#DORA board accountability#financial entity DORA obligations#ICT risk management framework EU

COMPARTIR

Comparte el conocimiento con tu red