DORA's impact on Rabobank and its customers

The Digital Operational Resilience Act, also known as DORA, is an EU regulation that focusses on strengthening the IT security of financial entities and making sure the financial sector in Europe is able to stay resilient in the event of a severe operational disruption, for example an outage of internet banking caused by a cyber-attack.

Strengthening the IT security

The DORA regulation brings harmonization of the rules relating to operational resilience for the financial sector. With the implementation of DORA, we can protect our customers even better against cyber threats and ensure a stable and secure financial system.

Impact on financial entities and ICT third-party service providers

1. Is there a deadline for complying to it?

DORA will apply as per 17th January 2025. By that date all parties governed by DORA, should be DORA compliant.

2. What does Rabobank do to be compliant with DORA?

DORA builds upon existing applicable regulations, so Rabobank, as a financial entity, already complies with a substantial part of this new DORA regulation. We have a program for the implementation of DORA governing the whole Rabo organization.

3. What will be the impact of DORA on customers and clients of Rabobank?

A such there will not be any direct impact on Rabobank customers or clients. Rabobank is dedicated to meeting the requirements outlined by DORA, ensuring we remain the resilient bank our customers can rely on.

4. What will be the impact of DORA on ICT third-party service providers?

DORA also applies to suppliers who provide ICT services to financial entities, as they are considered as an important part of the financial ecosystem. ‘ICT services’ cover a broad scope of services: from typical software services and cloud services to payment and data services. The technical standards that are enforced on the financial entities are also in force for these third parties.

DORA distincts 2 groups:

  1. The critical big tech suppliers (such as Microsoft) that will have to adhere to DORA directly and will fall under direct supervision of a regulator if they are appointed as critical service providers by the regulator, and;
  2. All other third-party suppliers that provide ICT services to financial entities who will be impacted indirectly.

The DORA regulation prescribes basically that financial entities may only do business with third-party suppliers with whom they have agreed additional DORA contractual clauses and implemented the required risk management controls.

5. What does Rabobank offer to do if the customer is a financial entity?

If you as a Rabobank customer, are also a financial entity yourself, is it possible that you are subjected to DORA as well. Rabobank delivers a variety of products and services, so if you assess that one of the Rabobank services or products qualifies as an ICT service and is in scope of your DORA compliance program, then of course Rabobank will help you to become DORA compliant.

More information

If you have any additional questions you can reach out to fm.nl.dora-financialinstitutions@rabobank.nl.