Financial Entity (DORA)

Financial entity is the collective term Article 2(2) of DORA uses for the undertakings listed in Article 2(1), points (a) to (t): from credit institutions through investment firms and insurers to crowdfunding service providers. ICT third-party service providers fall within the Regulation's scope but are not financial entities.

DORALast reviewed:

A collective term with a hard edge

Article 2(1) of Regulation (EU) 2022/2554 lists, in points (a) to (u), the undertakings the Regulation applies to. Paragraph 2 then draws a definition out of that list: the undertakings named in points (a) to (t) are collectively referred to as financial entities. Point (u) names ICT third-party service providers; they are within scope, but they are not financial entities.

That single distinction carries the whole Regulation. Almost every substantive obligation is addressed to financial entities, while ICT third-party service providers are reached through contracts and, if designated as critical, through the Oversight Framework. An ICT provider serving the sector needs to grasp this about its own position first: DORA does not impose the ICT risk management framework on it, but its customers are obliged to impose most of the substance of it through the contract.

The categories in scope

The list covers the supervised financial sector almost completely:

  • credit institutions, payment institutions including exempted payment institutions, account information service providers, and electronic money institutions including exempted electronic money institutions
  • investment firms, crypto-asset service providers and issuers of asset-referenced tokens
  • central securities depositories, central counterparties, trading venues and trade repositories
  • managers of alternative investment funds, management companies and data reporting service providers
  • insurance and reinsurance undertakings, together with insurance, reinsurance and ancillary insurance intermediaries
  • institutions for occupational retirement provision, credit rating agencies, administrators of critical benchmarks, crowdfunding service providers and securitisation repositories

What governs in each case is the legal definition of the category concerned; Article 3 refers throughout to the relevant sectoral legislation. A firm that holds one of these authorisations is in scope on that basis, wherever in the Union it is established.

Who is not covered

Article 2(3) carves out certain undertakings, among them managers of alternative investment funds as referred to in Article 3(2) of Directive 2011/61/EU; insurance and reinsurance undertakings as referred to in Article 4 of Directive 2009/138/EC; institutions for occupational retirement provision operating pension schemes with no more than 15 members in total; natural or legal persons exempted pursuant to Directive 2014/65/EU; insurance intermediaries that are microenterprises or small or medium-sized enterprises; and post office giro institutions. Under paragraph 4, Member States may additionally exclude certain bodies listed in Directive 2013/36/EU that are located in their territory, so this one point does have to be checked against national law.

An entity that recognises itself in one of these groups should verify the exclusion against the referenced legislation and document the result. The carve-outs are narrow and hang on technical definitions, not on self-assessment.

Proportionality rather than all-or-nothing

DORA does not apply to every addressee at the same depth. Article 4 anchors the principle of proportionality: the rules of Chapter II are implemented in accordance with size and overall risk profile and the nature, scale and complexity of the entity's services, activities and operations. Application of Chapters III, IV and V, Section I is likewise proportionate, as specifically provided for in the rules of those Chapters. Competent authorities consider how the principle has been applied when they review the ICT risk management framework.

Proportionality is therefore not a licence. It calls for a reasoned design, not a reduction by preference.

The size categories the Regulation uses

Article 3 defines size classes that individual provisions attach to. A microenterprise is a financial entity (other than a trading venue, central counterparty, trade repository or central securities depository) that employs fewer than 10 persons and has an annual turnover and/or annual balance sheet total not exceeding EUR 2 million. Alongside it the Regulation also defines the small enterprise and the medium-sized enterprise. A number of easements attach to these categories, for instance the control function under Article 6(4), internal audit, redundant ICT capacities and the testing programme obligation under Article 24.

The simplified ICT risk management framework

For an exhaustively named group, Article 16 provides a separate, reduced framework; Articles 5 to 15 do not apply to them. Covered are small and non-interconnected investment firms, payment institutions exempted pursuant to Directive (EU) 2015/2366, institutions exempted pursuant to Directive 2013/36/EU in respect of which the Member State has not used the option in Article 2(4), electronic money institutions exempted pursuant to Directive 2009/110/EC, and small institutions for occupational retirement provision.

That framework is still substantial. It requires, among other things, a sound and documented ICT risk management framework; continuous monitoring of the security and functioning of all ICT systems; prompt identification of sources of ICT risk and anomalies; identification of key dependencies on ICT third-party service providers; continuity of critical or important functions through business continuity plans and response and recovery measures including back-up and restoration; regular testing of those plans and measures; and feeding the operational conclusions back into the ICT risk assessment process. The framework has to be documented, reviewed periodically and upon major ICT-related incidents, and presented to the supervisor in a report on request.

Incident reporting under Chapter III and the ICT third-party risk requirements of Chapter V, Section I are untouched by Article 16.

How Rizzqo keeps the scope workable

Whether a company falls under DORA is settled by the regulation. What has to be done afterwards is settled by your own estate. In Rizzqo the DORA catalogue is not applied to the company as a whole but distributed across individual objects through classification: a core banking system, an outsourced data centre and a software service each pick up the requirements belonging to their category.

That matters particularly for smaller entities, for which the regulation provides a simplified regime. The volume of work follows what is actually operated rather than the length of the catalogue. Where a requirement does not apply, that is recorded with a reason on the object instead of in a collective note.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework