OneClickComply
    Back to BlogStandards & Frameworks

    DORA Compliance for Asset Managers: 2026 Verdict

    21 August 2026
    DORA compliance for asset managers and investment firms

    TL;DR

    • DORA compliance for asset managers means mapping ICT risk, vendor contracts, and incident reporting to one framework, not three separate spreadsheets.
    • Third-party ICT risk oversight is the top DORA enforcement focus for investment firms in 2026 - critical vendors need contractual exit clauses.
    • ISO 27001 or Cyber Essentials alone does not satisfy DORA for asset managers - the scope and reporting deadlines are wider.
    • Threat-led penetration testing on a three-year cycle applies only to entities designated as significant - most mid-size firms can skip it in 2026.
    • OneClickComply automates the ICT risk register and evidence trail so compliance teams stop rebuilding audits by hand.

    DORA compliance for asset managers and investment firms means rebuilding ICT risk management, vendor oversight, and incident reporting around one EU regulation instead of a patchwork of internal policies. The Digital Operational Resilience Act has applied to in-scope financial entities since 17 January 2025, and 2026 is the year supervisors start checking whether firms actually did the work.

    Why this matters

    Asset managers and investment firms run on outsourced infrastructure: portfolio management systems, trade execution platforms, custodians, cloud hosting. DORA treats every one of those relationships as a source of operational risk, not just a vendor invoice.

    Regulators aren't asking whether you have a policy document. They're asking whether you can name your critical ICT providers, prove you tested resilience, and show an incident timeline with timestamps. OneClickComply automates that evidence trail so it exists before an examiner asks for it, not after.

    Firms that treated DORA as a 2025 box-tick are the ones getting flagged in 2026 supervisory reviews. The gap usually isn't ICT security itself — it's the paperwork proving oversight of the third parties running that security.

    Who this is for

    This guide is for compliance leads, COOs, and heads of risk at UK asset managers, investment firms, and fund managers with EU clients, EU-domiciled funds, or delegated portfolio management arrangements. If your firm outsources trading infrastructure, custody, or portfolio systems to third-party ICT providers, DORA's third-party risk rules apply to you directly, regardless of firm size.

    It's also for firms that assumed Brexit put DORA out of scope. If you serve EU counterparties or manage EU-domiciled funds, you're in scope in 2026 whether your head office sits in London or Edinburgh.

    What to look for in DORA compliance for asset managers and investment firms

    ICT risk management framework

    DORA requires a documented, board-approved ICT risk management framework, not a standalone IT security policy. For asset managers, this framework has to cover trading systems, portfolio management platforms, and data feeds — the tools that keep funds operating day to day.

    A framework without asset-level detail fails the first supervisory question: which systems, if they failed, would stop you executing trades.

    Third-party ICT risk oversight

    This is where most asset managers are weakest. DORA requires a register of every ICT third party, a criticality tier for each, and contract clauses covering audit rights, exit strategy, and subcontracting.

    If your custodian, execution platform, or cloud host has an outage, you need to already know how critical that vendor is rated — not work it out during the incident.

    Incident classification and reporting

    DORA sets tiered timelines for classifying and reporting major ICT-related incidents to the relevant competent authority. Investment firms need a documented process for triaging an incident, deciding whether it meets the major threshold, and filing on time.

    Missing the classification step is the most common failure point — firms report late because nobody owned the decision of whether the incident counted.

    Digital operational resilience testing

    Every in-scope firm needs a basic testing programme: vulnerability scans, scenario-based testing, and resilience exercises. Firms designated as significant also face threat-led penetration testing (TLPT) on a three-year cycle.

    Most mid-size asset managers won't hit the TLPT threshold in 2026, but basic resilience testing still applies — don't confuse not significant with exempt.

    Governance and board accountability

    DORA puts ICT risk ownership at board level, not with IT alone. Board members need to understand the ICT risk register, sign off the resilience testing strategy, and receive incident reports.

    A framework that never reaches board minutes is a framework an auditor will mark as incomplete.

    Where to focus first

    Third-party risk mapping — the one regulators check first. Investment firms with more than a handful of critical ICT vendors need a live register, not a static spreadsheet from the 2025 project kickoff. Vendor risk management software built for wealth management firms maps criticality tiers and contract clauses automatically. Verdict: Buy — this is the section examiners open first.

    Software selection for the full framework. Running DORA compliance across email threads and shared drives breaks down once you have more than three critical vendors and a board reporting cycle. A DORA compliance software comparison for UK financial services firms sets out what a platform needs to cover for full-scope compliance. Verdict: Buy — spreadsheets don't survive a second audit cycle.

    Incident reporting workflow. Build the triage decision tree before an incident happens, not during one. Assign a named owner for the is-this-major call. Verdict: Consider — do this internally first, automate the timestamps once the process is proven.

    Threat-led penetration testing. Only relevant if your firm is designated significant under DORA's criteria. Confirm your designation status before budgeting for a three-year TLPT cycle you may not need. Verdict: Skip unless designated significant — check status before spending.

    Get DORA-ready without the spreadsheets

    Automate ICT risk registers, vendor oversight, and evidence collection in one place.

    What to avoid

    • Treating ISO 27001 as DORA-equivalent. ISO 27001 covers information security management well, but DORA adds third-party contract requirements and incident reporting timelines ISO 27001 doesn't touch.
    • Using Cyber Essentials as a substitute. Cyber Essentials is a UK baseline scheme for basic cyber hygiene. It's useful, but it doesn't cover DORA's vendor criticality mapping or board governance requirements.
    • Running one penetration test and calling resilience testing done. DORA's testing requirement is a programme, not a one-off event — a single test from last year won't cover 2026's reporting cycle.

    Verdict comparison

    CriterionWhy it matters for asset managers2026 priority
    ICT risk frameworkCovers trading and portfolio systems, not just ITBuy now
    Third-party risk registerTop supervisory focus areaBuy now
    Incident reporting workflowTiered deadlines, late filing is a common failureBuild internally, automate next
    Resilience testingTLPT only for significant entitiesConfirm designation first
    Board governanceOwnership has to sit above ITAdd to board agenda

    A sharp way to think about sequencing: if your ICT vendor register isn't live and reviewed quarterly, nothing else in your DORA programme will hold up under examination.

    Frequently asked questions

    One last thing

    The firms that pass DORA reviews cleanly in 2026 aren't the ones with the thickest policy binder — they're the ones whose ICT vendor register updates automatically when a contract changes. Manual registers go stale within a quarter; automated ones don't.

    Key DORA dates

    17 Jan 2025

    DORA enforcement start date

    3 years

    TLPT testing cycle for significant entities