DORA: Test Governance as a Duty – icoso consulting S.L.

Insights

DORA: Test Governance as a Duty

Insight · Daniel Osorio Fernandez, icoso consulting S.L.

With DORA, testing in the financial sector has finally moved from good practice to legal duty. The decisive question is no longer “are we testing enough?” but “can we prove it?”.

Context: The Digital Operational Resilience Act (DORA) has applied directly since 17 January 2025 to roughly 22,000 financial entities in the EU — from banks and insurers to investment firms. Core areas: ICT risk management, incident reporting, resilience testing, third-party management and information sharing.

What changes in testing, concretely

DORA demands programmatic testing of digital operational resilience: regular, risk-based, across all critical ICT systems — from vulnerability assessments to scenario-based testing. For certain institutions, threat-led penetration testing (TLPT) comes on top. This means test activities must be planned, prioritised, documented and demonstrable to the supervisor — ad-hoc testing before releases is no longer enough.

The gap in practice

Many institutions have capable test teams but no test governance: what's missing is a consolidated test register across all critical systems, uniform risk criteria, defined repetition cycles and evidence an examiner can read without translation. That bracket is exactly what DORA demands — and exactly what is most often missing.

A pragmatic start in three steps

  • Inventory: identify critical functions and systems and map them against existing test activities — where do you test regularly, where only on occasion?
  • Risk-based test programme: define test types, frequencies and responsibilities per criticality; bind third-party providers contractually.
  • Industrialise evidence: document results, findings and remediation so that reports to board and supervisor require no rework.

Bottom line

DORA does not punish too little test effort — it punishes lack of steerability. Organise testing as a governance discipline and you don't just satisfy the regulation, you win in daily operations: fewer production incidents, clearer priorities, reliable statements towards management.

Want to make your test governance DORA-proof? Our banking & insurance page shows how we support — or contact us directly.

Let's talk about your project.

Straightforward and personal — we'll get back to you quickly.

Get in touch

Or directly: +34 619 13 73 23 · info@icoso.es