Within financial sector critical national infrastructure, DORA has a settled institutional home. It lives in the ICT function. The Digital Operational Resilience Act is read as a regulation about technology resilience, owned by the chief information officer or the chief information security officer, addressed through technology controls, testing, and third-party management. This categorisation is technically defensible. The regulation does concern digital operational resilience, and ICT is where digital resilience is engineered.
It is also strategically wrong, and the organisations that have made it are building DORA compliance programmes that will satisfy the technical requirements and fail the institutional ones. DORA's testing obligations, its governance requirements, and its third-party risk provisions demand institutional decision systems and governance structures that the ICT function does not own and cannot build. The technology is the achievable part. The institutional architecture to govern it is the part most firms do not have, and the part their ICT-located DORA programmes are not equipped to deliver.
What DORA Actually Requires
DORA is frequently summarised as a set of technical resilience requirements, and it does contain those. But its substantive demands are governance demands, and they reach well beyond the ICT function.
The regulation requires a documented ICT risk management framework that is owned and overseen by the management body, not by the ICT function. It requires the management body to define, approve, and oversee the implementation of the framework, and to bear ultimate responsibility for it. This is a governance requirement: it places ICT risk on the board's agenda as a matter of direct accountability, in much the same way that NIS2 places cybersecurity there. The framework is not an ICT artefact. It is a governance artefact that the ICT function contributes to.
DORA requires digital operational resilience testing, including, for significant entities, threat-led penetration testing conducted against live production systems. This is partly technical, but the obligation to design a testing programme that genuinely tests resilience, to act on its findings, and to evidence that the organisation's resilience has been validated under realistic conditions is an institutional obligation. A testing programme that runs the tests and does not drive change is technically compliant and substantively worthless, and the difference between the two is a matter of governance, not technology.
DORA requires comprehensive management of ICT third-party risk, including the maintenance of a register of all ICT third-party arrangements, the assessment of concentration risk, and the establishment of exit strategies for critical providers. This is a governance and procurement obligation as much as a technical one. It requires the organisation to understand its dependencies, govern them, and maintain the institutional capability to exit them. The ICT function can map the technical dependencies. It cannot, on its own, govern the commercial relationships, manage the concentration risk, or build the institutional exit capability that DORA requires.
The Institutional Gap
The pattern across all of these requirements is the same. DORA specifies a technical surface and an institutional substance, and the institutional substance is where the difficulty lies.
The technical surface is what the ICT function naturally addresses: the controls, the testing infrastructure, the dependency mapping, the technical resilience measures. This work is demanding but tractable. It is the kind of work the ICT function knows how to do, has the capability to do, and can complete to an evidenced standard.
The institutional substance is what DORA actually requires and what the ICT-located programme tends to miss: the governance framework owned by the board, the decision systems that act on testing findings, the institutional management of third-party risk, the organisational capability to exit critical dependencies. This is not ICT work. It is governance, decision-system, and institutional capability work, and the ICT function neither owns it nor has the authority to build it.
The result is a characteristic gap. The DORA programme delivers a sophisticated technical resilience capability and an underdeveloped institutional one. The board has approved a framework it does not genuinely own. The testing runs but does not drive institutional change because the decision systems to act on its findings do not exist. The third-party register is maintained but the concentration risk is not genuinely governed and the exit strategies are documents rather than capabilities. The programme is technically impressive and institutionally hollow, and the hollowness is invisible until DORA's requirements are tested by a real disruption or a serious regulatory examination.
Why the Mislocation Persists
DORA ends up in the ICT function for reasons that are understandable and that produce the wrong outcome. The regulation's name and subject matter point to technology. Digital operational resilience sounds like an ICT concern, and the natural institutional response is to assign it to the function that owns digital systems. The assignment feels correct, and it is correct for the technical surface, which is why it persists.
The institutional substance of DORA does not have an obvious owner. The governance framework, the decision systems, the third-party risk governance, the exit capability, these cut across functions and do not belong cleanly to any of them. Faced with a regulation that has a clear technical component and a diffuse institutional component, organisations assign it to the function that owns the clear part and allow the diffuse part to fall into the gaps between functions, where it goes unaddressed.
The people who understand DORA's technical requirements are not, in most organisations, the people who can build its institutional substance. The CISO can specify the testing programme. The CISO cannot reform the board's governance of ICT risk, redesign the organisation's decision systems, or build the institutional capability to govern and exit third-party dependencies. Those require authority and capability that sit elsewhere in the organisation, and the DORA programme, located in ICT, does not reach them.
What Genuine Compliance Looks Like
A financial sector CNI operator that wants to comply with DORA in substance has to treat it as the institutional programme it is, which means locating it differently and resourcing it differently. The programme needs an owner with the authority to reach across functions: not the CISO, but someone at or close to board level who can drive the governance reform, the decision-system development, and the institutional capability building that DORA requires. The ICT function contributes the technical surface; it does not own the programme.
The governance framework needs to be genuinely owned by the board, which requires the board engagement, competence development, and information architecture changes that genuine ownership demands. A framework the board has approved but does not genuinely govern is the institutional hollowness that DORA is designed to prevent. The testing programme needs to be connected to decision systems that act on its findings, which means building the institutional mechanism by which a test result becomes an organisational change. The third-party risk management needs to be a genuine governance and procurement capability, not a maintained register.
DORA is a financial regulation that reads as an ICT regulation and is, in substance, an institutional one. The firms that locate it correctly, resource its institutional substance, and build the governance and decision systems it actually requires will achieve the resilience the regulation intends. The firms that leave it in the ICT function will build excellent technical resilience on top of institutional foundations that DORA's requirements were specifically designed to strengthen and that, in these firms, remain unbuilt. The technology was never the hard part. DORA knew that. Most of the firms complying with it have not yet caught up.
