DORA registry
ICT Risk
DORA statutory definition of ICT risk for financial entities.
Canonical Definition
Any reasonably identifiable circumstance in relation to the use of network and information systems which, if materialised, may compromise the security of those systems, of any technology dependent tool or process, of operations and processes, or of the provision of services, by producing adverse effects in the digital or physical environment (Regulation (EU) 2022/2554, Article 3).
Business Impact
What happens when different meanings of ICT Risk are used in parallel.
Compliance Risk
ICT risk register, DORA reporting, operational resilience programmes, third-party ICT due diligence.
Governance Metadata
This definition is governed. Not merely documented.
- Owner
- Head of Operational Resilience
- Status
- aligned
- Version
- v1
- Effective Date
- 2026-01-17
- Source
- Regulation (EU) 2022/2554 (DORA) Article 3; ICT Risk Management Framework v3
- Domain
- DORA