Happy New Year from DORA! Getting Ready for the EU’s Digital Operational Resilience Act
Turning the calendar page to December naturally leads to reflection about the year that has just passed as well as a gaze forward to see what looms in the future. In the present case, 2024 was a year many referred to as organized chaos that was characterized by plenty of growth but also plenty of disruption. Now, whilst we prepare for 2025 and set our tasks and goals for the year with the hopes of conditions that are more “normal” alas, we have to deal with DORA.
The EU’s Digital Operational Resilience Act (DORA) comes into effect in January 2025. DORA differs from MIFiD II because it’s short on explicit rules and long on suggested guidelines. Many of the customers and prospects that we talk to complain that they wish that regulators would “Tell me what you want me to do, and I will do it” while others boldly proclaim “This is nothing we are not already doing!” Both of these responses miss the mark because DORA is designed to be self-reflective. So, whilst there will be a good measure of “hurry up and wait” to DORA, it is a good time to think about running yourself through the ringer.
What Is DORA?
DORA is meant to address a perceived gap in EU financial regulation: how to address operational resilience in a 21st century enterprise. While it was possible in the past to construct a “high wall / wide moat” defense, that no longer works given the interconnected relationships with cloud providers and other third parties that modern businesses rely upon.
Instead of dealing with operational risks by simply allocating capital to cover potential losses, DORA goes deeper and wider to both help prevent disruptions in information and communications technology (ICT) and to have plans in place to handle them when they occur. Put another way, DORA goes beyond protection to mandate measures for detection, containment, recovery and repair as well.
The five pillars of DORA are ICT Risk Management, Incident Reporting, Operational Resilience Testing, Third-Party Risk Management, and Information Sharing. Broadly, this means creating and maintaining a thorough risk management plan that includes procedures for incident reporting, regular testing programs, analysis of dependencies with third parties and plans to address any disruptions with them, and, perhaps most importantly, policies and procedures to share information on both the successes and challenges
Getting to the Heart of DORA
Unlike past mandates like Dodd Frank and MIFiD II, DORA is less about specific rules and more about principles and objectives. This may change over time as DORA matures, but for now it’s important to realize that the key to compliance is to do the work of self reflection and analysis that meets both the letter and the spirit of the regulation. At this point, lawyers and consultants seem to be reaping the greatest amount of work (and profit) from DORA but that too will change over time.
At its heart, DORA is about reflection and analysis. Taking that perspective, it’s possible to make DORA work for your business now. In addition to meeting requirements, DORA is a good motivator and tool to examine current operations and identify gaps that require attention. In the long run, it will lead to better performance so why not get started sooner rather than later? Instead of treating DORA as an annoying cost of doing business, welcome it as an opportunity to get a step ahead of the competition.
DORA is About Data
All of the above is important but the core insight about DORA is that effective compliance will be entirely dependent on data. Are you confident that you will have access to all your trading data in real-time following an outage from all of your third-party providers? What about the data schema you require? Can you drive the trade processing “machines” without pulling in small armies of talented support staff to do so – if they’re even available!? Is it possible to extract disparate and siloed data sets from across your trading/middle office tech stack and then re-shape and normalize it for easy use?. All of these questions need to be addressed and steps need to be taken to address any gaps that appear.
In order to meet business needs for DORA and beyond, data is the key. Not only is access to your trading data fundamental to business continuity during unforeseen downtime, it also lays the foundation to improve operational efficiency from top to bottom. Not many can say “Yes” with confidence once they examine the issue because there are always outliers. However, trading Data is 100% interoperable if you lay the right technology foundations and this is a core competency for BornTec CrossCheck. Contact us to learn more about how we can support your efforts at operational resilience.