The European Supervisory Authorities (EBA, EIOPA, and ESMA) have published a statement calling for a cross-sectoral, risk-based, and consistent supervisory approach to mitigate the ICT risks stemming from frontier AI models.
DORA – the EU Digital Operational Resilience Act
Ben Gibbins reacts to the recent publication of the new PS26/2: Operational incident and third party reporting policy which was recently published by the FCA.
The UK’s financial regulators have signed a MoU with the European Supervisory Authorities to enhance cooperation and oversight of critical third parties that fall under the UK’s CTP regime and the EU DORA regulations.
Saturday 17th January marks the first anniversary of the Digital Operational Resilience Act (DORA), which has set a new standard for ICT security and operational resilience across the European financial sector.
The European Supervisory Authorities (EBA, EIOPA, and ESMA – the ESAs) have published a list of designated critical ICT third-party providers (CTPPs) under the Digital Operational Resilience Act (DORA).
Six months after the EU’s DORA came into effect, a new Censuswide survey commissioned by Veeam Software has found that 96% of EMEA financial services organizations still feel their current level of data resilience falls short.
The European Commission has announced that it has decided to open infringement procedures by sending a letter of formal notice to 13 Member States for failing to fully transpose the DORA Directive.
The European Supervisory Authorities have set out a roadmap to explain the process for implementing a pan-European oversight framework for critical ICT third-party service providers under DORA.
While for most financial organizations DORA compliance has been an exercise built upon strong existing compliance, business continuity, and risk management processes, the focus on third party service providers in DORA could be a weak area. Andre Troskie explains why…
The European Banking Authority (EBA) has announced that it has narrowed down the scope of its existing Guidelines on ICT and security risk management measures.





