Zum Hauptinhalt

How DNB Assesses Digital Resilience under DORA

DORA in Practice: From Questionnaire to a Mature and Auditable Framework

As of 17 January 2025, Regulation (EU) 2022/2554 – the Digital Operational Resilience Act (DORA) – forms the legal framework for the digital resilience of financial institutions. DNB has announced that in 2026 it will introduce a renewed survey: the SBA-Cyber Resilience. Will the AFM follow? And what does this concretely mean for institutions in terms of internal governance and risk management?

DNB Assesses Both Content and Substantiation

During the DORA seminar held in September 2025, DNB outlined its supervisory approach to DORA. The familiar Sector-Wide Information Security Analysis (SBA-IB) has been revised and expanded to include third-party ICT risk, now comprising a total of 45 controls. The SBA-IB will continue under the new name SBA-Cyber Resilience and will be issued for the first time in 2026.

The maturity levels assigned to the controls will not only be assessed on their stated level but also on how that level has been substantiated. DNB announced that it will use risk-identifying interviews (RIGs), deep dives, and on-site inspections to gain insight into this.

From Structure to Steering Information

Institutions will not only be asked to describe their ICT risk management processes but also to demonstrate that these are integrated within their organisation, governance, and decision-making processes – ensuring that the risk and control framework is sound in design, existence, and operation. This means, among other things:

  • Documented and formalised risk appetite and tolerance levels, including periodic review or recalibration;
  • Conducted risk and threat assessments, including prior to entering into contracts with third-party ICT service providers that support (potentially) critical or important functions;
  • Periodic evaluation of policies, crisis plans, and recovery measures;
  • Demonstrable monitoring of the effectiveness and execution of implemented measures and resilience testing.

The structure lies in a robust risk and control framework; the steering lies in the testing, monitoring, and reporting of its embedding.

Proportionality Offers Flexibility, but Requires Justification

Based on FAQs from the seminar, DNB allows for a risk-based and proportionate approach. However, it must be clear and demonstrable that the choices made are appropriate within the organisation’s risk profile. Proportionality is not a licence for leniency.

One way to document this is within the risk analysis itself. Many DORA requirements will appear in the analysis as mitigating measures for ICT risks. If the organisation can demonstrate that alternative measures or controls are more appropriate than those prescribed by DORA, the risk analysis is the right place to record this, for instance in an explanatory field.

An (explicit) approval from the compliance officer or the board may also be an option, as deviations from statutory requirements must be owned at the appropriate level of accountability.

Practical Challenges in Implementation

DORA is about continuously strengthening operational resilience. Implementation has often been approached as a project or an “Excel exercise”, leading to fragmented alignment between policy and operational execution.

By January 2026, DORA will already have been in force for one year, meaning the (mandatory) annual review of the ICT Risk Framework must take place – a specific DORA requirement. In preparation, it may be helpful to start in Q4 with an assessment of how far the measures in that framework have already been embedded operationally.

For example, review the periodic reports produced by the second line (risk management) within the organisation. What is currently being reported regarding ICT control processes and operational resilience? Or by the first line? Does this information provide sufficient insight for the board to make informed decisions?

Towards a Mature and Auditable Framework

A mature ICT risk management framework under DORA does not consist merely of documentation but embodies a continuous cycle of defining, assessing, controlling, monitoring, and evaluating – the well-known PDCA cycle.

When drafting policies and defining procedures or mitigating measures, it is therefore essential to consider not only how controls are practically implemented, but also how they can be tested and verified. Establishing second-line monitoring becomes far easier with this approach, ensuring that design, existence, and operation – and thus the framework itself – are demonstrably auditable.

Investing time in strengthening governance, risk management, and control frameworks in this way contributes not only to compliance but, more importantly, to trust – from supervisors, clients, and internal stakeholders alike.

Conclusion

DNB’s message is clear: digital resilience is an integral part of sound business operations. The DNB has already sent an information request to several banks, covering approximately 20 topics and documents.

For the 2026 survey of the pension and insurance sectors, many organisations will discover whether they have succeeded in translating policy into concrete, auditable measures – in design, existence, and operation.

If you are uncertain about your organisation’s maturity level or wish to strengthen your ICT Risk Framework in preparation for the 2026 survey, please contact our specialists.

We're ready to get started! Are you?