What the First Year of DORA Has Taught Us About Operational Resilience in Financial Services
The Digital Operational Resilience Act has been in force since January 2025. Fourteen months on, patterns are emerging about what works, what does not, and where organisations are still falling short. This article examines the practical lessons from the first year of DORA compliance.
When the Digital Operational Resilience Act came into force on 17 January 2025, it represented the most significant regulatory intervention in ICT risk management the European financial sector had ever seen. Now, over a year into its application, the initial scramble has subsided and a clearer picture is forming about what DORA compliance actually looks like in practice.
The Compliance Landscape Fourteen Months On
The first year of DORA has been characterised by three distinct phases. The initial months saw a rush of gap analyses and framework documentation as organisations that had delayed preparation tried to catch up. The middle period brought the harder work of embedding new processes into daily operations. More recently, supervisory authorities have begun their first round of reviews and assessments, and the findings are revealing.
Many organisations achieved technical compliance relatively quickly. They documented their ICT risk management frameworks, mapped their critical third-party service providers, and established incident reporting procedures. Where they have struggled is with the deeper, more operational aspects of the regulation.
Where Organisations Are Falling Short
Third-party risk management remains superficial. DORA requires financial entities to maintain a comprehensive register of ICT third-party service providers and to conduct thorough due diligence on critical providers. In practice, many organisations have created the register but have not meaningfully assessed concentration risk or developed credible exit strategies for their most critical dependencies.
Testing programmes lack rigour. The regulation mandates threat-led penetration testing for significant financial entities and regular resilience testing more broadly. Early supervisory reviews suggest that many testing programmes are designed to confirm existing assumptions rather than genuinely challenge organisational resilience. Scenarios are too predictable, and the lessons from tests are not being systematically fed back into risk management frameworks.
Incident reporting is inconsistent. DORA introduced harmonised incident reporting requirements across the EU financial sector. However, the classification of what constitutes a major ICT-related incident varies significantly between organisations, leading to inconsistent reporting and making it difficult for supervisory authorities to build an accurate picture of sector-wide risk.
Board-level engagement is variable. The regulation places explicit responsibility on management bodies for ICT risk management. While most boards have received briefings and approved frameworks, genuine ongoing engagement with ICT resilience as a strategic priority remains inconsistent.
Lessons for UK Financial Services
Although DORA is an EU regulation, its implications extend well beyond the European Union. UK financial services firms with EU operations must comply directly, and the principles underpinning DORA closely mirror the expectations set by the FCA and PRA under their own operational resilience framework.
The UK operational resilience deadline of March 2025 created a parallel compliance challenge. Organisations that approached both frameworks as connected, rather than separate regulatory exercises, have generally achieved better outcomes. The underlying message from both regimes is the same. Operational resilience is not about documentation. It is about demonstrated capability.
What the Next Twelve Months Will Bring
Supervisory authorities across Europe are expected to intensify their oversight of DORA compliance throughout 2026. The European Supervisory Authorities have signalled their intention to focus particularly on third-party concentration risk and the quality of resilience testing programmes. Financial entities that achieved only surface-level compliance during the first year should expect scrutiny.
For UK firms, the FCA and PRA continue to refine their expectations around operational resilience, with increasing emphasis on the quality of scenario testing and the ability to demonstrate recovery within impact tolerances. The convergence between UK and EU approaches creates both challenges and opportunities for firms operating across jurisdictions.
Practical Recommendations
- Review your ICT third-party register and honestly assess whether your exit strategies for critical providers are credible and tested
- Evaluate your resilience testing programme against the standard of genuine challenge rather than compliance confirmation
- Ensure your incident classification criteria are clear, consistently applied, and aligned with regulatory expectations
- Brief your board not just on framework compliance but on actual resilience performance, including test results and incident trends
- If you operate across UK and EU jurisdictions, map the overlaps and gaps between DORA and the FCA/PRA framework to avoid duplication and identify blind spots
Building Genuine Resilience
The first year of DORA has reinforced a lesson that the operational resilience community has been emphasising for years. Regulatory compliance and genuine resilience are related but not identical. Organisations that treat DORA as a tick-box exercise will find themselves exposed when real disruption occurs. Those that use the regulatory framework as a catalyst for building genuine operational capability will be better protected and better positioned competitively.
Oakwood works with financial services organisations across the UK and Europe to build operational resilience capability that goes beyond compliance. To discuss how we can support your organisation, please visit our contact page or explore our training programmes at Oakwood Risk Training.
Related services
More insights
Keep reading.
Related thinking from the Oakwood team.
Operational resilience: what 'beyond March 2025' actually looks like
The FCA's transitional period has closed. The interesting question now isn't whether you're compliant — it's whether the framework you built is doing any real work.
Supply chain resilience: five lessons from a disruptive 2025
From Red Sea disruption to concentrated cloud outages, last year was an unusually clean test of how resilient your suppliers really are. The results were not flattering.
Why most business continuity plans fail under pressure
The plan is rarely the problem. The problem is the gap between the document and the organisation's ability to operate it.
