DORA Says Financial Entities Must Control Their ICT Risk. Cloud AI Is ICT Risk.
Digital Operational Resilience Act Implications for AI-Dependent Financial Processes
---
January 17, 2025: DORA — the Digital Operational Resilience Act, the EU law requiring financial entities to control every technology risk in their operation — took effect across all 22,000 regulated financial entities in the EU. Banks, insurers, investment firms, payment processors. Every one of them now legally required to maintain formal registers of their technology providers, maintain audit rights over those providers, and document exit strategies for all critical technology services.
That same week, finance teams across Europe opened ChatGPT to answer their usual Monday questions about margin data, supplier pricing, and quarterly reconciliations.
---
DORA Doesn't Ban AI. It Bans Uncontrolled AI.
DORA's scope covers every information and communication technology service that processes data for a regulated financial entity. Article 3 — the definitions section — is broad by design. A tool qualifies as a covered technology service under DORA based on what it does, not what the vendor calls it. ChatGPT, when used by your finance team to analyze financial data, is processing data for a regulated financial entity. Under DORA's definition, that makes it a covered service, regardless of whether OpenAI markets it as an enterprise financial tool.
DORA doesn't ban AI in finance. It bans uncontrolled AI — specifically, AI tools that your finance teams are already using daily but that nobody has formally registered, contracted, or audited.
Controlled and uncontrolled AI diverge on five specific requirements that DORA's Article 28 places on contracts with technology service providers. First, contractual audit rights: the financial entity must have the legal right to audit and inspect the provider's systems. Second, an exit strategy: documented procedures for switching providers within 12 months if needed. Third, data residency: evidence that financial data stays within specified geographic jurisdictions. Fourth, incident reporting: a service commitment guaranteeing notification of major disruptions within 24 hours. Fifth, management accountability: documentation that the board-level leadership — not IT — has reviewed and approved the arrangement.
Standard enterprise agreements from the major US cloud AI providers do not routinely include all five. Their standard terms address data protection in ways that satisfy basic GDPR requirements. Getting contractual audit rights over the systems that run your queries, a documented 12-month exit strategy, and a 24-hour incident notification commitment requires custom negotiation — and most financial entities have not had that conversation.
---
The Management Body Problem
Article 5 of DORA places direct accountability for technology risk management on the management body — the board of directors or equivalent governing body — not the IT department. Technology risk is a board-level responsibility under EU law.
When finance teams use AI tools that aren't formally registered, contracted, or audited — what's known as shadow AI, where employees use AI tools individually and informally without any organizational oversight — the management body has failed its Article 5 obligation. Not because the finance team did something wrong. Individual employees using AI for productivity is rational behavior. The failure is governance: a management body that approved productivity tools without asking whether those tools met the technology requirements the entity is legally obligated to enforce.
"I did not know our finance team was using consumer AI for financial queries" is not a DORA defense. Under Article 5, the management body is responsible for knowing and controlling the technology risks in their operation. Supervisors apply that standard precisely because the gap between what executives know and what their teams actually do is where systemic risk accumulates.
---
What the Register Looks Like in Practice
DORA requires financial entities to maintain a register of all covered technology service providers. The register isn't a spreadsheet of approved software from IT. It's a formal document covering every technology service that processes financial data for the entity, with contracts attached confirming the five Article 28 requirements are met.
Run a quick internal test: ask your compliance team to produce, within 24 hours, a complete register of every AI tool your finance department used in the past 12 months. Every tool. Every query that involved financial data. Every contract governing those interactions.
At most financial entities, that list will contain tools nobody registered, queries nobody logged, and financial data that crossed US jurisdiction without audit rights, without incident reporting channels, and without exit strategies. Whatever gap exists between the formal technology register and what finance teams actually use is the real DORA exposure.
Each unregistered tool used to process financial data is an item in the register that doesn't exist. Each month of usage without registration extends the exposure period. Supervisors building their enforcement capacity through 2025 and 2026 will be asking exactly these questions — and the honest answer at most entities, right now, is "we don't know what we've been using or what it processed."
