Regulation, Reporting & RiskNew course

Digital Operational Resilience Act (DORA): ICT Risk Management and Regulatory Compliance for Financial Institutions

Led by Sarkis Marzaani · Financial Complience Trainer

Duration
6 Hours
Price
£640 + VAT
Delivery
Online, in person or hybrid
Availability
Scheduled dates or privately on request

Introduction

The Digital Operational Resilience Act (DORA) establishes a comprehensive regulatory framework designed to strengthen the operational resilience of financial institutions across the European Union. As financial services become increasingly dependent on digital technologies, cloud computing, third-party service providers, and interconnected information systems, organizations must ensure their ability to prevent, withstand, respond to, and recover from ICT-related disruptions while maintaining critical business services.

DORA introduces harmonized requirements covering ICT risk management, incident reporting, digital operational resilience testing, third-party ICT risk, governance, and regulatory oversight. This workshop provides financial professionals with a practical understanding of DORA’s regulatory expectations, implementation strategies, and governance principles, enabling institutions to enhance resilience, strengthen compliance, and support sustainable digital operations in an increasingly complex technological environment.

Course Objectives

 By the end of this workshop, participants will be able to:

  1. Explain the objectives, scope, and regulatory requirements of the Digital Operational Resilience Act (DORA).

  2. Identify key ICT risks affecting financial institutions and evaluate appropriate risk management measures.

  3. Apply DORA governance principles to strengthen operational resilience frameworks.

  4. Understand requirements for ICT incident reporting, resilience testing, and business continuity planning.

  5. Evaluate third-party ICT risk management and oversight responsibilities under DORA.

  6. Develop practical approaches to achieving and maintaining DORA compliance within their organizations.

Training Methodology

This workshop combines expert-led presentations, practical case studies, regulatory analysis, facilitated discussions, scenario-based exercises, and implementation examples. Participants will explore DORA requirements through real-world financial sector scenarios, exchange professional experiences, and develop practical approaches for strengthening ICT governance, operational resilience, and regulatory compliance within their institutions.

 

Organizational Impact

Organizations participating in this workshop will benefit by:

  1. Strengthening ICT governance and operational resilience capabilities.

  2. Improving compliance with DORA regulatory requirements.

  3. Enhancing ICT risk identification, assessment, and mitigation practices.

  4. Strengthening oversight of third-party ICT service providers.

  5. Improving incident response, recovery, and business continuity capabilities.

  6. Increasing organizational resilience against cyber and operational disruptions.

Personal Impact

Participants will benefit by:

  1. Developing practical knowledge of DORA requirements.

  2. Strengthening ICT risk management and governance expertise.

  3. Improving regulatory compliance capabilities.

  4. Enhancing decision-making during technology-related incidents.

  5. Expanding professional expertise in operational resilience.

  6. Increasing career opportunities within risk, compliance, technology, and regulatory functions.

Target Audience

This workshop is designed for:

  1. Chief Risk Officers

  2. Compliance Officers

  3. ICT Risk Managers

  4. Information Security Managers

  5. Cybersecurity Professionals

  6. Internal Auditors

  7. Operational Risk Managers

  8. Business Continuity Managers

  9. IT Governance and Technology Managers

  10. Financial Regulators and Supervisory Professionals

 

 

Agenda

 

One-Day Workshop Outline (6 Hours)

Module 1 – DORA, ICT Risk Management, Governance, and Operational Resilience

  1. Introduction to DORA and its regulatory objectives

  2. Scope, applicability, and key compliance obligations

  3. ICT governance and management responsibilities

  4. ICT risk management framework and lifecycle

  5. ICT asset identification and critical function mapping

  6. Risk assessment methodologies and control frameworks

  7. Integrating DORA within enterprise risk management

  8. ICT incident classification and reporting requirements

  9. Business continuity and disaster recovery under DORA

  10. Digital operational resilience testing, cyber resilience, and security governance

Module 2 – Third-Party Risk, Compliance, and Sustainable DORA Implementation

  1. Managing ICT third-party and cloud service provider risks

  2. Contractual oversight and outsourcing governance

  3. Lessons learned from major ICT disruptions in financial services

  4. Governance structures supporting DORA implementation

  5. Compliance monitoring and internal assurance practices

  6. Audit readiness and regulatory examinations

  7. Metrics, reporting, and continuous improvement

  8. Integrating DORA with existing regulatory frameworks and standards

  9. Building an organizational roadmap for operational resilience

  10. Future trends and practical approaches for achieving and maintaining DORA compliance

More in Regulation, Reporting & Risk