Practice note
DORA in practice for payment and e-money institutions
The Digital Operational Resilience Act has applied since January 2025. For smaller payment and e-money institutions, the practical burden sits largely in ICT third-party arrangements.
5 min readJurisdictions: EU

DORA applies to a wide range of EU financial entities, including payment institutions, e-money institutions, investment firms and crypto-asset service providers. It sets requirements for ICT risk management, incident reporting, resilience testing and the management of ICT third-party risk.
Where the work tends to concentrate
- Maintaining a register of information on all contractual arrangements with ICT third-party service providers.
- Ensuring contracts with ICT providers contain the provisions DORA requires, particularly for critical or important functions.
- Classifying and reporting major ICT-related incidents within the prescribed timelines.
- Documenting an ICT risk management framework proportionate to the size and risk profile of the firm.
Proportionality
DORA incorporates proportionality, and certain smaller entities benefit from a simplified ICT risk management framework. Proportionality does not remove obligations around third-party contracts or incident reporting, which remain the areas where supervisors most often find gaps.
Contracting with technology vendors
Many fintechs rely on cloud, core platform and KYC vendors whose standard terms were not drafted with DORA in mind. Renegotiating these terms — or documenting why a provider is not supporting a critical function — should be part of every vendor onboarding and renewal.
This article is general commentary and does not constitute legal advice. Regulatory positions change; please seek advice on your specific circumstances.



