The European Digital Operational Resilience Act (DORA) came into application on 17 January 2025. Eighteen months on, the subject has changed in nature: national authorities — the ACPR for banking and insurance, the AMF for capital markets — have entered a phase of in-depth supervision. What was a compliance project is becoming a permanent regime.
What DORA actually requires
The regulation imposes four blocks of obligations: rigorous management of information and communication technology risk, regular operational resilience testing, oversight of critical IT providers, and a cyber incident notification mechanism.
Taken separately, none of these is revolutionary for a mature institution. It is their combination — and above all their frequency — that changes the picture.
The real shift: from photograph to film
The most useful reading of DORA is not legal but operational. The regulation demands living governance: a comprehensive and up-to-date map of digital assets, and evolving policies for prevention, business continuity and crisis management.
The operative word is “up-to-date”. A map that is accurate at audit time but frozen thereafter does not satisfy the requirement. DORA imposes a change of posture: moving out of point-in-time compliance and into durable operational resilience.
That is precisely the definition of a continuous improvement system. Institutions that already had a Lean culture across their operational processes hold a clear advantage: they know how to keep a reference framework alive, measure gaps and close action plans. Those that treated DORA as a project with an end date rediscover each quarter that the framework has drifted.
| “Project” approach | “Continuous improvement” approach |
|---|---|
| Mapping done once | Mapping updated at every architecture change |
| Tests scheduled before the audit | Testing cycle built into the operational calendar |
| Frozen provider register | Periodic review triggered by contractual events |
| Compliance owned by a project manager | Responsibilities embedded in business processes |
AI adds a layer, not an exception
In parallel, artificial intelligence is settling into the sector’s foundations: compliance, credit risk, automation of the heaviest processes. Agentic AI — agents that execute tasks end to end rather than simply responding — promises to free up time on routine work and redirect it towards client advice and complex cases.
But governance, compliance and confidentiality remain the main brake on deployment. And from DORA’s standpoint, an AI agent embedded in a critical process is a digital asset like any other: it belongs in the asset map, in the testing perimeter, and in the chain of provider dependencies.
What this means for you
- Check when your ICT asset map was last updated. If it dates back to the initial compliance campaign, that is the first gap an inspection will find.
- Attach DORA to your continuous improvement system rather than to a dedicated project: indicators, periodic reviews, responsibilities carried by business processes.
- Bring your AI use cases into the resilience perimeter at the scoping stage, not after go-live — including agents supplied by a third party.
Helios Advisory supports banking and insurance players on digital transformation and the continuous improvement of their operations. Explore our services.
Sources
- DORA 2026: complying with the European regulation — Elitek
- DORA 2026: cybersecurity and banking governance — Haas Avocats
- Agentic AI in banking and insurance — Earnix

Leave a Reply