DORA and Resilience

Insights from the
front line

The gaps Finvisor is identifying most consistently across client portfolios: incomplete or inaccurate Registers of Information, ICT incident classification procedures that do not meet the regulatory threshold, and third-party concentration risk that has not been analysed at board level. The analysis below covers DORA as it is being supervised in practice — not as it was intended at the time of publication.

Payments Digital Assets AML/CTF DORA Governance M&A
AllRegulatory briefingsAML / CTFdigital assetsdora & ResiliencePaymentsgovernance
No items found.
—
Dora and Resilience
—
Regulatory Briefing

CBI Dear CEO letter on ICT risk: the six gaps and what payment, e-money and crypto firms must do now

On 20 August 2026 the Central Bank of Ireland wrote to payment and e-money firms on ICT governance, risk management and controls. The letter names six gaps found on inspection, ties each back to DORA, and expects evidence that fixes work. The read-across to CASPs is direct.

Sep 2026

Get Insights Delivered

By subscribing you agree to receive Finvisor regulatory updates by email. We use your address only for this purpose and you can unsubscribe at any time. See our Privacy Policy.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Free Downloads

CBI RSO 2026: CASP Briefing
Apr 6
•
5
Pages
•
PDF
Request a Copy
CBI RSO 2026: EMI & PI Briefing
Apr 6
•
5
Pages
•
PDF
Request a Copy

Maturity Assessments

ICT Maturity AssessmentAML/CTF Maturity Assessment

Got a regulatory question?

Our team is available for confidential discussions on any regulatory matter.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Talk to the Team