lei partnerships small

Commercial Partnerships

Our partnership programme offers flexible, customisable solutions to meet you and your client bases LEI needs.

lei customer support small

Help Centre

Find the help and support you need for your LEI from our highly trained support staff

DORA

The financial landscape is undergoing a radical digital transformation. As banks, investment firms, and insurance companies move away from legacy systems toward cloud computing and integrated software solutions, their reliance on Information and Communication Technology (ICT) has never been higher. However, this evolution brings a new set of vulnerabilities. To address these, the European Union has introduced a landmark regulation: the Digital Operational Resilience Act (DORA).

With the implementation date of 17 January 2025 fast approaching, it is essential for entities within the financial sector and their ICT service providers to understand their obligations, the requirements for compliance, and the critical role of the Legal Entity Identifier (LEI) in this new regulatory framework.

Understanding the Basics: What is DORA?

DORA is a regulation (Regulation (EU) 2022/2554) designed to harmonise security and resilience standards across the European financial industry. Unlike previous guidelines that varied between member states, DORA provides a single, unified framework that ensures all institutions can withstand, respond to, and recover from ICT risks and incidents.

The purpose of this legislation is to shift the focus from traditional financial stability (having enough capital) to operational resilience (ensuring systems keep running during a crisis). It was adopted by the European Parliament and the Council to create a safer digital environment for clients and users of financial services.

Why is DORA Necessary?

Before DORA, regulators like the European Banking Authority (EBA), the European Securities and Markets Authority (ESMA), and the European Insurance and Occupational Pensions Authority (EIOPA); collectively known as the European Supervisory Authorities (ESAs); had different approaches to ICT risk management.

This fragmentation created gaps and weaknesses in the oversight of third-party service providers. DORA closes these gaps by bringing ICT providers under direct supervision, ensuring that a failure at a major cloud or analytics provider does not trigger a systemic collapse of the European financial system.

The Five Pillars of the DORA Framework

To achieve operational resilience, DORA is built upon five core elements. Every entity in scope must align its internal processes, governance, and technology with these pillars.

1. ICT Risk Management Framework

The starting point for compliance is a robust ICT risk management framework. Management bodies and teams are now legally responsible for the organisation’s digital strategy.

  • Identification: Constant monitoring of threats and vulnerabilities.
  • Protection: Implementing security measures such as encryption and access controls.
  • Detection: Setting up mechanisms to identify anomalies in real-time.
  • Response and Recovery: Detailed continuity plans and disaster recovery protocols to ensure functions remain active during disruptions.

2. ICT Incident Management and Reporting

When incidents occur, transparency is mandatory. Firms must establish procedures to classify ict incidents based on criteria set by the ESAs.

  • Reporting: Major ict-related incidents must be reported to the relevant authorities.
  • Templates: Use of standardised templates to ensure data consistency across the EU.
  • Timeline: Strict deadlines for initial notification, intermediate reports, and final analysis.

3. Digital Operational Resilience Testing

It is no longer enough to claim security; you must prove it. DORA mandates a range of tests, including:

  • Vulnerability assessments and open-source analysis.
  • Performance testing and gap analysis.
  • TLPT (Threat-Led Penetration Testing): For significant entities, advanced penetration testing must be conducted every three years to simulate real-world cyber-attacks.

4. ICT Third-Party Risk Management

This is perhaps the most impactful part of the regulation. Banks, credit institutions, and investment firms must manage risks associated with their ict service providers.

  • Contracts: Agreements must include specific clauses regarding data location, audit rights, and service levels.
  • Register of Information: Entities must maintain a register of all outsourcing arrangements.
  • Exit Strategies: Firms need a clear way to terminate contracts without disrupting their operations.

5. Information Sharing

DORA encourages organisations to share intelligence regarding cyber threats. By exchanging knowledge and insights, the industry can collectively improve its detection capabilities and response to threat actors.

The Role of the Legal Entity Identifier (LEI) in DORA

LEI Code

A cornerstone of the oversight framework is the unambiguous identification of all parties involved. ESMA, in its Final Report on Register of Information, explicitly stated that entities must use the Legal Entity Identifier (LEI) to identify ICT third-party service providers.

Why the LEI is Mandatory

The LEI is a 20-character alphanumeric code that provides a global standard for identifying legal persons. Under DORA, the LEI serves several vital functions:

  • Aggregation: It allows regulators to see the total reliance of the financial sector on a single provider (e.g., a specific cloud platform).
  • Traceability: It maps dependencies within complex corporate structures.
  • Integrity: It ensures that data in the reporting templates is accurate and verifiable.

