Image generated with AI
Financial institutions today must ensure regulatory excellence, technological innovation capability, and geopolitical resilience at the same time. With DORA, NIS2, and further European requirements, it is becoming clear: digital infrastructure is no longer just an IT issue. It is a core part of governance, risk management, and long-term viability.
T-Systems supports financial institutions in translating these requirements into a resilient operational and architectural reality. Designated under DORA by the European Supervisory Authorities as a critical ICT third-party service provider, T-Systems brings a strong understanding of regulatory requirements, operational experience, and deep insight into the expectations of highly regulated markets.
Here, T-Systems combines technological performance with controllable European operating models. The AI Factory of Deutsche Telekom and T-Systems also provides a powerful European AI infrastructure that enables modern AI workloads within a sovereign and governance-capable framework. This allows innovative use cases to be realized without compromising on transparency, control, and compliance.
Many providers deliver individual building blocks such as cloud, security, connectivity, or consulting. T-Systems combines these capabilities into an integrated platform tailored to the requirements of highly regulated financial institutions.
The difference lies not in a mere bundling of services, but in consistently integrating technology, regulation, and operations. This creates an approach that not only enables modern IT for financial services, but also makes it resilient, sovereign, and auditable. With T-Systems, financial institutions gain a strategic partner that does not merely accompany digital transformation, but drives it forward securely, in a sovereign manner, and with measurable added value.
A critical ICT service provider fails. A disruption hits a business-critical process. The incident is technically under control, but the real question comes afterwards: who knew what and when? Which function was affected? What dependencies existed? Which contractual control rights apply? What evidence is available? And can the management plausibly explain to the supervisory authority that the institution has control over its digital value creation? This is precisely where DORA begins.
The Digital Operational Resilience Act is not simply another regulatory framework. DORA changes the governance logic of digital risks in the financial sector. What was long treated as a task for IT, information security, or outsourcing management is now moving to the core of management responsibility. Digital resilience thereby becomes a leadership task. Because DORA does not only ask whether systems are protected. DORA asks whether an institution remains capable of acting under real stress conditions.
DORA examines whether:
For the executive management, this creates a different demand on governance. ICT risk is no longer merely an operational risk in the second or third line of defense. It is a risk to business continuity, market confidence, and regulatory credibility. Digital resilience of critical financial processes does not arise from the robustness of individual systems, but from the ability of the entire organization to anticipate disruptions, absorb them, adapt, and restore operations in a controlled manner.
This also changes the perspective on outsourcing. Under DORA, it is not sufficient to contractually engage a service provider and review them periodically. Institutions must understand which providers are relevant for critical or important functions, how concentration risks arise, what control and information rights exist, and how a service provider failure would affect business processes. Outsourcing management thus becomes an ongoing governance process, not a documentation discipline.
The consequences of insufficient maturity are significant. When supervisory authorities identify material DORA deficiencies, it is not merely a matter of remediation in individual policies. It is a matter of regulatory credibility: institutions must establish binding action plans for identified weaknesses, manage their implementation in a timely manner, and transparently demonstrate progress to the supervisory authority. This ties up management capacity, generates costs, and simultaneously increases pressure on Risk, Compliance, IT, Procurement, and Legal departments.
It becomes even more critical when deficiencies are not remediated within the required timeframe or when an ICT incident exposes weaknesses in governance and management. In such cases, supervisory measures, tightened requirements, restrictions on outsourcing, or sanctions may follow. At the same time, a trust problem arises. Because in the financial sector, resilience is not merely technical availability. Resilience is the ability to remain in control under uncertainty.
This applies in particular to the relationship between financial institutions and ICT third-party providers classified as critical. The European Supervisory Authorities have designated an initial group of 19 critical ICT third-party providers. Deutsche Telekom is among these ICT third-party providers classified as critical for the European financial sector. This classification is the ultimate expression of systemic relevance. It demonstrates that digital infrastructure, cloud, cybersecurity, and operational service quality are today part of the stability architecture of the financial market.
For T-Systems, this creates a particular perspective. We do not speak about DORA from the outside. We are a part of the operational reality that DORA addresses: critical ICT services, regulatory requirements, secure operating models, auditability, resilience, and controllability. That is precisely why DORA should not be understood as an isolated compliance project, but as a transformation task for digital operating models in the financial sector.
