Skip to content
Merrow

Compliance

DORA is a resilience test, not a compliance checkbox

Merrow Research Team · 14 May 2026

What actually changes operationally for UK-serving financial firms under DORA, beyond the paperwork.

Most compliance frameworks reward good documentation. DORA is unusual in that it's explicitly designed to test whether the documentation reflects reality — through mandated resilience testing, not just an audit of policy documents.

For UK-serving financial firms with EU exposure, the operational shift that tends to get underestimated is around third-party risk: DORA extends scrutiny to critical ICT third parties in a way that makes vendor management a resilience question, not just a procurement one.

The firms we've seen handle this well treated it as an opportunity to actually test their incident response process end to end, rather than a paperwork exercise to complete once and file away.