ServiceNow’s Stacey Carr explains why the EU’s Digital Operational Resilience Act provides an opportunity for forward-thinking organizations to build resilience.
The banking and financial landscape in Ireland is set to change with the introduction of the Digital Operational Resilience Act (DORA), a new regulatory framework for digital operational resilience in the EU.
DORA mandates additional standards across a variety of areas, including risk management, testing, reporting, and third-party monitoring. Additionally, there must be a robust information and communications technology management program overseen by the board of directors, including policies, procedures, systems, and training.
The new regulation, which will take effect from January 17, 2025, will broadly impact approximately 20 types of financial institutions, including banks, investment companies, and crypto-asset-related companies. Irish financial institutions must implement the new guidelines by a specified date or face potential penalties. The Central Bank of Ireland has set these fines, which are in line with GDPR fines and amount to 2% of global annual turnover.
DORA is much more than an additional administrative challenge in an already highly regulated industry. This is a valuable opportunity for forward-thinking organizations. But to reap the benefits, you must implement a technology strategy that incorporates resilience.
Dora’s influence
Online banking, digital payment systems, and remote identity verification have transformed the sector. According to a survey by the European Investment Bank, 62% of large financial services companies have taken steps to improve their digitalization in 2022. Digitization brings greater convenience and a better customer experience through digital services, but it also exposes financial services organizations to a variety of sophisticated cyber-attacks.
In fact, SecurityScorecard reports that 78% of Europe’s largest financial institutions experienced a third-party breach in the past year. EU regulators are working with organizations to strengthen security measures as a defense against this danger. This is exactly where DORA comes into play.
DORA requires organizations to maintain transparency and measurable operational resilience. Under this law, robust risk management, continuous monitoring and regular testing are key elements of digital resilience.
How technology solutions can help
Making the right technology investments is essential to effectively enhance operational resilience. According to the updated regulations, organizations must be able to provide:
- A unified framework for enterprise-wide information and communications technology (ICT) risk management
- Report ICT incidents in real time
- Proactively manage third-party risks
- Regular testing to assess the effectiveness of measures to improve operational resilience
- Ability to easily share information between critical operations in companies providing financial services
Organizations in the financial services sector are already starting to make progress on these fronts, especially when it comes to cybersecurity. According to research from ServiceNow and ThoughtLab, two-thirds of companies in EMEA, Asia Pacific, and the US already list cybersecurity as a top investment area. Approximately 60% of companies report reduced expenses and increased profits as a result of their risk management efforts. However, there is still work to be done in this area.
According to the same study, approximately four in 10 financial services industry leaders believe that the lack of a unified platform that provides a comprehensive view of operational risk is an impediment to ensuring business resilience. I am. In line with DORA regulations that require businesses to proactively manage third-party risk, financial services institutions need a clear and unhindered understanding of their end-to-end operations. This is the only way to quickly identify and respond to risks when they occur.
Deploying the right technology
Adopting a comprehensive platform strategy is essential to meeting DORA requirements and achieving a complete view. This platform must provide at least the following:
- Connected data and intelligent insights
- Features that support informed decisions, connected conversations, and operational resiliency
- Seamless information flow to improve employee and customer experiences
Using disparate legacy systems and outdated manual processes is no longer viable. Systems that are at risk from human error and processing delays run the risk of becoming less efficient and not compliant with regulations. Therefore, platform modernization is the best approach.
Strengthening resilience
Adopting a platform-based approach can help financial services organizations improve operational efficiency and remain flexible and compliant in the face of ever-changing regulations. DORA focuses on the need for this type of technology by bringing transparency and resilience to the fore in financial services challenges.
Following DORA is not something you do reluctantly. This is an opportunity for industry organizations to strengthen their resilience. Companies that do so will ultimately be successful in meeting future regulatory and operational needs.
Written by Stacey Kerr
Stacey Carr is the Senior Sales Director for EMEA at ServiceNow, a cloud computing platform for managing digital workflows. She has over 20 years of experience in financial services and is skilled in strategic business analysis, customer relationships, and business transformation.
Find out how new technology trends will change tomorrow with our new podcast, Future Human: The Series.listen now spotifyupon apple Or wherever you get your podcasts.