Auditors, lawyers, tax consultants and management consultants: Four perspectives. One solution. Worldwide. Find out …
Our clients entrust us with their most important legal matters. Learn more about our legal services!
Tax laws are complex and dynamic. We face the challenge of tax law together with you - find out more.
Baker Tilly advises biotech startup Real Collagen GmbH investment by US investor
Countdown to September – The EU Data Act and its implications
Electronic salary statements: BAG allows purely digital provision
Procurement law – legal framework for emergency procurements in the event of a cyberattack
Tax CMS in tax audits: BStBK calls for clear regulations
Baker Tilly wins transfer pricing specialist Christian Jacob
Industry-specific knowledge is essential in order to create the best conditions for customised solutions. Find out …
After ECJ ruling: Financial investors still have no direct access to medical care centers
Hospital reform: New exemption from merger control in the hospital sector
Benefit from bundled interdisciplinary competencies, expert teams and individual solutions. Learn more!
From January 17, 2025, the Digital Operational Resilience Act (DORA) will be applied and previous supervisory requirements for IT will be (gradually) removed. For affected financial companies, this has consequences with regard to internal auditing and service provider management. The next step is the submission of the information register.
Financial service providers benefit from the use of a wide range of highly specialized information and communication technologies (ICT). The DORA Regulation harmonizes the regulatory framework for the management of ICT-related risks across Europe. The aim is to make the European financial sector more digitally resilient.
DORA imposes comprehensive requirements on financial institutions for the management of ICT risks, including
It is essential to review and adapt existing IT systems and processes to ensure that the DORA fit is successful. This applies to banks, insurance companies, investment firms, payment service providers – but also to companies that were previously outside the scope of the regulatory IT requirements (such as rating agencies).
DORA introduces strict requirements for financial institutions to monitor and control third-party ICT providers. The register of third-party provider contracts, which financial institutions must mandatorily keep, plays a central role in this respect. The register serves to control risks arising from the use of third-party ICT providers.
The deadline for submitting the information register to the German Federal Financial Supervisory Authority (“BaFin”) marks the next milestone in the implementation of DORA. German financial companies must submit their information registers to BaFin by April 11, 2025.
According to DORA, financial companies must keep a complete and up-to-date register of all contracts with third-party ICT providers. The contents include, among other things:
The register serves not only for internal risk monitoring purposes, but also for supervision by regulatory authorities. It enables improved transparency regarding dependencies on third-party providers and potential concentration risks. Particularly in cases where many financial institutions use the same third-party providers, the register helps to identify risks to the stability of the financial sector at an early stage.
Maintaining this register requires not only careful recording of contract details, but also continuous updating and review. Financial institutions must ensure that all relevant information is fully and correctly documented. In addition, DORA requires that this data is reviewed at regular intervals for potential risks and considered with strategic measures such as exit strategies.
The information register therefore goes beyond the previous requirements for the outsourcing register. For financial institutions, this means an expansion of their documentation obligations and a closer integration of risk and contract management. IT service providers should be prepared for more intensive audits and greater involvement in resilience programs.
In Germany, the Digital Operational Resilience Act will apply from January 17, 2025. The previous regulatory requirements (xAIT) for IT will be (gradually) repealed: KAIT (capital management supervisory requirements for IT), VAIT (insurance supervisory requirements for IT) and ZAIT (payment services regulatory requirements for IT) were repealed as of January 16, 2025. Institutions that fall under DORA will be exempt from BAIT (banking supervisory requirements for IT) from January 17, 2025. Chapter 11 of BAIT will also be repealed from this date. With the revision of Art. 1a (2) of the German Banking Act by the Financial Market Digitization Act (FinMadiG), further institutions will have to apply DORA from January 1, 2027. BAIT will therefore be completely repealed as of December 31, 2026.
This replacement of the regulatory requirements has implications for the internal audit of financial service providers in their area of application. Due to the transition to DORA, the audit universe must be reviewed and adapted. This involves mapping the requirements of BAIT against those of the new regulation and filling gaps in the existing audit universe.
DORA poses a regulatory challenge, but at the same time offers the opportunity to strengthen stakeholder confidence. A proactive approach not only ensures compliance, but also provides a competitive advantage in the digitalized financial world. As experienced specialists, we offer comprehensive services for DORA implementation:
We support you in the successful implementation of DORA - contact us!
Ralph Hüsemann
Partner
German CPA
Daniel Boms
Director
Certified Information Systems Auditor
Contact now
Contact us
View all news