DORA compliance for asset managers and investment firms means rebuilding ICT risk management, vendor oversight, and incident reporting around one EU regulation instead of a patchwork of internal policies. The Digital Operational Resilience Act has applied to in-scope financial entities since 17 January 2025, and 2026 is the year supervisors start checking whether firms actually did the work.
Why this matters
Asset managers and investment firms run on outsourced infrastructure: portfolio management systems, trade execution platforms, custodians, cloud hosting. DORA treats every one of those relationships as a source of operational risk, not just a vendor invoice.
Regulators aren't asking whether you have a policy document. They're asking whether you can name your critical ICT providers, prove you tested resilience, and show an incident timeline with timestamps. OneClickComply automates that evidence trail so it exists before an examiner asks for it, not after.
Firms that treated DORA as a 2025 box-tick are the ones getting flagged in 2026 supervisory reviews. The gap usually isn't ICT security itself — it's the paperwork proving oversight of the third parties running that security.
Who this is for
This guide is for compliance leads, COOs, and heads of risk at UK asset managers, investment firms, and fund managers with EU clients, EU-domiciled funds, or delegated portfolio management arrangements. If your firm outsources trading infrastructure, custody, or portfolio systems to third-party ICT providers, DORA's third-party risk rules apply to you directly, regardless of firm size.
It's also for firms that assumed Brexit put DORA out of scope. If you serve EU counterparties or manage EU-domiciled funds, you're in scope in 2026 whether your head office sits in London or Edinburgh.
What to look for in DORA compliance for asset managers and investment firms
ICT risk management framework
DORA requires a documented, board-approved ICT risk management framework, not a standalone IT security policy. For asset managers, this framework has to cover trading systems, portfolio management platforms, and data feeds — the tools that keep funds operating day to day.
A framework without asset-level detail fails the first supervisory question: which systems, if they failed, would stop you executing trades.
Third-party ICT risk oversight
This is where most asset managers are weakest. DORA requires a register of every ICT third party, a criticality tier for each, and contract clauses covering audit rights, exit strategy, and subcontracting.
If your custodian, execution platform, or cloud host has an outage, you need to already know how critical that vendor is rated — not work it out during the incident.
Incident classification and reporting
DORA sets tiered timelines for classifying and reporting major ICT-related incidents to the relevant competent authority. Investment firms need a documented process for triaging an incident, deciding whether it meets the major threshold, and filing on time.
Missing the classification step is the most common failure point — firms report late because nobody owned the decision of whether the incident counted.
Digital operational resilience testing
Every in-scope firm needs a basic testing programme: vulnerability scans, scenario-based testing, and resilience exercises. Firms designated as significant also face threat-led penetration testing (TLPT) on a three-year cycle.
Most mid-size asset managers won't hit the TLPT threshold in 2026, but basic resilience testing still applies — don't confuse not significant with exempt.
Governance and board accountability
DORA puts ICT risk ownership at board level, not with IT alone. Board members need to understand the ICT risk register, sign off the resilience testing strategy, and receive incident reports.
A framework that never reaches board minutes is a framework an auditor will mark as incomplete.
Where to focus first
Third-party risk mapping — the one regulators check first. Investment firms with more than a handful of critical ICT vendors need a live register, not a static spreadsheet from the 2025 project kickoff. Vendor risk management software built for wealth management firms maps criticality tiers and contract clauses automatically. Verdict: Buy — this is the section examiners open first.
Software selection for the full framework. Running DORA compliance across email threads and shared drives breaks down once you have more than three critical vendors and a board reporting cycle. A DORA compliance software comparison for UK financial services firms sets out what a platform needs to cover for full-scope compliance. Verdict: Buy — spreadsheets don't survive a second audit cycle.
Incident reporting workflow. Build the triage decision tree before an incident happens, not during one. Assign a named owner for the is-this-major call. Verdict: Consider — do this internally first, automate the timestamps once the process is proven.
Threat-led penetration testing. Only relevant if your firm is designated significant under DORA's criteria. Confirm your designation status before budgeting for a three-year TLPT cycle you may not need. Verdict: Skip unless designated significant — check status before spending.
Get DORA-ready without the spreadsheets
Automate ICT risk registers, vendor oversight, and evidence collection in one place.
What to avoid
- Treating ISO 27001 as DORA-equivalent. ISO 27001 covers information security management well, but DORA adds third-party contract requirements and incident reporting timelines ISO 27001 doesn't touch.
- Using Cyber Essentials as a substitute. Cyber Essentials is a UK baseline scheme for basic cyber hygiene. It's useful, but it doesn't cover DORA's vendor criticality mapping or board governance requirements.
- Running one penetration test and calling resilience testing done. DORA's testing requirement is a programme, not a one-off event — a single test from last year won't cover 2026's reporting cycle.
Verdict comparison
| Criterion | Why it matters for asset managers | 2026 priority |
|---|---|---|
| ICT risk framework | Covers trading and portfolio systems, not just IT | Buy now |
| Third-party risk register | Top supervisory focus area | Buy now |
| Incident reporting workflow | Tiered deadlines, late filing is a common failure | Build internally, automate next |
| Resilience testing | TLPT only for significant entities | Confirm designation first |
| Board governance | Ownership has to sit above IT | Add to board agenda |
A sharp way to think about sequencing: if your ICT vendor register isn't live and reviewed quarterly, nothing else in your DORA programme will hold up under examination.
Frequently asked questions
One last thing
The firms that pass DORA reviews cleanly in 2026 aren't the ones with the thickest policy binder — they're the ones whose ICT vendor register updates automatically when a contract changes. Manual registers go stale within a quarter; automated ones don't.
