# DORA (Regulation (EU) 2022/2554): Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (Digital Operational Resilience Act, DORA)

Source: https://www.bankingnewsai.com/ai-regulation/documents/eu-dora-regulation-2022-2554
Last updated: Oct 5, 2026

Regulation (EU) 2022/2554, the Digital Operational Resilience Act (DORA), was adopted on 14 December 2022, published in the Official Journal on 27 December 2022 and has applied since 17 January 2025 (Article 64). It is the EU's binding rulebook for ICT risk at banks and other financial entities, and it never mentions artificial intelligence by name: AI systems are ICT assets, and AI models, platforms and cloud services bought from vendors are 'ICT services' under Article 3. A bank must therefore run its AI under the ICT risk management framework (Articles 5-16), classify and report major incidents (Articles 17-23), test resilience (Articles 24-27), and manage vendors under Articles 28-30, including a register of information on every ICT contract and exit strategies for services supporting critical or important functions. Critical ICT third-party providers are designated by the European Supervisory Authorities under Article 31; the first list of 19, published on 18 November 2025, includes Amazon Web Services, Google Cloud, Microsoft, IBM and Oracle but no stand-alone AI model developer.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) |
| Type | Regulation |
| Status | In force |
| Published | Dec 27, 2022 |
| Effective | Jan 17, 2025 |
| Applies to | Financial entities in the EU listed in Article 2(1) — including credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, insurers and ICT third-party service providers — with proportionality for small firms (Article 4); every EU bank is covered, whether it builds AI in-house or buys it from a vendor |
| Official text | https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng |

## Key points

- Application: in force since 17 January 2025; Article 64 sets entry into force on the twentieth day after OJ publication and application from 17 January 2025. Directly applicable in every Member State, no transposition.
- Scope (Article 2(1)): credit institutions are point (a); the same list covers payment and e-money institutions, investment firms, crypto-asset service providers and insurers, and point (u) brings ICT third-party service providers into scope. Article 4 applies proportionality by size, risk profile, and the nature, scale and complexity of services.
- Governance (Article 5): the management body defines, approves, oversees and is responsible for the ICT risk management framework and 'bear[s] the ultimate responsibility for managing the financial entity's ICT risk' (Article 5(2)(a)); under Article 6(4) larger entities assign ICT risk to a control function separated from internal audit under the three-lines model.
- ICT risk management (Articles 6-16): documented framework reviewed at least yearly (Article 6(5)), identification of ICT assets (Article 8), protection and prevention (Article 9), detection (Article 10), response and recovery (Article 11), backup and restoration (Article 12), learning (Article 13), communication (Article 14); Article 16 is the simplified framework for smaller entities.
- Incidents (Articles 17-23): management process (Article 17), classification criteria (Article 18), and Article 19 reporting of major ICT-related incidents to the competent authority through an initial notification, intermediate report and final report, plus voluntary notification of significant cyber threats (Article 19(2)) and notice to affected clients (Article 19(3)); content and templates are harmonised under Article 20.
- Testing (Articles 24-27): a resilience testing programme (Article 24) and, for entities identified by their authority, threat-led penetration testing at least every three years on live production systems (Article 26(1)-(2)).
- Third-party risk (Articles 28-30): ICT third-party risk is part of ICT risk and the entity 'remain[s] fully responsible' (Article 28(1)(a)); a third-party risk strategy (Article 28(2)); a register of information on all contractual arrangements maintained at entity, sub-consolidated and consolidated level and reported at least yearly (Article 28(3)); pre-contract due diligence and concentration-risk assessment (Articles 28(4), 29); exit strategies for services supporting critical or important functions (Article 28(8)); mandatory contract terms (Article 30).
- Oversight of critical providers (Articles 31-44): the ESAs designate critical ICT third-party service providers (Article 31) and appoint a Lead Overseer, who can issue recommendations (Article 35(1)(d)) and, after non-compliance, impose periodic penalty payments of up to 1% of average daily worldwide turnover for up to six months (Article 35(6)-(8)).
- Enforcement on financial entities (Article 50): Member States set effective, proportionate and dissuasive administrative penalties and remedial measures; the Regulation itself fixes no fine amounts for banks.

