DORA – time for a post-implementation compliance audit

12 March 2025 | Knowledge, News, The Right Focus

DORA entered into force on 17 January, together with new requirements for operational digital resilience within the financial sector and rules on the provision of ICT services in the financial market.

The final versions of the implementing acts for DORA are also expected to be published in the near future. According to current plans, a draft law implementing DORA, which will regulate the supervision of the Polish Financial Supervision Authority (KNF) in this area, should reach the Sejm (the lower house of the Polish Parliament) in the first quarter of this year.

DORA requirements for the financial sector

Under the new rules, financial institutions must meet new obligations, including in the following areas:

  • ICT risk management, i.e. the development of robust mechanisms for identifying, assessing and monitoring digital risks
  • ICT incident management, classification and reporting, i.e. appropriate procedures for responding to and reporting incidents  
  • Testing operational digital resilience, i.e. ensuring regular reviews of the effectiveness of security systems and crisis management
  • Managing the risks posed by ICT third-party service providers, i.e. ensuring security throughout the supply chain

To this end, financial institutions must ensure adequate internal preparation in terms of applicable policies, procedures, records or documentation (as required by the relevant Regulatory Technical Standards – RTS) and external preparation covering the security of contractual relationships with ICT service providers.

Has the financial sector managed to implement DORA

Although formally the financial sector should be ready, the fact that the adaptation processes have involved hundreds of documents and contracts means that many firms may still not be fully prepared. In addition, new sets of Q&As and authority positions on the application of DORA have been published, such as those on the exemption of ICT services related to regulated financial services from the DORA regime.

The remediation of supplier contracts is also a time-consuming process. This is because compliance depends on the other party and the length of associated negotiations.

One of the most common problems is the regulation of subcontractors and the imposition of additional obligations on ICT suppliers. The fact that the RTS on subcontracting have not yet been officially adopted does not make it easier for the parties to reach an agreement. In addition, for existing cloud contracts, DORA expands the definition of subcontractor used to date, which stems from the now repealed Cloud Computing Communication.

DORA – post-implementation compliance audits

Before 17 January 2025, financial institutions were racing against time to implement all the requirements of DORA, often overlooking more or less important issues.

In the interests of due diligence, it is therefore worth re-mapping any gaps and taking appropriate corrective action. A post-implementation compliance audit can be a solution.

As part of a compliance check, the post-implementation audit should cover not only the review and possible adjustment of internal procedures and policies, the verification of the accuracy of the register of information, the qualification of suppliers and the contracts concluded with them but also  the actual implementation of the relevant processes and compliance with all the requirements set out both in the DORA itself and in the implementing acts.

Any questions? Contact us

Latest Knowledge

Payment Services Regulation (PSR) – between consumer protection and due diligence

The draft Payment Services Regulation (PSR) is one of the most significant elements of the reform of the EU legal framework for payment services. Its principal aim is to enhance the security of cashless transactions and to reduce the scale of financial fraud, in particular that arising from the growth of digital channels. At the same time, the new rules are intended to introduce a liability model that will not result in risk being transferred entirely to financial institutions, whilst retaining an important role for independent due diligence on the part of the user.

Energy deregulation – key changes for businesses and energy consumers

The President has now signed the Energy Deregulation Act (UDER92). The new provisions cover both the relationships between energy undertakings and consumers, and matters relating to investment, district heating, and the administrative obligations of energy market participants. The Act introduces changes in the areas of billing, communication with consumers, grid connection, and the operations of undertakings in the energy and district heating sectors. We set out the key points to note.

Banking sector overview | Banking today and tomorrow | July 2026

Under the draft legislation, banks will be required to offer existing borrowers a switch from WIBOR-based to POLSTR-based interest rates, a mechanism intended to speed up the voluntary transition of financial instruments to the new benchmark. The banking sector has responded positively to the proposal, according to Tadeusz Białek, President of the Polish Bank Association.

“Withdraw from contract here” – what next for the new button in online shops, on trading platforms and in mobile apps?

From 19 June, national legislation was to require businesses in the European Union entering into distance contracts with consumers via an online interface to provide consumers with the option to withdraw from the contract via a dedicated function/button. However, due to Poland’s delay in transposing Directive 2023/2673, which requires the use of such a button, this obligation has been postponed in our country. We look at what remote contract withdrawal entails and which transactions the new feature will apply to.

Municipal master plans – new deadline, same old challenges

On 11 June 2026, the President signed into law a bill extending the deadline for municipalities to adopt their master plans (plany ogólne). The key deadline for adopting master plans was moved from 30 June to 31 August 2026. We examine the reasons behind this change and consider what the absence of a master plan might mean for potential investors and their future projects.

Record fines and the upcoming 21st sanctions package – what should businesses expect?

The past year has brought a series of enforcement actions that clearly signal a tightening approach by the Polish customs and revenue authorities towards breaches of the sanctions regime. Importantly, businesses should already be preparing for further changes, as the European Union has announced its 21st sanctions package and updated the list of designated persons and entities. We examine the key developments and offer guidance on how to minimise the risk of non-compliance.

A sea change in the rules governing board members’ liability for a company’s tax arrears

The bill amending the General Tax Code (No. UC138) fundamentally overhauls the rules governing the tax liability of third parties for capital companies’ tax arrears.  It comes in response to recent CJEU judgments, the Ombudsman’s February statement and the post-audit report of the Supreme Chamber of Audit (NIK) of December 2025. We examine what’s changing, who will be affected by the new rules and what steps are worth taking right now.

Partner in name, but only if male: the linguistic trap in Polish corporate law

One of the structures available under Polish law is the ‘spółka partnerska’ (professional partnership), modelled on the Anglo-Saxon Limited Liability Partnership. As defined in the Polish Commercial Companies Code, this is a vehicle for individuals practising liberal professions, such as doctors, architects and accountants. And yet, the provisions governing professional partnerships make no mention of their applicability to women. We therefore examine whether there is no room for female partners, feminine-gendered forms, or simply linguistic empathy.

Can you sue over words aimed at an entire community?

A damaging public statement does not necessarily refer to a specific individual. Sometimes, the author attributes negative characteristics to a whole group of people, portrays them as a threat or uses language that could be seen as demeaning. Statements of this kind frequently concern LGBTQ+ people. This raises the question: can a member of the targeted community bring a lawsuit seeking compensation or an apology, even if they were not named directly? We decided to look into this.

Contact us:

Monika Maćkowska-Morytz

Monika Maćkowska-Morytz

Advocate / Partner / Head of the Personal Data Protection and Cyber Security Practice

+48 660 765 918

m.mackowska-morytz@kochanski.pl