DORA is more than just a regulation for us. It is a mandate to make digital resilience in the financial sector reliable, verifiable, and operationally effective. As a part of the critical ICT landscape, but also for demonstrating it through our operations.
For financial institutions, this also represents a strategic opportunity. Those who treat DORA merely as a regulatory compliance exercise will primarily see effort: policies, registers, audits, contractual clauses. Those who understand DORA as a leadership agenda can develop a more robust operating model from it: with clearer responsibilities, better ICT provider governance, resilient testing, traceable evidence, and stronger trust in critical digital services.
The central DORA question is not whether regulatory requirements are met, but whether the organization can keep its critical business services continuously available under disruptions and restore them in a controlled manner. That is precisely why DORA belongs on the management agenda. Not as an IT topic. Not as audit preparation. But as a litmus test for how resiliently a financial institution steers its digital future.
DORA pushes institutions to reconsider digital value creation: not only in terms of efficiency and scalability, but also in terms of controllability, resilience, and auditability. That is precisely where the real work begins.
A critical ICT service fails. A cloud provider delivers too late. A service provider contract contains no enforceable control rights. BaFin identifies material deficiencies. A remediation program ties up personnel and budget. Sanctions are looming. And in parallel, contractual penalties, customer complaints, and reputational damage are looming on the horizon.
The Digital Operational Resilience Act was created precisely for situations like these. DORA is designed to ensure that banks, insurance companies, asset managers, payment service providers, and other financial entities can not only document their digital business and operational capabilities, but also manage them under real stress conditions.
The regulation is therefore more than another compliance framework. It is a part of a larger regulatory development: following GDPR and NIS2, it is becoming increasingly clear in the financial sector who bears responsibility, what evidence is expected, and what consequences inadequate governance can have.
DORA assigns responsibility for ICT risk management to the management body. Members of the management body does not need to know every technical detail. But it must understand which digital dependencies are critical to the business model.
Which ICT services support payment transactions, securities processing, customer access, risk models, or regulatory reporting? Which third-party providers are involved? Which outsourcing arrangements affect critical or important functions? Which control rights apply in an emergency? Which budgets, roles, and escalation paths are defined?
If these questions can only be answered within individual departments but cannot be managed at the leadership level, a governance risk arises. It is not about the detailed knowledge of individual departments, but about a robust governance model that provides management with the necessary overview of critical ICT dependencies, risks, and resilience.
DORA is closely aligned with the logic of NIS2 here. NIS2 also explicitly places governing bodies in a position of responsibility for cybersecurity risk management. The message of both regimes is clear: digital risks cannot be fully delegated to IT, compliance, or procurement teams. For financial institutions, this means: insufficient DORA maturity can trigger personal accountability, to the extent that national law provides for this. It is therefore not only a matter of technical deficiencies, but also of whether the organization was appropriately managed and supervised.
Under DORA, BaFin and European supervisory authorities will not only examine whether policies exist, but also whether governance, controls, and evidence are robust. An institution must be able to demonstrate that ICT risks are identified, assessed, managed, and monitored. It must be able to explain how major ICT-related incidents are classified and reported. It must maintain its Register of Information, manage critical third-party providers, and test digital resilience.
The value of supervisory evidence lies not in the documentation itself, but in the evidence of effective governance. Where this evidence is lacking, the question arises as to whether the institution actually has control over its material ICT risks, dependencies, and resilience capabilities. A comparison with the GDPR is instructive here. The GDPR has shown how quickly a topic that was originally technical becomes a board-level issue when penalty frameworks, public decisions, and reputational risks converge. There, possible sanctions range up to 20 million euros or 4 percent of the total worldwide annual turnover.
DORA works differently. For financial institutions, there is no fully harmonized EU schedule of fines as with the GDPR. The specific sanctions are determined at the national level. But the logic is similar: the inability to provide evidence itself becomes a risk.
If a material DORA deficiency is identified, the matter does not end with an audit report. Remediation begins. The institution must develop remediation plans, define responsibilities, meet deadlines, and demonstrate progress to the supervisory authority. This is precisely where DORA becomes costly, even before any fine has been imposed. Because remediation ties up management capacity, business units, and budget. Risk, Compliance, IT, Security, Procurement, Legal, and business continuity must all deliver simultaneously. External consulting, special audits, retrospective documentation, contract renegotiations, and technical adjustments can quickly generate significant costs.
