DORA for Asset & Fund Managers (UCITS / AIFMD)
DORA for the firms that run Europe's funds: protecting NAV integrity, valuation and the delegation chain.
DORA for the firms that run Europe's funds: protecting NAV integrity, valuation and the delegation chain.
UCITS management companies and authorised AIFMs are explicitly named as financial entities under Article 2 of DORA, so the full digital operational resilience framework applies to the firms managing Europe's collective investment vehicles. For asset managers the regulation is less about retail-facing systems and more about the engines that price, trade and report on funds: portfolio and order management systems, fund accounting and NAV calculation, market-data feeds and the long chain of delegates and outsourcers that sit behind them.
DORA reframes ICT risk as a board-level resilience obligation rather than an IT housekeeping task. ManCos and AIFMs must build a documented ICT risk-management framework, classify and report major ICT-related incidents, test their digital resilience, and contractually govern every ICT third-party dependency. Because asset management runs on delegation, the hardest part for most firms is mapping and overseeing the providers who actually operate critical functions on their behalf.
DORA applies to authorised UCITS management companies and AIFMs as financial entities under Article 2(1). Sub-threshold AIFMs registered under Article 3(2) AIFMD are excluded by Article 2(3)(a) of DORA, but a manager that opts into full authorisation or breaches the AIFMD thresholds comes into scope, so the exact authorisation status must be confirmed and kept under review. The simplified framework of Article 16 is not available to management companies or AIFMs: Article 16(1) is a closed list (small and non-interconnected investment firms, exempted payment and e-money institutions, certain exempted credit institutions and small IORPs). In-scope managers therefore apply Articles 5 to 15 in full, calibrated through the proportionality principle of Article 4 and the specific reliefs DORA grants to microenterprises, and document that calibration.
DORA sits on top of the AIFMD and UCITS delegation and outsourcing regimes rather than replacing them: where those directives govern the conduct, substance and liability of delegation, DORA governs the operational resilience of the ICT that underpins delegated and outsourced functions. This matters acutely for dependencies on depositaries, fund administrators, transfer agents and valuation/NAV providers, whose outages translate directly into delayed or mispriced NAVs. Firms should align their AIFMD/UCITS outsourcing inventories with the DORA Register of Information so a single dependency is not governed by two inconsistent contractual standards.
NAV calculation and the valuation function are core ICT-dependent processes whose failure produces direct, quantifiable investor harm. DORA expects documented availability, integrity and continuity controls around the pricing and fund-accounting chain, plus tested fallbacks for when the primary engine or its inputs fail. A late or incorrect NAV is the asset-management equivalent of a critical service outage.
Most ManCos and AIFMs delegate fund accounting, NAV production and investor register/TA functions to third parties, making those providers critical ICT dependencies under DORA. Each must appear in the Register of Information with appropriate contractual rights to information, audit, business continuity and exit. Concentration on a small number of large administrators is itself a resilience risk the firm must assess and document.
OMS/PMS, EMS and connectivity to brokers, trading venues and custodians are ICT systems supporting critical or important functions. Their unavailability can prevent dealing, settlement and rebalancing within required windows, so DORA requires resilience, monitoring and recovery objectives (RTO/RPO) calibrated to trading and settlement cutoffs rather than generic IT targets.
Pricing depends on continuous, accurate market-data and reference-data feeds from index, pricing and benchmark providers. DORA treats these data dependencies as ICT third-party services that must be inventoried, monitored for integrity and continuity, and backed by alternative sources or stale-data procedures so a feed outage does not silently corrupt valuations.
Asset managers operate against hard deadlines: NAV strike and publication, dealing cutoffs, and regulatory/investor reporting. DORA's continuity and incident-handling expectations should be mapped to these time-critical windows, because a resilience event that merely delays processing can still breach fund documentation, prospectus commitments and supervisory reporting obligations.
Delegation under AIFMD/UCITS frequently runs several layers deep, and subcontracted ICT (cloud, hosting, sub-administrators) can sit far from the manager's direct line of sight. DORA requires the firm to look through these chains, identify the ICT third-party services supporting critical or important functions, and retain accountability even where operation is delegated.
Everything tailored to your sector, ready to use on day one.
Yes if you are an authorised UCITS management company or an authorised AIFM, as both are named financial entities in Article 2(1) of DORA. Sub-threshold AIFMs registered under Article 3(2) AIFMD are excluded by Article 2(3)(a), but opting into full authorisation or exceeding the AIFMD thresholds brings you in, so confirm your exact status. Self-managed funds and internally managed AIFs are treated as the relevant management entity for scoping.
No. Article 16 of DORA reserves the simplified framework to a closed list of entity types: small and non-interconnected investment firms, payment and e-money institutions benefiting from the PSD2 and EMD exemptions, certain exempted credit institutions and small IORPs. UCITS management companies and AIFMs are not on it, whatever their size. What a smaller manager can rely on is Article 4: the framework must be implemented in proportion to size, risk profile and the nature, scale and complexity of services, and several provisions expressly relieve microenterprises, for example on the independent internal-audit review of the framework. Document that calibration; do not claim a regime the Regulation does not offer.
DORA layers on top of, rather than replaces, the AIFMD and UCITS delegation and outsourcing requirements. Those regimes still govern substance, conduct and liability of delegation, while DORA governs the operational resilience of the ICT underpinning delegated and outsourced functions. In practice you should reconcile your existing outsourcing arrangements with the DORA Register of Information and contractual requirements so a single provider is governed consistently.
To the extent the administrator delivers ICT services supporting a critical or important function, such as NAV production, fund accounting or the investor register, the associated ICT services fall within DORA's third-party risk regime. You must include the arrangement in your Register of Information and ensure the contract contains DORA's mandatory provisions on access, audit, business continuity, sub-outsourcing and exit. Where the administrator subcontracts ICT, you also need visibility into that chain.
They can be. A NAV calculation error, valuation outage or dealing disruption is an ICT-related incident, and if it meets DORA's major-incident classification thresholds it must be reported to your competent authority within the prescribed timelines. The assessment turns on factors such as the number of clients/funds affected, duration, data loss and economic impact, so you should pre-define which fund operations would cross those thresholds.
DORA has applied since 17 January 2025, so the framework is already in force and supervisors expect demonstrable compliance now. Practical starting points are completing your Register of Information, mapping ICT dependencies behind NAV, dealing and reporting, remediating third-party contracts for the mandatory DORA clauses, and establishing incident classification and digital resilience testing. Prioritise the providers supporting critical or important fund functions.
Start free: check your DORA scope, run a gap analysis, or estimate implementation cost. Need the full risk view? See the Risk Assessment Toolkits or compare all kits. All prices exclude VAT; an EU VAT invoice is issued at checkout. Professional templates, not legal advice.
Workbooks, playbooks and certifications built for EU financial entities. Add several to your cart: volume discounts apply automatically.
Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.