In Ireland, DORA contraventions by financial entities supervised by the Central Bank can be dealt with through its Administrative Sanctions Procedure — generally up to EUR 10 million or 10% of annual turnover (whichever is greater) for a firm, and up to EUR 1 million for a responsible individual. Critical ICT providers face a separate EU regime with a daily periodic penalty of up to 1% of average daily worldwide turnover.
DORA gives supervisors real teeth. It is worth understanding the two distinct enforcement systems that can apply.
Enforcement in Ireland (financial entities)
For financial entities supervised by the Central Bank of Ireland, contraventions may be dealt with through the Administrative Sanctions Procedure:
Firms — generally up to EUR 10 million or 10% of annual turnover, whichever is greater.
Responsible individuals — up to EUR 1 million, alongside other possible sanctions.
(Institutions for occupational retirement provision fall under the Pensions Authority rather than the Central Bank.)
The separate EU regime for critical providers
Critical ICT third-party service providers are subject to a separate EU oversight framework, not the Irish regime. Where such a provider fails to comply with specified oversight measures, its Lead Overseer may impose a daily periodic penalty payment of up to 1% of average daily worldwide turnover, for up to six months.
How to reduce your risk
The best protection is demonstrable, good-faith compliance: identified gaps being actively closed, with priority on the areas the Central Bank has flagged (incident reporting, the register of information). See DORA readiness assessment.
Reduce your exposure with a clear view of your gaps. Book a readiness assessment.