DORA in Practice: What Operational Resilience Means for Banking Professionals | eBSI

DORA in Practice: What Operational Resilience Means for Banking Professionals

Operational resilience has become a banking discipline

Modern banking depends on digital infrastructure for payments, customer access, lending, trade finance, compliance, treasury and internal operations. A major technology failure is therefore no longer an inconvenience confined to the IT department; it can become a business interruption affecting customers, markets and regulatory obligations. The Digital Operational Resilience Act, DORA, responds to this reality by creating a common European framework for ICT risk management, incident reporting, resilience testing and third-party technology risk.

For banking professionals, the important point is that resilience is an organisation-wide responsibility. Every business function depends on systems, data and external providers. Trade finance relies on document platforms and sanctions screening; retail banking relies on digital channels and payment infrastructure; compliance depends on monitoring tools and data; credit teams depend on models and information systems. A failure in one area can propagate quickly.

Preparation, prevention and detection

Effective resilience begins with understanding what is critical. Banks should know which services must continue during disruption, which systems support those services and which third parties sit underneath them. Without this map, recovery planning becomes speculative. Criticality assessments should therefore connect technology dependencies to actual customer and business outcomes.

Prevention remains essential. Secure configuration, patching, access management, monitoring and effective change control reduce the probability of failure. DORA, however, also reflects a broader principle: some failures will occur despite preventive controls. Resilience therefore depends on the organisation's ability to detect disruption quickly, contain it and continue delivering critical services.

Detection requires both technology and clear escalation. Staff should understand what constitutes an incident, how unusual activity is reported and when an event may become sufficiently serious to require regulatory notification. Ambiguity during an incident consumes valuable time.

Response, recovery and learning

When disruption occurs, responsibilities need to be explicit. Who leads the response? Who communicates with customers? Who determines whether a service should be suspended? Who liaises with supervisors? These decisions should not be invented during a crisis. Scenario exercises and documented authority make the response faster and more consistent.

Recovery involves more than restoring a system. Data integrity may need to be checked, transactions reconciled and downstream processes reviewed. A service that is technically online but operating with corrupted or incomplete information is not genuinely recovered. Banks should therefore define recovery criteria that include business correctness, not only system availability.

Every significant incident should also produce learning. Root-cause analysis, remediation tracking and review of communication and escalation are central to resilience. Near misses deserve attention because they reveal weaknesses before a large loss occurs.

Third-party technology risk under DORA

Banks increasingly depend on cloud services, software providers, payment processors and specialist vendors. Outsourcing can improve efficiency, but it does not transfer accountability. Institutions need to understand the resilience of critical suppliers, contractual rights, incident-notification arrangements, recovery capabilities and exit options.

Concentration risk is particularly important. If many critical functions depend on one provider, the failure of that provider may affect several institutions simultaneously. DORA's attention to critical third-party providers reflects the systemic nature of this risk.

Artificial intelligence adds another layer. Banks increasingly use external AI models and services within analytics, fraud detection, customer service and productivity tools. The same resilience questions apply: where is data processed, how are models updated, how quickly can the bank switch provider and what happens when the external service is unavailable?

Resilience testing and organisational culture

Testing should be designed to reveal weakness rather than demonstrate compliance. Scenario-based exercises can examine the loss of a customer portal, a cloud outage, ransomware, corrupted data or failure of a third-party provider. More advanced institutions may also consider AI-related scenarios, such as widespread incorrect output or the loss of a model service embedded in a critical process.

People remain central. A technically well-designed recovery plan is ineffective if staff cannot follow it under pressure. Training, communication and realistic exercises therefore matter. Senior management involvement is equally important because resilience affects reputation, customer trust and financial performance.

DORA encourages a useful cultural shift. Traditional operational risk often focused on preventing failure; modern resilience accepts that some disruption is inevitable and concentrates on the bank's ability to continue delivering essential services. That requires redundancy, contingency, clarity and informed decision-making.

Conclusion

For banking professionals, digital competence is now part of professional competence. Managers do not need to configure firewalls, but they should understand which technology supports their function, what fallback arrangements exist and how supplier dependencies affect risk. The eBSI Banking Academy therefore treats operational resilience as a core component of contemporary banking knowledge.

DORA is most useful when it changes behaviour between incidents rather than merely producing regulatory reports. Institutions that understand their dependencies, test them honestly and learn from failure become more resilient not only to cyberattack but to technology change generally. Operational resilience is ultimately about trust: customers expect access to their money, businesses expect payments to move and markets expect financial institutions to function when conditions are difficult.

Resilience should be visible in ordinary management information

DORA will have the greatest value where resilience becomes part of normal management rather than an annual compliance exercise. Senior management should receive information on significant incidents, recurring vulnerabilities, supplier dependencies, testing outcomes and overdue remediation. These indicators make it possible to see whether operational weakness is accumulating before a major event occurs.

Business functions should also understand their own resilience assumptions. A manager should know which applications are critical to the function, how long they can be unavailable and what manual alternatives exist. This knowledge is particularly important when digital transformation removes older fallback processes. Efficiency can unintentionally reduce resilience if the organisation becomes dependent on one highly optimised system with no practical alternative. DORA encourages banks to examine that trade-off explicitly and to ensure that critical services remain recoverable under realistic conditions.

Documentation should support action rather than merely demonstrate compliance. Critical procedures, contact details and decision authorities should be accessible when normal systems are unavailable. Institutions should test whether staff can actually use the plan under realistic conditions. A resilience framework that works only when all ordinary tools remain available is unlikely to be useful during the disruption for which it was designed.