DORA makes ICT risk a board-level responsibility. Under Article 5, the management body must define, approve, oversee and remain accountable for the ICT risk management framework — and keep its own knowledge current, including through training.
For many boards, DORA represents a genuine change in posture: ICT risk is no longer something to delegate and forget.
The management body’s duties
Under Article 5, the management body must define, approve, oversee and be accountable for the ICT risk management framework. Accountability cannot be delegated away to IT or an outsourced provider.
What this means in practice
ICT risk on the board agenda, with documented oversight
Clear ownership and reporting lines
Evidence that leadership understands the firm’s ICT dependencies and risk appetite
Board-level training to maintain relevant knowledge
Why it matters
DORA’s enforcement framework can reach individuals in controlled-function roles, not just firms. Demonstrable board engagement is both a compliance requirement and a protection. See DORA penalties and enforcement.
Want a board-ready summary of your DORA position? Book a readiness assessment.