EU Financial Services · CFO Pain #4

Manager Liability Under DORA: The Governance Artifacts Regulators Will Ask to See

Under Member-State transpositions of DORA — e.g., Ireland’s S.I. No. 20 of 2025 (European Union (Digital Operational Resilience) (No. 2) Regulations 2025), under which the Central Bank of Ireland may impose DORA-specific sanctions alongside those available under Central Bank Act 1942 s. 33AQ (which caps natural-person monetary penalties at €1,000,000 via s. 33AQ(4)(b) and (6)(a)) — individual senior managers can face personal monetary penalties up to €1,000,000. DORA itself (Art. 50) requires Member States to set effective, proportionate and dissuasive penalties and leaves the maximum amounts to national transposition. The management body holds ultimate accountability for ICT risk. Here is what EU supervisors ask to see, and where a controlled terminology record actually helps.

In brief: DORA (Regulation (EU) 2022/2554) places ICT risk accountability on the management body. Under Member-State transpositions of DORA — e.g., Ireland’s S.I. No. 20 of 2025, under which the Central Bank of Ireland may impose DORA-specific sanctions alongside those available under Central Bank Act 1942 s. 33AQ (which caps natural-person monetary penalties at €1,000,000 via s. 33AQ(4)(b) and (6)(a)) — individual senior managers can face personal monetary penalties up to €1,000,000. DORA itself (Art. 50) requires Member States to set effective, proportionate and dissuasive penalties and leaves the maximum amounts to national transposition. Supervisors ask for a paper trail — ICT risk framework, Register of Information, incident reports — with consistent terminology. Compliance Glossary documents the shared definitions those artifacts rely on.

Why DORA landed on the CFO personally

Under DORA, ICT risk is not a problem the CFO can delegate. Ocorian's management-accountability briefing:

"The responsibility for compliance with DORA lies with the management body of the in-scope regulated financial entity, which holds ultimate accountability for the entity's information and communication technology (ICT) risk management and operational resilience strategy."

In most EU financial entities the CFO sits on that management body. DORA has applied since 17 January 2025 across banks, insurers, investment firms, crypto-asset service providers, and payment institutions. Partisia's DORA analysis states the liability numbers plainly:

"Financial institutions face fines up to 10% of annual turnover or €10 million for serious breaches; individual senior managers up to €1 million."

Editorial note: firm-level caps vary across Member-State transpositions; DORA itself (Art. 50) delegates penalty amounts to national law.

Partisia's summary reflects the upper bound applied in some member states; DORA Article 50 leaves exact percentages to national transposition, and DLA Piper's divergence analysis shows material variation across member states. For critical ICT third-party service providers, the Lead Overseer regime adds a separate periodic penalty of up to 1% of average daily worldwide turnover, imposed daily for up to 6 months. The individual ceiling is what changes the audit-committee conversation.

The stakes, in CFO terms

In member states that have transposed the individual-penalty regime, the €1M ceiling is a direct hit to the person, not the legal entity. D&O cover typically responds to civil matters, but regulatory fines for wilful or grossly negligent breach are often excluded. The CFO's own balance sheet is exposed before the firm's is.

Career and reputation risk sit on top. A reasoned supervisory finding that the management body failed its oversight duty is a visible signal to boards, markets, and future employers. The question is not "did we have an ICT policy" but "can we produce the approved artifacts on demand, with version history and named approvers."

What supervisors ask to see

Across the RoI ITS (Commission Implementing Regulation (EU) 2024/2956), the ICT risk-management RTS (Commission Delegated Regulation (EU) 2024/1774), and early supervisory expectations, the artifacts that matter for management-body defence are a short list:

Each has to stand up as a governance artifact: author, reviewer, approver, timestamp, and framework version. "We had a policy" is not the same as "we can show a four-eyes approval with timestamps".

Where terminology control fits

Compliance Glossary does not build ICT risk capability, write your resilience strategy, or fill in the Register of Information. The problem we address is narrow: the terms inside these artifacts have to match.

When the ICT policy uses one definition of "major ICT-related incident", the incident response playbook uses a different threshold, and the RoI refers to "ICT third-party service providers" without the "critical" designation, you hand the supervisor an inconsistency. DORA treats those differences as meaningful legal categories. A controlled, versioned, four-eyes-approved glossary of the DORA vocabulary — "ICT third-party service provider", "critical function", "major ICT-related incident", "RTO", "RPO", "concentration risk", "Lead Overseer" — prevents the drift.

Register DailyMind as an ICT third-party service provider

DailyMind LTD must be registered. DailyMind LTD is a distinct ICT third-party service provider under DORA Art. 28(1). Financial-entity customers should add DailyMind to their Register of Information alongside Atlassian. Whether the arrangement qualifies as “critical” (Art. 31) depends on customer-specific assessment, but it must be REGISTERED. Required data fields are defined by the EBA RTS on register of information (Commission Delegated Regulation (EU) 2024/1773).

For current pricing, see the Atlassian Marketplace.

The procurement angle

DORA Article 28 due-diligence duties operate as a procurement filter inside EU financial services. Banks and insurers tightening their own RoI submissions prefer vendors whose governance posture is demonstrably clean. A Forge-native glossary reinforces the "DORA-ready" narrative.

Frequently asked questions

Who is personally liable under DORA?

DORA puts ultimate accountability on the management body of each in-scope financial entity. Under Member-State transpositions of DORA — e.g., Ireland’s S.I. No. 20 of 2025, under which the Central Bank of Ireland may impose DORA-specific sanctions alongside those available under Central Bank Act 1942 s. 33AQ (which caps natural-person monetary penalties at €1,000,000 via s. 33AQ(4)(b) and (6)(a)) — individual senior managers can face personal monetary penalties up to €1,000,000. DORA itself (Art. 50) requires Member States to set effective, proportionate and dissuasive penalties and leaves the maximum amounts to national transposition. Management-body members must demonstrate active, ongoing oversight of the ICT risk management framework.

What governance artifacts will DORA supervisors ask to see?

Competent authorities and, for critical third-party providers, the Lead Overseer, ask for the ICT risk management framework, the board-approved digital operational resilience strategy, the Register of Information on third-party arrangements, major incident reports, testing plans and results, and evidence that the management body reviewed and approved each. Artifacts need author, approver, timestamp, and version history.

Does a Confluence glossary replace DORA ICT risk management?

No. Compliance Glossary does not build ICT risk capability, run resilience tests, or produce a Register of Information on your behalf. It documents the shared definitions — "ICT third-party service provider", "critical function", "major ICT-related incident", "RTO", "RPO" — that these artifacts rely on, so your policies, RoI submission, and incident reports use the same language.

Does Compliance Glossary count as a new DORA Article 28 ICT third-party service provider?

Yes — the conservative position is to register DailyMind LTD. DailyMind is a distinct legal entity from Atlassian and is the publisher of the Compliance Glossary app, so it is a separate ICT third-party service provider under DORA Art. 28(1). Add DailyMind to your Register of Information alongside Atlassian using the data fields defined by the EBA RTS (Commission Delegated Regulation (EU) 2024/1773). Whether the arrangement qualifies as “critical” (Art. 31) depends on your own assessment, but the arrangement itself must be REGISTERED. Because Compliance Glossary runs on Atlassian Forge inside your existing Confluence Cloud contract, the entry is lighter than a standalone SaaS tool (no separate hosting stack to document), but it is still required.

Build the DORA paper trail, without adding a vendor

For current pricing, see the Atlassian Marketplace.

Evaluate in Confluence Read the Security Whitepaper

Related reading