EIOPA · DORA 226 - 3314
ICT risk management (DORA)
- Regulation
- (EU) 2022/2554 - Digital Operational Resilience Act (DORA)
- Article
- N/A
- Topic
- ICT risk management (DORA)
- Submitted
- 2025-04-07
- Answered
- 2025-11-21
Question
Are financial entities permitted to determine more than one risk tolerance level of ICT risk?
Background
DORA itself uses the term risk tolerance level (singular). But the supplementing Delegated Regulation EU 2024/1774 uses both risk tolerance level (singular) and risk tolerance levels (plural). Thus, questions arise, if some or all financial entities are permitted to / required to determine more than one risk tolerance level of ICT risk. References in the singular/risk tolerance level: Article 6 (8) (b) and Article 5 (2) (d) REGULATION (EU) 2022/2554, Article 3 (1) (a), (c), (d) and Article 11 (2) (f) Delegated Regulation EU 2024/1774. References in the plural/risk tolerance levels: Article 3 (2) (b) and Article 31 (1) (a) and (c) Delegated Regulation EU 2024/1774.
Answer
The question has been rejected because the question is seeking confirmation of a requirement already clearly set out in the regulation.
This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.
Similar Q&As
More Q&As on this topic
📋 Track EU financial regulation continuously
Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.
14-day free trial. No credit card required.