It becomes particularly critical when remediation does not only affect individual documents, but also the operating model itself: unclear provider governance, missing exit strategies, weak incident processes, insufficient recovery evidence, or a lack of transparency regarding sub-outsourcing. The risk calculation therefore reads not only as: "How high is the fine?", but also as: "Fine plus remediation costs plus management bandwidth plus audit effort plus delays to strategic transformation programs plus reputational damage."
This is precisely what makes DORA relevant for the executive management. The costs do not arise only through sanctions. They arise as soon as the organization is unable to provide robust evidence that critical ICT dependencies, risks, and resilience requirements are being effectively managed.
DORA places particular emphasis on ICT third parties. Financial institutions must understand which providers are relevant for critical or important functions and what concentration risks arise. The risk does not lie solely in the failure of a service provider. It also lies in recognizing too late that central business processes, data flows, or operating models depend on a small number of providers.
DORA thus shifts the understanding of outsourcing. A simple service provider contract is not sufficient for this. Institutions need ongoing governance: control rights, information rights, exit strategies, sub-outsourcing transparency, incident processes, and evidence of resilience. If these elements are missing, a service provider can quickly become a contractual risk. If responsibilities are unclear, reporting obligations are not clearly defined, or service levels are not robust, the consequences go beyond operational problems. Contract penalties, escalations with customers, internal liability issues, and regulatory discussions may also follow.
The new dimension becomes clear in the case of ICT third-party service providers classified as critical. For these, DORA provides for a dedicated European oversight regime. The Lead Overseer can impose daily penalty payments of up to one percent of the average global daily turnover for certain violations, for a maximum of six months. This primarily affects the provider. But it shows how closely digital infrastructure is now linked to financial market stability. For institutions, third-party risk management thus becomes a strategic area of governance.
The most critical moment arises when an ICT incident escalates not only technically, but also organizationally. A critical service is unavailable. Customers cannot execute transactions. A service provider delivers information too late. Reporting channels are unclear. Responsibilities are not functioning. The internal situation assessment is inconsistent. The supervisory authority is asking questions. Impacts become public—among customers and in the media. At that point, it is no longer just about restoring services. It is about trust.
DORA requires institutions to be able to detect, classify, report, and follow up on major ICT-related incidents. What matters is not merely whether a system is operational again, but whether the institution can continue to act effectively under pressure. This is where DORA connects with the experience gained from GDPR and NIS2. The GDPR has shown that data and security incidents can quickly lead to public attention, sanctions, and loss of trust. NIS2 reinforces management responsibility for cybersecurity measures and provides for penalty frameworks of at least 10 million euros or 2 percent of global annual turnover for essential entities.
DORA applies this logic to the digital operational resilience of the financial sector: cyber and ICT risks are no longer peripheral technical risks. They are business risks.
What these scenarios have in common:
The key questions are:
For financial institutions, the opportunity lies in not treating DORA merely as a regulatory obligation. Those who consistently integrate governance, digital resilience, and ICT third-party risk management not only reduce supervisory risks. They also strengthen their operational capacity and the trust of customers, investors, and regulators. DORA makes it clear that financial institutions need partners who can provide critical ICT services and operate them resiliently, maintain control, and provide demonstrable evidence of their performance. DORA is therefore not the end of a compliance checklist. It is the beginning of a new question in the financial sector: can an institution maintain its critical IT-supported business processes in a stable and controlled manner even under realistic stress conditions?
Supervisors are not merely interested in whether a financial institution understands DORA; they expect evidence that the institution has its digital dependencies under control.
For financial institutions, DORA is not simply another compliance requirement. The regulation changes how supervisors view digital value creation, outsourced ICT services, and operational dependencies. At its core, it comes down to one question: can an institution demonstrate at any time, in a comprehensible manner, which digital services are relevant to critical or important functions, which third parties they depend on, and how the resulting risks are managed?
