Chapter II — ICT risk management
Section V — Learning and evolving
Further harmonisation of ICT risk management tools, methods, processes and policies
Summary
Empowers the European Supervisory Authorities (ESAs) to develop regulatory technical standards (RTS) further specifying the elements of the ICT risk management framework. These RTS detail the components of ICT security policies, business continuity management, and audit review requirements.
Key Requirements
- 1
ESAs develop RTS for ICT risk management framework components
- 2
RTS specify ICT security policies and procedures details
- 3
RTS define business continuity management requirements
- 4
Standards for ICT audit reviews and testing approaches
Detailed Analysis
Article 15 is a delegation article that empowers the European Supervisory Authorities — the EBA, EIOPA, and ESMA — to develop regulatory technical standards (RTS) that provide granular detail on how the ICT risk management framework requirements should be implemented. This two-tier approach (Level 1 regulation + Level 2 technical standards) is standard in EU financial regulation and allows technical requirements to be updated without amending the regulation itself.
The RTS developed under this article cover several critical areas: the specific elements to be included in ICT security policies and procedures, the detailed requirements for business continuity management including testing methodologies, and the standards for ICT audit reviews. These technical standards translate DORA's principle-based requirements into implementable specifications.
The development of RTS by the ESAs involves consultation with industry, which provides financial entities with an opportunity to influence the practical implementation details. However, once finalized, the RTS have the same binding force as the regulation itself and must be complied with within the specified timelines.
For financial entities, Article 15 means that compliance requires monitoring not just the Level 1 DORA text but also the evolving body of RTS. The technical standards may impose specific requirements regarding security control frameworks, testing frequencies, documentation formats, and reporting templates that go beyond what the regulation itself specifies.
Ready to automate compliance with Article 15?
Valendir maps every DORA requirement to actionable controls, evidence, and workflows.