For teams

What does DORA require of the management body, ICT auditors and staff training?

DORA duties: the management body is answerable for ICT risk, approves strategy, continuity plans, audit plans and third-party policy, sets the training budget, and its members follow specific training. An independent control function and ICT auditors check it. All staff take compulsory ICT security awareness and resilience training. Applies from 17 Jan 2025.

The Digital Operational Resilience Act puts ICT risk on the board of every EU financial entity it covers, and has done since 17 January 2025. Article 5 makes the management body answerable for ICT risk, with a list of approvals, and requires its members to keep their knowledge current through training. Article 6 adds an independent control function and ICT auditors with real expertise, and Article 13(6) makes security training compulsory for all staff.

17 Jan 2025DORA applies
BoardAnswerable for ICT risk
YearlyFramework review, at least
All staffCompulsory training

Every quotation is from Regulation (EU) 2022/2554 (DORA), OJ L 333, 27 December 2022, read on 2 October 2026; no amendment had been adopted by then. It covers the financial entities listed in Article 2, from credit institutions and investment firms to insurers, fund managers and crypto-asset service providers. This is not legal advice.

What does Article 5 make the board responsible for?

Article 5(2) says "The management body of the financial entity shall define, approve, oversee and be responsible for the implementation of all arrangements related to the ICT risk management framework." It then lists what that means:

Article 5(2)The management body shall
(a)"bear the ultimate responsibility for managing the financial entity's ICT risk"
(b)Put in place policies for the availability, authenticity, integrity and confidentiality of data
(c)Set clear roles and responsibilities for all ICT-related functions
(d)Set and approve the digital operational resilience strategy, including the ICT risk tolerance
(e)Approve, oversee and review the ICT business continuity policy and response and recovery plans
(f)Approve and review ICT internal audit plans, ICT audits and material changes to them
(g)Allocate and review the budget, including security awareness programs, resilience training and "ICT skills for all staff"
(h)Approve and review the policy on ICT third-party service providers
(i)Set up reporting channels on third-party arrangements, material changes and major ICT-related incidents

Article 5(3) adds that entities other than microenterprises must create a role to monitor third-party ICT arrangements, or name a member of senior management to oversee that risk.

Does DORA require the board to be trained?

Yes, in Article 5(4): "Members of the management body of the financial entity shall actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk and its impact on the operations of the financial entity, including by following specific training on a regular basis, commensurate to the ICT risk being managed." That is a personal duty on each member, not only a duty on the entity. Compare NIS2, where Member States must require board members to follow training; our NIS2 guide for management bodies covers it.

DORA management body checklist

DORA provision,What it requires (summary),How we meet it,Owner,Evidence kept,Last reviewed,Notes
Article 5(2),"Management body defines, approves, oversees and is responsible for the ICT risk management framework",,,,,
Article 5(2)(a),Holds final responsibility for managing ICT risk,,,,,
Article 5(2)(b),"Policies for availability, authenticity, integrity and confidentiality of data",,,,,
Article 5(2)(c),Clear roles and responsibilities for all ICT-related functions,,,,,
Article 5(2)(d),"Sets and approves the digital operational resilience strategy, including ICT risk tolerance",,,,,
Article 5(2)(e),Approves and reviews ICT business continuity policy and response and recovery plans,,,,,
Article 5(2)(f),"Approves and reviews ICT internal audit plans, ICT audits and material changes",,,,,
Article 5(2)(g),"Allocates and reviews budget, including ICT security awareness programs, resilience training and ICT skills for all staff",,,,,
Article 5(2)(h),Approves and reviews the policy on ICT third-party service providers,,,,,
Article 5(2)(i),"Reporting channels on third-party arrangements, material changes and major ICT-related incidents",,,,,
Article 5(4),"Members keep up to date with sufficient knowledge and skills, including specific training on a regular basis",,,,,
Article 6(4),"ICT risk managed and overseen by an independent control function (not microenterprises)",,,,,
Article 6(5),"Framework documented and reviewed at least once a year, and after major ICT-related incidents",,,,,
Article 6(6),"Internal audit of the framework by auditors with sufficient ICT risk knowledge, skills, expertise and independence",,,,,
Article 13(6),"ICT security awareness and resilience training compulsory for all employees and senior management",,,,,
"Regulation (EU) 2022/2554 (DORA), applies from 17 January 2025, read 2 October 2026. Template from credentialpress.com/guides/dora-management-body-and-training. Not legal advice.",,,,,,

What does Article 6 require of control and audit?

