DORA – time for a post-implementation compliance audit

12 March 2025 | Knowledge, News, The Right Focus

DORA entered into force on 17 January, together with new requirements for operational digital resilience within the financial sector and rules on the provision of ICT services in the financial market.

The final versions of the implementing acts for DORA are also expected to be published in the near future. According to current plans, a draft law implementing DORA, which will regulate the supervision of the Polish Financial Supervision Authority (KNF) in this area, should reach the Sejm (the lower house of the Polish Parliament) in the first quarter of this year.

DORA requirements for the financial sector

Under the new rules, financial institutions must meet new obligations, including in the following areas:

  • ICT risk management, i.e. the development of robust mechanisms for identifying, assessing and monitoring digital risks
  • ICT incident management, classification and reporting, i.e. appropriate procedures for responding to and reporting incidents  
  • Testing operational digital resilience, i.e. ensuring regular reviews of the effectiveness of security systems and crisis management
  • Managing the risks posed by ICT third-party service providers, i.e. ensuring security throughout the supply chain

To this end, financial institutions must ensure adequate internal preparation in terms of applicable policies, procedures, records or documentation (as required by the relevant Regulatory Technical Standards – RTS) and external preparation covering the security of contractual relationships with ICT service providers.

Has the financial sector managed to implement DORA

Although formally the financial sector should be ready, the fact that the adaptation processes have involved hundreds of documents and contracts means that many firms may still not be fully prepared. In addition, new sets of Q&As and authority positions on the application of DORA have been published, such as those on the exemption of ICT services related to regulated financial services from the DORA regime.

The remediation of supplier contracts is also a time-consuming process. This is because compliance depends on the other party and the length of associated negotiations.

One of the most common problems is the regulation of subcontractors and the imposition of additional obligations on ICT suppliers. The fact that the RTS on subcontracting have not yet been officially adopted does not make it easier for the parties to reach an agreement. In addition, for existing cloud contracts, DORA expands the definition of subcontractor used to date, which stems from the now repealed Cloud Computing Communication.

DORA – post-implementation compliance audits

Before 17 January 2025, financial institutions were racing against time to implement all the requirements of DORA, often overlooking more or less important issues.

In the interests of due diligence, it is therefore worth re-mapping any gaps and taking appropriate corrective action. A post-implementation compliance audit can be a solution.

As part of a compliance check, the post-implementation audit should cover not only the review and possible adjustment of internal procedures and policies, the verification of the accuracy of the register of information, the qualification of suppliers and the contracts concluded with them but also  the actual implementation of the relevant processes and compliance with all the requirements set out both in the DORA itself and in the implementing acts.

Any questions? Contact us

Latest Knowledge

Polish AI boom

According to the latest data, nearly 15,000 companies dealing with artificial intelligence were registered in Poland in 2025.[1] This testifies to an undoubted boom in AI, as well as to the dynamic changes related to the development of this technology. However, amid the rush to implement AI, do companies consider the most important issue: securing the outcomes of their work and protecting themselves against competitors? In this article, we explore this issue and suggest ways to avoid costly problems.

Length of service now includes periods of self-employment

The length of service no longer depends solely on work carried out under a contract of employment. The amendment to the Labour Code introduces significant changes, as work carried out under civil law contracts or as part of business activity will now also be included when calculating service, which affects employees’ rights. What will this mean for employees and employers?

Banking sector overview | Banking today and tomorrow | February 2026

The Polish banking sector is undergoing intense reshuffling on a scale not seen for years. Large banks are changing owners, foreign players are shifting their strategies and new investors are entering the market. The question is whether these are just temporary shifts in capital or the beginning of lasting change in the industry’s balance of power.

31 January. Don’t forget about the DAC7 Directive

The deadline for meeting the obligations under the DAC7 directive and the Polish regulations implementing it is fast approaching. Online platform operators must fulfil their reporting obligations by 31 January 2026 at the latest with regard to 2025 data. For many, this is the final opportunity not only to prepare the required information, but also to verify whether DAC7 obligations apply to them and, if so, to what extent.

The New Consumer Credit Act – extensive regulation with a broad market impact

In 2025, the Polish financial market entered another phase of adjustments to EU legislation. The draft new Consumer Credit Act implementing the CCD2 Directive, alongside the regulations on distance financial services, represents one of the most comprehensive attempts to standardise the rules for providing finance to consumers. The changes are so extensive that they cover all stages, from advertising and customer acquisition to the assessment of creditworthiness, the structure of agreements, the scope of the lender’s liability, withdrawal rules and the detailed organisation of remote sales.

Energy Radar 2026: Your roadmap to energy transition

Energy is no longer the exclusive domain of engineers and politicians; it is becoming the foundation of the business strategy of any company that wants to remain competitive. And 2026 will see a multitude of legislative changes that will fundamentally alter the current approach to the rules for grid connection, energy trading and reporting obligations.

Contact us:

Monika Maćkowska-Morytz

Monika Maćkowska-Morytz

Advocate / Partner / Head of the Personal Data Protection and Cyber Security Practice

+48 660 765 918

m.mackowska-morytz@kochanski.pl