AMISOURCE.

All insightsDORAFinanceCompliance

DORA is in force: what AI suppliers to the financial sector must be able to prove

Published 6 min read

Since 17 January 2025, the EU's Digital Operational Resilience Act — DORA — applies. It covers twenty types of financial entities: banks, insurers, payment institutions and their critical suppliers. And because AI systems in that sector are almost always part of the supply chain, the question arrives earlier than many expected: what must you, as an AI supplier, be able to prove?

DORA is about the supply chain, not just the bank

The core of DORA is that digital resilience must be demonstrable through the entire chain. Financial entities are accountable for their ICT service providers — and for those providers' subcontractors. An AI solution that predicts credit risk, automates customer dialogue or analyses transactions is, in that perspective, an ICT system to be governed like any other: with contracts, controls and evidence.

In practice, financial entities ask their suppliers questions like:

  • Which data is processed, where, and under which terms?
  • How fast can you report an incident affecting our solution — and to whom?
  • What happens if you disappear? Is there an exit plan that actually works?
  • How is the solution's resilience tested, and can you participate in our threat-led penetration tests (TLPT)?

Three things to have in place — before the customer asks

1. Contracts that survive an audit. DORA sets requirements on ICT contract content: service levels, incident reporting, data portability and termination terms. Standard MSAs rarely suffice. We have seen procurements stall for weeks on this point — not on the technology.

2. Incident readiness that includes AI. Financial entities must report major ICT incidents on thresholds measured in hours. If your AI solution is part of their service, your own incident process must feed their clock. "We'll get back to you on Monday" is not an answer.

3. Documented governance. Model choices, data flows, evaluations and human control points — documented so they hold up to both the customer's risk function and the supervisor. The same principle as in the pharmaceutical world where we have roots: what isn't documented didn't happen.

Where this differs from other regulations

GDPR asks "are you allowed to?", DORA asks "will you survive? — and can you prove it, in real time, through the whole chain?". That difference makes DORA a supplier question to a much higher degree than most AI-related regulation. It is also why we see financial entities starting to require a DORA track in supplier agreements already at the first contract renewal after the act took effect.

Our recommendation

If you deliver AI to the financial sector: do a DORA read of your own delivery now, before a customer does it for you. Map the data flows, write the incident routine in hours rather than days, and get the contract library in order. It is bounded work — and it sells itself in the next procurement.

Sources

  • EIOPA — overview of DORA's scope (20 entity types), eiopa.europa.eu
  • Mayer Brown — DORA takes effect, 17 January 2025
  • Regulation (EU) 2022/2554 (DORA), eur-lex.europa.eu

Next step

Ready to talk about where AI pays off in your business?

Book a free 30-minute intro call. We listen, ask questions and tell you honestly whether we're the right partner — or not.