Home › DORA › Governance

DORA Compliance

DORA Governance & Board Responsibility

Key takeaway

DORA makes ICT risk a board-level responsibility. Under Article 5, the management body must define, approve, oversee and remain accountable for the ICT risk management framework — and keep its own knowledge current, including through training.

For many boards, DORA represents a genuine change in posture: ICT risk is no longer something to delegate and forget.

The management body’s duties

Under Article 5, the management body must define, approve, oversee and be accountable for the ICT risk management framework. Accountability cannot be delegated away to IT or an outsourced provider.

What this means in practice

  • ICT risk on the board agenda, with documented oversight

  • Clear ownership and reporting lines

  • Evidence that leadership understands the firm’s ICT dependencies and risk appetite

  • Board-level training to maintain relevant knowledge

Why it matters

DORA’s enforcement framework can reach individuals in controlled-function roles, not just firms. Demonstrable board engagement is both a compliance requirement and a protection. See DORA penalties and enforcement.

Next step

Want a board-ready summary of your DORA position? Book a readiness assessment.