EIOPA · DORA 226 - 3314

ICT risk management (DORA)

Regulation
(EU) 2022/2554 - Digital Operational Resilience Act (DORA)
Article
N/A
Topic
ICT risk management (DORA)
Submitted
2025-04-07
Answered
2025-11-21

Question

Are financial entities permitted to determine more than one risk tolerance level of ICT risk?

Background

DORA itself uses the term risk tolerance level (singular). But the supplementing Delegated Regulation EU 2024/1774 uses both risk tolerance level (singular) and risk tolerance levels (plural). Thus, questions arise, if some or all financial entities are permitted to / required to determine more than one risk tolerance level of ICT risk. References in the singular/risk tolerance level: Article 6 (8) (b) and Article 5 (2) (d) REGULATION (EU) 2022/2554, Article 3 (1) (a), (c), (d) and Article 11 (2) (f) Delegated Regulation EU 2024/1774. References in the plural/risk tolerance levels: Article 3 (2) (b) and Article 31 (1) (a) and (c) Delegated Regulation EU 2024/1774.

Answer

The question has been rejected because the question is seeking confirmation of a requirement already clearly set out in the regulation.

This Q&A is published by European Insurance and Occupational Pensions Authority and is non-binding. It does not constitute legal advice. Updated weekly from official ESA sources.

Similar Q&As

More Q&As on this topic

📋 Track EU financial regulation continuously

Forseti monitors EU financial regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.