This is precisely where the Register of Information comes in. It is more than a a regulatory register. For supervisory authorities, it becomes an instrument for making ICT third parties, critical functions, contractual relationships, and potential concentration risks visible across institutions. For financial institutions, this means: those who do not document their ICT supply chains properly will also be unable to demonstrate their operational resilience convincingly.
Particularly relevant in this context is the management of critical ICT third-party service providers. Banks, insurers, and other financial market participants must not only know which providers they use. They must also be able to assess which services are business-critical, which exit options are realistically available, how responsibilities are distributed in the shared responsibility model, and whether contractual rights, reporting obligations, audit options, and emergency processes are sufficient. Supervisors therefore do not expect a static list of suppliers, but an active management model. This brings concentration risks into a sharper focus. When central business processes, cloud services, security functions, or operating models depend on a small number of providers, a risk arises that cannot be assessed on technical grounds alone. It affects business continuity, market stability, contract governance, and the institution's strategic capacity to act. Institutions must be able to demonstrate how they identify, limit, and manage such dependencies in the event of a crisis.
DORA therefore requires a closer integration of ICT risk management, outsourcing governance, information security, business continuity, and board-level perspective. Supervisors will in future ask more precisely whether institutions can both procure and manage their critical ICT services: with clear roles, robust controls, traceable evidence, and an operating model that also functions under stress.
For financial institutions, this creates a practical mandate for action: DORA must be translated into governance, provider management, cloud strategy, incident processes, resilience testing, and contract management. What matters is not merely formal compliance with individual requirements, but whether the institution can demonstrate its digital operational resilience during disruptions, cyberattacks, provider failures, or regulatory audits.
The classification as a critical ICT third-party provider is not a seal, an offering label, or a statement that a provider "offers DORA". It means: the European supervisory authorities assess certain ICT service providers as so relevant to financial companies that failures, governance weaknesses, or concentration risks can potentially impact the stability of the financial sector. This is precisely why EBA, EIOPA, and ESMA designated 19 critical ICT third-party providers under DORA for the first time in November 2025. These providers fall under a direct European oversight framework. The supervisory authorities therefore examine not only financial institutions themselves, but also whether systemically relevant ICT providers have adequate risk, governance, and resilience structures in place. Deutsche Telekom AG is also listed in the official list as a critical ICT third-party provider. Source: ESMA/ESA CTPP list, official PDF list.
Why this matters is illustrated by recent outages at major cloud and technology platforms. Recently, a disruption at a US cloud provider in a central infrastructure component led to errors and cascading issues across several dependent services. One of the causes identified was a problem in automated DNS management that affected additional services. Shortly before, another leading cloud provider documented an outage of its global traffic management service, during which customers in multiple regions experienced increased latencies and timeouts. Both cases demonstrate: a technical error in a central infrastructure component can propagate along digital supply chains.
For financial institutions, this is the decisive point: their own operational resilience no longer depends solely on internal systems. It also depends on how well critical providers, cloud platforms, managed services, security tools, and subcontractors are managed, tested, and contractually integrated. Under DORA, an outage at a provider does not simply remain "an external problem". It prompts questions about the institution's own risk management, such as: which critical functions are affected? What dependencies exist? What alternatives are available? How quickly can the institution respond? And can it demonstrate this level of control to the supervisory authority?
In doing so, DORA shifts the perspective from traditional outsourcing management to systemic resilience. When many financial companies rely on the same platforms, operating models, or providers, concentration risks emerge that extend beyond the individual institution. It is precisely this connection between individual outsourcing and potential market stability that the classification of critical ICT third-party providers addresses.
What remains important, however, is this: direct oversight of critical ICT third-party providers does not replace the responsibility of financial institutions. The European Central Bank explicitly emphasizes in its Supervisory Priorities 2026–2028 that DORA oversight of critical third-party providers complements, but does not replace, banks' third-party risk management. Banks must continue to manage their ICT third parties themselves, assess risks, review contracts, plan exit strategies, and test failure scenarios. Source: ECB Supervisory Priorities 2026–2028.
For T-Systems, the classification of Deutsche Telekom AG as a critical ICT third-party provider is therefore above all one thing: an expression of a special responsibility within the financial ecosystem. It makes clear that ICT services for regulated industries must be more than just technically reliable: they must support governance, enable audits, ensure resilience, and integrate with financial institutions’ risk-management frameworks.
