The European regulation imposing digital operational resilience requirements on financial entities, including toward their providers.
The Digital Operational Resilience Act, or DORA, is a European regulation applicable since January 2025 that aims to strengthen the digital operational resilience of the financial sector, banks, insurers, asset managers and associated providers. It harmonizes requirements for managing information-technology risk, imposing a framework that covers IT-risk governance, incident detection and management, incident reporting to authorities, resilience testing, including advanced penetration testing, and above all the control of risk linked to critical third-party providers. This last component is particularly notable, since DORA for the first time places large IT service providers, notably cloud providers, under direct oversight when deemed critical to the financial system. For insurance and risk management, DORA is doubly relevant, it creates obligations whose breach constitutes a regulatory exposure, and it explicitly recognizes the concentration risk on infrastructure providers that lies at the heart of cyber accumulation issues. It dovetails with other texts such as the GDPR and the NIS2 directive, whose application to the financial sector it refines.
Since January 2025, a French life insurer applies DORA. In practice, it has mapped its forty-two IT providers and identified two critical cloud providers: AWS hosting its policy-management system and Microsoft Azure carrying its messaging and collaborative tools. It conducted an advanced penetration test (TIBER-EU) on its pricing infrastructure and documented a continuity plan for AWS unavailability. In March 2025, a security incident at a data-processing sub-contractor is notified to the ACPR within four hours, as DORA requires. Failure to report would have exposed the executive to personal liability.
DORA, digital operational resilience act, résilience opérationnelle numérique