On 20 August 2026 the Central Bank of Ireland wrote to payment and e-money firms on ICT governance, risk management and controls. The letter names six gaps found on inspection, ties each back to DORA, and expects evidence that fixes work. The read-across to CASPs is direct.

Finvisor Regulatory Briefing, September 2026. Board, CEO, Head of Compliance and CIO reading.
On 20 August 2026 the Central Bank of Ireland wrote to payment institutions and e-money institutions about ICT governance, risk management and controls. The letter reports the results of a thematic inspection of how firms manage ICT risk and their ICT providers. Operational and cyber resilience was already a 2026 supervisory priority; the Regulatory and Supervisory Outlook refers to it more than a hundred times.
The letter is direct about what fell short and what the Central Bank now expects. ICT risk belongs to the board and the executive, and outsourcing does not change that, group arrangements included. Our reading is simple: treat this as supervisory intent. The letter names the gaps, points each one back to a DORA article, and asks for evidence rather than assurances that the fixes have worked. The Central Bank is done watching. Do not wait for a call.
Control maturity has improved since the 2021 review. These are the weaknesses that remained, at varying materiality. Measure each against your own arrangements.
Every firm is told to review its governance and ICT risk management. Each area ties back to a specific DORA obligation.
Governance and risk management (DORA Article 5). Complete a full DORA gap analysis and fix the findings in priority order. The board and executive own ICT risk, and the second line has to challenge it locally rather than defer to the group. Report against a risk appetite the firm has actually set.
ICT continuity management (DORA Article 11). Get the BIA complete and reconciled to the asset inventory. Test resilience against cyber and other severe but plausible outages. Document the crisis communications plan, then test it.
ICT outsourcing and third-party risk (DORA Articles 28 to 30). Make contracts DORA-specific, group arrangements included. Hold a workable exit and transition plan for every critical provider. Assess subcontractors and track them along the whole chain.
CASPs authorised under MiCAR are financial entities under DORA (Article 2). The ICT, continuity and third-party duties apply to them too, and MiCAR Article 34 repeats them on governance, continuity and security. Read this letter as a preview of CASP supervision. DORA has applied since 17 January 2025; the letter expects gap analyses finished and remediation moving, not queued behind other work.
Reliance on a group or outsourced provider is not a defence. Outsourcing does not take the risk off your books, and using a group entity does not either. The Central Bank wants genuine local substance and a second line that can push back on the people running the service. Cyber and operational resilience stay on the 2026 agenda; boards are expected to act, and any gap a firm finds is expected to be closed quickly.
Board. Have we had a proper briefing on this letter and on our own ICT risk against it? Does our ICT reporting show where risk is going, or only where it has been? Does relying on the group leave us short of real substance as an Irish-regulated firm? Have we set an ICT risk appetite the board actually uses?
Executive management. Do we have a current DORA gap analysis with owners and dates against each fix? Have we tested continuity and recovery for real, not just on paper? Do we hold enough local ICT capability to direct and challenge our providers? Are our crisis communications and incident reporting written down and rehearsed?
Head of Compliance and Risk. Can the second line challenge ICT risk without leaning on the group that runs the service? Does our monitoring plan cover DORA and the points in this letter? Is ICT risk tracked against a set appetite, with real metrics and thresholds? Do our indicators warn us early, or do we only see problems after the event?
Head of Technology or CIO. Is the BIA complete, tied to the asset inventory, with consistent recovery time objectives? Do we have a workable exit and transition plan for every critical provider, cloud included? Do we assess and monitor subcontractors along the whole outsourcing chain? Are our contracts, group ones included, specific enough for DORA?
Finvisor works inside your team, not from a distance. We draft the documents, run the timeline, handle the regulator and give the board evidence it can stand over: a DORA gap analysis against the letter with findings ranked and costed; ICT governance and reporting reviewed, with a risk appetite set and forward-looking indicators; the BIA rebuilt and resilience tested against real outages; contracts brought up to DORA's standard with subcontractors assessed and exit plans that would actually work; crisis communications and major-incident reporting written and rehearsed; and an independent ICT and DORA audit that gives the board evidence the controls are there and working.
Finvisor is hosting an invitation-only breakfast workshop on the Dear CEO letter at The Stephen's Green Club, Dublin, on Tuesday 29 September 2026 (9.00 to 11.00am), with Niamh Vianney Muldoon, CISO and Board Member at BNY, and Michelle McGuire, Head of Consulting Operations at Finvisor. Register here. To benchmark your ICT framework against the letter, scope a DORA gap analysis or commission an independent ICT review, see how we support firms on DORA and operational resilience or email info@finvisor.global.
This briefing reflects Finvisor's reading of the Central Bank of Ireland's Dear CEO letter on ICT Governance, Risk Management and Controls (20 August 2026) and is not legal or regulatory advice. Firms should take advice on their own circumstances before acting on it.
We use strictly necessary cookies to run this site, and optional analytics cookies (Google Analytics) to understand how it is used. Analytics cookies are only set if you accept them. See our Cookie Policy and Privacy Policy.