DORA is not a compliance topic. DORA is a question of governance capability. More precisely: it is about whether financial institutions can effectively manage and maintain their critical ICT processes and dependencies even under stress conditions.
For years, technology in banking and financial services was discussed primarily in terms of efficiency, scalability, and cost. All important. But no longer sufficient. Today, payment processes, securities settlement, customer access, risk models, reporting, fraud prevention, and regulatory processes depend on complex digital ecosystems: cloud providers, software providers, data platforms, cybersecurity partners, outsourced operating models, critical infrastructure. This shifts the management perspective: the focus is on whether the organization masters its critical dependencies, effectively manages service providers, and remains capable of acting even under stress. DORA makes exactly that visible.
The regulation moves digital resilience from the engine room to the boardroom. ICT risk is no longer a technical subcategory. It is a part of operational risk, business continuity, regulatory credibility, and ultimately market trust. This is why DORA should not be treated as yet another regulatory compliance exercise. The real value lies elsewhere: in transparency about critical services, concentration risks, exit options, decision rights, incident readiness, and the resilience of the operating model. The classification of critical ICT third-party providers by European supervisory authorities underscores this shift. Digital infrastructure has become a part of the stability architecture of the financial sector. For leadership teams, the question is therefore not only: "Are we compliant?". The question is: "Can we maintain the governance and operational capability of the institution when central IT services, interfaces, and dependencies are under stress?". That is precisely where DORA becomes relevant. Because resilience is not demonstrated through documentation alone; it is demonstrated by the ability to continue taking action and maintaining control.
DORA marks a turning point in the regulation of digital operational resilience in the financial sector. The regulation addresses not only technical security requirements, but also the question of how institutions systematically understand, manage, and control their digital dependencies in the event of a crisis. From a corporate governance perspective, this is crucial. Information and communication technology is no longer a downstream operational factor, but a part of the critical production function of banks, insurers, and capital market participants. When payment transactions, securities settlement, customer access, or risk models are operated digitally, operational resilience becomes a prerequisite for market confidence.
DORA translates this insight into concrete governance requirements. Institutions must know their ICT risks, clearly assign responsibilities, manage critical third-party providers, assess exit options, report incidents, and regularly test their resilience. This brings the digital supply chain into the focus of supervision. Particularly relevant in this context is the role of critical ICT third-party service providers. Deutsche Telekom is one of the 19 ICT third-party service providers classified as critical for the financial sector by European supervisory authorities. This classification is not a marketing label, but an expression of systemic relevance. It shows that digital infrastructure, cloud, security, and operating models are today directly linked to financial market stability.
For financial institutions, the opportunity lies in not treating DORA as a mere compliance exercise. Those who consistently integrate resilience, governance, and provider management not only reduce regulatory risks. They also strengthen their operational capacity to act, their level of control, and the trust of customers, investors, and regulators. DORA thus makes visible what will matter in the financial sector in the future: efficiency, innovation, and robust digital sovereignty under real stress conditions.
Cloud has long been a part of critical value creation for banks, insurers, and financial services providers. Core banking-adjacent applications, data platforms, customer portals, security services, analytics environments, and operational processes are increasingly running in hybrid, private, or public cloud models. As a result, under DORA, cloud is not viewed as a purely infrastructural matter, but as a part of ICT risk management, third-party governance, and operational resilience.
For financial institutions, this means: it's not sufficient to only document which cloud services they use. They must also be able to explain which business processes depend on these services, which data and critical functions are affected, which sub-service providers are involved, and how outages, security incidents, or performance disruptions are managed. This is precisely where cloud governance becomes a matter of supervisory relevance. A key requirement is transparency about dependencies. Financial institutions must map their cloud relationships in the Register of Information (see above) and keep it continuously up to date. What matters here is not only the direct contractual partner. Also relevant are service chains, operating models, locations, sub-outsourcing, support structures, and technical dependencies within the cloud architecture. Cloud users must be able to demonstrate where critical services run, what control rights exist, and what fallback options are realistic.
DORA also brings the question of exit capability more prominently to the fore. Financial institutions must assess whether they can switch, repatriate, or transition critical cloud services to a different operating model if needed. This is not a purely contractual exercise. It concerns architecture, data portability, operational processes, interfaces, know-how, testability, and costs. An exit strategy that exists only on paper will not satisfy supervisory expectations.
