DORA: 2026, the year compliance becomes a permanent exercise

The European Digital Operational Resilience Act (DORA) came into application on 17 January 2025. Eighteen months on, the subject has changed in nature: national authorities — the ACPR for banking and insurance, the AMF for capital markets — have entered a phase of in-depth supervision. What was a compliance project is becoming a permanent regime.

What DORA actually requires

The regulation imposes four blocks of obligations: rigorous management of information and communication technology risk, regular operational resilience testing, oversight of critical IT providers, and a cyber incident notification mechanism.

Taken separately, none of these is revolutionary for a mature institution. It is their combination — and above all their frequency — that changes the picture.

The real shift: from photograph to film

The most useful reading of DORA is not legal but operational. The regulation demands living governance: a comprehensive and up-to-date map of digital assets, and evolving policies for prevention, business continuity and crisis management.

The operative word is “up-to-date”. A map that is accurate at audit time but frozen thereafter does not satisfy the requirement. DORA imposes a change of posture: moving out of point-in-time compliance and into durable operational resilience.

That is precisely the definition of a continuous improvement system. Institutions that already had a Lean culture across their operational processes hold a clear advantage: they know how to keep a reference framework alive, measure gaps and close action plans. Those that treated DORA as a project with an end date rediscover each quarter that the framework has drifted.

“Project” approach“Continuous improvement” approach
Mapping done onceMapping updated at every architecture change
Tests scheduled before the auditTesting cycle built into the operational calendar
Frozen provider registerPeriodic review triggered by contractual events
Compliance owned by a project managerResponsibilities embedded in business processes

AI adds a layer, not an exception

In parallel, artificial intelligence is settling into the sector’s foundations: compliance, credit risk, automation of the heaviest processes. Agentic AI — agents that execute tasks end to end rather than simply responding — promises to free up time on routine work and redirect it towards client advice and complex cases.

But governance, compliance and confidentiality remain the main brake on deployment. And from DORA’s standpoint, an AI agent embedded in a critical process is a digital asset like any other: it belongs in the asset map, in the testing perimeter, and in the chain of provider dependencies.

What this means for you

  1. Check when your ICT asset map was last updated. If it dates back to the initial compliance campaign, that is the first gap an inspection will find.
  2. Attach DORA to your continuous improvement system rather than to a dedicated project: indicators, periodic reviews, responsibilities carried by business processes.
  3. Bring your AI use cases into the resilience perimeter at the scoping stage, not after go-live — including agents supplied by a third party.

Helios Advisory supports banking and insurance players on digital transformation and the continuous improvement of their operations. Explore our services.

Sources


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *