What does proportionality mean under EU DORA?
DORA Article 4 says financial entities must implement ICT risk management rules proportionately, taking into account their size and overall risk profile and the nature, scale, and complexity of their services, activities, and operations. The same lens also applies to ICT-related incident management, digital operational resilience testing, and ICT third-party risk management where the relevant chapters provide for it.
A smaller, lower-complexity entity may justify simpler governance, fewer layers of documentation, less extensive testing within the applicable programme, or less complex supplier oversight than a large systemic entity. The entity must still meet express duties and minimum frequencies, including annual testing of ICT systems and applications supporting critical or important functions where Article 24 applies. The justification must be tied to the entity's ICT risk facts.
- Start with DORA scope and role: determine whether the organisation is a financial entity, an ICT third-party service provider, both, or excluded. Apply Article 4 to an in-scope financial entity's duties rather than using it to scale away a provider's contractual commitments or critical-provider oversight duties.
- For an in-scope financial entity, record the factors: size, overall ICT risk profile, nature of services, scale of operations, complexity, critical or important functions, outsourced ICT services, and exposure to disruption.
- Map what is being scaled: governance detail, control depth, documentation, test type and scope, remediation sequencing, supplier monitoring, or evidence retained for supervisory review. Do not reduce an express minimum frequency unless DORA or the competent authority permits it.
- Do not treat as a waiver of the core obligation to manage ICT risk, handle incidents, report major ICT-related incidents, maintain required third-party records, or meet requirements when identified by the competent authority.
Does EU DORA let a financial entity opt out of DORA?
No. affects how DORA requirements are applied and evidenced; it does not remove DORA for an entity that is in scope. Separate scope exclusions are listed in DORA Article 2, and the in Article 16 still contains mandatory ICT risk, monitoring, continuity, testing, dependency, and training duties.
Which DORA facts should be documented before relying on ?
Document the entity type, whether any Article 2 exclusion or Article 16 simplified-framework status applies, the entity's size and overall ICT risk profile, the nature and scale of its services, the complexity of operations, critical or important functions, key ICT assets, outsourced ICT services, major ICT-related incident history, and any supervisory instruction or testing result that changes the risk picture.
Article 4 defines DORA proportionality and Article 2 defines covered financial entities and exclusions.