## What changed for banks

Before DORA, ICT and outsourcing risk at EU banks was governed by guidelines (the EBA outsourcing and ICT-risk guidelines) and national law. DORA turned it into a single directly applicable regulation covering ICT risk, incident reporting, testing and third-party risk, and added direct EU oversight of critical technology providers. For AI it matters because it is the legal hook for every vendor-model, cloud and API dependency a bank has: model providers sit inside the Article 28 third-party regime, and the ESAs' 31 July 2026 statement on frontier AI models (JC 2026 25) updates on DORA oversight activities for critical providers to address that risk.

## Use cases it governs

- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)
- [Model risk management](https://www.bankingnewsai.com/ai-regulation/by-use-case#model-risk)

## What does DORA require of banks that use AI and third-party ICT providers?

DORA (Regulation (EU) 2022/2554) requires every EU bank to manage ICT risk under a board-owned framework (Articles 5-6), report major ICT incidents to its competent authority (Article 19), test its resilience (Articles 24-26) and manage ICT third-party risk (Articles 28-30). It has applied since 17 January 2025 and does not name AI, but AI models, platforms and cloud services are ICT assets or ICT services, so a bank's AI vendors are inside the third-party regime: the bank stays fully responsible, must record each contract in its register of information, assess concentration risk before signing, include the Article 30 contract terms and hold a tested exit plan for services supporting critical or important functions. The largest providers are separately overseen by the ESAs as critical ICT third-party providers under Articles 31-44.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Article 5(2) — Management body responsibility | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for ICT risk, including that of AI systems and AI vendors. | In force since 17 Jan 2025 | [DORA (Regulation (EU) 2022/2554)](https://www.bankingnewsai.com/ai-regulation/documents/eu-dora-regulation-2022-2554) |
| Articles 6-16 — ICT risk management framework | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Maintain a documented ICT risk framework, reviewed at least yearly, covering asset identification, protection, detection, response and recovery, backup and learning; AI systems and their data are ICT assets within it. | In force since 17 Jan 2025 | [DORA (Regulation (EU) 2022/2554)](https://www.bankingnewsai.com/ai-regulation/documents/eu-dora-regulation-2022-2554) |
| Article 19 — Reporting of major ICT-related incidents | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Submit an initial notification, an intermediate report and a final report on major ICT-related incidents to the competent authority, and inform affected clients without undue delay. | In force since 17 Jan 2025 | [DORA (Regulation (EU) 2022/2554)](https://www.bankingnewsai.com/ai-regulation/documents/eu-dora-regulation-2022-2554) |
| Article 26 — Threat-led penetration testing | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Entities identified by their competent authority run advanced TLPT at least every three years on live production systems supporting critical or important functions, including those outsourced to ICT providers. | In force since 17 Jan 2025 | [DORA (Regulation (EU) 2022/2554)](https://www.bankingnewsai.com/ai-regulation/documents/eu-dora-regulation-2022-2554) |
| Article 28(1)-(2) — Third-party risk strategy | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Manage ICT third-party risk as part of ICT risk, remain fully responsible for DORA compliance when using vendors, and adopt and review a third-party risk strategy and policy for services supporting critical or important functions. | In force since 17 Jan 2025 | [DORA (Regulation (EU) 2022/2554)](https://www.bankingnewsai.com/ai-regulation/documents/eu-dora-regulation-2022-2554) |
| Article 28(3) — Register of information | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Keep a register of all contractual arrangements for ICT services, distinguishing those supporting critical or important functions, and report on it to the competent authority at least yearly. | In force since 17 Jan 2025 | [DORA (Regulation (EU) 2022/2554)](https://www.bankingnewsai.com/ai-regulation/documents/eu-dora-regulation-2022-2554) |
| Articles 28(4) and 29 — Pre-contract assessment and concentration risk | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Before contracting, assess whether the service supports a critical or important function, perform due diligence, and weigh ICT concentration risk, including providers that are not easily substitutable and subcontracting chains. | In force since 17 Jan 2025 | [DORA (Regulation (EU) 2022/2554)](https://www.bankingnewsai.com/ai-regulation/documents/eu-dora-regulation-2022-2554) |
| Article 28(8) — Exit strategies | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Hold documented, periodically tested exit plans for ICT services supporting critical or important functions, with alternative solutions and transition plans that avoid business disruption. | In force since 17 Jan 2025 | [DORA (Regulation (EU) 2022/2554)](https://www.bankingnewsai.com/ai-regulation/documents/eu-dora-regulation-2022-2554) |
| Article 30 — Key contractual provisions | [EU AI Act](https://www.bankingnewsai.com/ai-regulation/eu-ai-act) | Contracts must set out service descriptions, data processing and storage locations, data availability and return on exit or insolvency, incident assistance, cooperation with authorities and termination rights, with further terms for critical or important functions. | In force since 17 Jan 2025 | [DORA (Regulation (EU) 2022/2554)](https://www.bankingnewsai.com/ai-regulation/documents/eu-dora-regulation-2022-2554) |
| Articles 31-35 — Critical ICT third-party providers | [EBA](https://www.bankingnewsai.com/ai-regulation/eba) | The ESAs designate critical providers (first list of 19 published 18 Nov 2025), appoint Lead Overseers and can issue recommendations; banks must keep using the Article 28-30 controls for these providers regardless. | List published 18 Nov 2025; updated yearly | [official text](https://www.eba.europa.eu/publications-and-media/press-releases/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital) |

