Skip to main content

DORA (Digital Operational Resilience Act)

Regulation (EU) 2022/2554, applicable from 17 January 2025, establishing ICT risk management and incident-reporting requirements for financial entities. Financial institutions subject to DORA are exempt from NIS2 for their ICT obligations. For AI-related cybersecurity incidents at financial institutions, DORA's reporting chain applies alongside (not instead of) the AI Act Article 73 serious-incident notification.

Defined in 2 GAGE programs, which carry 2 distinct definitions of it. The wording above is taught in EU AI Act Implementation Expert.

How each discipline defines it

The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.

EU AI Act Implementation Expert

Regulation (EU) 2022/2554, applicable from 17 January 2025, establishing ICT risk management and incident-reporting requirements for financial entities. Financial institutions subject to DORA are exempt from NIS2 for their ICT obligations. For AI-related cybersecurity incidents at financial institutions, DORA's reporting chain applies alongside (not instead of) the AI Act Article 73 serious-incident notification.

AI Data Governance: The Data Chair

Regulation (EU) 2022/2554, in general application since 17 January 2025, requiring EU financial entities to manage ICT risk, including third-party ICT risk, comprehensively: maintaining a register of information on ICT third-party arrangements, conducting due diligence, embedding audit and access rights in contracts, and mapping subcontracting chains.

Where it is taught

The exact lessons this term appears in. The first 7 topics of every program are free with a free account.

Terms it appears with

Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.