Equally important is the management of concentration risks. If several critical functions rely on the same cloud provider, the same region, the same platform technology, or the same operational processes, a technical outage can quickly become business-critical. Financial institutions must therefore not only compare providers, but also understand dependencies across applications, processes, and business areas. This is precisely where it is determined whether cloud sovereignty is more than just a buzzword.
DORA also requires a robust resilience testing logic. Cloud failure scenarios must be embedded in business continuity, incident response, crisis communication, and technical recovery procedures. This includes scenarios such as provider outages, regional failures, identity or network issues, faulty configuration changes, security incidents, or restricted access to management portals. It is crucial that financial institutions not only describe their response capabilities, but also regularly test and document them. For collaboration with cloud and managed service partners, this means: financial institutions need operating models that incorporate security, compliance, transparency, and control from the outset. This includes clear responsibilities within the shared responsibility model, traceable service and control processes, auditable evidence, defined communication channels for incidents, and governance that involves IT as well as risk, compliance, legal, procurement, and board-level perspectives.
Sovereign cloud approaches play a central role here. Especially in regulated markets, it is not just about scalability and performance, but also about control over data, operating locations, legal jurisdictions, access options, and dependencies. For financial institutions, this makes it relevant whether cloud services are technically capable while also supporting compliance and demonstrability, operational resilience, and digital sovereignty.
T-Systems does not view cloud in isolation, but as an interplay of cloud services, T Cloud Private, Sovereign Cloud, Managed Cloud, cybersecurity, governance, and regulated operations. For financial institutions, this creates practical added value: cloud transformation is not only accompanied technologically, but also translated into a robust DORA logic.
DORA is an important milestone for financial institutions. But the regulation does not stand alone. Together with NIS2 and the AI Act, a broader regulatory framework is emerging in Europe that permanently places digital resilience, cybersecurity, governance, and risk management on the agenda. For banks, insurers, and other financial market participants, this means: regulatory requirements can no longer be viewed in isolation. DORA addresses digital operational resilience in the financial sector. NIS2 tightens requirements for cybersecurity and risk management for critical and important entities. The AI Act introduces new requirements for the responsible use of artificial intelligence. Together, these frameworks show the direction regulation is heading: away from point-in-time compliance evidence, towards continuous management of digital risks.
This is particularly evident in governance. Financial institutions must know which ICT services are relevant for critical functions, which third parties are involved, which security and control processes apply, and how new technologies such as AI are embedded in existing risk models. Resilience thus becomes not only a task for IT or compliance. It also affects risk, security, legal, procurement, business functions, and the management body.
DORA focuses on ICT risk management, incident reporting, resilience testing, and third-party risk management. NIS2 reinforces the perspective on cybersecurity, reporting obligations, and supply chain risks. The AI Act covers how AI systems are assessed, monitored, and operated responsibly. For financial institutions, this creates a shared challenge: risks must remain manageable across technologies, providers, data, processes, and responsibilities.
This also changes the role of cloud, managed services, and data platforms. When critical processes run in hybrid or sovereign cloud models and AI applications are simultaneously integrated into business processes, more than mere technical performance is required. Financial institutions must be able to understand where data is processed, which providers and sub-service providers are involved, how cyber risks are managed, and which control mechanisms apply to automated decisions.
Resilience therefore becomes a permanent task. Not because regulation constantly demands more documentation, but because digital value creation is becoming more dynamic. New cloud models, new AI applications, new threat landscapes, and new supply chains continuously change the risk profile of an institution. Those who address DORA, NIS2, and the AI Act separately risk duplication of effort, gaps, and contradictory governance.
The better approach is an integrated resilience model. Financial institutions should consolidate their regulatory requirements around common topics: governance, risk management, third-party management, incident processes, auditability, cybersecurity, data control, and operational testing. This transforms individual compliance projects into a robust operating model.
T-Systems can provide support here, because digital resilience is not just a matter of consulting. It emerges from the interplay of secure infrastructure, sovereign cloud architectures, managed services, cybersecurity, governance, and regulated operations. Especially for financial institutions, it will be crucial to choose partners who understand this connection and can translate regulatory requirements into technical and operational control.