Financial institutions are expected to become more resilient to cyberattacks and ICT disruptions. The objective of the Digital Operational Resilience Act (DORA) is commendable, but for many companies it remains difficult to translate into practice. One aspect in particular is often neglected: audit-ready access management. Our DORA Access Readiness Check shows what DORA specifically requires and how organisations can obtain a robust assessment of their current access management maturity within four weeks.
DORA and the Neglected Issue of Access Rights
DORA has applied since January 2025. Banks, insurance companies, payment institutions and investment firms must no longer simply be generally prepared for cyberattacks and ICT disruptions. They must also be able to demonstrate that they effectively manage, document and regularly review key security processes.
Access management plays a central role in this context. With DORA, access rights management is evolving from an internal control issue into an audit-relevant component of digital resilience. Financial institutions must be able to demonstrate in a transparent and traceable manner who has access to which systems, how access rights are granted and reviewed, and whether privileged accounts are adequately controlled. Yet many organisations still lack the necessary overview.
Typical Weaknesses in Access Management
What companies often face is a complex and difficult-to-manage web of access rights. Permissions have grown over the years, and role models have been expanded without ever being consistently cleaned up. Technical and privileged accounts are sometimes insufficiently transparent. Orphaned access rights and unclear responsibilities increase the security risk.
In addition, recertifications are often carried out only irregularly, if at all. When they do take place, two gaps frequently emerge: On the one hand, the process is not documented in sufficient detail, leaving organisations without the necessary evidence. On the other hand, the approach is often not sufficiently risk-based, which in turn creates security risks.
Under DORA, it is no longer sufficient to manage access rights on an ad hoc basis. Institutions must be able to demonstrate that they manage them systematically, in line with risk, and in a transparent and traceable manner.
What Does DORA Specifically Require?
In short, DORA requires robust management of ICT access rights. Article 9(4) refers to policies, procedures and controls that restrict physical and logical access to information and ICT assets to what is required for legitimate and approved functions and activities. It also requires access rights to be controlled and properly managed.
Although not explicitly named as such, this indirectly addresses established practices in Access Management and Privileged Access Management. Access rights should be granted according to the principle of least privilege: as much as necessary, as little as possible. In addition to securely managing privileged accounts, DORA places emphasis on logging and traceability. Regular reviews and recertifications are also required in order to reassess risks.
Where Do We Stand?
As a first step, six questions can help companies assess their current maturity level:
- Are role models up to date and transparent?
- Is there an overview of privileged and technical accounts?
- Are orphaned access rights identified?
- Are recertifications documented?
- Does session monitoring work for privileged access?
- Can those responsible provide robust information to internal audit and supervisory authorities?
Anyone who cannot immediately answer these questions and frequently has to respond with “no” has an urgent need for action. Not only to meet DORA requirements, but above all to improve the security of access and, consequently, the data and information behind it.
DORA Access Readiness Check – The Path to an Action Plan
There is no need for despair, however. Building DORA-compliant access management does not necessarily require excessive time and resources. Ideally, companies proceed in four steps:
#1 Assessment of the Current State
The process should begin with a kick-off to define the scope of the assessment in more detail. Which systems need to be reviewed? Which tenants are relevant? Which organisational units need to be included? The project team should then closely examine and critically assess the existing documentation. What do the current Identity and Access Management and Privileged Access Management policies specify? Which access control concept is being followed? Which role models are in place? How are recertifications documented?
The objective is to establish a clear picture of the current state of access management. This makes it possible to identify existing challenges and address them on the path towards DORA-compliant access management.
#2 Data Collection
What the team has documented in theory should then be verified in practice. This can be done, for example, through structured interviews, usually conducted with IT and IAM experts and typically lasting between 60 and 90 minutes.
This helps create a comprehensive picture. IT teams provide insight into the technical implementation. IAM and IGA managers explain role models, recertification processes and access management procedures. Information security officers assess risks and control requirements.
This reveals whether documented requirements, technical implementation and actual day-to-day practices are genuinely aligned.
#3 Evaluation
Once the project team has gathered all relevant information, the next step is evaluation. A structured assessment framework can help here. It should not focus solely on DORA, but also incorporate the associated Regulatory Technical Standards as well as established requirements from the BAIT/VAIT tradition and ISO 27001.
The findings can then be mapped against this assessment framework. A five-level maturity model has proven effective for this purpose, supplemented by a risk rating for identified deviations.
The completed assessment framework ultimately provides a clear indication of where urgent action is required in order to meet regulatory requirements.
#4 Results
The final step is to develop an action plan. By taking an individual view of the organisation, its specific circumstances, the input from relevant stakeholders and the assessment results, concrete measures can be derived.
For implementation, prioritisation is recommended:
- Quick wins can generally be implemented within up to three months.
- Medium-term measures may require up to 12 months.
- Strategic initiatives should be considered over the longer term.
To ensure that all stakeholders have the same level of understanding, the process should conclude with a presentation of the results, outlining identified risks and highlighting and initiating the required measures.
You’ll Never Walk Alone
This approach is lean and leads to results quickly. Even so, it can still be highly challenging for organisations. Those looking for support can therefore involve access management experts.
Our USO team, for example, offers the “DORA Access Readiness Check” service. Together, we work through exactly the steps described above. Around four weeks after the initial kick-off meeting, organisations receive:
- the completed assessment framework, including maturity level and risk rating for each control area,
- a gap list describing all identified deviations in detail,
- a prioritised action plan including an indication of effort and implementation recommendations for each measure, and
- a management report and final presentation for the board or executive management.
This gives companies the necessary foundation to gain clarity about DORA requirements for access management and to implement the required measures quickly.
Milestone Achieved!
The mere mention of DORA often causes uncertainty. This is primarily because those responsible are not always entirely clear about what is required – let alone how these requirements can be implemented in practice.
In access management in particular, however, the obligations can be addressed effectively through a strategic four-stage approach. Organisations that take a close look at their current state, examine how processes are actually carried out in practice and compare these practices against the target state required by DORA can derive meaningful measures. This not only supports DORA compliance, but also strengthens access security overall.