DORA sits alongside, not inside, the AI Act. The AI Act regulates what an AI system does and how it is classified; DORA regulates whether the bank can keep operating, detect failures and exit when the system or its provider fails. A credit-scoring model bought from a vendor is therefore subject to the AI Act's high-risk regime on its own timetable and to DORA's contract, register, concentration and exit rules today. The ECB's guide on outsourcing cloud services sets out how the ECB expects banks it supervises to apply these provisions to cloud, and the EBA's remote-onboarding guidelines require the same ICT-risk discipline for identity-verification vendors.

Supervision runs through the bank's competent authority — the ECB for significant institutions under the Single Supervisory Mechanism, national authorities for others — while the ESAs oversee designated critical providers through a Lead Overseer. The ESAs' joint statement on frontier AI models (JC 2026 25, 31 July 2026) includes an update on ongoing and planned DORA oversight activities for critical providers to address frontier-AI risk, so AI risk is being handled inside the existing third-party framework.

The Regulation leaves penalties to Member States for financial entities (Article 50), so exposure differs by country and supervisor; what is uniform is the register of information, the incident reporting chain and the contract content, which authorities can test directly.

### What this means in practice

- List every AI model, API and platform in use (including embedded vendor AI and shadow tools) and decide whether each supports a critical or important function; that decision drives the contract, register and exit obligations.
- Make sure each AI vendor appears in the Article 28(3) register of information with its subcontractors, and check the Article 30 contract terms, in particular data location, return of data on exit, incident assistance and audit rights.
- Run the Article 29 concentration assessment across the whole portfolio: several AI and software services that depend on the same hyperscaler are one dependency for resilience purposes.
- Write and test an exit plan for any AI service supporting a critical or important function, including how the model, prompts, fine-tuning data and outputs would be moved or replaced.
- Add AI-related failures (model outage, poisoned data, vendor-side compromise) to incident classification under Article 18 and the Article 19 reporting workflow.
- Do not assume a designated critical provider relieves the bank of its own Article 28 duties; the Lead Overseer's oversight does not replace the bank's due diligence.

