Digital Operational Resilience Act (DORA): ICT Risk Management and Regulatory Compliance for Financial Institutions
Led by Sarkis Marzaani · Financial Complience Trainer
- Duration
- 6 Hours
- Price
- £640 + VAT
- Delivery
- Online, in person or hybrid
- Availability
- Scheduled dates or privately on request
Introduction
The Digital Operational Resilience Act (DORA) establishes a comprehensive regulatory framework designed to strengthen the operational resilience of financial institutions across the European Union. As financial services become increasingly dependent on digital technologies, cloud computing, third-party service providers, and interconnected information systems, organizations must ensure their ability to prevent, withstand, respond to, and recover from ICT-related disruptions while maintaining critical business services.
DORA introduces harmonized requirements covering ICT risk management, incident reporting, digital operational resilience testing, third-party ICT risk, governance, and regulatory oversight. This workshop provides financial professionals with a practical understanding of DORA’s regulatory expectations, implementation strategies, and governance principles, enabling institutions to enhance resilience, strengthen compliance, and support sustainable digital operations in an increasingly complex technological environment.
Course Objectives
By the end of this workshop, participants will be able to:
Explain the objectives, scope, and regulatory requirements of the Digital Operational Resilience Act (DORA).
Identify key ICT risks affecting financial institutions and evaluate appropriate risk management measures.
Apply DORA governance principles to strengthen operational resilience frameworks.
Understand requirements for ICT incident reporting, resilience testing, and business continuity planning.
Evaluate third-party ICT risk management and oversight responsibilities under DORA.
Develop practical approaches to achieving and maintaining DORA compliance within their organizations.
Training Methodology
This workshop combines expert-led presentations, practical case studies, regulatory analysis, facilitated discussions, scenario-based exercises, and implementation examples. Participants will explore DORA requirements through real-world financial sector scenarios, exchange professional experiences, and develop practical approaches for strengthening ICT governance, operational resilience, and regulatory compliance within their institutions.
Organizational Impact
Organizations participating in this workshop will benefit by:
Strengthening ICT governance and operational resilience capabilities.
Improving compliance with DORA regulatory requirements.
Enhancing ICT risk identification, assessment, and mitigation practices.
Strengthening oversight of third-party ICT service providers.
Improving incident response, recovery, and business continuity capabilities.
Increasing organizational resilience against cyber and operational disruptions.
Personal Impact
Participants will benefit by:
Developing practical knowledge of DORA requirements.
Strengthening ICT risk management and governance expertise.
Improving regulatory compliance capabilities.
Enhancing decision-making during technology-related incidents.
Expanding professional expertise in operational resilience.
Increasing career opportunities within risk, compliance, technology, and regulatory functions.
Target Audience
This workshop is designed for:
Chief Risk Officers
Compliance Officers
ICT Risk Managers
Information Security Managers
Cybersecurity Professionals
Internal Auditors
Operational Risk Managers
Business Continuity Managers
IT Governance and Technology Managers
Financial Regulators and Supervisory Professionals
Agenda
One-Day Workshop Outline (6 Hours)
Module 1 – DORA, ICT Risk Management, Governance, and Operational Resilience
Introduction to DORA and its regulatory objectives
Scope, applicability, and key compliance obligations
ICT governance and management responsibilities
ICT risk management framework and lifecycle
ICT asset identification and critical function mapping
Risk assessment methodologies and control frameworks
Integrating DORA within enterprise risk management
ICT incident classification and reporting requirements
Business continuity and disaster recovery under DORA
Digital operational resilience testing, cyber resilience, and security governance
Module 2 – Third-Party Risk, Compliance, and Sustainable DORA Implementation
Managing ICT third-party and cloud service provider risks
Contractual oversight and outsourcing governance
Lessons learned from major ICT disruptions in financial services
Governance structures supporting DORA implementation
Compliance monitoring and internal assurance practices
Audit readiness and regulatory examinations
Metrics, reporting, and continuous improvement
Integrating DORA with existing regulatory frameworks and standards
Building an organizational roadmap for operational resilience
Future trends and practical approaches for achieving and maintaining DORA compliance
More in Regulation, Reporting & Risk
Bank Capital & Liquidity Stress Tests
The importance of resilience in adverse market conditions.
IFRS (International Financial Reporting Standards)
Accounting standards for the preparation of financial statements.
IFRS 9 Financial Instruments
Enabling information produced internally to be used for risk management purposes.
