DORA: Operational Resilience and Why AI Vendors Are Now In Scope
DORA: operational resilience, and why AI vendors are now in scope
Regulation (EU) 2022/2554, the Digital Operational Resilience Act, applies to financial entities in the European Union and to the third parties that provide them with information and communication technology services. If you sell AI into financial services, or you are a financial entity deploying AI, DORA is probably the most consequential instrument in this course for you commercially.
The five pillars
DORA organises its requirements into risk management, incident reporting and classification, digital operational resilience testing, management of third party risk, and information sharing. The first four create obligations. The fifth is voluntary.
The pillar that changes behaviour most is third party risk. DORA reaches through the financial entity to the provider. Contracts with providers of information and communication technology services must contain specified terms, including audit and access rights, exit strategies, and service level descriptions. Providers designated as critical come under direct oversight by the European Supervisory Authorities, which is unusual, because it means a supplier can be supervised without being a regulated financial entity itself.
Why this matters if you sell AI
An AI system supplied to a bank is an information and communication technology service. That means your contract has to carry DORA terms, your client will need a documented exit strategy from you, and you may be asked to support resilience testing that you had not budgeted for. Firms that treat this as a procurement formality discover late that the audit and exit clauses are not negotiable in the way commercial terms usually are.
The practical advice is to read the register of information requirement early. Financial entities must maintain a register of their contractual arrangements for information and communication technology services. If you are a supplier, you will be asked to populate fields in it, and you should know what they are before a client asks.
Where DORA meets ISO/IEC 42001
The overlap is real but partial. DORA is about whether the service keeps running and can be recovered. ISO/IEC 42001 is about whether the AI system behaves acceptably. A model can be perfectly resilient in the DORA sense, available and recoverable and tested, while producing outputs that are unfair, unexplainable or wrong. The two frameworks answer different questions and neither substitutes for the other.
Where they genuinely share evidence is incident classification, third party inventories, and testing regimes. Build those once.
A note on the structured data
In our measurement of how well the European Union’s machine-readable citation graph records what instruments actually cite, DORA scored 85.3 per cent, among the better covered. If you are tracing DORA’s dependencies programmatically, the structured metadata is reasonably trustworthy, which is not true across the board.