## FAQ

### Does DORA apply to AI systems at banks?

Yes, indirectly. DORA does not use the term 'artificial intelligence', but an AI system is an ICT asset and an AI service bought from a vendor is an 'ICT service' (Article 3), so the ICT risk management framework (Articles 5-16), incident reporting (Articles 17-23) and third-party rules (Articles 28-30) apply to it. AI-specific duties come from the AI Act, not DORA.

### When does DORA take effect?

DORA has applied since 17 January 2025 (Article 64). It entered into force 20 days after its publication in the Official Journal on 27 December 2022 and is directly applicable in all Member States.

### What are the penalties under DORA?

For banks and other financial entities, Article 50 requires Member States to lay down effective, proportionate and dissuasive administrative penalties and remedial measures and to give competent authorities the necessary powers; the Regulation does not set a fixed amount. For critical ICT third-party providers, a Lead Overseer can impose a periodic penalty payment of up to 1% of average daily worldwide turnover for up to six months (Article 35(6)-(8)).

### Which AI and cloud providers are designated as critical under DORA?

On 18 November 2025 the ESAs published the first list of 19 critical ICT third-party providers: Accenture, Amazon Web Services EMEA, Bloomberg, Capgemini, Colt Technology Services, Deutsche Telekom, Equinix (EMEA), Fidelity National Information Services, Google Cloud EMEA, IBM, InterXion HeadQuarters, Kyndryl, LSEG Data and Risk, Microsoft Ireland Operations, NTT DATA, Oracle Nederland, Orange, SAP and Tata Consultancy Services. No stand-alone AI model developer is on the list; the cloud hyperscalers on it are the channel through which many banks consume AI. The list is to be updated yearly (Article 31(9)).

### How does DORA compare with the EU AI Act for banks?

They are complementary. DORA governs the resilience, incident and vendor risk of all ICT, including AI, and has applied since January 2025; the AI Act governs the AI systems themselves by risk class, with high-risk obligations for credit scoring deferred to 2 December 2027. A bank using a third-party AI model needs both: an AI Act classification and a DORA contract, register entry and exit plan.

## Related documents

- [Regulation (EU) 2026/1744 (Digital Omnibus on AI)](https://www.bankingnewsai.com/ai-regulation/documents/eu-digital-omnibus-ai-regulation-2026-1744) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI) (Jul 24, 2026)
- [Commission guidelines on AI Act Article 50 transparency](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-ai-act-article-50-transparency-2026) — Commission Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689 (AI Act) (Jul 20, 2026)
- [Draft Commission guidelines on high-risk classification](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-draft-guidelines-high-risk-classification-2026) — Draft Commission Guidelines on the classification of high-risk AI systems under Article 6 of the AI Act (May 19, 2026)
- [EBA factsheet on the AI Act](https://www.bankingnewsai.com/ai-regulation/documents/eba-ai-act-factsheet-banking-payments-2025) — AI Act: implications for the EU banking and payments sector (EBA factsheet) (Nov 21, 2025)
- [Commission GPAI model guidelines](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-gpai-obligations-2025) — Commission Guidelines on the scope of the obligations for general-purpose AI models established by Regulation (EU) 2024/1689 (AI Act) (Jul 18, 2025)
- [General-Purpose AI Code of Practice](https://www.bankingnewsai.com/ai-regulation/documents/eu-gpai-code-of-practice-2025) — General-Purpose AI Code of Practice under the AI Act (Transparency, Copyright, and Safety and Security chapters) (Jul 10, 2025)
- [Commission guidelines on the AI system definition](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-ai-system-definition-2025) — Commission Guidelines on the definition of an artificial intelligence system established by Regulation (EU) 2024/1689 (AI Act) (Feb 6, 2025)
- [Commission guidelines on prohibited AI practices](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-prohibited-ai-practices-2025) — Commission Guidelines on prohibited artificial intelligence practices established by Regulation (EU) 2024/1689 (AI Act) (Feb 4, 2025)

Last reviewed Oct 5, 2026. Cite the official text (https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/eu-dora-regulation-2022-2554
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