---
The Contract Gap Nobody Reads
Many compliance teams have already negotiated "enterprise agreements" with major AI providers and believe this closes the DORA gap. Reading those agreements carefully matters.
US-headquartered providers' enterprise AI agreements typically include data processing agreements that satisfy GDPR basics, geographic restrictions that limit some data to EU regions, and standard security certifications like SOC 2 and ISO 27001 — independent audits confirming basic security practices. What they typically do not include is contractual audit rights over the actual systems running your queries (an Article 28 requirement), exit strategy provisions within 12 months (an Article 28 requirement), 24-hour incident notification commitments for service disruptions (an Article 19 requirement), or documentation of management body review (an Article 5 requirement).
Enterprise labeling doesn't transform a consumer-heritage product into a DORA-compliant technology provider. The contractual requirements are specific. Either the contract contains them or it doesn't. A compliance officer reviewing an enterprise AI agreement against DORA's Article 28 checklist will find specific gaps that a general data protection review would not surface.
---
The €530 Million Signal
Understanding how EU financial regulators will enforce DORA requires looking at how they've enforced similar rules. In May 2025, the Irish Data Protection Commission issued a €530 million GDPR fine against TikTok for unauthorized EU-to-US data transfers. The fine was the largest data protection penalty of 2025.
Financial services faces more aggressive regulatory scrutiny than consumer media platforms, not less. The European Banking Authority, the insurance regulator EIOPA, and the markets regulator ESMA — the three EU supervisory bodies responsible for DORA implementation — all published implementation guidance in 2025. Supervisory capacity is being built specifically to audit technology third-party risk management at regulated entities.
Once supervisors audit an entity's technology register and find systematic gaps — unregistered AI tools, missing contracts, financial data processed without audit rights — the regulatory relationship changes. Entities that get ahead of DORA's AI requirements now, and can present clean registers to supervisors, build compliance credibility that pays dividends through every subsequent examination. Entities that wait will be explaining gaps rather than demonstrating governance.
---
What DORA-Compliant Financial AI Looks Like
A financial entity that deploys sovereign financial AI built around DORA's requirements from the ground up can produce, for any supervisor's request: a formal register entry showing the AI provider as a registered technology service; a contract including explicit audit rights over the infrastructure processing financial data; EU data residency documentation showing where queries and financial data are processed; a 24-hour incident notification channel with defined commitments; and a documented exit strategy with a 12-month implementation timeline.
Stralevo's architecture was built inside the compliance framework that DORA requires — not retrofitted to meet it afterward. EU data residency is the default, not a configuration option. Audit rights are built into the service agreement because the architecture was designed to be auditable from day one. Every AI query generates a transaction-level record at query time, making the audit trail a standard output rather than a document assembled under supervisory pressure.
Beyond satisfying DORA, there is a performance argument that compliance-focused finance leaders often miss: AI tools that pass DORA's third-party risk requirements are, by construction, better engineered for financial use cases than consumer tools that were never designed to meet those standards. The contractual discipline required for DORA compliance tends to coexist with the architectural discipline required for verified, source-cited financial AI. Regulation and capability point the same direction.
---
The Replacement, Not the Ban
Finance leaders who do best in DORA's enforcement environment are not the ones who banned AI from their departments. Banning AI produces clean registers and slower finance teams. Leaders who win are the ones who replaced shadow AI — consumer tools running outside the compliance framework — with controlled AI that their management bodies can register, audit, and defend.
Their finance teams keep the AI productivity benefits. Their compliance teams have contracts and registers they can show supervisors. Their management bodies have fulfilled Article 5's accountability requirement. One architectural decision produces all three outcomes simultaneously.
Supervisory conversations about AI tool governance are coming on DORA's schedule, not financial entities' preferred timeline. Entities that have replaced unregistered AI tools with DORA-compliant alternatives before that conversation arrives will answer questions about their AI governance program. Entities that haven't will be answering questions about why they didn't.