Three things a board will be asked about. Under Article 6(4), entities other than microenterprises must give the management and oversight of ICT risk to a control function with "an appropriate level of independence", and keep ICT risk management, control and internal audit functions separate. Under Article 6(5), the framework must be documented and reviewed "at least once a year", and after major ICT-related incidents. Under Article 6(6), it must be audited regularly by auditors who "possess sufficient knowledge, skills and expertise in ICT risk, as well as appropriate independence".

Article 6(6) is where a credential helps. DORA names none, but an internal audit team asked to show ICT expertise can point to ISACA's CISA, which ISACA describes as validating "a modern IT auditor". Our guide to the CISA exam and the CISA or CISM comparison cover the options.

What training must all staff receive?

Article 13(6) requires financial entities to "develop ICT security awareness programmes and digital operational resilience training as compulsory modules in their staff training schemes", applicable "to all employees and to senior management staff", with "a level of complexity commensurate to the remit of their functions". Where appropriate, ICT third-party service providers are included too. Article 5(2)(g) makes the board fund it. Our guide to EU laws that require training compares DORA with NIS2, the GDPR and the AI Act.

How does DORA fit with the AI Act?

Banks and insurers using AI for credit scoring or life and health pricing will also face the AI Act's high-risk rules from 2 December 2027, and the AI Act lets financial institutions meet some of its governance duties through the internal governance rules they already follow. Our guide to the AI Act for banks and insurers sets out the overlap.

What should the board do this quarter?

Use the checklist to record, for each Article 5 duty, the policy, the owner and the date the board last approved it. Book the members' Article 5(4) training and keep the record. Confirm that the ICT control function is independent, that the framework was reviewed in the last year, and that the ICT auditors' expertise is documented. For the people who will run this, the CISA study guide and the CISM study guide are on the teams page. Credential Press is independent of the EU institutions and of ISACA.

Frequently asked questions

What does DORA require of the board?

Article 5(2) makes the management body define, approve, oversee and be responsible for the ICT risk management framework, and makes it answerable for managing the entity's ICT risk. It approves the resilience strategy, continuity and recovery plans, ICT audit plans and third-party policy, and allocates the budget.

Does DORA require training for board members?

Yes. Article 5(4) says members of the management body shall actively keep up to date with sufficient knowledge and skills to understand and assess ICT risk, including by following specific training on a regular basis, commensurate to the ICT risk being managed.

Does DORA require training for all staff?

Yes. Article 13(6) requires financial entities to make ICT security awareness programs and digital operational resilience training compulsory modules in staff training, for all employees and senior management, at a complexity matched to their role.

What does DORA say about ICT auditors?

Article 6(6) requires the ICT risk management framework of financial entities, other than microenterprises, to be audited regularly by auditors who possess sufficient knowledge, skills and expertise in ICT risk, and appropriate independence.

When did DORA start to apply?

17 January 2025. It is a regulation, so it applies directly in every Member State to the financial entities listed in Article 2.

Is there a certification DORA requires?

No. DORA requires knowledge, skills, expertise and training, and names no certificate. Credentials such as the CISA for ICT auditors are one way to evidence the expertise Article 6(6) asks for.

Which books help ICT audit and security leads?

Cover of CISA Exam Guide

CISA Exam Guide

Certified Information Systems Auditor. 12 chapters, 355 pages.

Cover of CISM Exam Guide

CISM Exam Guide

Certified Information Security Manager. 12 chapters, 342 pages.

Sources

Every quotation above was read from the Official Journal text on 2 October 2026 through the EU Publications Office.

Credential Press is independent of the EU institutions and of ISACA. This is not legal advice.