Home · Glossary · DORA (Digital Operational Resilience Act)
Enterprise AI glossary · Compliance & Regulation

DORA (Digital Operational Resilience Act)

The EU regulation on digital operational resilience for financial entities — extends to ICT third-party risk management, which catches LLM and AI vendor concentration risk.

Definition

What DORA (Digital Operational Resilience Act) means in practice

The Digital Operational Resilience Act is the EU regulation on digital operational resilience for financial entities — banks, insurers, investment firms, payment service providers. The provisions matter for AI in two ways. First, ICT third-party risk management explicitly catches AI and LLM vendor relationships: financial entities must assess vendor concentration risk, contractual undertakings, and recovery posture. Second, the operational-resilience testing regime includes scenario testing against major vendor failures — a category that includes cloud LLM provider disruption. DORA is one of the regulatory drivers behind the CRO framing shift toward vendor concentration risk and the operational requirement to maintain a multi-model architecture with at least one self-hosted open-weights model as the recovery path.

Go deeper
EU AI Act compliance architecture →

All 62 terms, in plain language

Sovereign AI, RAG, agentic AI, IDP, MLOps and the regulations that shape enterprise AI.

Browse the glossary →Talk to an engineer →