The ICT Risk Professional’s Role
DORA turns ICT risk management from an IT housekeeping task into a regulated, board-level discipline — and the ICT risk professional is the person who makes it work day to day.
Why this role exists
Pillar 1 of DORA — ICT Risk Management, Art. 5–16 — requires every financial entity to build, operate and continuously improve an ICT risk management framework. That framework does not run itself. It needs a professional who can translate a 64-article Regulation and 13 technical standards into controls, evidence and reporting that survive a supervisory inspection.
Before DORA, ICT risk in EU finance was governed by a patchwork — EBA guidelines for banks, EIOPA guidelines for insurers, national practices. DORA replaces that patchwork with a single, directly-applicable standard. The ICT risk professional is the role created, in effect, by that shift: a second-line specialist who owns the framework as a living system.
The three dimensions of the job
Design
Build the framework, the policies, the ICT risk taxonomy and the asset model the entity will be measured against.
Operate
Run the risk lifecycle — identify, protect, detect, respond, recover, learn — and keep it evidenced.
Assure
Test, challenge, report and remediate so the framework holds up to internal audit and the supervisor.
Where the role sits
The ICT risk professional belongs to the second line of defence — the independent ICT risk management function. The first line operates the technology; the second line monitors and challenges it; the third line (internal audit) assures the whole framework. Independence between these lines is not a nicety — it is a DORA requirement that supervisors test against the organisation chart, not just the policy wording.
That was your free preview
Enrol to unlock all 23 lessons, every knowledge check, the dedicated certification exam, the downloadable toolkit and your verifiable certificate — lifetime access.
Secure payment via Stripe · 30-day money-back guarantee.