The Digital Operational Resilience Act (DORA) is a European Union regulation that requires banks and financial institutions to strengthen their operational resilience. The legislation took effect on 17thJanuary 2025 and firms face fines in the millions if they do not comply.
EU DORA regulations introduced rigorous responsibilities for institutions and their 3rd party providers. These might include data providers, systems providers or companies managing outsourced services. Solidatus advanced data lineage supports DORA compliance requirements relating to ICT-risk management, resilience testing and third-party risk management – relating to 3 of the 5 pillars of DORA regulations.
Solidatus provides advanced data lineage that helps organizations meet key DORA compliance requirements. Its functionality supports DORA solutions across ICT-risk management, resilience testing and third-party risk management – relating to 3 of the 5 pillars of DORA regulations.
Although the Digital Operational Resilience Act (DORA) is an EU regulation, it affects many UK, US, and global organizations operating in, or providing services to, the European financial market. In the UK, DORA regulations apply when British banks, insurers, or ICT service providers support EU financial institutions or manage outsourced functions linked to EU entities. Similarly, US and other international firms that deliver ICT, cloud, or data services to EU-based clients fall within DORA’s scope, especially when their operations directly impact the resilience of regulated EU financial institutions.
UK, US, and global firms should assess overlaps between their domestic rules and EU DORA regulations, ensuring that cross-border arrangements, third-party contracts, and ICT-risk management practices remain aligned.
Manage operational risk and system dependencies, know which systems to test and understand the impact of third-party provider-related issues
As part of planning, mitigation and evaluation requirements, Solidatus helps you gain a full overview of all systems and their dependencies, helping you see the business impact of an incident, know which systems to bring back first – and to recover quicker if a system goes down.
With a full view across all siloes of the organization – including how critical each system is – you’ll know which departments, customers and partners are impacted – and be able to communicate with them.
With an end-to-end view of all systems, see which resilience tests you need to perform around critical systems – and which tests you have completed. Perform impact analysis and test what-if scenarios to understand the impact on critical infrastructure – and how other systems would be affected should a system go down.
Quickly evaluate the impact on a supplying system to understand whether a critical report or a less critical one is involved.
Demonstrate to clients and regulators, that you have resilience in place and can respond appropriately if a 3rd party supplier or data center goes down.
Additionally, in order to work out your recovery time objective (RTO), you can add information from 3rdparty system providers on their service level agreements (SLAs) regarding recovery times, to understand general times. Then in a live situation, Solidatus will run calculations on all impacted systems to help you estimate the time. This helps you advise internal and external groups on when you plan to be back to business as usual.