Important Notice: The DORA LEI requirement specifies that an LEI must be active. If a provider has a lapsed LEI, it is considered non-compliant. Entities must ensure annual renewal through a trusted provider like LEI Worldwide.

Who Must Comply? Scope and Applicability

The scope of DORA is incredibly broad, covering almost all organisations in the financial landscape. This includes:

  • Credit institutions and Banks.
  • Investment firms and Investment funds.
  • Insurance companies and re-insurance undertakings.
  • Crypto-asset service providers (under MiCA).
  • Credit rating agencies.
  • ICT third-party service providers (even those based in the UK or other non-EU jurisdictions if they serve EU clients).

The Concept of Proportionality

While the rules are strict, DORA applies a principle of proportionality. The level of compliance requirements depends on the size, risk profile, and importance of the entity. For example, a small insurance agency will not face the same penetration testing standards as a global systemic bank.

Practical Steps for Implementation

With the 17 January 2025 deadline approaching, firms should follow these steps to ensure they are ready for the force of the law.

1. Conduct a Gap Analysis

Compare your current ict risk management policies against the RTS (Regulatory Technical Standards) issued by the ESAs. Identify gaps in your documentation, tools, and security measures.

2. Audit Your ICT Providers

Review your contracts with ict service providers. Ensure they have an active LEI. If they do not, they must register for one immediately. Use an LEI Look Up tool to verify the status of your partners.

3. Establish Governance and Oversight

Ensure your board of directors understands their responsibility. DORA is not just an “IT issue”; it is a governance requirement. Training for employees and management is essential.

4. Implement Automation and Software Solutions

Managing a register of information manually is prone to failure. Utilise a platform or suite of tools designed for DORA compliance. Automation in incident management and reporting will save significant time and reduce the risk of regulatory action.

5. Update Business Continuity Plans

Your business continuity and recovery strategies must be tested against realistic scenarios. Ensure your team knows exactly how to respond to cyberattacks or system disruptions.

The Impact on ICT Service Providers

If you are a provider of cloud computing, software, or data analytics to the financial sector, DORA changes your relationship with your clients.

  • Direct Oversight: Critical ict providers may be assigned a Lead Overseer from one of the ESAs.
  • Audit Obligations: You must allow your financial clients to conduct audits and insists on certain security standards.
  • Liability: There is a greater level of accountability for service failures that impact the stability of the market.

For these providers, obtaining and maintaining an LEI is the starting point for continued support of the European market.

Frequently Asked Questions

What is the exact date DORA becomes law?

DORA entered into force in 2023, but its provisions apply fully from 17 January 2025.

Do UK firms need to care about DORA?

Yes. If a UK-based organisation provides ict services to a firm within the European Union, they must comply with the contractual and identification requirements (including the LEI) set out in the regulation.

What happens if an LEI is lapsed?

A lapsed LEI is the same as having no LEI in the eyes of the regulator. Entities must ensure their LEIs are renewed annually. LEI Worldwide offers automated renewal services to prevent this issue.

Who are the ESAs?

The European Supervisory Authorities (ESAs) consist of the EBA (Banking), ESMA (Securities/Markets), and EIOPA (Insurance). They are responsible for drafting the Regulatory Technical Standards (RTS) that provide the technical details of DORA.

Summary: A New Era of Digital Trust

The Digital Operational Resilience Act represents a significant change in how the financial sector views technology. By treating ICT risk with the same importance as credit or market risk, the EU is building a more resilient and stable economy.

Compliance requires a multi-faceted approach:

  • Strong governance and management involvement.
  • Rigorous testing and incident monitoring.
  • Transparent reporting and oversight of third parties.
  • The use of global standards like the LEI for clear identification.

Navigating the landscape of regulations, articles, and technical standards can be daunting. However, by taking action now; conducting a gap analysis, updating contracts, and ensuring all ict providers have active LEIs; your organisation will not only meet compliance requirements but also gain a competitive insight into its own operational integrity.

How We Can Support Your DORA Journey

At LEI Worldwide, we specialise in helping firms manage the identification aspect of regulatory compliance. We can help you:

  • Conduct an LEI Health Check: Identify which of your ict service providers lack an active LEI.
  • Streamline Registration: Bulk register or renew LEIs for your entire supply chain.

Automate Compliance: Use our Watchlist tool to monitor the status of your partners and ensure no lapsed codes trigger a compliance breach.

×

Request a Demo