KPMG Finds DORA Evidence Gaps in ECB Banks

ECB banks are moving past DORA adoption and into the harder phase of proving resilience with auditable evidence, stronger testing, and board-ready metrics.

Updated

What is this trend?

KPMG’s ECB bank review shows DORA compliance is now being judged by proof of effective controls, not just policy adoption, exposing gaps in resilience evidence.

  • Less than half had board-approved ICT risk appetite statements.
  • Exit strategies and third-party concentration risk are still weak.
  • Testing exists, but advanced scenario and TLPT coverage is limited.
  • Continuity, security, vendor risk, and incident response need end-to-end evidence.
  • Risk teams must build continuous evidence pipelines for regulators and boards.

What’s the latest?

KPMG’s review of 23 ECB-related banks shows the next hurdle is not policy adoption but proving that DORA works in practice.

How it developed

  1. Board-Level Cyber Governance, Live Node Dependency Triage, and Real-Time Continuity Planning
  2. Always-On Risk Operations, Harder Verification Gates, and Faster Provenance Checks

Go deeper

Curated long-form picks on this trend — podcasts, videos, and analysis, by seniority.

Stay ahead in Risk Management

Get the weekly Risk Management brief in your inbox — the developments, what they mean by seniority, and what to do next.